Host machine access methods and systems
By sending configuration commands to the host machine through the network management platform, the configuration of the bridge address and virtual machine interface address is triggered, and routes are created. This solves the problems of high labor costs and significant security risks in existing technologies, and realizes the convenience and security of automatic access to the host machine.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NEW H3C TECH CO LTD
- Filing Date
- 2024-12-30
- Publication Date
- 2026-05-26
AI Technical Summary
In existing technologies, connecting external devices to the host machine via serial ports and management ports not only incurs labor costs and is inconvenient to operate, but also poses serious security risks.
The network management platform sends configuration commands to the host machine, triggering the host machine to configure the bridge address and virtual machine interface address. Routes are then created based on these addresses, enabling the network management platform to automatically connect to the host machine.
It achieves ease of operation, saves labor costs, improves security, and avoids additional network connection complexity and potential security risks.
Smart Images

Figure CN119854263B_ABST
Abstract
Description
Technical Field
[0001] This disclosure belongs to the field of communication technology, specifically relating to a host access method and system. Background Technology
[0002] In kernel-based virtual machine (KVM) technology, business systems are deployed within virtual machines, which in turn run on physical machines, often referred to as the host machine. Because virtual machines operate on a host machine, managing and maintaining both the virtual machines and business systems typically requires accessing the host machine and obtaining parameters of its hardware and software modules.
[0003] A common way for maintenance personnel to access the host machine is to use external devices to connect to the host machine through its serial port and management port. However, this method not only consumes manpower and is inconvenient to operate, but also poses serious security risks. Summary of the Invention
[0004] This disclosure proposes a host machine access method and system. By sending configuration commands to the host machine through a network management platform, the host machine is triggered to configure routing node addresses such as bridge addresses and virtual machine interface addresses. The network management platform can create a route between itself and the host machine based on the bridge address, and then automatically connect the host machine based on the route. This method is not only convenient to operate and saves manpower costs, but also improves security.
[0005] The first aspect of this disclosure provides a host machine access method, applied to a host machine, wherein the host machine includes a virtual machine running a business system, and the host machine connects to a network management platform through a business port. The method includes:
[0006] The address configuration instruction set is received from the network management platform through the service port. The address configuration instruction set is sent by the network management platform in response to the access instruction. The access instruction is input to the network management platform from the port of the service system.
[0007] Configure the routing node address according to the address configuration instruction set. The routing node address includes a bridge address and a virtual machine interface address. The bridge corresponding to the bridge address is used to connect the host machine and the virtual machine corresponding to the virtual machine interface address.
[0008] Send the bridge address to the network management platform so that the network management platform can configure a first route based on the bridge address. The first route refers to the route from the network management platform to the host machine.
[0009] The network management platform is connected to the host machine according to the access request, which is sent by the network management platform based on the first route.
[0010] An embodiment of the second aspect of this disclosure provides a host machine access method applied to a network management platform. The network platform connects to the host machine via a service port. The host machine includes a virtual machine running a service system. The method includes:
[0011] In response to an access command input through the port of the business system, an address configuration command set is sent to the host machine through the business port;
[0012] In response to receiving a bridge address from the host machine, the network management platform is configured to route to the host machine based on the bridge address to obtain a first route;
[0013] Based on the first route, an access request is sent to the host machine so that the host machine authorizes the network management platform to access.
[0014] An embodiment of the third aspect of this disclosure provides a host access system, the system including a host machine and a network management platform connected via a service port of the host machine, the host machine including a virtual machine, and the virtual machine running a service system; wherein...
[0015] The network management platform is used to respond to access commands input through the port of the business system and send an address configuration command set to the host machine through the business port;
[0016] The host machine is used to configure the routing node address, which includes a bridge address and a virtual machine interface address, and to send the bridge address to the network management platform. The bridge corresponding to the bridge address is used to connect the virtual machine corresponding to the virtual machine interface address and the host machine.
[0017] The network management platform is further configured to configure a route from the network management platform to the host machine based on the bridge address to obtain a first route; and to send an access request to the host machine based on the first route.
[0018] The host machine is also used to connect the network management platform to the host machine according to the access request.
[0019] An embodiment of the fourth aspect of this disclosure provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the method described in the first or second aspect above.
[0020] An embodiment of the fifth aspect of this disclosure provides a computer-readable storage medium having a computer program stored thereon, the program being executed by a processor to implement the method described in the first or second aspect above.
[0021] The technical solutions provided in this disclosure have at least the following technical effects or advantages:
[0022] In this disclosed technical solution, the host machine is connected to the network management platform via a service port, meaning the network management platform is connected to the host machine's business system. Based on this, the network management platform can send an address configuration command set to the host machine through the service port to trigger the host machine to configure a routing node address. The routing node address includes a bridge address and a virtual machine interface address. The bridge is used to connect the host machine and the virtual machine; therefore, the bridge address can be used as the host machine's address, allowing the network management platform to construct a route to the host machine based on the bridge address, and then access the host machine based on this route. Therefore, this embodiment of the disclosure achieves automatic access to the host machine by sending commands from the network management platform to the host machine, which is not only convenient and saves manpower costs but also improves security.
[0023] Additional aspects and advantages of this disclosure will be set forth in part in the description which follows, and in part will be obvious from the description or may be learned by practice of this disclosure. Attached Figure Description
[0024] Various other advantages and benefits will become apparent to those skilled in the art upon reading the following detailed description of preferred embodiments. The accompanying drawings are for illustrative purposes only and are not intended to limit the scope of this disclosure. Furthermore, the same reference numerals denote the same parts throughout the drawings.
[0025] In the attached diagram:
[0026] Figure 1 A schematic diagram of a typical host machine access scenario is shown;
[0027] Figure 2 This diagram illustrates the structure of a host access system according to an embodiment of the present disclosure;
[0028] Figure 3A This illustration shows a flowchart of a host access method provided in an embodiment of the present disclosure. Figure 1 ;
[0029] Figure 3B This illustration shows a flowchart of a host access method provided in an embodiment of the present disclosure. Figure 2 ;
[0030] Figure 4 This diagram illustrates the signaling interaction of a host access method provided in an embodiment of the present disclosure.
