A private network NAT cross-virtual private cloud interconnection access method and device

By obtaining binding requests and establishing port mapping relationships through the target NAT gateway, the network latency and security issues in cross-tenant access are resolved. This enables flexible concurrent access and secure isolation of private network NAT across virtual private clouds, improving network performance and scalability.

CN119892399BActive Publication Date: 2026-05-29CHINA TELECOM CLOUD TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CLOUD TECH CO LTD
Filing Date
2024-12-06
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

Existing technologies suffer from problems such as increased network latency, reduced network bandwidth, impact on network high availability, increased operational and maintenance difficulty, increased security risks, and higher investment costs in cross-tenant access. In particular, when private network NAT is used for cross-virtual private cloud interconnection access, it is impossible to achieve flexible concurrent access and secure isolation.

Method used

By obtaining the binding request of the second tenant through the target NAT gateway, recording the binding relationship, and establishing port mapping relationship, flexible access and security control across tenants can be achieved, including SNAT and DNAT operations, to ensure network performance and scalability.

Benefits of technology

It enables flexible concurrent access across tenants while maintaining secure isolation between private clouds, improving network performance and scalability, and ensuring network security and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119892399B_ABST
    Figure CN119892399B_ABST
Patent Text Reader

Abstract

The application relates to a cloud computing network and discloses a private network NAT cross-virtual private cloud interconnection access method and device. The method is executed by a target NAT gateway. The target NAT gateway corresponds to a first tenant. The method comprises the following steps: obtaining a binding request of a second tenant; the binding request is used for binding a port of the second tenant to the target NAT gateway; if the first tenant allows the binding request of the second tenant, a binding relationship is recorded; the binding relationship is used for indicating that the first tenant allows to select the port of the second tenant when an access rule is configured. The application realizes flexible and concurrent access between cross tenants, meanwhile, the security isolation between private clouds is maintained, and the network performance and expansibility are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cloud computing network technology, and specifically to a method and apparatus for private network NAT interconnection and access across virtual private clouds. Background Technology

[0002] Currently, while accessing the local VPC via cross-tenant access to the remote private network IP resolves IP address conflicts, it cannot directly use the remote private network VPC IP for SNAT and DNAT. It relies on peering connections, increasing network latency, reducing bandwidth, impacting network high availability, increasing maintenance complexity, and potentially introducing security risks. Peering connections provide high-speed point-to-point connections within the private network without address translation, offering good security, but have limited connection limits, require significant bandwidth, are complex to configure, and cannot communicate without a direct VPC connection. Private network NAT enables one-to-many dynamic connections, is simple to configure, consumes little bandwidth, and allows communication while maintaining VPC isolation, but does not support point-to-point static connections. Therefore, existing technologies suffer from technical drawbacks such as increased network latency, reduced bandwidth, compromised network high availability, increased maintenance complexity, increased security risks, and higher investment costs. Summary of the Invention

[0003] In view of this, the present invention provides a method and apparatus for private network NAT interconnection and access across virtual private clouds, which realizes flexible concurrent access between tenants, while maintaining secure isolation between private clouds, and improves network performance and scalability.

[0004] In a first aspect, the present invention provides a method for private network NAT interconnection access across virtual private clouds, the method being executed by a target NAT gateway; the target NAT gateway corresponds to a first tenant, and the method includes: obtaining a binding request from a second tenant; the binding request being used to bind the port of the second tenant to the target NAT gateway; if the first tenant allows the binding request of the second tenant, then recording the binding relationship; the binding relationship being used to instruct the first tenant to allow the selection of the port of the second tenant when configuring access rules.

[0005] In one alternative implementation, the binding request includes: a local port and a remote NAT identifier.

[0006] In one optional implementation, if the first tenant allows the second tenant's binding request, the binding relationship is recorded, including:

[0007] Send a port binding message to the first tenant; the port binding message includes the binding task ID and the policy ID;

[0008] Receive the result message returned by the first tenant; the result message includes the allow / deny instruction and the corresponding reason code.

[0009] In one alternative implementation, the method further includes:

[0010] Establish the first mapping relationship; the first mapping relationship is used to indicate that the target port is mapped to the first port of the first host; the target port is the port of the second host; the first host is the host within the private network of the target NAT gateway;

[0011] Obtain the first request message for accessing the target port;

[0012] According to the first mapping relationship, the target address of the first request message is translated to the first port of the first host, so as to forward the request message to the first host.

