Computing power service access method and system and node information uploading method of computing power service

By working together with cloud servers, computing power gateways, and data center gateways, address translation rules and IP security encryption tunnels are used to solve the problem of being unable to access computing power resources without fixed IP addresses, enabling reliable access and secure transmission of these resources and improving resource utilization.

CN119484386BActive Publication Date: 2025-11-11PURPLE MOUNTAIN LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411943234.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-11-11
Estimated Expiration
2044-12-26

AI Technical Summary

Technical Problem

The inability to directly access computing resources without a fixed IP address leads to a waste of computing resources.

Method used

By working together with cloud hosts, computing power gateways, data center gateways, and server room gateways, access to computing power services without fixed IP addresses is achieved through address translation rules and IP security encryption tunnels. This includes address and port replacement and forwarding, and an IPSEC encrypted logical tunnel is built to ensure security.

Benefits of technology

It enables reliable access and secure transmission of computing resources without fixed IP addresses, thereby improving the utilization rate of computing resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119484386B_ABST
    Figure CN119484386B_ABST
Patent Text Reader

Abstract

This invention discloses a method, system, and node information uploading method for accessing computing power services. The method, applied to a cloud host, includes: receiving an access request from the cloud host; based on the target computing power service mapping relationship configured on the cloud host, determining the private network address and private network port corresponding to the target computing power service according to the private network address and private network port corresponding to the cloud host in the access request, replacing the message information, and obtaining the target access request; forwarding the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without a fixed IP address. This invention solves the technical problem of wasted computing power resources caused by the inability to directly access computing power services in computing power resources without fixed IP addresses.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computing power network technology, and more specifically, to a method, system, and method for uploading node information of computing power services. Background Technology

[0002] Currently, there are various types of computing power service resources with different performance levels. Integrating them can enable effective collaborative work. Through computing power networks, different computing resources can work together to achieve higher computing efficiency and performance. However, because there are multiple computing power service resources, accessing these services presents certain difficulties. Some services cannot be accessed directly, leading to a waste of computing power resources.

[0003] There is currently no effective solution to the above problems. Summary of the Invention

[0004] This invention provides a method, system, and node information uploading method for accessing computing power services, in order to at least solve the technical problem of wasted computing power resources caused by the inability to directly access computing power services in computing power resources without fixed IP addresses.

[0005] According to one aspect of the present invention, a method for accessing computing power services is provided, applied to a cloud host, comprising: receiving a cloud host access request, wherein the cloud host access request is determined by a data center gateway based on a pre-configured cloud host address translation rule, and the data center access request is obtained by the computing power gateway converting an initial access request received from a user terminal based on a preset address translation rule for computing power services without fixed IP addresses; determining the private network address and private port corresponding to the target computing power service based on the target computing power service mapping relationship configured on the cloud host, according to the private network address and private network port corresponding to the cloud host in the cloud host access request, replacing the message information, and obtaining a target access request; forwarding the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without fixed IP addresses.

[0006] Optionally, forwarding the target access request to the data center gateway corresponding to the target computing power service includes: determining a first IP secure encrypted tunnel based on the private network address and private network port corresponding to the target computing power service in the target access request; and forwarding the target access request to the data center gateway corresponding to the target computing power service through the first IP secure encrypted tunnel, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service.

[0007] Optionally, the target access request is forwarded to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service. This includes: adding an IPsec header to the target access request to obtain a modified target access request and forwarding the modified target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway removes the IPsec header from the modified target access request to obtain the target access request and forwards it to the service instance corresponding to the target computing power service.

[0008] Optionally, the above method further includes: receiving a response message sent by the service instance corresponding to the target computing power service; determining the private network address and private network port of the cloud host based on the configured source address translation rules and the source address and source port in the response message, and obtaining a first response message; forwarding the first response message to the data center gateway, so that the data center gateway converts the first response message into a second response message and forwards the second response message to the computing power gateway, so that the computing power gateway converts the second response message into a target response message based on the address translation rules for computing power services without fixed IP addresses and sends the target response message to the user terminal.

[0009] According to one aspect of the present invention, a method for accessing computing power services is provided, applied to a computing power gateway, comprising: receiving an initial access request from a user terminal; determining the public IP address and public port of a corresponding cloud host based on a preset address translation rule for computing power services without fixed IP addresses, according to the destination address and destination port in the initial access request, and replacing the message information to obtain a data center access request; forwarding the data center access request to the data center gateway, so that the data center gateway converts the data center access request into a cloud host access request based on a pre-configured cloud host address translation rule and forwards it to the cloud host, so that the cloud host converts the cloud host access request into a target access request based on a configured target computing power service mapping relationship and forwards the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without fixed IP addresses.

[0010] Optionally, based on a preset address translation rule for computing power services without fixed IP addresses, the destination address and destination port in the initial access request are used to determine the public IP address and public port of the corresponding cloud host, and the message information is replaced to obtain a data center access request. This includes: determining the service identifier corresponding to the target computing power service based on the initial access request; determining the target service instance identifier based on the service identifier corresponding to the target computing power service according to the address translation rule without fixed IP addresses; and replacing the message information based on the public IP address and public port of the cloud host corresponding to the target service instance identifier to obtain the data center access request.

[0011] Optionally, the above method further includes: receiving a second response message forwarded by a data center gateway, wherein the second response message is obtained by the data center gateway based on a first response message, and the first response message is obtained by the cloud host based on a response message sent by the service instance corresponding to the target computing power service according to the configured source address translation rules; determining a service identifier based on the public IP address and public port of the cloud host in the second response message according to the address translation rules for computing power services without fixed IP addresses; replacing the public IP address and public port of the cloud host based on the service identifier to generate a target response message; and sending the target response message to the user terminal.

[0012] According to one aspect of the present invention, a computing power service access method is provided for application in a data center gateway, comprising: receiving a data center access request sent by a computing power gateway, wherein the data center access request is obtained by the computing power gateway converting an initial access request sent by a user terminal based on a preset address conversion rule for computing power services without fixed IP addresses; determining the private address and private port corresponding to the cloud host based on the public IP address and public port of the cloud host in the data center access request according to a pre-configured cloud host address conversion rule, and replacing the message information to obtain a cloud host access request; forwarding the cloud host access request to the cloud host, so that the cloud host converts the cloud host access request into a target access request based on a configured target computing power service mapping relationship and forwards it to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without fixed IP addresses.

[0013] Optionally, the above method further includes: receiving a first response message forwarded by a cloud host, wherein the first response message is obtained by the cloud host converting a response message sent by the service instance corresponding to the target computing power service based on the configured source address translation rules; converting the private network address and private network port of the cloud host in the first response message into the public network address and public network port of the cloud host to obtain a second response message; and forwarding the second response message to the computing power gateway, so that the computing power gateway converts the second response message into a target response message based on the address translation rules for computing power services without fixed IP addresses and sends the target response message to the user terminal.

[0014] According to another aspect of the present invention, a method for uploading node information of a computing power service is provided, applied to a data center gateway. This method is applied to any of the aforementioned computing power service access methods and includes: uploading and storing node information corresponding to the computing power service to a computing power network management platform, so that the computing power network management platform determines a non-fixed IP computing power service address conversion rule based on the node information corresponding to the computing power service and sends it to the computing power gateway. The node information corresponding to the computing power service includes a corresponding service identifier and a service instance identifier. The service instance corresponding to the computing power service is a non-fixed IP computing power service instance. The service identifier represents the destination address and destination port of the unified access corresponding to the target computing power service, and the service instance identifier represents the public IP address and public port of the cloud host corresponding to the non-fixed IP computing power service instance.

[0015] Optionally, the node information corresponding to the computing power service in the data center gateway is uploaded to the computing power network management platform, including: uploading the node information corresponding to the computing power service to the computing power network management platform based on the second IP secure encrypted tunnel.

