A method and apparatus for implementing multi-carrier egress networks in a cloud network.
By building virtual networks and multi-line EIP address pools through a software-defined networking (SDN) controller, the problem of virtual machines in the cloud platform being unable to bind multiple EIP addresses is solved, enabling flexible control and automatic switching of multi-carrier networks, and improving the reliability and performance of the cloud platform.
Patent Information
- Application Number
- CN202411782564.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-05
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-12-05
AI Technical Summary
Existing cloud platforms cannot bind virtual machines to EIP addresses with multiple external network plane attributes, and cannot automatically switch to the optimal carrier link, resulting in limited service reliability and performance in multi-carrier network environments.
A software-defined networking (SDN) controller is used to build a virtual network, establish a multi-line elastic public network EIP address pool, bind network cards through static routing or BGP multi-line address pool, and combine traffic control policies and link detection to achieve flexible control and automatic switching of multiple carrier exits.
This enables cloud servers to provide bandwidth from multiple carriers, automatically select the optimal link, improve network reliability and performance, and ensure that the system can switch to a backup link when a carrier link fails, thus meeting high reliability requirements.
Smart Images

Figure CN119814531B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing network technology, and in particular to a method and apparatus for implementing a multi-carrier egress network in a cloud network. Background Technology
[0002] The next-generation IaaS cloud platform, CloudOS 4.0, supports multi-AZ resource deployment, ultra-large-scale clusters (supporting over 10,000 nodes per AZ), and hardware-software collaboration. Its core resource pool capabilities meet the demands of providing ultra-large-scale, high-performance, secure, and reliable cloud services.
[0003] Enhance the management and scheduling capabilities of the IaaS platform for ultra-large-scale resource pools, support ultra-large-scale data center networking and multi-AZ architecture, possess resource pool network management capabilities for up to 5,000 nodes, support 5,000 servers per AZ, and increase region scale by more than 10 times, reaching the industry's advanced level. Meet the business needs of enterprises for dual-site three-center multi-active and disaster recovery applications.
[0004] The next-generation cloud platform CloudOS 4.0, developed based on the national cloud, has been fully productized, commercialized, and deployed on the network. As an independent and controllable cloud foundation with "one cloud, multiple states, and one cloud, multiple chips", and as one of the core components of CloudOS 4.0, it provides a high-performance, highly available, and highly reliable basic cloud network foundation.
[0005] Problems with existing technology:
[0006] 1. Currently, cloud platforms, whether public or private, can only bind virtual machines to EIP addresses with a fixed external network plane attribute, typically the China Telecom 163 plane attribute. In the networks of large ISPs, there are external network planes with multiple service attributes, such as those of mobile and China Unicom operators.
[0007] 2. In the process of promoting cloud computing on telecommunications service platforms, EIPs, in addition to connecting to the public network, also need to connect to the internal DCN network, CN2 network, and transport network of the telecommunications company, including the various VPN networks carried on each network. For example, cloud tenant A has multiple virtual machines VM1, VM2, ..., VMn that need to access multiple networks. Scenario 1: VM1 needs to access the CN2 network, and VM2 needs to access the DCN network; Scenario 2: VM1 needs to access both the CN2 network and the DCN network simultaneously.
[0008] 3. In gaming scenarios, customer terminals may reside with different carriers, potentially as many as 7-8 carriers, such as China Telecom. In this case, a virtual machine needs to provide multiple external EIP addresses and select the optimal EIP to provide service based on the customer's latency. Furthermore, it should automatically switch to another carrier's link if one fails. Currently, the cloud platform does not provide this functionality. Summary of the Invention
[0009] This application discloses a method and apparatus for implementing a multi-carrier egress network in a cloud network.
[0010] In a first aspect, this application discloses a method for implementing a multi-carrier egress network in a cloud network, the method comprising:
[0011] A virtual network controlled by a software-defined networking (SDN) controller is established, wherein the software includes a three-layer structure: a flow control (TC) area, a network element service area, and a resource access layer.
[0012] Establish a multi-line elastic public network EIP address pool with preset operators to realize a multi-exit deployment mode;
[0013] To enable a single cloud host to provide bandwidth from multiple carriers to the outside world, a pre-defined network interface card (NIC) can be bound to a pre-defined carrier's elastic public IP (EIP). Alternatively, the cloud host can be configured with static routing to select the carrier link, or a network interface card can be started on the cloud host and bound to an EIP in the BGP multi-line address pool.