[0013] In one optional implementation, the source IP and source MAC in the outer Underlay header of the first request message are the physical network card information of the host that sent the first request message; the source IP and source MAC in the inner Overlay header of the first request message are the gateway information of the subnet of the host that sent the first request message.

[0014] In one alternative implementation, the method further includes:

[0015] Establish a second mapping relationship; the second mapping relationship is used to map the source address from the third host to the external address.

[0016] Obtain the second request message for accessing the external network initiated by the third host;

[0017] According to the second request message, translate the source IP and source MAC in the Overlay of the second request message to the external address;

[0018] Use the translated source address and encapsulate the virtual link of the host of the tenant where the target NAT gateway is located to forward the second request message.

[0019] In one optional implementation, the outer Underlay source address of the encapsulated second request message is the physical network interface card (NIC) information of the third host; the inner Overlay source address is the logical NIC information of the third host.

[0020] Secondly, the present invention provides a private network NAT cross-virtual private cloud interconnection access device, the device comprising:

[0021] The request retrieval module is used to retrieve the binding request of the second tenant; the binding request is used to bind the port of the second tenant to the target NAT gateway.

[0022] The binding record module is used to record the binding relationship if the first tenant allows the second tenant's binding request; the binding relationship is used to indicate to the first tenant that the second tenant's port can be selected when configuring access rules.

[0023] Thirdly, the present invention provides a computer device, comprising: a memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to perform a private network NAT cross-virtual private cloud interconnection access method according to the first aspect or any corresponding embodiment described above.

[0024] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions for causing a computer to execute a private network NAT cross-virtual private cloud interconnection access method according to the first aspect or any corresponding embodiment described above.

[0025] Fifthly, the present invention provides a computer program product, including computer instructions, which are used to cause a computer to execute a private network NAT cross-virtual private cloud interconnection access method according to the first aspect above or any corresponding embodiment thereof.

[0026] The technical solution provided by this invention may include the following beneficial effects:

[0027] This invention provides a method for private network NAT cross-virtual private cloud interconnection and access, executed by a target NAT gateway, which corresponds to a first tenant. A binding request from a second tenant is obtained. This binding request binds the second tenant's port to the target NAT gateway, serving as the first step in cross-tenant access and laying the foundation for subsequent SNAT and DNAT operations, enabling flexible resource allocation and dynamic network expansion. The first tenant approves the second tenant's binding request to prevent unauthorized access and ensure the security of cross-tenant access. Recording the binding relationship provides the first tenant with a selection basis when configuring access rules. Through this binding relationship, the first tenant can select the second tenant's port when configuring access rules, achieving flexible concurrent access between tenants while maintaining secure isolation between private clouds, improving network performance and scalability. Attached Figure Description

[0028] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the drawings used in the description of the specific embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0029] Figure 1 This is a flowchart of a private network NAT cross-virtual private cloud interconnection access method provided by an embodiment of the present invention;

[0030] Figure 2This is a flowchart illustrating, according to an exemplary embodiment, the binding of a port of a remote VPC in the control plane to the NAT of the local VPC private network;

[0031] Figure 3 This is a flowchart illustrating a DNAT implementation method according to an exemplary embodiment;

[0032] Figure 4 This is a flowchart illustrating an SNAT implementation method according to an exemplary embodiment;

[0033] Figure 5 This is a schematic diagram of the structure of a private network NAT cross-virtual private cloud interconnection access device provided in an embodiment of the present invention;

[0034] Figure 6 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention. Detailed Implementation

[0035] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0036] It should be understood that the term "instruction" mentioned in the embodiments of the present invention can be a direct instruction, an indirect instruction, or an indication of an association. For example, A instructing B can mean that A directly instructs B, for example, B can be obtained through A; it can also mean that A indirectly instructs B, for example, A instructs C, B can be obtained through C; or it can mean that there is an association between A and B.

[0037] In the description of the embodiments of the present invention, the term "correspondence" may indicate that there is a direct or indirect correspondence between the two, or that there is an association between the two, or that there is a relationship of instruction and being instructed, configuration and being configured, etc.