[0016] According to another aspect of the present invention, a computing power service access system is also provided, which uses any of the above-described computing power service access methods to access computing power services, including: a computing power gateway, a data center, and a cloud host. The computing power gateway is used to receive an initial access request from a user terminal, and based on a preset address translation rule for computing power services without a fixed IP address, determines the public IP address and public IP port of the corresponding cloud host according to the destination address and destination port in the initial access request, and obtains a data center access request after replacing the message information. The data center gateway, located in the data center, is used to, based on the cloud host address translation rule configured on the data center gateway, determine the public IP address and public IP port of the corresponding cloud host according to the destination address and destination port in the data center access request. The system uses the public IP address and public port of the cloud host to determine the private IP address and private port of the cloud host. After replacing the message information, it obtains the cloud host access request. The cloud host is used to determine the private IP address and private port of the target computing power service based on the target computing power service mapping relationship configured in the cloud host. After replacing the message information, it obtains the target access request and forwards the target access request to the data center gateway corresponding to the target computing power service through the first IP security encrypted tunnel. This allows the data center gateway to forward the target access request to the service instance corresponding to the target computing power service, where the target computing power service is a computing power service without a fixed IP address.

[0017] Optionally, the above system also includes a computing power network management platform, which is used to receive node information corresponding to computing power services uploaded by the data center gateway, determine the address conversion rules for computing power services without fixed IP addresses based on the node information corresponding to the computing power services, and send the address conversion rules for computing power services without fixed IP addresses to the computing power gateway. The node information corresponding to the computing power services includes the corresponding service identifier and service instance identifier. The service identifier represents the destination address and destination port of the unified access corresponding to the target computing power service, and the service instance identifier represents the public network address and public network port of the cloud host corresponding to the computing power service instance without fixed IP addresses.

[0018] Optionally, the cloud server is located in a data center.

[0019] According to another aspect of the present invention, a non-volatile storage medium is also provided, the non-volatile storage medium including a stored program, wherein, when the program is running, it controls the device where the non-volatile storage medium is located to execute any of the above-described computing service access methods.

[0020] According to another aspect of the present invention, a computer device is also provided, the computer device including a processor, the processor being configured to run a program, wherein the program executes any of the above-described computing power service access methods during runtime.

[0021] According to another aspect of the present invention, a computer program product is also provided, including a computer program that, when executed by a processor, implements any of the above-described computing power service access methods.

[0022] In this embodiment of the invention, a computing power service access method is applied to cloud hosts. It receives cloud host access requests, where the cloud host access request is determined by the data center gateway based on pre-configured cloud host address translation rules. The data center access request is obtained by the computing power gateway converting the initial access request received from the user terminal based on a preset address translation rule for computing power services without fixed IP addresses. Based on the target computing power service mapping relationship configured on the cloud host, the private network address and private network port corresponding to the target computing power service are determined according to the private network address and private network port corresponding to the cloud host in the cloud host access request. After replacing the message information, the target access request is obtained. The target access request is forwarded to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service. The service instance corresponding to the target computing power service is a computing power service instance without fixed IP addresses, achieving the goal of allowing users to access computing power resources without fixed IP addresses. This improves the utilization rate of computing power resources and solves the technical problem of wasted computing power resources caused by the inability to directly access computing power services in computing power resources without fixed IP addresses. Attached Figure Description

[0023] The accompanying drawings, which are included to provide a further understanding of the invention and form part of this application, illustrate exemplary embodiments of the invention and, together with their description, serve to explain the invention and do not constitute an undue limitation thereof. In the drawings:

[0024] Figure 1 This is a flowchart illustrating a method for accessing computing power services applied to a cloud host, according to an embodiment of the present invention.

[0025] Figure 2 This is a flowchart illustrating a method for accessing computing services applied to a computing power gateway, according to an embodiment of the present invention.

[0026] Figure 3 This is a flowchart illustrating a method for accessing computing services applied to a data center gateway, according to an embodiment of the present invention.

[0027] Figure 4 This is an architecture diagram of a computing power service access system provided according to an embodiment of the present invention;

[0028] Figure 5 This is an architecture diagram of a computing power service access system provided according to an optional embodiment of the present invention. Detailed Implementation

[0029] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0030] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0031] Currently, a large number of fragmented, small-scale computing resources are scattered in data centers with poor network environments. The host or server resources in these data centers were originally designed for local users to access the external network or to push local monitoring and data collection information to external servers. Therefore, these data centers were not initially designed with fixed IP addresses. This means that while these computing resources have the ability to access the external network, they cannot be accessed by external users, resulting in wasted computing resources. To solve this technical problem, this invention proposes a method for accessing computing services. Figure 1 This is a flowchart illustrating a method for accessing computing power services applied to cloud hosts according to an embodiment of the present invention, as shown below. Figure 1 As shown, this method is applied to cloud servers and includes the following steps:

[0032] Step S102: Receive cloud host access request. The cloud host access request is determined by the data center gateway based on the pre-configured cloud host address translation rules and the data center access request is obtained by the computing power gateway converting the initial access request sent by the user terminal based on the preset no-fixed-IP computing power service address translation rules.

[0033] In this step, a cloud host access request is received. This request includes the private network address and port of the cloud host. When a user wants to access the computing power service, it sends an initial access request to the computing power service access system. This initial request is then processed by the computing power gateway and the data center gateway to form a cloud host access request. The initial access request uses the service identifier and service port of the computing power service the user wants to access as the destination address and destination port of the message.

[0034] Users can initiate access requests to computing power services by entering the destination address and destination port, i.e., the service identifier, in their browser. For example, entering 5.5.5.5:80 in the browser will initiate a request to access computing power services. Users can set the computing power gateway in the computing power service access system as the default gateway for traffic, so that the computing power gateway in the computing power service access system will receive the access requests sent by users.

[0035] After the computing power gateway receives the initial access request, it will modify the destination address and destination port in the initial access request to the public address and access port of the cloud host based on the no fixed computing power service address translation rule, that is, the correspondence between the service identifier of the computing power service and the public network address and access port of the corresponding cloud host, and obtain the data center access request. The no fixed computing power service address translation rule can be obtained from the computing power network management platform.

[0036] Data center access requests are sent to the data center gateway, a device located at the edge of the data center network responsible for connecting the internal and external networks. At the data center gateway, the public IP address and port number of the cloud host are mapped to its private IP address and port number. Upon receiving the cloud host access request, the gateway then forwards it to the cloud host. For example, after the data center access request reaches the data center, the data center egress gateway automatically modifies the cloud host's public IP address (47.xxx.xxx.186) to its private IP address (172.27.21.76), thus receiving the access request.

[0037] Step S104: Based on the target computing power service mapping relationship configured on the cloud host, determine the private network address and private network port corresponding to the target computing power service according to the private network address and private network port corresponding to the cloud host in the cloud host access request, replace the message information, and obtain the target access request.

[0038] After receiving an access request from the data center gateway, the cloud server performs address translation based on the private network address and port of the cloud server stored in the request. The cloud server can, according to its own DNAT (Destination Network Address Translation) configuration (i.e., the target computing service mapping relationship configured in the cloud server), translate the private network address and port of the cloud server into the private network IP_C+PORT_C of the computing service without a fixed IP address before forwarding. Upon receiving the access request, the cloud server, based on the Destination Network Address Translation (DNAT) rules, maps the private network address and port of the cloud server in the access request to the real private network IP and port number of the service deployment. Destination Network Address Translation (DNAT) is a network address translation technology that can change the destination IP address and port information in the packet header. DNAT rules can be standard destination NAT rules used in common application scenarios. These rules can be used directly without customization, or customized according to specific business needs or security policies. These rules can include specific source IP addresses, destination IP addresses, port numbers, or protocol types.

[0039] On the cloud server, based on the transport type TYPE_A for accessing the computing power service without a fixed IP address, an idle port number PORT_B is selected as the mapping port for accessing the computing power service without a fixed IP address.