[0014] Based on preset traffic control strategies, the backend control of network elements and multi-carrier exits is realized;
[0015] Based on the pre-set virtual machines within the operator's network, the latency of the network of multiple EIPs bound to a single virtual machine for each customer is obtained, thereby enabling the detection of operator links;
[0016] Based on link delay or interruption, implement operator link or operator exit switching control.
[0017] In one exemplary embodiment of this disclosure, the software-defined network (SDN) controller in the method, which has a three-layer structure of flow control (TC) zone, network element service zone, and resource access layer, further includes:
[0018] The first layer is the TC zone, which is responsible for accessing external networks, including external network traffic, NAS traffic, dedicated line POP, high-speed cloud devices, and VPN devices. The network elements deployed in this zone are AGW and SGW. AGW is responsible for publishing public network CIDR, and SGW is responsible for rate limiting.
[0019] The second layer is the network element service area, where the deployed service areas provide tenants with network services from layer 3 to layer 7, including leased lines, IGW, NAT, VPN access, and load balancer.
[0020] The third layer is the resource access layer, which is responsible for providing virtual network access services for VMs, containers, and bare metals. The network element types are DVR and SmartNIC.
[0021] In one exemplary embodiment of this disclosure, the method further includes:
[0022] Multiple operators connect to the egress switch, and each operator's egress and the egress switch enable the link health check function;
[0023] On the cloud platform, an EIP address pool is provided for each operator, and a multi-line EIP address pool is also provided. The EIPs in the address pool automatically select the operator with the optimal route.
[0024] The customer can choose between the EIP in the operator's single-line address pool and the EIP in the BGP multi-line address pool.
[0025] In one exemplary embodiment of this disclosure, the method further includes:
[0026] This solution allows a single cloud host to provide bandwidth from multiple carriers by binding a pre-defined network interface card (NIC) to a pre-defined elastic public IP address from a BGP multi-line address pool. Alternatively, the cloud host can be configured with static routing to select the carrier link, or the cloud host can start a NIC to bind an EIP from the BGP multi-line address pool. Customers can choose to use this solution based on their network latency requirements and configuration flexibility.
[0027] In one exemplary embodiment of this disclosure, the method further includes:
[0028] When traffic is diverted, the default operator's bandwidth establishes BGP neighbor with the egress switch, the network element AGW establishes BGP neighbor with the egress switch, and publishes EIP routes to the outside world. The EIP is weighted and controlled through routing policies to achieve the routing priority selection of operator links.
[0029] When traffic goes out, the SDN controller controls the traffic to be NAT mapped to a public EIP address on the IGW. Then, after traffic rate limiting on the SGW, different VLAN headers are added to the traffic from the preset carrier. The VLAN ID in the VLAN header controls the carrier network selection of the traffic. Then, within each VLAN, the traffic enters the egress switch through the default route. On the egress switch, according to the different VLAN headers of the traffic, it is forwarded to the carrier egress corresponding to the VLAN header.
[0030] In one exemplary embodiment of this disclosure, the method further includes:
[0031] Link latency information is provided to customers, who can then select the operator that prioritizes traffic based on link quality.
[0032] For multi-line BGP, the link with the lowest latency is selected first for forwarding traffic.
[0033] In one exemplary embodiment of this disclosure, the method further includes:
[0034] When ping tests detect a carrier link outage, for multi-line BGP EIPs, the controller prioritizes forwarding traffic to the carrier link with the second lowest latency.
[0035] For EIP traffic from a single operator, an alarm is sent to the customer, who then switches the operator's link exit point.
[0036] Secondly, this application discloses an apparatus for implementing a multi-carrier egress network in a cloud network, the apparatus comprising:
[0037] The virtual network construction module is used to establish a virtual network controlled by a software-defined networking (SDN) controller. The software includes a three-layer structure: a traffic control (TC) area, a network element service area, and a resource access layer.
[0038] The multi-exit deployment module is used to establish an address pool of multi-line elastic public network EIPs of a preset operator to realize the multi-exit deployment mode;
[0039] The EIP binding module is used to bind a preset network card to a preset operator's elastic public network EIP to achieve a solution where a single cloud host provides bandwidth from multiple operators. The cloud host can select the operator link by configuring static routing inside, or the cloud host can start a network card to bind an EIP in the BGP multi-line address pool.
[0040] The default operator determination module is used to implement backend control of network elements and multiple operator exits based on preset traffic control policies;
[0041] The carrier link detection module is used to obtain the network latency of multiple EIPs bound to a single virtual machine for each customer based on a preset virtual machine within the carrier network, thereby realizing the detection of carrier links.