[0038] In this embodiment of the invention, "predefined" can be achieved by pre-storing corresponding codes, tables or other means that can be used to indicate relevant information in the device (e.g., including terminal devices and network devices). The invention does not limit the specific implementation method.

[0039] According to an embodiment of the present invention, a method for private network NAT interconnection access across virtual private clouds is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0040] This embodiment provides a method for private network NAT to interconnect and access across virtual private clouds. Figure 1 This is a flowchart of a private network NAT cross-virtual private cloud interconnection access method according to an embodiment of the present invention, such as... Figure 1 As shown, the method is executed by the target NAT gateway; the target NAT gateway corresponds to the first tenant, and the method flow includes the following steps:

[0041] Step S101: Obtain the binding request of the second tenant; the binding request is used to bind the port of the second tenant to the target NAT gateway.

[0042] A NAT (Network Address Translation) gateway is a network device used to translate addresses between private and public networks. NAT allows devices within an internal network (private network) to use private IP addresses, while translating these private IP addresses into public IP addresses when communicating with external networks (such as the Internet). In this embodiment, the target NAT gateway refers to the NAT gateway corresponding to the first tenant, which handles network address translation and access control related to the first tenant and performs operations related to the first tenant.

[0043] The target NAT gateway receives a binding request from the second tenant. This binding request binds the second tenant's port to the target NAT gateway. The first tenant can then access the second tenant through the target NAT gateway without needing additional network elements or complex routing configurations. Here, the first tenant refers to an independent entity that owns its own private resources (such as virtual machines, servers, storage, etc.) within the network environment. The second tenant is another independent entity; unlike the first tenant, the second tenant's resources may reside in a different virtual private cloud. The second tenant's port refers to the specific interface within the second tenant's private resources used for network communication.

[0044] Step S102: If the first tenant allows the second tenant's binding request, then record the binding relationship; the binding relationship is used to indicate to the first tenant that the second tenant's port can be selected when configuring access rules.

[0045] If the first tenant allows the second tenant's binding request, the target NAT gateway will record this binding relationship. A binding relationship is an association or mapping established between the two tenants after the first tenant allows the second tenant's binding request. The binding relationship instructs the target NAT gateway, when configuring access rules, to allow the first tenant to select the second tenant's port as the access target, providing a secure and controllable channel for cross-tenant communication. It clearly defines which ports can be accessed, as well as the access permissions and conditions. Binding relationships help maintain network security and stability.

[0046] In summary, through the binding relationship, the first tenant can select the port of the second tenant when configuring access rules, realizing flexible concurrent access between tenants, while maintaining the security isolation between private clouds, and improving network performance and scalability.

[0047] Optionally, before step S101 above, a policy ID is confirmed based on the policy name, tenant ID, and target NAT ID. The policy name is an identifier used to identify the target NAT gateway's access policy. The tenant ID is an identifier used to uniquely identify the tenant requesting binding, ensuring accurate identification of which tenant initiated the binding request. The target NAT ID is an identifier used to uniquely identify the target NAT gateway, indicating which NAT gateway is the target of the binding request. The policy ID is a unique identifier generated after verifying and accepting the binding request, representing the record of this binding operation at the policy control level. This implementation determines which tenants have permission to bind to the target NAT gateway and returns a policy ID to identify this binding operation, ensuring the security of network resources.

[0048] In one alternative implementation, the binding request in step S101 above includes: local port and remote NAT identifier.

[0049] The local port refers to the specific port that the second tenant wants to bind to on the first tenant's NAT gateway. In network communication, a port is a logical address used to distinguish different services and applications. The remote NAT identifier is an identifier used to uniquely identify the first tenant's NAT gateway, including the NAT gateway's IP address, name, or other attributes that uniquely identify the NAT gateway.

[0050] In this implementation, the local port specifies the specific port that the second tenant wants to bind to, while the remote NAT identifier is used to uniquely identify the NAT gateway of the first tenant and is the basis for establishing a private network NAT binding relationship across tenants.

[0051] In an optional implementation, if the first tenant allows the second tenant's binding request, step S102 above involves recording the binding relationship, including:

[0052] Step S1021: Send a port binding message to the first tenant; the port binding message includes the binding task ID and the policy ID.