[0040] NAT mapping rules can be configured on the cloud server in advance: For traffic from users accessing the no-fixed-IP computing power service, set DNAT translation rules: Perform DNAT translation on packets whose destination address, transport type, and destination port match the cloud server's private IP_B+TYPE_A+port_B (the port mapped by the no-fixed-IP computing power service), and translate the destination address and destination port of the packet into the no-fixed-IP computing power service's private IP_C+PORT_C before forwarding. For traffic from the no-fixed-IP computing power service back to the user, set SNAT translation: The cloud server will perform SNAT translation on packets whose source address and transport type match the no-fixed-IP computing power service's private IP_C+TYPE_A, and translate the source address into the cloud server's private IP_B before forwarding. The cloud server can, based on its own DNAT configuration, translate the destination address and destination port of the packet (i.e., the private IP address and corresponding port number in the cloud server's access request) into the no-fixed-IP computing power service's private IP_C+PORT_C to obtain the target access request.

[0041] Cloud servers act as access proxies for computing resources without fixed IP addresses, serving as a bridge for users to access such resources. Cloud servers can be located in data centers, specifically geographically. Within a single data center in a region, one or more cloud servers with fixed public IP addresses can be activated, allowing external access by users. The cloud server acts as an access proxy for computing resources without fixed IP addresses within that region. A cloud server can have two addresses: a public IP address (north-southbound) for external access and a private IP address within the data center for use on the internal east-west network. When users access a cloud server externally, they use the public IP address and port; when other hosts within the data center need to access the cloud server, they use the private IP address and port.

[0042] For example, a cloud server with a fixed public IP address can be set up within a data center to act as an access proxy for computing resources without a fixed IP address. The cloud server's east-west private IP address is 172.27.21.76, and its bound public IP address is 47.xxx.xxx.186.

[0043] Step S106: Forward the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without a fixed IP address.

[0044] Based on the private network address corresponding to the target computing power service, the cloud host can forward cloud host access requests to the data center gateway corresponding to the target computing power service. For example, the cloud host can forward cloud host access requests through the first IP secure encrypted tunnel (IPSEC tunnel). That is, according to the flow of interest configuration, the traffic (cloud host access request) enters the IPsec tunnel and is sent to the egress router of the data center without a fixed IP address. After de-encapsulation, it continues to be forwarded to the computing power service instance through the data center gateway according to the real private network IP address C+PORT C.

[0045] The cloud server can install an IPsec client, enabling it to establish an IPsec encrypted tunnel with computing resources that do not have fixed IP addresses. Similarly, the IPsec client can be enabled on the existing network egress router or optical modem in the data center where the computing resources without fixed IP addresses reside. Then, internal network addresses are assigned to each computing resource in the data center to connect to the egress router or optical modem. After both the cloud server and the computing resources have completed IPsec client configuration, the IPsec client in the data center where the computing resources without fixed IP addresses reside initiates a connection request, establishing an IPsec encrypted logical tunnel to the public IP address bound to the cloud server. Changes in the IP address of the computing resources without fixed IP addresses will not affect the use of the upper-layer IPsec encrypted tunnel.

[0046] As an optional embodiment, forwarding the target access request to the data center gateway corresponding to the target computing power service includes: determining a first IP security encryption tunnel based on the private network address and private network port corresponding to the target computing power service in the target access request; and forwarding the target access request to the data center gateway corresponding to the target computing power service through the first IP security encryption tunnel, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service.

[0047] Optionally, based on the IPsec tunnel's configuration of packets of interest, access requests to the deployed service will be forwarded through the IPsec secure encrypted tunnel. Upon reaching the IPsec exit of the data center corresponding to the computing power resource without a fixed IP address, the data center gateway can locate the corresponding host's port number based on the private network address and port of the target computing power service. The access request then reaches the service instance corresponding to the target computing power service. The IPsec tunnel's configuration of packets of interest typically refers to network traffic that triggers the establishment of the IPsec tunnel and applies encryption and integrity protection. Matching rules for packets of interest can be configured to identify and filter out packets of interest. Specifically, these rules can be based on IP address, port number, protocol type, etc. The use of IPsec secure encrypted tunnels achieves the goal of accessing computing power resources without fixed IP addresses, effectively preventing attackers from obtaining computing power information and ensuring the security of packet transmission between computing power resources and user terminals.

[0048] By employing cloud servers as access proxies and utilizing bidirectional NAT, the problem of direct access to computing resources without fixed IP addresses was resolved. Furthermore, by constructing an IPsec encrypted logical tunnel, reliable access to computing resources without fixed IP addresses and secure transmission of computing services were achieved.

[0049] As an optional embodiment, forwarding the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, includes: adding an IPsec header to the target access request to obtain a modified target access request and forwarding the modified target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway removes the IPsec header from the modified target access request to obtain the target access request and forwards it to the service instance corresponding to the target computing power service.

[0050] IPsec (Internet Protocol Security) is a network layer security protocol that provides confidentiality, integrity, and authentication for data transmission at the IP layer. IPsec can operate in two modes: Transport Mode and Tunnel Mode. Transport Mode is primarily used to protect communication between two hosts, while Tunnel Mode can be used to protect communication across the entire network. The IPsec header is a crucial component of the IPsec protocol, containing essential information for encrypting and authenticating data packets. There are two types of IPsec headers: the ESP (Encapsulating Security Payload) header and the AH (Authentication Header) header. When a cloud host forwards a target access request to the data center gateway, an IPsec header can be added to the target access request before forwarding it. This ensures the security of data transmission between the cloud host and the data center gateway. IPsec supports two-way authentication, ensuring the identities of both communicating parties. This helps prevent man-in-the-middle attacks and increases the security of the communication link. Removing the IPsec header at the data center gateway facilitates further processing of the access request.

[0051] As an optional embodiment, a response message is received from the service instance corresponding to the target computing power service; based on the configured source address translation rules, the private network address and private network port of the cloud host are determined according to the source address and source port in the response message, and a first response message is obtained; the first response message is forwarded to the data center gateway, so that the data center gateway converts the first response message into a second response message and forwards the second response message to the computing power gateway, so that the computing power gateway converts the second response message into a target response message based on the address translation rules for computing power services without fixed IP addresses and sends the target response message to the user terminal.

[0052] Optionally, after the computing resources process the user's access request, a response message will be generated for the user. This response message can be forwarded to the cloud host, for example, through an IP secure encrypted tunnel. The cloud host can use Source Network Address Translation (SNAT) rules to translate the real private IP address and port of the computing resources (which lack a fixed IP address) in the response message into the private IP address and port of the cloud host. The cloud host then forwards the access request, which passes through the data center gateway and the computing power gateway. Finally, the private IP address and port of the cloud host are converted into a service identifier, resulting in the target response message. This target response message is then forwarded to the user through the computing power gateway.

[0053] For example, after processing a user request, the computing power service returns a response message. This message enters the IPsec tunnel and is sent to the cloud host. After SNAT translation, the cloud host replaces the source address from 192.168.1.3 with 172.27.21.76, which is the cloud host's private network address, and sends it to the data center gateway. The data center gateway translates the source address from 172.27.21.76 to 47.xxx.xxx.186, which is the cloud host's public network address, and sends it to the computing power gateway. The computing power gateway then translates the source address and source port information back to 5.5.5.5:80, which is the service identifier, and finally sends the target response message to the user.

[0054] In summary, the forwarding process of the response message sent to the user after the computing power service processes the user's traffic request is the reverse of the access request forwarding process. It first goes through the IPSEC tunnel to reach the cloud host, and then passes through the data center gateway and computing power gateway in sequence to reach the user end.

[0055] Figure 2 This is a flowchart illustrating a method for accessing computing services applied to a computing power gateway, according to an embodiment of the present invention. Figure 2 As shown, this method is applied to a computing power gateway and includes the following steps:

[0056] Step S202: Receive the initial access request sent by the user terminal.

[0057] Step S204: Based on the preset address conversion rules for computing power services without fixed IP addresses, determine the public IP address and public port of the corresponding cloud host according to the destination address and destination port in the initial access request, and replace the message information to obtain the data center access request.