[0042] The operator exit switching module is used to control the switching of operator links or operator exits based on link delays or interruptions.
[0043] Thirdly, this application discloses an electronic device comprising: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to perform the method as described in any of the preceding aspects.
[0044] Fourthly, this application discloses a non-transitory computer-readable storage medium in which, when the instructions in the storage medium are executed by a processor of an electronic device, enable the electronic device to perform the methods described in any of the preceding aspects.
[0045] Fifthly, this application discloses a computer program product in which, when the instructions in the computer program product are executed by a processor of an electronic device, the electronic device is enabled to perform the method described in any of the preceding aspects.
[0046] This application provides a method and apparatus for implementing a multi-carrier egress network in a cloud network. The method includes: establishing a virtual network controlled by a Software-Defined Networking (SDN) controller, wherein the software comprises a three-layer structure: a traffic control (TC) area, a network element service area, and a resource access layer; establishing an address pool of pre-defined multi-line elastic public IPs (EIPs) from a pre-defined carrier to achieve a multi-egress deployment mode; binding pre-defined carrier EIPs to pre-defined network interface cards (NICs) to provide multi-carrier bandwidth to a single cloud host, wherein the cloud host internally configures static routing to select carrier links, or the cloud host starts a NIC to bind an EIP from the BGP multi-line address pool; implementing background control of network elements and multi-carrier egress based on a pre-defined traffic control strategy; obtaining network latency information for multiple EIPs bound to a single virtual machine for each customer based on pre-defined virtual machines within the carrier network, thereby enabling carrier link detection; and implementing carrier link or carrier egress switching control based on link latency or interruption. This disclosure provides a flexible multi-carrier outbound network solution for cloud servers. It can also provide customers with optimal carrier bandwidth selection suggestions by detecting link quality. Furthermore, when a carrier network fails, it can automatically switch to the optimal backup line, achieving high reliability of multi-carrier networks. Attached Figure Description
[0047] Figure 1 This is a flowchart illustrating the steps of a method for implementing a multi-carrier egress network in a cloud network, as described in this application.
[0048] Figure 2 This is a schematic diagram of a virtual network controlled by an SDN controller, which is part of a method for implementing a multi-carrier egress network in a cloud network according to this application.
[0049] Figure 3 This is a schematic diagram of a multi-carrier egress deployment mode for a method of implementing a multi-carrier egress network in a cloud network, as described in this application.
[0050] Figure 4 This is a schematic diagram of the EIP address pool in a method for implementing a multi-carrier egress network in a cloud network, as described in this application.
[0051] Figure 5AThis is a schematic diagram illustrating a scenario in which cloud host operator links are selected from China Telecom, China Unicom, and China Mobile, respectively, as part of a method for implementing multi-operator egress networks in a cloud network according to this application.
[0052] Figure 5B This is a schematic diagram of a scenario where cloud host operator link selection uses BGP multi-line, which is a method for implementing multi-operator egress networks in a cloud network according to this application.
[0053] Figure 6 This is a schematic diagram of the network elements and the multi-carrier egress backend of a method for implementing a multi-carrier egress network in a cloud network, as described in this application.
[0054] Figure 7 This is a structural block diagram of an apparatus for implementing a multi-carrier egress network in a cloud network, according to this application.
[0055] Figure 8 This is a block diagram of an electronic device according to this application.
[0056] Figure 9 This is a block diagram of a computer-readable storage medium according to this application. Detailed Implementation
[0057] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0058] The method disclosed herein for implementing a multi-carrier egress network in a cloud network includes:
[0059] Step S110: Establish a virtual network controlled by a software-defined networking (SDN) controller, wherein the software includes a three-layer structure: a traffic control (TC) area, a network element service area, and a resource access layer.
[0060] Step S120: Establish an address pool for a pre-defined multi-line elastic public network EIP from a carrier to achieve a multi-exit deployment mode;
[0061] Step S130: Bind a preset network card to a preset operator's elastic public IP to achieve a solution where a single cloud host provides bandwidth from multiple operators to the outside world. The cloud host can select the operator link by configuring static routing inside the cloud host, or the cloud host can start a network card to bind an EIP in the BGP multi-line address pool.
[0062] Step S140: Based on the preset traffic control strategy, realize the back-end control of network elements and multi-operator exits;
[0063] Step S150: Based on the preset virtual machines within the operator's network, obtain the network latency of multiple EIPs bound to a single virtual machine for each customer, thereby enabling the detection of operator links.
[0064] Step S160: Based on the link delay or interruption, implement operator link or operator exit switching control.