[0053] The binding task ID is a unique identifier used to identify the current binding request and its associated processing flow. The policy ID is a unique identifier set by the first tenant for the private network NAT access policy. By providing the policy ID, it's possible to verify whether the second tenant's binding request complies with the access rules and security policies set by the first tenant. Providing both the binding task ID and the policy ID ensures the accuracy of the request.

[0054] Step S1022: Receive the result message returned by the first tenant; the result message includes an allow / deny instruction and the corresponding reason code.

[0055] The allow / deny instruction indicates whether the first tenant agrees to the second tenant's binding request. If the first tenant denies the binding request, the reason code will provide the specific reason for the denial. The second tenant can understand the reason for the denial based on the reason code and may take appropriate measures to resolve the issue or adjust the request. Receiving the allow / deny instruction and reason code ensures the validity of the binding relationship and provides a basis for subsequent network communication.

[0056] like Figure 2 As shown, the process of binding the port of the remote VPC (private cloud) in the control plane to the NAT of the local VPC private network is as follows:

[0057] Tenant A and Tenant B reside in two separate VPCs. Tenant A possesses private network NAT resources. Tenant B invokes the bind private network NAT interface, requesting to bind a port to Tenant A's NAT. The bind interface first verifies the policy, retrieving policy information from Tenant A. Based on the policy, it determines whether to accept the binding request. If verification and determination pass, Tenant A is prompted to accept or reject the port binding to the private network NAT; if accepted, the binding relationship is recorded. Based on the recorded binding relationship, when configuring access rules on Tenant A's NAT, port B can be selected.

[0058] In one alternative implementation, the method further includes:

[0059] Step S201: Establish a first mapping relationship; the first mapping relationship is used to indicate that the target port is mapped to the first port of the first host; the target port is the port of the second host; the first host is a host in the private network of the target NAT gateway.

[0060] A DNAT (Destination Network Address Translation) rule is defined, a technique that translates the destination address of a data packet from an external address to an internal address. A first mapping relationship is established to guide packet forwarding and address translation. This mapping relationship maps the destination port (i.e., the port of the second host) to the first port of the first host. The first host refers to the host within the private network of the target NAT gateway, while the destination port originally belonged to the second host. However, after mapping, requests to access that port will be redirected to the first port of the first host.

[0061] Step S202: Obtain the first request message for accessing the target port.

[0062] Retrieves network requests that attempt to access the previously defined target port.

[0063] Step S203: According to the first mapping relationship, the target address of the first request message is translated to the first port of the first host, so as to forward the request message to the first host.

[0064] Based on the previously established mapping relationship, the acquired request message undergoes address translation and is forwarded to the correct host. Specifically, the destination address of the request message is modified from the original destination port (the port of the second host) to the first port of the first host, and then the modified message is forwarded to the first host.

[0065] For example, such as Figure 3 As shown, a DNAT rule is established on the private network NAT-A instance, for example, mapping the target port Port-B:8080 to internal host A:8080. Any request attempting to access Port-B:8080 will be redirected by the NAT device to port 8080 of internal host A. When host A (or other external host) initiates an access request to Port-B:8080, this request packet will be captured by the NAT device. On the NAT-A instance, according to the predefined DNAT rule (such as mapping Port-B:8080 to internal host A:8080), the target address of the request packet accessing Port-B:8080 is translated to port 8080 of internal host A. NAT-A then forwards the modified packet to internal host A, completing the end-to-end access request.

[0066] This implementation method is a complete process of DNAT translation: first, a mapping relationship is established, then access requests are captured, and finally, address translation is performed and requests are forwarded according to the mapping relationship, so that external users can indirectly access hosts in the private network of the NAT gateway by accessing a specific external port (target port) without directly exposing the real address of the internal host.

[0067] In one optional implementation, the source IP and source MAC in the outer Underlay header of the first request message are the physical network card information of the host that sent the first request message; the source IP and source MAC in the inner Overlay header of the first request message are the gateway information of the subnet of the host that sent the first request message.

[0068] The first request message is encapsulated in two layers during transmission: an outer layer (Underlay header) and an inner layer (Overlay header).

[0069] The source IP and source MAC addresses in the outer (underlay header) contain information about the physical network interface card (NIC) of the host that sent the first request packet. The NIC is the physical interface through which a host directly connects to the network, and it has a unique MAC address and an IP address typically assigned by a subnet. This information is used for routing and forwarding at the lower network layer (underlay network) to ensure that packets reach the correct next-hop device.