[0031] Figure 5A A schematic diagram of the host access device provided in an embodiment of this disclosure is shown. Figure 1 ;
[0032] Figure 5B A schematic diagram of the host access device provided in an embodiment of this disclosure is shown. Figure 2 ;
[0033] Figure 6 A schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure is shown;
[0034] Figure 7 A schematic diagram of a storage medium provided according to an embodiment of the present disclosure is shown. Detailed Implementation
[0035] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.
[0036] It should be noted that, unless otherwise stated, the technical or scientific terms used in this disclosure shall have the ordinary meaning as understood by one of ordinary skill in the art to which this disclosure pertains.
[0037] The following describes the implementation scenarios and related technologies involved in the embodiments of this disclosure.
[0038] This disclosure relates to KVM technology scenarios, see references... Figure 1 The scenario diagram illustrates how KVM technology allows for the deployment of at least one virtual machine (VM) on a single physical device (i.e., the host machine). Each VM can run a business system. The host machine can be configured with interfaces for information transmission, including management ports, serial ports, and service ports. The management port transmits login credentials, configuration information, monitoring information, and system update information for managing and maintaining the host machine. It also supports remote login to the host machine via a network (e.g., a Secure Shell (SSH) protocol). The serial port, or serial communication interface, is used for communication between the host machine and external devices (such as consoles, modems, printers, etc.). In the KVM environment described in this disclosure, the serial port supports access to the host machine's console. The service port is the interface on the host machine used to handle business system traffic. It connects the VM to the external network for transmitting business communication data, such as web service data and database query data.
[0039] Since virtual machines run on a host machine, they involve the management, monitoring, and maintenance of business systems within the virtual machine. This requires accessing the host machine to collect status information such as the host machine's temperature, central processing unit (CPU), memory, and hard disk, in order to inspect, start and stop the virtual machine, and locate problems.
[0040] A common method for host machine access is as follows: Figure 1 As shown, maintenance personnel connect an external electronic device (such as a laptop) to the host machine via a serial port and management port, acting as a network management device. They then log in to the host machine via the serial port and configure the network address of the host machine's management port, thus directly accessing the host machine. However, this method is not only labor-intensive and inconvenient to operate, but also carries the risk of data leakage. Furthermore, when maintenance is needed, coordination with maintenance personnel is required, making it impossible to maintain the host machine's status in a timely manner. (See also...) Figure 1 It can be seen that the virtual machine accesses the network through the service port, and from a logical functional perspective, the virtual machine and the host machine can be considered as independent devices. Based on this, if the virtual machine automatically connects to the host machine via the network, the operations and maintenance personnel must pre-configure and maintain the network address of the management port via the serial port. Furthermore, the operations and maintenance personnel must pre-configure the network connection from the network management platform to the management port, and the network connecting to the host machine should be isolated from the network connected to the virtual machine. This not only still requires manpower, but also exposes the host machine's network interface to the network, posing a significant security risk. Additionally, it requires adding a network connection from the network management platform to the management port, increasing the network load.
[0041] The technical solution proposed in this disclosure involves a network management platform connected only to the host machine's business system, meaning the network management platform and the host machine share only one network connection. Subsequently, the network management platform sends configuration commands to the host machine, triggering the host machine to configure a bridge address. This allows for the creation of a route between the host machine and the bridge address, enabling automatic host machine access based on this route. This not only facilitates operation and saves manpower costs but also improves security.
[0042] The following describes a host access method, system, apparatus, electronic device, and storage medium according to embodiments of this disclosure. Specific embodiments are described in detail below. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. Embodiments of this disclosure will be described below with reference to the accompanying drawings.
[0043] See Figure 2 , Figure 2A schematic diagram of the structure of a host access system provided in an embodiment of the present disclosure is shown. The host access system may include a network management platform 1000 and a host 2000. The network management platform 1000 and the host 2000 are connected through the service port network of the host 2000.
[0044] The network management platform 1000 can be a standalone physical server, a server cluster consisting of multiple physical servers, a distributed system, a cloud platform, or cloud software. The network management platform 1000 can be configured to manage the network between the platform and virtual machines, as well as various network nodes. The network management platform 1000 can also be configured to read metadata from business systems based on service ports to manage the corresponding business systems, and can visualize the ports of the managed business systems through a user interface, thereby facilitating the operation and maintenance of the managed business systems. In this embodiment, the network management platform 1000 can also be configured to maintain a series of access commands and the sending strategy for these commands. In response to a trigger operation by the access host, it sends various commands to the host according to the sending strategy, instructing the host to configure itself according to the corresponding commands to meet the conditions for accessing the network management platform.
[0045] The host machine 2000 can be a standalone physical machine. At least one virtual machine can be deployed on the host machine 2000, and each virtual machine runs a business system. The host machine 2000 can create business function support modules (hereinafter referred to as function support modules) based on the business systems running in each of the at least one virtual machine. Optionally, the function support module can include multiple function plugins, and these function plugins can support different functions. The function support module can interact with the business system through the data channel within the host machine. Optionally, the data channel supports the transmission of data in a matching protocol format, which is determined through negotiation between the function support module and the business system.
[0046] At least one virtual machine has a management interface for each virtual machine. The host machine 2000 can connect to the management interface of the virtual machine via a bridge, allowing the virtual machine to access the host machine 2000. Specifically, the management interface of at least one virtual machine is connected to a bridge. For example, the management interface of virtual machine 01 is interface 001, which is connected to the host machine 2000 via bridge br0; the management interface of virtual machine 02 is interface 002, which is connected to the host machine 2000 via bridge br1.