[0058] Step S206: The data center access request is forwarded to the data center gateway, so that the data center gateway converts the data center access request into a cloud host access request based on the pre-configured cloud host address translation rules and forwards it to the cloud host. The cloud host converts the cloud host access request into a target access request based on the configured target computing power service mapping relationship and forwards the target access request to the data center gateway corresponding to the target computing power service. The data center gateway then forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without a fixed IP address.

[0059] Users can initiate an access request, i.e., an initial access request, by entering the destination address and destination port (i.e., the service identifier) ​​in their browser. For example, entering 5.5.5.5:80 in the browser will initiate an access request for the computing power service. Users can set the computing power gateway in the computing power service access system as the default gateway for traffic, so that the computing power gateway in the computing power service access system will receive the initial access request sent by the user.

[0060] After receiving the initial access request, the computing power gateway can modify the destination address and destination port in the initial access request to the public address and access port of the cloud host based on the fixed computing power service address conversion rules issued by the computing power network management platform, that is, the correspondence between the service identifier of the computing power service and the public network address and access port of the corresponding cloud host, and thus obtain the data center access request.

[0061] As an optional implementation, based on a preset fixed-IP-free computing power service address translation rule, the destination address and destination port in the initial access request are used to determine the corresponding public IP address and public IP port of the cloud host, and the message information is replaced to obtain a data center access request. This includes: determining the service identifier corresponding to the target computing power service based on the initial access request; determining the target service instance identifier based on the service identifier corresponding to the target computing power service according to the fixed-IP-free computing power service address translation rule; and replacing the message information based on the public IP address and public IP port of the cloud host corresponding to the target service instance identifier to obtain the data center access request.

[0062] Optionally, after receiving the initial access request from the user, the computing power gateway identifies the destination address and destination port, i.e., the service identifier, in the initial access request. For example, the service identifier could be 5.5.5.5:80, where 5.5.5.5 is the destination address and 80 is the destination port. Based on the destination address and destination port SID_A:PORT_D in the initial access request, the computing power gateway can find the service instance access address corresponding to this service identifier as IP_A:PORT_B, modify the destination address and destination port of the packet to the public network address and access port of the cloud host, and then forward it. The mapping between the service identifier and the service instance identifier can be pre-stored in the computing power network management platform, from which the computing power gateway can directly read.

[0063] For example, if the service identifier is 5.5.5.5:80, the computing power gateway queries the corresponding computing power routing information in the computing power routing table based on the service identifier, and then modifies the destination address and destination port of the packet to the public IP address and port number of the cloud host, 47.xxx.xxx.186:50000, to obtain the data center access request.

[0064] As an optional embodiment, a second response message forwarded by the data center gateway is received. The second response message is obtained by the data center gateway based on the first response message, which is obtained by the cloud host based on the response message sent by the service instance corresponding to the target computing power service according to the configured source address translation rules. Based on the address translation rules for computing power services without fixed IP addresses, the service identifier is determined according to the public IP address and public port of the cloud host in the second response message. Based on the service identifier, the public IP address and public port of the cloud host are replaced to generate a target response message. The target response message is then sent to the user terminal.

[0065] Optionally, the computing power gateway receives the second response message forwarded by the data center gateway. Since there is no fixed IP computing power service address translation rule, it determines the service identifier based on the public IP address and public port of the cloud host in the second response message. Then, based on the service identifier, it determines the target response message and sends it to the user terminal.

[0066] Figure 3 This is a flowchart illustrating a method for accessing computing services applied to a data center gateway according to an embodiment of the present invention, as shown below. Figure 3 As shown, this method is applied to a data center gateway and includes the following steps:

[0067] Step S302: Receive a data center access request from the computing power gateway. The data center access request is obtained by the computing power gateway converting the initial access request received from the user terminal based on a preset non-fixed IP computing power service address conversion rule.

[0068] Step S304: Based on the pre-configured cloud host address translation rules, determine the private network address and private network port corresponding to the cloud host according to the public network address and public network port of the cloud host in the data center access request, and replace the message information to obtain the cloud host access request.

[0069] Step S306: Forward the cloud host access request to the cloud host so that the cloud host can convert the cloud host access request into a target access request based on the configured target computing power service mapping relationship and forward it to the data center gateway corresponding to the target computing power service. The data center gateway will then forward the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without a fixed IP address.

[0070] A data center gateway is a device located at the edge of a data center network, responsible for connecting the internal and external networks. It configures the mapping between the public IP address and public port of a cloud host and its private IP address and private port. Data center access requests are sent to the data center gateway, which maps the public IP address and port number of the cloud host to its private IP address and port number, receives the cloud host access request, and then forwards the request to the cloud host.

[0071] Specifically, after a data center access request arrives at the data center, the data center egress gateway will automatically change the public IP address of the cloud host (47.xxx.xxx.186) to the private IP address of the cloud host (172.27.21.76) to receive the cloud host access request.

[0072] As an optional embodiment, a first response message forwarded by a cloud host is received, wherein the first response message is obtained by the cloud host converting the response message sent by the service instance corresponding to the target computing power service based on the configured source address translation rules; the private network address and private network port of the cloud host in the first response message are converted into the public network address and public network port of the cloud host to obtain a second response message; the second response message is forwarded to the computing power gateway, so that the computing power gateway converts the second response message into a target response message based on the address translation rules for computing power services without fixed IP addresses and sends the target response message to the user terminal.

[0073] Optionally, the data center gateway receives the first response message forwarded by the cloud host, and converts the private network address and private port in the first response message into the public network address and public network port of the cloud host according to the mapping relationship between the public network address and public network port and the private network address and private network port configured by itself, to obtain the second response message, and sends the second response message to the computing power gateway. The computing power gateway determines the target response message according to the second response message and forwards the target response message to the user terminal.

[0074] Through the above steps, the goal of enabling users to access computing resources without fixed IP addresses is achieved, thereby improving the utilization rate of computing resources and solving the technical problem of wasted computing resources caused by the inability to directly access computing services in computing resources without fixed IP addresses.

[0075] This invention also proposes a method for uploading node information for computing power services, which can be applied to any of the above-mentioned computing power service access methods, including:

[0076] The node information corresponding to the computing power service is uploaded and stored in the computing power network management platform. This enables the computing power network management platform to determine the address translation rules for computing power services without fixed IP addresses based on the node information and send them to the computing power gateway. The node information corresponding to the computing power service includes the corresponding service identifier and service instance identifier. The service instance corresponding to the computing power service is a computing power service instance without fixed IP addresses. The service identifier represents the destination address and destination port of the unified access corresponding to the target computing power service, and the service instance identifier represents the public IP address and public port of the cloud host corresponding to the computing power service instance without fixed IP addresses.

[0077] Optionally, the node information corresponding to the computing power service in the data center gateway can be stored in the computing power network platform management. This node information may include the service identifier and service instance identifier corresponding to the computing power service. The data center gateway can report this node information to the computing power network management platform. The computing power gateway can query the public IP address and public port number of the cloud host corresponding to the service identifier from the fixed computing power service address translation rule information integrated and issued by the computing power network management platform. That is, the user will initiate an access request based on the service identifier. At the computing power gateway, based on the service identifier and service port, the corresponding cloud host's public IP address and port number will be queried from the information issued to the computing power gateway by the computing power network management platform. This allows the computing power gateway to convert the initial access request into a data center access request based on the cloud host's public IP address and public port number, and forward it to the data center gateway. The data center gateway will determine the cloud host's private IP address and port number, and then forward the access request to the cloud host, which will finally forward it to the computing power resource department.

[0078] As an optional embodiment, uploading the node information corresponding to the computing power service in the data center gateway to the computing power network management platform includes: uploading the node information corresponding to the computing power service to the computing power network management platform based on the second IP security encrypted tunnel.

[0079] Computing resources can also upload node information to the computing network management platform via an IP-secure encrypted tunnel (IPSEC encrypted tunnel). A computing service client can be installed at the data center gateway. Upon startup, this client can proactively initiate an IPSEC encrypted tunnel connection request to the computing network management platform based on the pre-configured address. Once the IPSEC encrypted tunnel is established between the computing service client and the computing network management platform, computing resources without fixed IP addresses in the data center gateway can upload node information to the computing network management platform via this IPSEC encrypted tunnel.