[0070] The source IP and source MAC addresses in the inner (overlay header) header contain gateway information for the subnet of the host that sent the first request packet. In an overlay network, packets are typically routed through logical gateways, which may not directly correspond to physical network devices. Therefore, the source IP and source MAC addresses in the inner header are actually the logical representation of the host's subnet within the overlay network, used for routing and forwarding at the overlay layer.

[0071] The source IP and source MAC information in the outer Underlay header and inner Overlay header of the request message in this embodiment are important identifiers when the message is transmitted and routed in the network. They together determine how the message is correctly processed and forwarded.

[0072] In one alternative implementation, the method further includes:

[0073] Step S301: Establish a second mapping relationship; the second mapping relationship is used to map the source address from the third host to the external address.

[0074] SNAT, or Source Network Address Translation, is a technique that translates the source address of a data packet from an internal address to an external address. It proposes a second mapping relationship, mapping the source address from a third-party host (internal host) to an external address. When the third-party host accesses the external network, its real internal IP address is hidden, and a public or external IP address is used instead, thus achieving address translation and hiding.

[0075] Step S302: Obtain the second request message for accessing the external network initiated by the third host.

[0076] When a third host needs to access an external network, it sends a second request message. This second request message includes the third host's source IP address and source MAC address, as well as the destination IP address and destination MAC address.

[0077] Step S303: According to the second request message, translate the source IP and source MAC in the Overlay of the second request message to the external address.

[0078] Upon receiving a request message from a third host, the source IP address and source MAC address in the Overlay portion of the request message are translated into external addresses based on the previously established second mapping relationship. When the request message reaches the external network, the external network receives the translated external address, not the third host's actual internal address.

[0079] Step S304: Use the converted source address and encapsulate the virtual link of the host of the tenant where the target NAT gateway is located to forward the second request message.

[0080] After the address translation is completed, the translated request message is encapsulated with the virtual link information of the host of the tenant where the target NAT gateway is located, and the message is forwarded to ensure that the request message can correctly reach the target network or server through the virtual link.

[0081] For example, such as Figure 4 As shown, an SNAT rule SNAT-1 is created on the private network NAT-A instance, mapping the source address from internal host B (third-party host) to the external address Port-C. Host B (third-party host) initiates a request packet to access the Internet. After the packet arrives at NAT-A, the source IP and MAC address in the overlay are translated to Port-C according to the SNAT-1 rule. NAT-A uses the translated source address Port-C, encapsulates host A's VLAN, and sends the packet across the VPC. The server on the Internet receives the request with the source address Port-C and sends a response. The response packet arrives at the public interface of NAT-A, looks up the session table, restores the original overlay source address, and sends it to internal host B. Host B receives the SNAT-translated response packet and completes the access.

[0082] This implementation is an SNAT process that hides and translates the source address when an internal host accesses an external network, while ensuring the correct forwarding and reception of request packets.

[0083] In one optional implementation, the outer Underlay source address of the encapsulated second request message is the physical network interface card (NIC) information of the third host; the inner Overlay source address is the logical NIC information of the third host.

[0084] The outer underlay source address is used to identify the physical origin of a packet within the network. The outer underlay source address is the physical network interface card (NIC) information of the third host. The physical NIC is the interface through which a host directly connects to a physical network (such as Ethernet), and its address is typically a unique identifier for that host within the physical network.

[0085] The inner overlay source address is used to logically identify the origin of a packet. In cloud environments, overlay networks are typically used to build virtual networks on top of physical networks to enable VPC interconnection across physical networks. The inner overlay source address is the logical network interface card (NIC) information of the third-party host. A logical NIC is a virtual interface of a host within the overlay network; its address is assigned within the overlay network and is used to logically distinguish different VPCs and hosts.

[0086] This implementation reflects the address information of messages during encapsulation and transmission, as well as the role of this address information at the physical and logical network layers, ensuring secure and efficient transmission of messages between VPCs.