[0047] In this embodiment, the host machine 2000 can respond to a series of access commands from the network management platform 1000, correspondingly configuring the network address of the virtual machine management interface, the network address of the bridge, and the route from the host machine 2000 to the network management platform 1000, to support the access of the network management platform 1000. It should be understood that the host machine 2000 receives various commands from the network management platform 1000 through the service port. Therefore, all commands received by the host machine 2000 are from the service system. For commands executed by the functional support module in the host machine 2000, the service system forwards them to the functional support module.
[0048] As can be seen, this implementation method integrates a series of configuration processes into the network management platform, triggering automatic access via commands, which saves labor costs. Furthermore, it eliminates the need for an additional network connection to the host machine, thus avoiding increased network connectivity complexity.
[0049] The following describes a host access method proposed according to an embodiment of this disclosure, in conjunction with the above implementation scenario and the accompanying drawings.
[0050] like Figure 3A As shown, this disclosure provides a host machine access method, which can be applied to a host machine, and the host machine can be implemented as follows: Figure 2 The host machine in the system is 2000. The method includes:
[0051] In step S311, the address configuration instruction set from the network management platform is received through the service port.
[0052] The address configuration instruction set is sent by the network management platform in response to the access instruction, which is input to the network management platform from the port of the business system.
[0053] As described above, the network management platform can manage at least one business system running on the host machine. For any given business system, after management, the network management platform can visualize the port of that business system on the interface. Furthermore, the network management platform can receive user-input access commands through a port of a business system, and transmit address configuration command sets to the host machine through a service port. It should be understood that the business system on the host machine that receives the address configuration command set can be the business system to which the port on the network management platform that receives access commands belongs. The implementation methods for the network management platform to manage at least one business system are detailed below and will not be elaborated here.
[0054] The address configuration instruction set includes a first address configuration instruction and a second address configuration instruction. In some embodiments, the host machine can receive both the first address configuration instruction and the second address configuration instruction. In other embodiments, the host machine can receive the first address configuration instruction, perform a configuration operation in response to the first address configuration instruction, and then receive the second address configuration instruction. In still other embodiments, the host machine can receive the second address configuration instruction, perform a configuration operation in response to the second address configuration instruction, and then receive the first address configuration instruction.
[0055] In step S312, the routing node address is configured according to the address configuration instruction set, wherein the routing node address includes the bridge address and the virtual machine interface address.
[0056] The bridge corresponding to the bridge address is used to connect the host machine and the virtual machine corresponding to the virtual machine interface address.
[0057] For example, the first address configuration instruction can instruct the configuration of the virtual machine interface address, and the second address configuration instruction can instruct the configuration of the bridge address.
[0058] In some embodiments, if the host machine receives a first address configuration instruction and a second address configuration instruction, it can utilize the business system to respond to the first address configuration instruction to configure a network address for the virtual machine's management interface, thereby obtaining the virtual machine interface address. Then, the business system encapsulates the second address configuration instruction into first encapsulated data conforming to a preset transmission protocol, and transmits the first encapsulated data to the host machine's functional support module via a data channel. The functional support module then configures the bridge address based on the first encapsulated data. Finally, the business system sends the bridge address and the virtual machine interface address to the network management platform.
[0059] In other embodiments, if the host machine first receives the first address configuration instruction, it can use the business system to respond to the first address configuration instruction to configure the network address for the management interface of the virtual machine, thereby obtaining the virtual machine interface address. Then, the business system sends the configuration result of the successfully configured virtual machine interface address to the network management platform. Furthermore, the business system can receive a second address configuration instruction, encapsulate the second address configuration instruction into first encapsulated data conforming to a preset transmission protocol, and transmit it through a data channel to the host machine's function support module. The function support module then configures the bridge address based on the first encapsulated data and sends the bridge address to the network management platform.
[0060] In some embodiments, if the host machine first receives a second address configuration instruction, the business system encapsulates the second address configuration instruction into first encapsulated data conforming to a preset transmission protocol, transmits it to the host machine's function support module through a data channel, and the function support module configures the bridge address based on the first encapsulated data. Then, the bridge address is sent to the network management platform. Alternatively, the host machine can receive a first address configuration instruction, and the business system responds to the first address configuration instruction to configure a network address for the virtual machine's management interface, obtaining the virtual machine interface address. Then, the configuration result of the virtual machine interface address is sent to the network management platform. The preset transmission protocol can be a transmission protocol supported by the data channel in the host machine, or a data transmission protocol determined through negotiation between the business system and the function support module.
[0061] In step S313, the bridge address is sent to the network management platform.
[0062] Sending the bridge address to the network management platform can trigger the network management platform to configure a first route. The first route refers to the route from the network management platform to the host machine. The starting node of the first route can be the network address of the network management platform, and the destination node can be the bridge address.
[0063] For example, the addresses involved in this disclosure can all be Internet Protocol (IP) addresses.
[0064] Furthermore, after sending the bridge address to the network management platform, the host machine can also receive a set of function configuration instructions from the network management platform, respond to the set of function configuration instructions, and configure the second route, account, password, and account access permissions. The second route is the route from the host machine to the network management platform, and the starting node of the second route can be the bridge address, and the destination node can be the network address of the network management platform.
[0065] Account access permissions could be configured, for example, to authorize the network management platform's IP address to access the account. This allows authorized network management platforms to access the host machine, while preventing unauthorized IP addresses from accessing it, thus ensuring the host machine's security.
[0066] The function configuration instruction set may include routing configuration instructions and access information configuration instructions. In some embodiments, the host machine may receive both routing configuration instructions and access information configuration instructions. In other embodiments, the host machine may receive routing configuration instructions, perform configuration operations in response to routing configuration instructions, and then receive access information configuration instructions. In still other embodiments, the host machine may receive access information configuration instructions, perform configuration operations in response to access information configuration instructions, and then receive routing configuration instructions.