[0065] This application provides a method and apparatus for implementing a multi-carrier egress network in a cloud network. The method includes: establishing a virtual network controlled by a Software-Defined Networking (SDN) controller, wherein the software comprises a three-layer structure: a traffic control (TC) area, a network element service area, and a resource access layer; establishing an address pool of pre-defined multi-line elastic public IPs (EIPs) from a pre-defined carrier to achieve a multi-egress deployment mode; binding pre-defined carrier EIPs to pre-defined network interface cards (NICs) to provide multi-carrier bandwidth to a single cloud host, wherein the cloud host internally configures static routing to select carrier links, or the cloud host starts a NIC to bind an EIP from the BGP multi-line address pool; implementing background control of network elements and multi-carrier egress based on a pre-defined traffic control strategy; obtaining network latency information for multiple EIPs bound to a single virtual machine for each customer based on pre-defined virtual machines within the carrier network, thereby enabling carrier link detection; and implementing carrier link or carrier egress switching control based on link latency or interruption. This disclosure provides a flexible multi-carrier outbound network solution for cloud servers. It can also provide customers with optimal carrier bandwidth selection suggestions by detecting link quality. Furthermore, when a carrier network fails, it can automatically switch to the optimal backup line, achieving high reliability of multi-carrier networks.
[0066] Example 1:
[0067] Reference Figure 1 The diagram illustrates a flowchart of a method for implementing a multi-carrier egress network in a cloud network, which can be applied to electronic devices. Specifically, the method may include the following steps:
[0068] In step S110, a virtual network controlled by a software-defined networking (SDN) controller can be established. The software includes a three-layer structure: a flow control (TC) area, a network element service area, and a resource access layer.
[0069] In this example embodiment, the software-defined network (SDN) controller, which has a three-layer structure of flow control (TC) zone, network element service zone, and resource access layer, further includes:
[0070] The first layer is the TC zone, which is responsible for accessing external networks, including external network traffic, NAS traffic, dedicated line POP, high-speed cloud devices, and VPN devices. The network elements deployed in this zone are AGW and SGW. AGW is responsible for publishing public network CIDR, and SGW is responsible for rate limiting.
[0071] The second layer is the network element service area. The service areas deployed in this area provide tenants with network services from layers 3 to 7, including leased lines, IGW, NAT, VPN access, and load balancer.
[0072] The third layer is the resource access layer, which is responsible for providing virtual network access services for VMs, containers, and bare metals. The network element types are DVR and SmartNIC.
[0073] In step S120, a multi-line elastic public network EIP address pool of a preset operator can be established to realize a multi-exit deployment mode.
[0074] In this example embodiment, the method further includes:
[0075] Multiple operators connect to the egress switch, and each operator's egress and the egress switch enable the link health check function;
[0076] On the cloud platform, an EIP address pool is provided for each operator, and a multi-line EIP address pool is also provided. The EIPs in the address pool automatically select the operator with the optimal route.
[0077] The customer can choose between the EIP in the operator's single-line address pool and the EIP in the BGP multi-line address pool.
[0078] In step S130, a preset network card can be bound to a preset operator's elastic public network EIP to enable a single cloud host to provide multi-operator bandwidth to the outside world. The cloud host can select operator links by configuring static routes inside, or the cloud host can start a network card to bind an EIP in the BGP multi-line address pool.
[0079] In this example embodiment, the method further includes:
[0080] This solution allows a single cloud host to provide bandwidth from multiple carriers by binding a pre-defined network interface card (NIC) to a pre-defined elastic public IP address from a BGP multi-line address pool. Alternatively, the cloud host can be configured with static routing to select the carrier link, or the cloud host can start a NIC to bind an EIP from the BGP multi-line address pool. Customers can choose to use this solution based on their network latency requirements and configuration flexibility.
[0081] In step S140, backend control of network elements and multiple operator exits can be implemented based on a preset flow control strategy.
[0082] In this example embodiment, the method further includes:
[0083] When traffic is diverted, the default operator's bandwidth establishes BGP neighbor with the egress switch, the network element AGW establishes BGP neighbor with the egress switch, and publishes EIP routes to the outside world. The EIP is weighted and controlled through routing policies to achieve the routing priority selection of operator links.
[0084] When traffic goes out, the SDN controller controls the traffic to be NAT mapped to a public EIP address on the IGW. Then, after traffic rate limiting on the SGW, different VLAN headers are added to the traffic from the preset carrier. The VLAN ID in the VLAN header controls the carrier network selection of the traffic. Then, within each VLAN, the traffic enters the egress switch through the default route. On the egress switch, according to the different VLAN headers of the traffic, it is forwarded to the carrier egress corresponding to the VLAN header.