[0080] The data center gateway includes multiple computing resources without fixed IP addresses. These resources can report their deployed node information (i.e., computing service information) to the computing network management platform via an IPsec encrypted tunnel. The reported computing service information includes: service identifier information SID_A:PORT_D and service instance access information. The service instance access information is the private network address (IP_C:PORT_C) assigned by the data center where the service was deployed. The computing network management platform then obtains this service information, integrates the computing node information, updates the service instance access information to the data center cloud host's public IP address and service mapping port (IP_A:PORT_B), and notifies the computing gateway device of the updated information. The computing gateway device can then perform address translation based on this information.

[0081] Specifically, the computing power network management platform can be deployed on the public IP address 47.xx111, and an IPsec client is installed on the platform. The computing power service collection module on the host within the data center without a fixed IP address reports the computing power service node information to the computing power network management platform via IPsec. The reported information may include service identifier, service port, protocol type, service instance access address, service instance access port, service private network VRF information, number of CPU cores of the service cloud host, CPU utilization of the service cloud host, memory of the service cloud host, remaining available memory of the service cloud host, disk storage space of the service cloud host, and remaining available disk storage space of the service cloud host. Among these, the service identifier is 5.5.5.5, the port is 80, the protocol type is TCP, and the service instance access address is 192.168.1.3:50000 (the actual deployment address, but this is a private network address and cannot be directly accessed by external users). The computing power network management platform updates the computing power information. Based on the deployment of the cloud host network, the above computing power service information is updated to: service identifier 5.5.5.5, port service 80, protocol type TCP, and service instance access address 47.xxx.xxx.186:50000; this is integrated and updated into new computing power service information. The updated computing power service information from the computing power network management platform continues to be distributed to the computing power gateway. The computing power gateway receives and stores it in the computing power routing table, forming a computing power route, corresponding to service identifier 5.5.5.5, port service 80, protocol type TCP, and service instance access address 47.xxx.xxx.186:50000.

[0082] Here is a specific example:

[0083] S1. System Construction: A cloud server with a fixed public IP address is set up in a data center within the region. The private IP address of this cloud server is 172.27.21.76, and its bound public IP address is 47.xxx.xxx.186. On the network egress router or optical modem of the data center where the computing resources without fixed IP addresses are located, the IPsec client function is installed and enabled. For the host within the data center that is planned to provide services, a private IP address of 192.168.1.3 is configured, and the service is deployed on the host's TCP port 50000. The host is connected to the same network segment interface of the data center's egress router or optical modem; this interface serves as the private network gateway for the computing service host. Complete the IPSEC client configuration for the cloud server and the data center where the computing power resources without a fixed IP address are located. The IPSEC client in the data center where the computing power resources without a fixed IP address are located uses IKE aggressive mode as the connection initiator to establish a two-way IPSEC encrypted logical tunnel, forming a two-way IPSEC encrypted tunnel between the data center exit without a fixed IP address and the public IP address of the cloud server 47.xxx.xxx.186.

[0084] S2. Cloud Server Configuration: Configure DNAT translation on the cloud server to forward traffic accessing the cloud server to the specific service deployed on the computing power resource without a fixed IP address. Configure DNAT rules: Map traffic accessing 172.27.21.76:50000 (50000 is the cloud server's idle TCP interface; other port numbers can also be selected) to the service's deployment address: 192.168.1.3:50000. Configure SNAT translation to modify the source address and source port information for traffic returned to users by the computing power service without a fixed IP address and forward it to the user. Configure SNAT rules: Map traffic with the computing power server address 192.168.1.3 as its source address to the cloud server's private network address: 172.27.21.76.

[0085] S3. Computing Resource Management: Deploy the computing network management platform on public IP address 47.xx111. Install the IPSEC client on the computing network management platform and complete the initial configuration. Continue using the IPSEC client installed and enabled on the network egress router or optical modem in the data center where the computing resources without fixed IP addresses are located, and complete the initial configuration. Complete the configuration of the IPSEC function client on the cloud host and the data center where the computing resources without fixed IP addresses are located. The IPSEC function client in the data center where the computing resources without fixed IP addresses are located uses IKE aggressive mode as the connection initiator to establish a bidirectional IPSEC encrypted logical tunnel, forming a bidirectional IPSEC encrypted tunnel between the egress of the data center without fixed IP addresses and the public IP address 47.xx111 of the computing network management platform. Install the computing service client on the computing resource host without a fixed IP address and actively initiate access requests to the computing network management platform, reporting the node information of the computing service to the computing network management platform through the IPSEC encrypted tunnel. The reported information may include the following: service identifier and the public IP address and port number of the cloud host corresponding to the service identifier. For example, the service identifier is 5.5.5.5, the port is 80, the protocol type is TCP, the public IP address of the cloud host is 47.xxx.xxx.186, the service instance access port number is 50000, and the service private network VRF information is 0.

[0086] S4. User Access: The user initiates a computing power service access request based on the service identifier. They enter 5.5.5.5:80 in their browser to access the service. The user sets the computing power gateway as the default gateway for their traffic, so the traffic reaches the computing power gateway. The computing power gateway looks up the corresponding computing power routing information in its computing power routing table based on the service identifier 5.5.5.5:80. It then modifies the destination address and destination port in the packet to the service instance access address 47.xxx.xxx.186:50000, using this as the destination address for further forwarding. After traffic arrives at the data center, the data center's egress gateway automatically modifies the destination address of the packet (47.xxx.xxx.186) to the private address of the cloud host corresponding to that public address (172.27.21.76). Once the packet reaches the cloud host according to the modified destination address, the DNAT configuration on the cloud host maps the TCP traffic accessing 172.27.21.76:50000 to the actual service deployment address: 192.168.1.3:50000. Based on the IPSEC tunnel's packet of interest configuration, packets destined for 192.168.1.3 will enter the IPSEC tunnel for forwarding, reaching the IPSEC egress of the data center without a fixed IP address. Then, based on the internal network address, the packets are further forwarded to port 50000 of the 192.168.1.3 host, ultimately reaching the computing service deployed on the host within the data center without a fixed IP address.

[0087] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that the present invention is not limited to the described order of actions, because according to the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0088] Through the above description of the embodiments, those skilled in the art can clearly understand that the computing power service access method according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of the present invention.

[0089] According to embodiments of the present invention, a computing power service access system for implementing the above-described computing power service access method is also provided. Figure 4 This is an architecture diagram of a computing power service access system provided according to an embodiment of the present invention, such as... Figure 4 As shown, the computing power service access system includes: a computing power gateway, a data center, and cloud hosts. The computing power gateway receives initial access requests from user clients and, based on preset address translation rules for computing power services without fixed IP addresses, determines the public IP address and public port of the corresponding cloud host according to the destination address and destination port in the initial access request. After replacing the message information, it obtains the data center access request. The data center gateway, located in the data center, determines the private IP address of the cloud host based on the cloud host address translation rules configured on the data center gateway, according to the public IP address and public port of the cloud host in the data center access request. After replacing the message information with the address and private network port, a cloud host access request is obtained. The cloud host is used to determine the private network address and private network port corresponding to the target computing power service based on the target computing power service mapping relationship configured in the cloud host access request. After replacing the message information, a target access request is obtained. The target access request is then forwarded to the data center gateway corresponding to the target computing power service through the first IP security encrypted tunnel, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service. The target computing power service is a computing power service without a fixed IP.

[0090] Figure 5This is an architecture diagram of a computing power service access system provided according to an optional embodiment of the present invention, such as... Figure 5 As shown, the above system also includes a computing power network management platform. The computing power network management platform is used to receive the node information corresponding to the computing power service uploaded by the data center gateway, determine the address conversion rules for computing power services without fixed IP based on the node information corresponding to the computing power service, and send the address conversion rules for computing power services without fixed IP to the computing power gateway. The node information corresponding to the computing power service includes the corresponding service identifier and service instance identifier. The service identifier represents the destination address and destination port of the unified access corresponding to the target computing power service, and the service instance identifier represents the public network address and public network port of the cloud host corresponding to the computing power service instance without fixed IP.