[0067] It should be understood that the second route, account, password, and account access permissions should all be configured by the host machine's functional support module. Based on this, upon receiving the route configuration instruction, the host machine uses its business system to encapsulate the route configuration instruction to obtain second encapsulated data conforming to a preset transmission protocol; the second encapsulated data is then transmitted to the host machine's functional support module via a data channel, and the functional support module configures the second route based on the second encapsulated data. Upon receiving the access information configuration instruction, the host machine uses its business system to encapsulate the access information configuration instruction to obtain third encapsulated data conforming to a preset transmission protocol; the third encapsulated data is then transmitted to the host machine's functional support module via the data channel, and the functional support module configures the account, password, and account access permissions based on the third encapsulated data.
[0068] Access information configuration instructions may include login information configuration instructions and permission configuration instructions. In some embodiments, the host machine can receive both login information configuration instructions and permission configuration instructions. Then, the business system can first encapsulate the login information configuration instructions and transmit the encapsulated instructions to the functional support module. The functional support module can then configure the account and password. Next, the host machine, using the business system, further encapsulates the permission configuration instructions and transmits them to the functional support module, whereby the functional support module can configure account access permissions. In other embodiments, the host machine can first receive the login information configuration instructions. Correspondingly, the host machine uses the business system to encapsulate the login information configuration instructions and transmits them to the functional support module. The functional support module can then configure the account and password and provide feedback on the configured account to the business system. After the business system sends the configured account to the network management platform, it receives permission configuration instructions from the network management platform. Then, the host machine uses the business system to encapsulate the permission configuration instructions and transmits them to the functional support module, whereby the functional support module can configure account access permissions.
[0069] For example, the second encapsulated data, the third encapsulated data, the encapsulated login information configuration instruction, and the encapsulated permission configuration instruction can all be protocol data of the protocol supported by the data channel.
[0070] In practical implementation scenarios, the functional support module can include multiple functional plugins, each supporting the same functions. After receiving encapsulated data transmitted from the business system, the functional support module can call the functional plugin that matches the configuration instructions in the encapsulated data to execute the operation indicated by the corresponding configuration instructions. For example, after receiving the first encapsulated data, the functional support module can call the functional plugin that performs the routing configuration function to configure the second route in response to the routing configuration instructions in the first encapsulated data. Similarly, after receiving the second encapsulated data, the functional support module can call the functional plugin that performs the account and password configuration function to configure the account and password in response to the access information configuration instructions in the second encapsulated data.
[0071] In step S314, the network management platform is connected to the host machine according to the access request.
[0072] The access request is sent by the network management platform based on the first route.
[0073] In some embodiments, a remote connection link, such as an SSH link, can be established between the network management platform and the host machine. Then, messages are transmitted using the first and second routes described above based on the remote connection link, so that the network management platform can access the host machine.
[0074] For example, the host machine can respond to a command to establish a remote connection, constructing a remote connection link with the network management platform based on the first route and the second route. This command to establish the remote connection can be sent by the network management platform upon receiving confirmation that the host machine has configured the second route. The host machine receives a login command from the network management platform via the remote connection link. The login command includes a login account and a login password. Subsequently, the host machine can verify the login account and password. Specifically, the host machine can determine whether the login account matches the username and whether the login password matches the password. If the login account matches the username and the login password matches the password, the verification of the login account and password is considered successful. The host machine can then send login information to the network management platform via the remote connection link, enabling the network management platform to confirm access to the host machine.
[0075] It should be noted that the remote connection link is a communication link based on the remote transmission protocol, and information transmitted over the remote connection link needs to be forwarded by routing. Therefore, when the host machine receives a login command from the network management platform through the remote connection link, it is sent by the network management platform based on the first route; conversely, when the host machine sends login information to the network management platform through the remote connection link, it is sent by the host machine based on the second route.
[0076] It should be understood that the SSH link is merely illustrative and does not constitute a limitation on the embodiments disclosed herein. In actual implementation scenarios, the connection link between the network management platform and the host machine can also be implemented as a network connection link based on Secure FTP (SFTP) or a connection link based on Console over IP (CoIP), etc. The embodiments disclosed herein are not limited in this regard.
[0077] It should be noted that during the above configuration process, each time the host machine successfully configures a piece of information, it can send a feedback message indicating successful configuration to the network management platform through the service port, triggering the network management platform to execute subsequent operations. If the host machine fails to configure any piece of information, it can send a feedback message indicating configuration failure to the network management platform, causing the network management platform to terminate the configuration process.
[0078] As can be seen, by adopting this implementation method, the internal network bridge of the host machine is used as the routing node of the host machine, and the management interface of the virtual machine is used as the connection node between the service port and the host machine. This allows the network management platform to build a connection link to the host machine based on the network between the platform and the business system. Thus, commands can be sent to the host machine through the network management device to achieve automatic access to the host machine. This not only saves manpower costs, but also eliminates the need to add a network connection to the host machine.
[0079] Furthermore, after receiving an access request from the network management platform, the host machine can also receive a configuration clearing command from the network management platform, and clear at least one of the following: the configuration information of the first route, the configuration information of the second route, the account, the password, and the account access permissions.
[0080] In some embodiments, the host machine may clear the root node address (e.g., bridge address and virtual machine interface address), the account, and the password. In other embodiments, the host machine may clear all the aforementioned configured configuration information.
[0081] For example, if the host machine clears all the configuration information configured above, the host machine can clear them in reverse order according to the configuration order of each configuration information. For example, if the host machine configures the above configuration information in the order of virtual machine interface address, bridge address, account and password, and second route, then after receiving the configuration clearing command, the host machine will clear the second route, account and password, bridge address, and virtual machine interface address in sequence.
[0082] The configuration clearing command is sent by the network management platform when it detects that the remote connection link has been disconnected. This allows the host machine to clear all configuration information after the current maintenance is completed, preventing the exposure of network addresses and login accounts of the routing nodes on the host machine, thus improving network security.
[0083] like Figure 3B As shown, this disclosure provides a host access method, which can be applied to a network management platform. The network management platform can be implemented as follows: Figure 2 The network management platform 1000.