[0085] In step S150, based on the preset virtual machines within the operator's network, the network latency of multiple EIPs bound to a single virtual machine for each customer can be obtained, thereby enabling the detection of operator links.
[0086] In step S160, the operator link or the operator's exit switching control can be implemented according to the link delay or interruption situation.
[0087] In this example embodiment, the method further includes:
[0088] Link latency information is provided to customers, who can then select the operator that prioritizes traffic based on link quality.
[0089] For multi-line BGP, the link with the lowest latency is selected first for forwarding traffic.
[0090] In this example embodiment, the method further includes:
[0091] When ping tests detect a carrier link outage, for multi-line BGP EIPs, the controller prioritizes forwarding traffic to the carrier link with the second lowest latency.
[0092] For EIP traffic from a single operator, an alarm is sent to the customer, who then switches the operator's link exit point.
[0093] Example 2:
[0094] In this example embodiment, the proper nouns are explained as follows:
[0095] SDN (Software Defined Network)
[0096] OVS (Open vSwitch, Virtual Switch)
[0097] VXLAN (Virtual eXtensible LAN)
[0098] EIP (Elastic IP Address Translation) enables 1:1 NAT.
[0099] Subnet (a feature that allows you to create subnets within a VPC)
[0100] VNI range VNI segment management.
[0101] In the embodiments of this example, as Figure 2 As shown, the virtual network controlled by the SDN controller is divided into three layers:
[0102] The first layer is the TC zone, responsible for accessing external networks, including external network traffic, NAS traffic, dedicated line POP, high-speed cloud devices, VPN devices, etc. These devices are all multi-active access. The network elements deployed in this zone are AGW and SGW. AGW is responsible for publishing public network CIDR, and SGW is responsible for rate limiting.
[0103] The second layer is the network element service area. The service areas deployed in this area provide tenants with network services from layers 3 to 7, including leased lines, IGW, NAT, VPN access, load balancer, etc.
[0104] The third layer is the resource access layer, which is responsible for providing virtual network access services for VMs, containers, and bare metals. The network element types are DVR and SmartNIC.
[0105] In the embodiments of this example, as Figure 3 As shown, the multi-exit deployment mode for operators is as follows:
[0106] Multiple carriers connect to the egress switch, and each carrier's egress and the egress switch have link health checks enabled. The cloud platform provides an EIP address pool for each carrier, and also a multi-line EIP address pool. The EIPs in this address pool automatically select the carrier with the optimal route. For example... Figure 4 As shown, customers can bind addresses from specific EIP address pools according to their needs.
[0107] Customers can choose between EIPs from the operator's single-line address pool and EIPs from the BGP multi-line address pool.
[0108] In this example embodiment, at the cloud host level, multiple network interface cards (NICs) are started on the cloud host, and each NIC is bound to a different carrier's EIP to achieve a solution where a single cloud host provides bandwidth from multiple carriers. Internally, static routing can be configured on the cloud host to select which carrier's link traffic should take, such as... Figure 5A As shown.
[0109] Alternatively, you can have the cloud server start a network interface card that binds to an EIP in the BGP multi-line address pool, such as... Figure 5B As shown.
[0110] In this example embodiment, the two binding scenarios differ. One scenario involves a cloud host running multiple network interface cards (NICs) bound to different ISPs. Customers can segment traffic to specific ISPs, reducing network latency for corresponding services and saving costs. However, this requires more sophisticated deployment, as customers need to manually configure traffic routing and select the NIC for each ISP. The other scenario involves a cloud host with a single NIC bound to an EIP in a BGP multi-line address pool. The ISP link is detected and selected by the SDN controller using the optimal ISP route. Customers don't need to configure routing to select the ISP link themselves, making it convenient. However, this method cannot select the ISP with the lowest latency for different customers, and the cost is higher.
[0111] In this example embodiment, the network element and multi-carrier egress backend are specifically implemented as follows: Figure 6 As shown:
[0112] When traffic is diverted, each operator's bandwidth establishes BGP neighbor relationships with the egress switch, and the network element AGW establishes BGP neighbor relationships with the egress switch, advertising EIP routes externally. For example, EIPs from the telecom resource pool are only advertised to the telecom egress via BGP routing policies, while EIPs from the BGP multi-line address pool are advertised to all operator egress points. Routing policies are used to weight these EIPs, controlling which operator's link has higher priority. When traffic leaves, the SDN controller performs corresponding NAT mapping on the IGW to public network EIP addresses. After traffic rate limiting on the SGW, different VLAN headers are added to traffic from different operators, using VLAN IDs to control which operator's network the traffic enters. Within each VLAN, traffic enters the egress switch via a default route. At the egress switch, based on the different VLAN headers, the traffic is forwarded to the appropriate operator's egress point.