[0087] This invention also provides a download process control device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0088] This invention provides a download process control device. Figure 5 This is a schematic diagram of a download process control device provided in an embodiment of the present invention. The device includes:

[0089] The request acquisition module 501 is used to obtain the binding request of the second tenant; the binding request is used to bind the port of the second tenant to the target NAT gateway;

[0090] The binding record module 502 is used to record the binding relationship if the first tenant allows the second tenant's binding request; the binding relationship is used to indicate to the first tenant that the second tenant's port can be selected when configuring access rules.

[0091] In an optional implementation, the request acquisition module 501 is further configured to:

[0092] Local port and remote NAT identifier.

[0093] In one optional implementation, the binding record module 502 includes:

[0094] The first binding record unit is used to send port binding messages to the first tenant; the port binding message includes the binding task ID and the policy ID;

[0095] The second binding record unit is used to receive the result message returned by the first tenant; the result message includes an allow / deny instruction and the corresponding reason code.

[0096] In one optional embodiment, the apparatus further includes a target mapping module, which comprises:

[0097] The first target mapping unit is used to establish a first mapping relationship; the first mapping relationship is used to indicate that the target port is mapped to the first port of the first host; the target port is the port of the second host; the first host is a host within the private network of the target NAT gateway;

[0098] The second target mapping unit is used to obtain the first request message for accessing the target port;

[0099] The third target mapping unit is used to translate the target address of the first request message to the first port of the first host according to the first mapping relationship, so as to forward the request message to the first host.

[0100] In an optional implementation, the target mapping module is further configured to:

[0101] The source IP and source MAC in the outer Underlay header of the first request message are the physical network card information of the host that sent the first request message; the source IP and source MAC in the inner Overlay header of the first request message are the gateway information of the subnet of the host that sent the first request message.

[0102] In one alternative embodiment, the apparatus further includes a source mapping module, which includes:

[0103] The first source mapping unit is used to establish the second mapping relationship; the second mapping relationship is used to map the source address from the third host to the external address.

[0104] The second source mapping unit is used to obtain the second request message for accessing the external network initiated by the third host;

[0105] The third source mapping unit is used to translate the source IP and source MAC in the Overlay of the second request message to an external address according to the second request message;

[0106] The fourth source mapping unit is used to use the translated source address and encapsulate the virtual link of the host of the tenant where the target NAT gateway is located to forward the second request message.

[0107] In an alternative implementation, the source mapping module is further configured to:

[0108] The outer Underlay source address of the second request message encapsulation is the physical network interface card (NIC) information of the third host; the inner Overlay source address is the logical NIC information of the third host.

[0109] Further functional descriptions of the above modules and units are the same as those in the corresponding embodiments described above, and will not be repeated here.

[0110] In this embodiment, the download process control device is presented in the form of a functional unit. Here, a unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that execute one or more software or fixed programs, and / or other devices that can provide the above functions.

[0111] This invention also provides a computer device having the above-described features. Figure 5 The diagram shows a private network NAT interconnection access device across virtual private clouds.

[0112] Please see Figure 6 , Figure 6 This is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present invention, such as... Figure 6 As shown, the computer device includes one or more processors 10, memory 20, and interfaces for connecting the components, including high-speed interfaces and low-speed interfaces. The components communicate with each other via different buses and can be mounted on a common motherboard or otherwise installed as needed. The processors can process instructions executed within the computer device, including instructions stored in or on memory to display graphical information in a graphical user interface on an external input / output device (such as a display device coupled to the interface). In an alternative implementation, multiple processors and / or multiple buses can be used with multiple memories and multiple memory modules, if desired. Similarly, multiple computer devices can be connected, each providing some of the necessary operations (e.g., as a server array, a group of blade servers, or a multiprocessor system). Figure 6 Take a processor 10 as an example.

[0113] Processor 10 may be a central processing unit, a network processor, or a combination thereof. Processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CAMP), a field-programmable gate array (FPGA), a general-purpose array logic (GPA), or any combination thereof.

[0114] The memory 20 stores instructions executable by at least one processor 10 to cause at least one processor 10 to perform the method shown in the above embodiments.

[0115] The memory 20 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computer device. Furthermore, the memory 20 may include high-speed random access memory and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In an optional embodiment, the memory 20 may optionally include memory remotely located relative to the processor 10, and these remote memories can be connected to the computer device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0116] The memory 20 may include volatile memory, such as random access memory; the memory may also include non-volatile memory, such as flash memory, hard disk or solid-state drive; the memory 20 may also include a combination of the above types of memory.