[0084] It should be pointed out that, Figure 3B Is with Figure 3A The implementation method of the network management platform corresponding to the implementation scenario shown is based on this, and in this embodiment, it is similar to... Figure 3A For the same or similar implementation methods, please refer to Figure 3A The descriptions in the corresponding embodiments are not repeated here.
[0085] The method includes:
[0086] In step S301, in response to the access command input through the port of the service system, an address configuration command set is sent to the host machine through the service port.
[0087] Among them, the port of the business system refers to the visual presentation of the business system operation entry on the interface of the network management platform after the business system on the host machine is managed by the network management platform.
[0088] It should be noted that at least one business system runs on the host machine, and each of these business systems runs within a virtual machine. Before receiving an access command input from a business system's port, the network management platform can receive metadata from the at least one business system running on the host machine via the service port, and generate a port for each of the at least one business system. In some embodiments, not all of the at least one business system may possess the remote access function of this disclosure embodiment. Based on this, the network management platform can determine and mark the business systems that support remote access function based on the metadata. Furthermore, the user can learn which ports can trigger remote access and the access command input through the marked business system's port to trigger the access processing of this disclosure embodiment.
[0089] Any metadata may include at least one of the following: functional description, model, version number, and working status of the corresponding business system. In some embodiments, the network management platform can determine whether the business system supports remote access functionality by the version number of the business system. For example, a business system with a version number lower than V1.0.5 (i.e., a relatively low version of the business system) does not have the remote access functionality of the present disclosure embodiment, while a business system with a version number higher than V1.0.5 has the remote access functionality of the present disclosure embodiment.
[0090] For ports of business systems with remote access capabilities, in some embodiments, the network management platform can use color to mark them. For example, the ports of business systems with remote access capabilities have a brighter color, while the ports of business systems without remote access capabilities have a dimmer color. In other embodiments, the network management platform can use symbols to mark them. For example, the ports of business systems with remote access capabilities are marked with a circular symbol in the upper right corner of the interface, while the ports of business systems without remote access capabilities are not marked with a circular symbol.
[0091] In step S302, in response to receiving the bridge address from the host machine, the route from the network management platform to the host machine is configured according to the bridge address to obtain the first route.
[0092] As described in the foregoing embodiments, the host machine configures the bridge address and virtual machine interface address according to the address configuration instruction set. The bridge corresponding to the bridge address is used to connect the virtual machine corresponding to the virtual machine interface address and the host machine, and the business system runs in the virtual machine. As described in the foregoing, the address configuration instruction set includes a first address configuration instruction and a second address configuration instruction. In some embodiments, the network management platform can send the first address configuration instruction and the second address configuration instruction together to the host machine, and then the network management platform can receive the bridge address and the virtual machine interface address. In other embodiments, the network management platform can first send the first address configuration instruction, receive the virtual machine interface address configured by the host machine in response to the first address configuration instruction, and then send the second address configuration instruction to the host machine. In still other embodiments, the network management platform can first send the second address configuration instruction, receive the bridge address configured by the host machine in response to the first address configuration instruction, and then send the first address configuration instruction to the host machine.
[0093] After the host machine receives the first address configuration instruction and the second address configuration instruction, the process of configuring the bridge address and the virtual machine interface address is detailed in the description of the above embodiments, and will not be repeated here.
[0094] Furthermore, after receiving the bridge address from the host machine, the network management platform can also send a set of function configuration instructions to the host machine to instruct the host machine to configure a second route, account, and password; the second route is the route from the host machine to the network management platform.
[0095] As described in the above embodiments, the function configuration instruction set includes routing configuration instructions and access information configuration instructions, and the access information configuration instructions may include login information configuration instructions and permission configuration instructions. In some embodiments, the network management platform may send both routing configuration instructions and access information configuration instructions to the host machine. In other embodiments, the network management platform may first send the access information configuration instructions to the host machine, and after receiving the account, password, and account access permissions from the host machine, then send the routing configuration instructions to the host machine. In still other embodiments, the network management platform may first send the login information configuration instructions to the host machine, and after receiving the account and password from the host machine, send the permission configuration instructions to the host machine, and after receiving the account access permissions from the host machine, then send the routing configuration instructions to the host machine.
[0096] After receiving the routing configuration command and access information configuration command, the host machine processes each configuration command and configures the second route, account, password and account access permissions. For details, please refer to the description in the above embodiment, which will not be repeated here.
[0097] During the above configuration process, the network management platform can receive feedback information from the host machine indicating whether the configuration of any information is successful or not. If the network management platform receives feedback information indicating successful configuration, it can continue to send subsequent configuration instructions to the host machine according to the configuration process. If the network management platform receives feedback information indicating failed configuration, it can end the configuration process.
[0098] As can be seen, by adopting this implementation method, a series of configuration commands and configuration processes are integrated into the network management platform. The network management platform sends configuration commands to the host machine according to the configuration process, which triggers the host machine to configure the information required for access. This eliminates the need for maintenance personnel to use an external PC for configuration, thus saving a lot of manpower costs.
[0099] In step S303, an access request is sent to the host machine based on the first route so that the host machine authorizes the network management platform to access.
[0100] After receiving feedback from the host machine that the second route has been successfully configured, the network management platform can send a command to the host machine to establish a remote connection. Based on the first and second routes, a remote connection link is established with the host machine. Then, the platform logs into the host machine using the login account and password through this remote connection link. Upon receiving login confirmation from the host machine, the platform confirms access to the host machine. This login confirmation is sent by the host machine after confirming that the login account matches the username and password; details are omitted here.
[0101] In some embodiments, after determining access to the host machine, the network management platform can periodically check the connection status of the remote connection link. If the remote connection link is disconnected, the network management platform can send a configuration clearing command to the host machine, instructing the host machine to clear at least one of the configuration information of the first route, the configuration information of the second route, the account, and the password. Examples of host machine clearing configuration information are detailed in the descriptions of the above embodiments and will not be repeated here.