[0113] In this example embodiment, the detection of the carrier link is implemented as follows: For the EIP purchased by the customer, the detection function is supported. A virtual machine will be started in the same location, such as Beijing, simulating the client within the same carrier network, and pinging the EIP. In this way, the network latency of multiple EIPs bound to a single virtual machine for each customer can be obtained, as shown in the table below.
[0114] EIP (Type) Link latency 10.1.1.1 (Telecommunications) 30ms 20.1.1.1 (Mobile) 50ms 30.1.1.1 (China Unicom) 100ms 40.1.1.1 (China Telecom) 300ms 50.1.1.1 (Multi-line BGP) 30ms
[0115] In this example embodiment, link latency information is provided to the customer, allowing the customer to choose which operator's bandwidth to prioritize for traffic based on link quality. For multi-line BGP, the link with the lowest latency is prioritized for forwarding traffic.
[0116] In this example embodiment, when a ping test detects an outage of a certain operator's link, for multi-line BGP EIPs, the controller controls the traffic to be forwarded to the operator's link with the second lowest latency. For EIP traffic from a single operator, an alarm is immediately sent to the customer, who then switches to the appropriate operator's link exit.
[0117] In this example embodiment, the above steps can provide cloud hosts with a flexible multi-carrier egress network solution. At the same time, by detecting the quality of the link, it can provide customers with suggestions on the optimal carrier bandwidth selection. Furthermore, when a carrier network fails, it can automatically switch to the optimal backup line, achieving the goal of high reliability of multi-carrier networks.
[0118] In this example embodiment, the present disclosure proposes an egress network solution that provides cloud hosts with flexible control over multiple carrier egress points. It can provide customers with optimal carrier bandwidth selection suggestions by detecting link quality, and automatically switch to the optimal backup line when a carrier network fails, thereby achieving high reliability of the multi-carrier network.
[0119] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, because according to this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions involved are not necessarily required by this application.
[0120] Reference Figure 7 The diagram illustrates a structural block diagram of an apparatus for implementing a multi-carrier egress network in a cloud network, the apparatus comprising:
[0121] The virtual network construction module 210 is used to establish a virtual network controlled by a software-defined networking (SDN) controller. The software includes a three-layer structure: a flow control (TC) area, a network element service area, and a resource access layer.
[0122] The multi-exit deployment module 220 is used to establish an address pool of multi-line elastic public network EIPs of a preset operator to realize the multi-exit deployment mode;
[0123] EIP binding module 230 is used to bind a preset network card to a preset operator's elastic public network EIP to enable a single cloud host to provide multi-operator bandwidth to the outside world. The cloud host can select the operator link by configuring static routing inside, or the cloud host can start a network card to bind an EIP in the BGP multi-line address pool.
[0124] The default operator determination module 240 is used to implement backend control of network elements and multiple operator exits based on preset traffic control policies.
[0125] The operator link detection module 250 is used to obtain the network latency of multiple EIPs bound to a single virtual machine for each customer based on a preset virtual machine within the operator network, thereby realizing the detection of operator links.
[0126] The operator exit switching module 260 is used to control the switching of operator links or operator exits based on link delay or interruption.
[0127] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.
[0128] Optionally, this application also provides an electronic device, including: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, it implements the various processes of the above method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.
[0129] This application also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the various processes of the above-described method embodiments and achieves the same technical effects. To avoid repetition, it will not be described again here. The computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc.
[0130] Figure 8This is a block diagram illustrating an electronic device 800. For example, the electronic device 800 may be a mobile phone, computer, digital broadcasting terminal, messaging device, game console, tablet device, medical device, fitness equipment, personal digital assistant, etc.
[0131] Reference Figure 8 The electronic device 800 may include one or more of the following components: a processing component 802, a memory 804, a power supply component 806, a multimedia component 808, an audio component 810, an input / output (I / O) interface 812, a sensor component 814, and a communication component 816.