[0091] Data interaction between the computing power network management platform and the data center gateway and computing power gateway can all be conducted through the IPsec tunnel. Specifically, on the cloud host and the IPsec client in the data center without a fixed IP address, IPsec configuration information and dual-end interest flow settings are completed (the dual-end interest flow settings are configured based on the cloud host's private network information and the computing power service information without a fixed IP address, allowing traffic accessing the computing power service without a fixed IP address to enter the IPsec tunnel on the cloud host side, and allowing traffic originating from the computing power service without a fixed IP address to enter the IPsec tunnel on the data center's egress router side). The IPsec client in the data center without a fixed IP address is configured as the connection initiator, initiating a connection establishment to the public IP address bound to the cloud host via IKE aggressive mode, thus establishing the dual-end IPsec encrypted logical tunnel. The IPsec client is installed on the host hosting the computing power network management platform, and the IPsec-related configurations and interest flow configurations for both the IPsec client on the host hosting the computing power network management platform and the IPsec client in the data center without a fixed IP address are completed. Configure the IPsec client (for data centers without fixed IP addresses) as the connection initiator, and initiate a connection establishment process via IKE aggressive mode to the public IP address bound to the cloud host, thus establishing a two-way IPsec encrypted logical tunnel. This allows the computing power network management platform to transmit information with data centers without fixed IP addresses through the IPsec tunnel.

[0092] In this process, the access request from the user first reaches the computing power gateway. Based on the service identifier in the access request, the computing power gateway retrieves the public IP address and port number of the cloud host corresponding to the service identifier from the computing power network management platform, and updates the destination address in the access request to the public IP address and port number of the cloud host. Further, the access request is forwarded to the data center gateway, where the public IP address of the cloud host is mapped to its private IP address, and the access request is then forwarded to the cloud host. The cloud host can use DNAT translation to convert its private IP address and port number to the private IP address and port number of the host corresponding to the computing power resource without a fixed IP address. Then, based on the IPsec encrypted tunnel, the access request is forwarded to the IPsec-enabled client in the data center where the computing power resource without a fixed IP address is located, and then forwarded to the corresponding computing power resource based on the private IP address and port number.

[0093] During the return trip, the cloud host is also used to receive the response message sent by the computing power service based on the first IP secure encrypted tunnel. Based on the source network address translation rules configured on the cloud host, it determines the private network address and private network port of the cloud host according to the source address and source port in the response message and obtains the first response message. The data center gateway is also used to translate the private network address and private network port of the cloud host in the first response message into the public network address and public network port of the cloud host and obtain the second response message. The computing power gateway is also used to determine the service identification information based on the message source address and source port information in the second response message according to the address translation rules for computing power services without fixed IP addresses integrated and issued by the computing power network management platform. Based on the service identification information, it replaces the message source address and source port in the second response message, generates the first target response message, and sends the target response message to the user terminal.

[0094] The computing power network management platform enables the perception and management of computing power services without fixed IP addresses, thereby improving the utilization rate and management efficiency of computing power resources.

[0095] As an optional implementation, the cloud server is located in a data center.

[0096] Optionally, cloud servers can be located in data centers, specifically divided by region. Within a single data center in a region, one or more cloud servers with fixed public IP addresses can be enabled. These cloud servers can be accessed externally by users. The cloud servers act as access proxies for computing resources without fixed IP addresses within that region.

[0097] Embodiments of the present invention may provide a computer device. Optionally, in this embodiment, the computer device may be located in at least one of a plurality of network devices in a computer network. The computer device includes a memory and a processor.

[0098] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the computing power service access method and system in this embodiment of the invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby realizing the aforementioned computing power service access method. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to a computer terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0099] The processor at the cloud host can access information and applications stored in the memory through the transmission device to perform the following steps: receiving a cloud host access request, wherein the cloud host access request is determined by the data center gateway based on the pre-configured cloud host address translation rules, and the data center access request is obtained by the computing power gateway converting the initial access request received from the user terminal based on the preset address translation rules for computing power services without fixed IP addresses; based on the target computing power service mapping relationship configured on the cloud host, determining the private network address and private port corresponding to the target computing power service according to the private network address and private network port corresponding to the cloud host in the cloud host access request, replacing the message information, and obtaining the target access request; forwarding the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without fixed IP addresses.

[0100] Optionally, the processor may also execute program code that performs the following steps: forwarding the target access request to the data center gateway corresponding to the target computing power service, including: determining the first IP security encryption tunnel based on the private network address and private network port corresponding to the target computing power service in the target access request; and forwarding the target access request to the data center gateway corresponding to the target computing power service through the first IP security encryption tunnel, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service.

[0101] Optionally, the processor may also execute program code that performs the following steps: forwarding the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, including: adding an IPsec header to the target access request to obtain a modified target access request and forwarding the modified target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway removes the IPsec header from the modified target access request to obtain the target access request and forwards it to the service instance corresponding to the target computing power service.

[0102] Optionally, the processor may also execute program code that performs the following steps: receiving a response message from the service instance corresponding to the target computing power service; determining the private network address and private network port of the cloud host based on the configured source address translation rules and the source address and source port in the response message, and obtaining a first response message; forwarding the first response message to the data center gateway, so that the data center gateway converts the first response message into a second response message and forwards the second response message to the computing power gateway, so that the computing power gateway converts the second response message into a target response message based on the address translation rules for computing power services without fixed IP addresses and sends the target response message to the user terminal.

[0103] The processor at the computing power gateway can access information and applications stored in the memory via the transmission device to perform the following steps: receiving an initial access request from the user; based on the preset address translation rules for computing power services without fixed IP addresses, determining the public IP address and public port of the corresponding cloud host according to the destination address and destination port in the initial access request, and replacing the message information to obtain a data center access request; forwarding the data center access request to the data center gateway, so that the data center gateway can convert the data center access request into a cloud host access request based on the pre-configured cloud host address translation rules and forward it to the cloud host, so that the cloud host can convert the cloud host access request into a target access request based on the configured target computing power service mapping relationship and forward the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway can forward the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without fixed IP addresses.

[0104] Optionally, the processor may also execute program code with the following steps: based on a preset fixed-IP computing power service address translation rule, determine the public IP address and public port of the corresponding cloud host from the destination address and destination port in the initial access request, and replace the message information to obtain a data center access request, including: determining the service identifier corresponding to the target computing power service according to the initial access request; determining the target service instance identifier according to the service identifier corresponding to the target computing power service based on the fixed-IP computing power service address translation rule; and replacing the message information according to the public IP address and public port of the cloud host corresponding to the target service instance identifier to obtain a data center access request.

[0105] Optionally, the processor may also execute program code for the following steps: receiving a second response message forwarded by the data center gateway, wherein the second response message is obtained by the data center gateway based on the first response message, and the first response message is obtained by the cloud host based on the response message sent by the service instance corresponding to the target computing power service according to the configured source address translation rules; determining the service identifier based on the public IP address and public port of the cloud host in the second response message according to the address translation rules for computing power services without fixed IP addresses; replacing the public IP address and public port of the cloud host based on the service identifier to generate a target response message; and sending the target response message to the user terminal.

[0106] The processor at the data center gateway can access information and applications stored in the memory through the transmission device to perform the following steps: receiving a data center access request from the computing power gateway, wherein the data center access request is obtained by the computing power gateway converting the initial access request received from the user terminal based on a preset address translation rule for computing power services without fixed IP addresses; based on the pre-configured cloud host address translation rule, determining the private address and private port corresponding to the cloud host according to the public IP address and public port of the cloud host in the data center access request and replacing the message information to obtain the cloud host access request; forwarding the cloud host access request to the cloud host, so that the cloud host converts the cloud host access request into a target access request based on the configured target computing power service mapping relationship and forwards it to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without fixed IP addresses.