[0102] For example, the remote connection link can disconnect in response to a user's trigger. For instance, from the moment the user logs into the host machine, the network management platform can always display the operation interface of the business system. If the user closes the operation interface, it can be considered that the maintenance of the host machine is over, and the remote connection link is disconnected.
[0103] In this way, a remote connection link will only be established when there is a need to maintain the host machine, and the remote connection link will be disconnected and the configuration information will be cleared after the maintenance is completed, which helps to improve security.
[0104] The following describes the host access method of this disclosure embodiment from the perspective of the interaction between the network management platform and the host machine, using exemplary implementation scenarios.
[0105] The connection method between the network management platform and the host machine can be found in [reference]. Figure 2 .like Figure 4 As shown in the example, the process of a network management platform accessing a host machine may include the following steps:
[0106] Step 41: The network management platform receives the access command input by the user through the port of the business system and sends the command to the business system to configure the virtual machine interface IP address.
[0107] Step 42: The business system configures the IP address for the virtual machine management interface. If the configuration is successful, it sends a configuration result indicating successful configuration to the network management platform and executes step S43. If the configuration fails, it sends a configuration result indicating failure to the network management platform and executes step 415.
[0108] Step 43: The network management platform sends a command to the business system to configure the bridge IP address.
[0109] Step 44: The business system encapsulates the instruction to configure the bridge IP address into protocol data and transmits it to the host machine's function support module through the data channel, so that the function support module can configure the bridge IP address.
[0110] If the configuration is successful, the configuration result and bridge IP address indicating successful configuration are sent to the network management platform, and step S45 is executed; if the configuration fails, the configuration result indicating failure is sent to the network management platform, and step 415 is executed.
[0111] Step 45: The network management platform configures the routing to the bridge IP address and sends login information configuration instructions to the business system.
[0112] Step 46: The business system encapsulates the login information configuration instructions into protocol data and transmits it to the host machine's function support module through the data channel, so that the function support module can configure the account and password.
[0113] If the configuration is successful, send the account and password to the network management platform and proceed to step S47; if the configuration fails, proceed to step 415.
[0114] Step 47: The network management platform sends instructions to the business system to configure access permissions.
[0115] Step 48: The business system encapsulates the instruction to configure access permissions into protocol data and transmits it to the function support module of the host machine through the data channel, so that the function support module can configure account access permissions.
[0116] If the configuration is successful, send a success message to the network management platform and proceed to step S49; if the configuration fails, proceed to step 415.
[0117] Step 49: The network management platform sends a command to the business system to configure the routing.
[0118] Step 410: The business system encapsulates the instruction for configuring access permissions into protocol data and transmits it to the function support module of the host machine through the data channel, so that the function support module can configure the routing of the bridge IP address to the network management platform.
[0119] If the configuration is successful, send a success message to the network management platform and execute step S411; if the configuration fails, execute step 415.
[0120] Step 411: The network management platform logs into the host machine using an account and password via the route to the bridge IP address. If the login is successful, proceed to step 412; if the login fails, proceed to step 415.
[0121] The network management platform considers the login successful if it receives a successful login notification. This successful login notification is sent from the host machine via the bridge IP address to the network management platform.
[0122] Step 412: The network management platform opens the operation interface corresponding to the business system and continuously checks whether the remote connection is in a connected state. If it is no longer in a connected state, proceed to step 413.
[0123] Step 413: The network management platform sends a command to the business system to clear the configuration information and clear the route to the bridge IP address.
[0124] Step 414: The business system responds to the instruction to clear configuration information, triggering the host machine to sequentially clear the route, account, bridge IP address, and virtual machine interface IP address from the bridge IP address to the network management platform.
[0125] Step 415, end configuration.
[0126] It should be understood that Figure 4 The host access method and related signaling interaction process shown are illustrative implementations of this disclosure and do not constitute a limitation on the implementation of the embodiments of this disclosure. In some other implementations, the network management platform may send some configuration instructions to the host together, or the network management platform may send the above configuration instructions in other sending orders. The embodiments of this disclosure are not limited in this respect.
[0127] In summary, in this disclosed technical solution, the host machine is connected to the network management platform via a service port, meaning the network management platform is connected to the host machine's business system. Based on this, the network management platform can send address configuration command sets to the host machine via the service port to trigger the host machine to configure routing node addresses. The routing node addresses include bridge addresses and virtual machine interface addresses. Since the bridge connects the host machine and the virtual machine, the bridge address can be used as the host machine's address, allowing the network management platform to construct a route to the host machine based on the bridge address, and then access the host machine based on this route. Therefore, this disclosed embodiment achieves automatic access to the host machine by sending commands from the network management platform to the host machine, which is not only convenient and saves manpower costs but also improves security.
[0128] This disclosure also provides a host access device in its embodiments. For example... Figure 5A As shown, Figure 5A The illustrated host access device can be deployed in the host machine to perform the operations corresponding to the host machine in any of the above embodiments. The device includes:
[0129] The receiving unit 501 is used to receive an address configuration instruction set from the network management platform through the service port. The address configuration instruction set is sent by the network management platform in response to an access instruction. The access instruction is input to the network management platform from the port of the service system.
[0130] Address configuration unit 502 is used to configure a routing node address according to the address configuration instruction set. The routing node address includes a bridge address and a virtual machine interface address. The bridge corresponding to the bridge address is used to connect the host machine and the virtual machine corresponding to the virtual machine interface address.
[0131] The sending unit 503 is used to send the bridge address to the network management platform so that the network management platform can configure a first route according to the bridge address, wherein the first route refers to the route from the network management platform to the host machine;
[0132] Access unit 504 connects the network management platform to the host machine according to an access request, wherein the access request is sent by the network management platform based on the first route.
[0133] In this embodiment of the disclosure, the device further includes a function configuration unit. The receiving unit 501 is further configured to receive a function configuration instruction set from the network management platform; the function configuration unit is configured to respond to the function configuration instruction set by configuring a second route, account, and password, wherein the second route is a route from the host machine to the network management platform.