[0132] Processing component 802 typically controls the overall operation of electronic device 800, such as operations associated with display, telephone calls, data communication, camera operation, and recording operations. Processing component 802 may include one or more processors 820 to execute instructions to complete all or part of the steps of the methods described above. Furthermore, processing component 802 may include one or more modules to facilitate interaction between processing component 802 and other components. For example, processing component 802 may include a multimedia module to facilitate interaction between multimedia component 808 and processing component 802.
[0133] Memory 804 is configured to store various types of data to support the operation of device 800. Examples of this data include instructions for any application or method operating on electronic device 800, contact data, phonebook data, messages, images, videos, etc. Memory 804 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0134] Power supply component 806 provides power to various components of electronic device 800. Power supply component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to electronic device 800.
[0135] Multimedia component 808 includes a screen that provides an output interface between the electronic device 800 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touchscreen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of the touch or swipe action but also the duration and pressure associated with the touch or swipe operation. In some embodiments, multimedia component 808 includes a front-facing camera and / or a rear-facing camera. When the device 800 is in an operating mode, such as a shooting mode or a video mode, the front-facing camera and / or the rear-facing camera may receive external multimedia data. Each front-facing camera and rear-facing camera may be a fixed optical lens system or have focal length and optical zoom capabilities.
[0136] Audio component 810 is configured to output and / or input audio signals. For example, audio component 810 includes a microphone (MIC) configured to receive external audio signals when electronic device 800 is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals may be further stored in memory 804 or transmitted via communication component 816. In some embodiments, audio component 810 also includes a speaker for outputting audio signals.
[0137] I / O interface 812 provides an interface between processing component 802 and peripheral interface modules, such as keyboards, click wheels, buttons, etc. These buttons may include, but are not limited to, home buttons, volume buttons, power buttons, and lock buttons.
[0138] Sensor assembly 814 includes one or more sensors for providing state assessments of various aspects of electronic device 800. For example, sensor assembly 814 may detect the on / off state of device 800, the relative positioning of components such as the display and keypad of electronic device 800, changes in position of electronic device 800 or a component of electronic device 800, the presence or absence of user contact with electronic device 800, orientation or acceleration / deceleration of electronic device 800, and temperature changes of electronic device 800. Sensor assembly 814 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. Sensor assembly 814 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, sensor assembly 814 may also include an accelerometer, gyroscope, magnetometer, pressure sensor, or temperature sensor.
[0139] Communication component 816 is configured to facilitate wired or wireless communication between electronic device 800 and other devices. Electronic device 800 can access wireless networks based on communication standards, such as WiFi, carrier networks (such as 2G, 3G, 4G, or 5G), or combinations thereof. In one exemplary embodiment, communication component 816 receives broadcast signals or broadcast operation information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, communication component 816 also includes a near-field communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on radio frequency identification (RFID) technology, Infrared Data Association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0140] In an exemplary embodiment, the electronic device 800 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the methods described above.
[0141] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions, which can be executed by a processor 820 of an electronic device 800 to perform the above-described method. For example, the non-transitory computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, etc.
[0142] Figure 9 This is a block diagram illustrating a computer-readable storage medium 1900. For example, the computer-readable storage medium 1900 can be provided as a server.
[0143] Reference Figure 9 The computer-readable storage medium 1900 includes a processing component 1922, which further includes one or more processors, and a memory resource represented by memory 1932 for storing instructions executable by the processing component 1922, such as an application program. The application program stored in memory 1932 may include one or more modules, each corresponding to a set of instructions. Furthermore, the processing component 1922 is configured to execute instructions to perform the methods described above.
[0144] The computer-readable storage medium 1900 may also include a power supply component 1926 configured to perform power management of the computer-readable storage medium 1900, a wired or wireless network interface 1950 configured to connect the computer-readable storage medium 1900 to a network, and an input / output (I / O) interface 1958. The computer-readable storage medium 1900 can operate on an operating system stored in memory 1932, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, or similar.
[0145] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.
[0146] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0147] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.
[0148] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this application can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0149] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0150] In the embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0151] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0152] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0153] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0154] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A method for implementing a multi-carrier egress network in a cloud network, characterized in that, The method includes: A virtual network controlled by a software-defined networking (SDN) controller is established. The software includes a three-layer structure: a traffic control (TC) area, a network element service area, and a resource access layer. Establish a pre-defined address pool of multi-line elastic public network EIPs from carriers to enable multi-exit deployment mode; To enable a single cloud host to provide bandwidth from multiple carriers to the outside world, the cloud host can bind a pre-defined network card to a pre-defined carrier's elastic public IP address. Alternatively, the cloud host can select a carrier link by configuring static routes or start a network card to bind an EIP in the BGP multi-line address pool. Based on preset traffic control strategies, the backend control of network elements and multi-carrier exits is realized; Based on the pre-set virtual machines within the operator's network, the latency of the network of multiple EIPs bound to a single virtual machine for each customer is obtained, thereby enabling the detection of operator links; Based on link delay or interruption, implement operator link or operator exit switching control.