[0107] Optionally, the processor may also execute program code for the following steps: receiving a first response message forwarded by the cloud host, wherein the first response message is obtained by the cloud host converting the response message sent by the service instance corresponding to the target computing power service based on the configured source address translation rules; converting the private network address and private network port of the cloud host in the first response message into the public network address and public network port of the cloud host to obtain a second response message; and forwarding the second response message to the computing power gateway, so that the computing power gateway converts the second response message into a target response message based on the address translation rules for computing power services without fixed IP addresses and sends the target response message to the user terminal.

[0108] This invention provides a method for accessing computing power services, applied to cloud hosts. The method involves receiving a cloud host access request, where the cloud host access request is determined by a data center gateway based on pre-configured cloud host address translation rules. The data center access request is obtained by the computing power gateway converting an initial access request received from a user terminal based on a preset address translation rule for computing power services without fixed IP addresses. Based on the target computing power service mapping relationship configured on the cloud host, the private network address and private network port corresponding to the target computing power service are determined according to the private network address and private network port corresponding to the cloud host in the cloud host access request. After replacing the message information, a target access request is obtained. The target access request is forwarded to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service. The service instance corresponding to the target computing power service is a computing power service instance without fixed IP addresses, achieving the goal of allowing users to access computing power resources without fixed IP addresses. This improves the utilization rate of computing power resources and solves the technical problem of wasted computing power resources due to the inability to directly access computing power services in computing power resources without fixed IP addresses. The inability to directly access computing services in computing resources without fixed IP addresses leads to a waste of computing resources.

[0109] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a non-volatile storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc.

[0110] Embodiments of the present invention also provide a non-volatile storage medium. Optionally, in this embodiment, the aforementioned non-volatile storage medium can be used to store the program code executed by the computing power service access method provided in the above embodiments.

[0111] Optionally, in this embodiment, the aforementioned non-volatile storage medium may be located in any computer terminal in the computer terminal group in the computer network corresponding to the cloud host, or in any mobile terminal in the mobile terminal group.

[0112] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: receiving a cloud host access request, wherein the cloud host access request is determined by the data center gateway based on a pre-configured cloud host address translation rule, and the data center access request is obtained by the computing power gateway converting the initial access request received from the user terminal based on a preset address translation rule for computing power services without fixed IP addresses; based on the target computing power service mapping relationship configured for the cloud host, determining the private network address and private port corresponding to the target computing power service according to the private network address and private network port corresponding to the cloud host in the cloud host access request, replacing the message information, and obtaining the target access request; forwarding the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without fixed IP addresses.

[0113] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: forwarding the target access request to the data center gateway corresponding to the target computing power service, including: determining a first IP security encryption tunnel based on the private network address and private network port corresponding to the target computing power service in the target access request; forwarding the target access request to the data center gateway corresponding to the target computing power service through the first IP security encryption tunnel, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service.

[0114] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: forwarding the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, including: adding an IPsec header to the target access request to obtain a modified target access request and forwarding the modified target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway removes the IPsec header from the modified target access request to obtain the target access request and forwards it to the service instance corresponding to the target computing power service.

[0115] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: receiving a response message from a service instance corresponding to the target computing power service; determining the private network address and private network port of the cloud host based on the configured source address translation rules and the source address and source port in the response message, and obtaining a first response message; forwarding the first response message to the data center gateway, so that the data center gateway converts the first response message into a second response message and forwards the second response message to the computing power gateway, so that the computing power gateway converts the second response message into a target response message based on the address translation rules for computing power services without fixed IP addresses and sends the target response message to the user terminal.

[0116] Optionally, in this embodiment, the aforementioned non-volatile storage medium may be located in any computer terminal in the computer terminal group in the computer network corresponding to the computing power gateway, or in any mobile terminal in the mobile terminal group.

[0117] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: receiving an initial access request from a user; based on a preset address translation rule for computing power services without fixed IP addresses, determining the public IP address and public port of the corresponding cloud host according to the destination address and destination port in the initial access request, and replacing the message information to obtain a data center access request; forwarding the data center access request to the data center gateway, so that the data center gateway converts the data center access request into a cloud host access request based on the pre-configured cloud host address translation rule and forwards it to the cloud host, so that the cloud host converts the cloud host access request into a target access request based on the configured target computing power service mapping relationship and forwards the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without fixed IP addresses.

[0118] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: based on a preset fixed-IP computing power service address translation rule, determining the public IP address and public port of the corresponding cloud host from the destination address and destination port in the initial access request, and replacing the message information to obtain a data center access request, including: determining the service identifier corresponding to the target computing power service according to the initial access request; determining the target service instance identifier according to the service identifier corresponding to the target computing power service based on the fixed-IP computing power service address translation rule; and replacing the message information according to the public IP address and public port of the cloud host corresponding to the target service instance identifier to obtain a data center access request.

[0119] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: receiving a second response message forwarded by the data center gateway, wherein the second response message is obtained by the data center gateway based on the first response message, and the first response message is obtained by the cloud host based on the response message sent by the service instance corresponding to the target computing power service according to the configured source address translation rules; determining the service identifier based on the public IP address and public port of the cloud host in the second response message according to the address translation rules for computing power services without fixed IP addresses; replacing the public IP address and public port of the cloud host based on the service identifier to generate a target response message; and sending the target response message to the user terminal.

[0120] Optionally, in this embodiment, the non-volatile storage medium may be located in any computer terminal in the group of computer terminals in the computer network corresponding to the data center gateway, or in any mobile terminal in the group of mobile terminals.

[0121] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: receiving a data center access request from a computing power gateway, wherein the data center access request is obtained by the computing power gateway converting an initial access request received from a user terminal based on a preset address conversion rule for computing power services without fixed IP addresses; based on a pre-configured cloud host address conversion rule, determining the private address and private port corresponding to the cloud host according to the public IP address and public port of the cloud host in the data center access request and replacing the message information to obtain a cloud host access request; forwarding the cloud host access request to the cloud host, so that the cloud host converts the cloud host access request into a target access request based on the configured target computing power service mapping relationship and forwards it to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without fixed IP addresses.

[0122] Optionally, in this embodiment, the non-volatile storage medium is configured to store program code for performing the following steps: receiving a first response message forwarded by a cloud host, wherein the first response message is obtained by the cloud host converting a response message sent by a service instance corresponding to the target computing power service based on the configured source address translation rules; converting the private network address and private network port of the cloud host in the first response message into the public network address and public network port of the cloud host to obtain a second response message; forwarding the second response message to the computing power gateway, so that the computing power gateway converts the second response message into a target response message based on the address translation rules for computing power services without fixed IP addresses and sends the target response message to the user terminal.

[0123] Embodiments of the present invention also provide a computer program product, including a computer program. Optionally, in this embodiment, when the computer program is executed by a processor, it can implement any of the above-described computing power service access methods.

[0124] The sequence numbers of the above embodiments of the present invention are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0125] In the above embodiments of the present invention, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0126] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0127] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0128] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0129] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a non-volatile storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0130] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A method for accessing computing power services, characterized in that, Applied to cloud servers, including: The system receives a cloud host access request, wherein the cloud host access request is determined by the data center gateway based on a pre-configured cloud host address translation rule according to the data center access request. The data center access request is obtained by the computing power gateway converting the initial access request sent by the received user terminal based on a preset no-fixed-IP computing power service address translation rule. The preset no-fixed-IP computing power service address translation rule determines the public IP address and public IP port of the corresponding cloud host based on the destination address and destination port in the initial access request. The cloud host address translation rule maps the public IP address and public IP port of the cloud host to the private IP address and private IP port of the cloud host. Based on the target computing power service mapping relationship configured on the cloud host, the private network address and private network port corresponding to the target computing power service are determined according to the private network address and private network port corresponding to the cloud host in the cloud host access request. After replacing the message information, the target access request is obtained. The target access request is forwarded to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without a fixed IP address.

2. The method according to claim 1, characterized in that, Forwarding the target access request to the data center gateway corresponding to the target computing power service includes: Based on the private network address and private network port corresponding to the target computing power service in the target access request, determine the first IP security encryption tunnel; The target access request is forwarded to the data center gateway corresponding to the target computing power service through the first IP secure encrypted tunnel, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service.