[0134] In this embodiment of the disclosure, the access unit 504 is further configured to, in response to an instruction to establish a remote connection, establish a remote connection link with the network management platform based on the first route and the second route; receive a login instruction sent from the network management platform through the remote connection link, the login instruction including a login account and a login password; if it is determined that the login account is consistent with the account and the login password is consistent with the password, then send login information to the network management platform through the remote connection link so that the network management platform determines that it has accessed the host machine.
[0135] In this embodiment of the disclosure, the address configuration instruction set includes a first address configuration instruction. The receiving unit 501 is further configured to receive the first address configuration instruction through the service port using the service system. The address configuration unit 502 is further configured to respond to the first address configuration instruction using the service system and configure the virtual machine interface address for the management interface of the virtual machine.
[0136] In this embodiment of the disclosure, the address configuration instruction set further includes a second address configuration instruction. The receiving unit 501 is further configured to receive the second address configuration instruction through the service port using the service system. The address configuration unit 502 is further configured to encapsulate the second address configuration instruction into first encapsulated data conforming to a preset transmission protocol; transmit the first encapsulated data to the function support module of the host machine through a data channel; and configure the bridge address based on the first encapsulated data using the function support module.
[0137] In this embodiment of the disclosure, the function configuration instruction set includes routing configuration instructions and access information configuration instructions. The receiving unit 501 is further configured to, upon receiving the routing configuration instruction, encapsulate the routing configuration instruction using the business system to obtain second encapsulated data conforming to a preset transmission protocol; transmit the second encapsulated data to the function support module of the host machine through a data channel, and configure the second route using the function support module based on the second encapsulated data; upon receiving the access information configuration instruction, encapsulate the access information configuration instruction using the business system to obtain third encapsulated data conforming to a preset transmission protocol; transmit the third encapsulated data to the function support module of the host machine through the data channel, and configure the account and password using the function support module based on the third encapsulated data.
[0138] In this embodiment of the disclosure, the apparatus further includes a clearing unit. The receiving unit 501 is further configured to receive a configuration clearing instruction from the network management platform, the configuration clearing instruction being sent by the network management platform upon detecting a disconnection of the remote connection link; the clearing unit is configured to clear at least one of the configuration information of the first route, the configuration information of the second route, the account, and the password.
[0139] The host access device and the host access method provided in the above embodiments of this disclosure are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.
[0140] like Figure 5B As shown, Figure 5B The illustrated host access device can be deployed in a network management platform to perform the operations corresponding to the network management platform in any of the above embodiments. The device includes:
[0141] The sending unit 511 is used to send an address configuration instruction set to the host machine through the service port in response to an access command input through the port of the service system;
[0142] The routing configuration unit 512 is configured to, in response to receiving a bridge address from the host machine, configure a route from the network management platform to the host machine based on the bridge address to obtain a first route;
[0143] The sending unit 511 is also configured to send an access request to the host machine based on the first route, so that the host machine authorizes the network management platform to access.
[0144] In this embodiment of the disclosure, the sending unit 511 is further configured to send a set of function configuration instructions to the host machine to instruct the host machine to configure a second route, account and password; the second route is the route from the host machine to the network management platform.
[0145] In this embodiment of the disclosure, the sending unit 511 is further configured to send an instruction to the host machine to establish a remote connection; establish a remote connection link with the host machine based on the first route and the second route; log in to the host machine using a login account and login password through the remote connection link; and, after receiving the login information from the host machine, determine to access the host machine, wherein the login information is sent by the host machine after determining that the login account is consistent with the account and the login password is consistent with the password.
[0146] In this embodiment of the disclosure, the device further includes a connection detection unit. The connection detection unit is configured to periodically detect the connection status of the remote connection link; the sending unit 511 is further configured to send a configuration clearing command to the host machine if the remote connection link is in a disconnected state, to instruct the host machine to clear at least one of the configuration information of the first route, the configuration information of the second route, the account, and the password.
[0147] The host access device and the host access method provided in the above embodiments of this disclosure are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.
[0148] This disclosure also provides an electronic device for performing a host access method. Please refer to... Figure 6 This illustration shows a schematic diagram of an electronic device provided by some embodiments of the present disclosure. It should be noted that this electronic device can be implemented as a host machine or a network management platform. For example... Figure 6 As shown, the electronic device 6 includes: a processor 600, a memory 601, a bus 602, and a communication interface 603. The processor 600, the communication interface 603, and the memory 601 are connected via the bus 602. The memory 601 stores a computer program that can run on the processor 600. When the processor 600 runs the computer program, it executes the host access method provided in any of the foregoing embodiments of this disclosure.
[0149] The memory 601 may include high-speed random access memory (RAM) or non-volatile memory, such as at least one disk storage device. Communication between the virtual devices in the system is achieved through at least one communication interface 603 (which can be wired or wireless), such as the Internet, wide area network, local area network, or metropolitan area network.
[0150] Bus 602 can be an ISA bus, PCI bus, or EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. The memory 601 is used to store programs. After receiving an execution instruction, the processor 600 executes the program. The host access method disclosed in any of the foregoing embodiments of this disclosure can be applied to the processor 600, or implemented by the processor 600.
[0151] The processor 600 may be an integrated circuit chip with signal processing capabilities. In implementation, each step of the above method can be completed by the integrated logic circuitry in the hardware of the processor 600 or by instructions in software form. The processor 600 may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this disclosure. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of this disclosure can be directly embodied in the execution of a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software modules may reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other mature storage media in the art. The storage medium is located in memory 601. Processor 600 reads the information in memory 601 and, in conjunction with its hardware, completes the steps of the above method.
[0152] The electronic device provided in this disclosure and the host access method provided in this disclosure are based on the same inventive concept and have the same beneficial effects as the methods they adopt, operate or implement.
[0153] This disclosure also provides a computer-readable storage medium corresponding to the host access method provided in the foregoing embodiments. Please refer to... Figure 7 The computer-readable storage medium shown is an optical disc 30, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it executes the host access method provided in any of the foregoing embodiments.