2. The method as described in claim 1, characterized in that, The software-defined network (SDN) controller in the method, which has a three-layer structure of flow control (TC) zone, network element service zone, and resource access layer, also includes: The first layer is the TC zone, which is responsible for accessing external networks, including external network traffic, NAS traffic, dedicated line POP, high-speed cloud devices, and VPN devices. The network elements deployed in this zone are AGW and SGW. AGW is responsible for publishing public network CIDR, and SGW is responsible for rate limiting. The second layer is the network element service area, where the deployed service areas provide tenants with network services from layer 3 to layer 7, including leased lines, IGW, NAT, VPN access, and load balancer. The third layer is the resource access layer, which is responsible for providing virtual network access services for VMs, containers, and bare metals. The network element types are DVR and SmartNIC.
3. The method as described in claim 1, characterized in that, The method further includes: Multiple operators connect to the egress switch, and each operator's egress and the egress switch enable the link health check function; On the cloud platform, an EIP address pool is provided for each operator, and a multi-line EIP address pool is also provided. The EIPs in the address pool automatically select the operator with the optimal route. The customer can choose between the EIP in the operator's single-line address pool and the EIP in the BGP multi-line address pool.
4. The method as described in claim 1, characterized in that, The method further includes: In the two binding scenarios—binding a pre-defined network interface card (NIC) to a pre-defined operator's elastic public IP (EIP) to enable a single cloud host to provide bandwidth from multiple operators, configuring static routing within the cloud host to select the operator's link, or starting a network interface card on the cloud host to bind an EIP from a BGP multi-line address pool—customers can choose to use the method based on their network latency requirements and configuration flexibility.
5. The method as described in claim 1, characterized in that, The method further includes: When traffic is diverted, the default operator's bandwidth establishes BGP neighbor with the egress switch, the network element AGW establishes BGP neighbor with the egress switch, and publishes EIP routes to the outside world. The EIP is weighted and controlled through routing policies to achieve the routing priority selection of operator links. When traffic goes out, the SDN controller controls the traffic to be NAT mapped to a public EIP address on the IGW. Then, after traffic rate limiting on the SGW, different VLAN headers are added to the traffic from the preset carrier. The VLAN ID in the VLAN header controls the carrier network selection of the traffic. Then, within each VLAN, the traffic enters the egress switch through the default route. On the egress switch, according to the different VLAN headers of the traffic, it is forwarded to the carrier egress corresponding to the VLAN header.
6. The method as described in claim 1, characterized in that, The method further includes: Link latency information is provided to customers, who can then select the operator that prioritizes traffic based on link quality. For multi-line BGP, the link with the lowest latency is selected first for forwarding traffic.
7. The method as described in claim 1, characterized in that, The method further includes: When ping tests detect a carrier link outage, for multi-line BGP EIPs, the controller prioritizes forwarding traffic to the carrier link with the second lowest latency. For EIP traffic from a single operator, an alarm is sent to the customer, who then switches the operator's link exit point.
8. An apparatus for realizing a multi-carrier egress network in a cloud network, characterized in that, The device includes: The virtual network construction module is used to establish a virtual network controlled by a software-defined networking (SDN) controller. The software includes a three-layer structure: a traffic control (TC) area, a network element service area, and a resource access layer. The multi-exit deployment module is used to establish an address pool of multi-line elastic public network EIPs of a preset operator to realize the multi-exit deployment mode; The EIP binding module is used to bind a preset network card to a preset operator's elastic public network EIP to enable a single cloud host to provide multi-operator bandwidth to the outside world. The cloud host can select the operator link by configuring static routing inside, or the cloud host can start a network card to bind an EIP in the BGP multi-line address pool. The default operator determination module is used to implement backend control of network elements and multiple operator exits based on preset traffic control policies; The carrier link detection module is used to obtain the network latency of multiple EIPs bound to a single virtual machine for each customer based on a preset virtual machine within the carrier network, thereby realizing the detection of carrier links. The operator exit switching module is used to control the switching of operator links or operator exits based on link delays or interruptions.
9. An electronic device, characterized in that, include: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Network route control system with multi-link mutual redundancy and backup
CN103368753A
Link switching method, device and equipment
CN109995646A