3. The method according to claim 1, characterized in that, The step of forwarding the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, includes: An IPsec header is added to the target access request to obtain a modified target access request. The modified target access request is then forwarded to the data center gateway corresponding to the target computing power service. This allows the data center gateway to remove the IPsec header from the modified target access request to obtain the target access request and forward it to the service instance corresponding to the target computing power service.

4. The method according to claim 1, characterized in that, Also includes: Receive the response message sent by the service instance corresponding to the target computing power service; Based on the configured source address translation rules, the private network address and private network port of the cloud host are determined according to the source address and source port in the response message, and the first response message is obtained. The first response message is forwarded to the data center gateway, so that the data center gateway converts the first response message into a second response message and forwards the second response message to the computing power gateway, so that the computing power gateway converts the second response message into a target response message based on the no-fixed-IP computing power service address translation rule and sends the target response message to the user terminal.

5. A method for accessing computing power services, characterized in that, Applications in computing power gateways include: Receive the initial access request sent by the user client; Based on the preset address conversion rules for computing power services without fixed IP addresses, the public IP address and public port of the corresponding cloud host are determined according to the destination address and destination port in the initial access request, and the message information is replaced to obtain the data center access request. The data center access request is forwarded to the data center gateway, so that the data center gateway, based on a pre-configured cloud host address translation rule, converts the data center access request into a cloud host access request and forwards it to the cloud host. The cloud host, based on a configured target computing power service mapping relationship, converts the cloud host access request into a target access request and forwards the target access request to the data center gateway corresponding to the target computing power service. The data center gateway then forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without a fixed IP address. The cloud host address translation rule maps the public IP address and public port of the cloud host to the private IP address and private port of the cloud host.

6. The method according to claim 5, characterized in that, The method, based on a preset address translation rule for computing power services without fixed IP addresses, determines the public IP address and public port of the corresponding cloud host from the destination address and destination port in the initial access request, and replaces the packet information to obtain the data center access request, including: Based on the initial access request, determine the service identifier corresponding to the target computing power service; Based on the address conversion rules for computing power services without fixed IP addresses, the target service instance identifier is determined according to the service identifier corresponding to the target computing power service. Based on the public IP address and public port of the cloud host corresponding to the target service instance identifier, the data center access request is obtained after replacing the message information.

7. The method according to claim 5, characterized in that, Also includes: The system receives a second response message forwarded by the data center gateway, wherein the second response message is obtained by the data center gateway based on the first response message, and the first response message is obtained by the cloud host based on the configured source address translation rules and the response message sent by the service instance corresponding to the target computing power service. Based on the address translation rules for computing power services without fixed IP addresses, the service identifier is determined according to the public IP address and public port of the cloud host in the second response message; Based on the service identifier, replace the public IP address and public port of the cloud host to generate the target response message; The target response message is sent to the user terminal.

8. A method for accessing computing power services, characterized in that, Applications in data center gateways, including: The system receives a data center access request from a computing power gateway. The data center access request is obtained by the computing power gateway converting the initial access request received from the user terminal based on a preset fixed IP computing power service address conversion rule. The preset fixed IP computing power service address conversion rule determines the public IP address and public IP port of the corresponding cloud host based on the destination address and destination port in the initial access request. Based on the pre-configured cloud host address translation rules, according to the public network address and public network port of the cloud host in the data center access request, the private network address and private network port corresponding to the cloud host are determined and the message information is replaced to obtain the cloud host access request. The cloud host access request is forwarded to the cloud host, so that the cloud host converts the cloud host access request into a target access request based on the configured target computing power service mapping relationship and forwards it to the data center gateway corresponding to the target computing power service. The data center gateway then forwards the target access request to the service instance corresponding to the target computing power service, wherein the service instance corresponding to the target computing power service is a computing power service instance without a fixed IP address.

9. The method according to claim 8, characterized in that, Also includes: The cloud host receives a first response message forwarded by the cloud host, wherein the first response message is obtained by the cloud host converting the response message sent by the service instance corresponding to the target computing power service based on the configured source address translation rules; The private network address and private network port of the cloud host in the first response message are converted into the public network address and public network port of the cloud host to obtain the second response message; The second response message is forwarded to the computing power gateway, so that the computing power gateway converts the second response message into a target response message based on the fixed IP computing power service address translation rule and sends the target response message to the user terminal.

10. A method for uploading node information for a computing power service, characterized in that, Applied to a data center gateway, wherein the method is applied in any one of the computing power service access methods of claims 1 to 9 above, including: The node information corresponding to the computing power service is uploaded and stored to the computing power network management platform, so that the computing power network management platform can determine the address translation rules for computing power services without fixed IP addresses based on the node information corresponding to the computing power service and send them to the computing power gateway. The node information corresponding to the computing power service includes the corresponding service identifier and service instance identifier. The service instance corresponding to the computing power service is a computing power service instance without fixed IP addresses. The service identifier represents the destination address and destination port of the unified access corresponding to the target computing power service. The service instance identifier represents the public network address and public network port of the cloud host corresponding to the computing power service instance without fixed IP addresses.

11. The method according to claim 10, characterized in that, Uploading the node information corresponding to the computing power service in the data center gateway to the computing power network management platform includes: The node information corresponding to the computing power service is uploaded to the computing power network management platform based on the second IP secure encrypted tunnel.

12. A computing power service access system, characterized in that, Accessing computing power services using any one of claims 1 to 9, comprising: a computing power gateway, a data center, and a cloud host, wherein, The computing power gateway is used to receive the initial access request sent by the user terminal, and based on the preset fixed IP computing power service address conversion rule, determine the public network address and public network port of the corresponding cloud host according to the destination address and destination port in the initial access request, and obtain the data center access request after replacing the message information. The preset fixed IP computing power service address conversion rule is to determine the public network address and public network port of the corresponding cloud host according to the destination address and destination port in the initial access request, and the cloud host address conversion rule is to map the public network address and public network port of the cloud host to the private network address and private network port of the cloud host. A data center gateway, located in the data center, is used to determine the private network address and private port corresponding to the cloud host based on the cloud host address translation rules configured on the data center gateway and the public network address and public network port of the cloud host in the data center access request, replace the message information, and obtain the cloud host access request. The cloud host is configured to determine the private network address and private port corresponding to the target computing power service based on the target computing power service mapping relationship configured on the cloud host, according to the private network address and private network port corresponding to the cloud host in the cloud host access request, replace the message information, obtain the target access request, and forward the target access request to the data center gateway corresponding to the target computing power service, so that the data center gateway forwards the target access request to the service instance corresponding to the target computing power service, wherein the target computing power service is a computing power service without a fixed IP address.

13. The system according to claim 12, characterized in that, Also includes: Computing power network management platform, among which, The computing power network management platform is used to receive node information corresponding to the computing power service uploaded by the data center gateway, determine the address conversion rule for computing power service without fixed IP based on the node information corresponding to the computing power service, and send the address conversion rule for computing power service without fixed IP to the computing power gateway. The node information corresponding to the computing power service includes a corresponding service identifier and a service instance identifier. The service identifier represents the destination address and destination port of the unified access corresponding to the target computing power service, and the service instance identifier represents the public network address and public network port of the cloud host corresponding to the computing power service instance without fixed IP.

14. The system according to claim 12, characterized in that, The cloud host is located in the data center.

15. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored program, wherein, when the program is executed, it controls the device where the non-volatile storage medium is located to execute the computing power service access method according to any one of claims 1 to 9.

16. A computer device, characterized in that, include: Memory and processor The memory stores computer programs; The processor is configured to execute a computer program stored in the memory, wherein when the computer program is executed, the processor performs the computing power service access method according to any one of claims 1 to 9.

17. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the computing power service access method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Cloud system, cloud public service system and mutual access method for cloud system

    CN106559511A

  • Data transmission method and device, and hybrid cloud system

    CN107959654A