[0154] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other optical and magnetic storage media, which will not be elaborated here.
[0155] The computer-readable storage medium provided in the above embodiments of this disclosure and the host access method provided in the embodiments of this disclosure are based on the same inventive concept and have the same beneficial effects as the methods adopted, run or implemented by the applications stored therein.
[0156] Although alternative embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make further changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0157] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of this application. It should be understood that the above description is only a specific embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of this application should be included within the scope of protection of this invention.
Claims
1. A host computer access method, characterized by, Applied to a host machine, wherein the host machine includes a virtual machine running a business system, and the host machine is connected to a network management platform through a business port, the method includes: The address configuration instruction set is received from the network management platform through the service port. The address configuration instruction set is sent by the network management platform in response to the access instruction. The access instruction is input to the network management platform from the port of the service system. Configure the routing node address according to the address configuration instruction set. The routing node address includes a bridge address and a virtual machine interface address. The bridge corresponding to the bridge address is used to connect the host machine and the virtual machine corresponding to the virtual machine interface address. Send the bridge address to the network management platform so that the network management platform can configure a first route based on the bridge address. The first route refers to the route from the network management platform to the host machine. The network management platform is connected to the host machine according to the access request, which is sent by the network management platform based on the first route.
2. The method according to claim 1, characterized in that, After sending the bridge address to the network management platform, the process also includes: Receive a set of function configuration instructions from the network management platform; In response to the function configuration instruction set, configure a second route, account and password, wherein the second route is the route from the host machine to the network management platform.
3. The method according to claim 2, characterized in that, The step of connecting the network management platform to the host machine according to the access request includes: In response to the instruction to establish a remote connection, a remote connection link with the network management platform is established based on the first route and the second route; The system receives a login command from the network management platform via the remote connection link. The login command includes a login account and a login password. If it is determined that the login account is consistent with the account and the login password is consistent with the password, then the login information is sent to the network management platform through the remote connection link so that the network management platform can determine that it has accessed the host machine.
4. The method according to claim 1, characterized in that, The address configuration instruction set includes a first address configuration instruction, and receiving the address configuration instruction set from the network management platform through the service port includes: The business system receives the first address configuration instruction through the business port. The step of configuring the routing node address according to the address configuration instruction set includes: The business system responds to the first address configuration instruction to configure the virtual machine interface address for the virtual machine's management interface.
5. The method according to claim 4, characterized in that, The address configuration instruction set further includes a second address configuration instruction, and receiving the address configuration instruction set from the network management platform through the service port further includes: The business system receives the second address configuration instruction through the business port; The step of configuring the routing node address according to the address configuration instruction set further includes: The second address configuration instruction is encapsulated into first encapsulated data that conforms to a preset transmission protocol; The first packaged data is transmitted to the host machine's functional support module via a data channel; The function support module is used to configure the bridge address based on the first encapsulation data.
6. The method according to claim 2, characterized in that, The function configuration instruction set includes routing configuration instructions and access information configuration instructions, and the method further includes: Upon receiving the routing configuration instruction, the business system encapsulates the routing configuration instruction to obtain second encapsulated data conforming to a preset transmission protocol; The second encapsulated data is transmitted to the host machine's functional support module via a data channel, and the functional support module configures the second route based on the second encapsulated data. After receiving the access information configuration instruction, the business system encapsulates the access information configuration instruction to obtain third encapsulated data that conforms to the preset transmission protocol; The third encapsulated data is transmitted to the host machine's functional support module through the data channel, and the functional support module configures the account and password based on the third encapsulated data.
7. The method according to claim 3, characterized in that, After connecting the network management platform to the host machine according to the access request, the process further includes: Receive a configuration clearing command from the network management platform, which is sent by the network management platform when it detects that the remote connection link is disconnected; Clear at least one of the following: the configuration information of the first route, the configuration information of the second route, the account, and the password.
8. A host machine access method, characterized in that, Applied to a network management platform, the network management platform connects to a host machine via a service port, the host machine includes virtual machines, and the virtual machines run a service system; the method includes: In response to an access command input through the port of the business system, an address configuration command set is sent to the host machine through the business port; In response to receiving a bridge address from the host machine, the network management platform is configured to route to the host machine based on the bridge address to obtain a first route; Based on the first route, an access request is sent to the host machine so that the host machine authorizes the network management platform to access.
9. The method according to claim 8, characterized in that, Following the receipt of the bridge address from the host machine, the process also includes: A set of function configuration instructions is sent to the host machine to instruct the host machine to configure a second route, account, and password; the second route is the route from the host machine to the network management platform.
10. The method according to claim 9, characterized in that, The access request to the host machine based on the first route includes: Send instructions to the host machine to establish a remote connection; A remote connection link with the host machine is established based on the first route and the second route; Log in to the host machine using the login account and password via the remote connection link; After receiving the login information from the host machine, the system determines to access the host machine. The login information is sent by the host machine after confirming that the login account matches the account and the login password matches the password.
11. The method according to claim 10, characterized in that, After sending an access request to the host machine based on the first route, the process further includes: Periodically check the connection status of the remote connection link; If the remote connection link is disconnected, a configuration clearing command is sent to the host machine to instruct the host machine to clear at least one of the configuration information of the first route, the configuration information of the second route, the account, and the password.
12. A host access system, characterized in that, The system includes a host machine and a network management platform connected via a service port of the host machine. The host machine includes virtual machines, and the virtual machines run the service system. The network management platform is used to respond to access commands input through the port of the business system and send an address configuration command set to the host machine through the business port; The host machine is used to configure the routing node address, which includes a bridge address and a virtual machine interface address, and to send the bridge address to the network management platform. The bridge corresponding to the bridge address is used to connect the virtual machine corresponding to the virtual machine interface address and the host machine. The network management platform is further configured to configure a route from the network management platform to the host machine based on the bridge address to obtain a first route; and to send an access request to the host machine based on the first route; The host machine is also used to connect the network management platform to the host machine according to the access request.