[0117] The computer device also includes an input device 30 and an output device 40. The processor 10, memory 20, input device 30, and output device 40 can be connected via a bus or other means. Figure 5 Taking the example of a connection between China and Israel via a bus.

[0118] This invention also provides a computer-readable storage medium. The methods described above according to embodiments of the invention can be implemented in hardware or firmware, or implemented as computer code that can be recorded on a storage medium, or implemented as computer code downloaded via a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code, which, when accessed and executed by the computer, processor, or hardware, implements the methods shown in the above embodiments.

[0119] A portion of this invention can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to the invention through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.

[0120] Although embodiments of the invention have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the invention, and such modifications and variations all fall within the scope defined by the appended claims.

Claims

1. A method for private network NAT interconnection and access across virtual private clouds, characterized in that, The method is executed by the target NAT gateway; The target NAT gateway corresponds to the first tenant, and the method includes: Obtain the binding request of the second tenant; the binding request is used to bind the port of the second tenant to the target NAT gateway; If the first tenant allows the second tenant's binding request, the binding relationship is recorded; the binding relationship is used to indicate that the first tenant is allowed to select the second tenant's port when configuring access rules, wherein the first tenant and the second tenant are different tenants, the first tenant refers to an independent entity that has its own private resources in the network environment, and the second tenant refers to another independent entity whose resources are located in a different virtual private cloud; Establish a first mapping relationship; the first mapping relationship is used to indicate that the target port is mapped to the first port of the first host; the target port is the port of the second host; the first host is a host within the private network of the target NAT gateway; Obtain the first request message for accessing the target port; Based on the first mapping relationship, the target address of the first request message is translated to the first port of the first host, so as to forward the request message to the first host without directly exposing the real address of the internal host.

2. The method according to claim 1, characterized in that, The binding request includes: the local port and the remote NAT identifier.

3. The method according to claim 2, characterized in that, If the first tenant allows the second tenant's binding request, then recording the binding relationship includes: Send a port binding message to the first tenant; the port binding message includes a binding task ID and a policy ID; Receive the result message returned by the first tenant; the result message includes an allow / deny instruction and the corresponding reason code.

4. The method according to claim 1, characterized in that, The source IP and source MAC in the outer Underlay header of the first request message are the physical network card information of the host that sent the first request message; the source IP and source MAC in the inner Overlay header of the first request message are the gateway information of the subnet of the host that sent the first request message.

5. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Establish a second mapping relationship; the second mapping relationship is used to map the source address from the third host to an external address; Obtain the second request message for accessing the external network initiated by the third host; According to the second request message, translate the source IP and source MAC in the Overlay of the second request message to the external address; The converted source address is used, and the virtual link of the host of the tenant where the target NAT gateway is located is encapsulated to forward the second request message.

6. The method according to claim 5, characterized in that, The outer Underlay source address of the second request message encapsulated is the physical network interface card (NIC) information of the third host; the inner Overlay source address is the logical NIC information of the third host.

7. A private network NAT cross-virtual private cloud interconnection access device, characterized in that, The device includes: The request acquisition module is used to acquire the binding request of the second tenant; the binding request is used to bind the port of the second tenant to the target NAT gateway; The binding record module is used to record the binding relationship if the first tenant allows the binding request of the second tenant; the binding relationship is used to indicate that the first tenant allows the selection of the port of the second tenant when configuring access rules, wherein the first tenant and the second tenant are different tenants, the first tenant refers to an independent entity that has its own private resources in the network environment, and the second tenant refers to another independent entity whose resources are located in a different virtual private cloud; The target mapping module is used to establish a first mapping relationship; the first mapping relationship is used to indicate that the target port is mapped to the first port of the first host; the target port is the port of the second host; the first host is a host within the private network of the target NAT gateway; obtain the first request packet to access the target port; according to the first mapping relationship, translate the target address of the first request packet to the first port of the first host, so as to forward the request packet to the first host without directly exposing the real address of the internal host.

8. A computer device, characterized in that, include: A memory and a processor are interconnected and communicate with each other. The memory stores computer instructions, and the processor executes the computer instructions to perform the private network NAT cross-virtual private cloud interconnection access method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to execute the private network NAT cross-virtual private cloud interconnection access method according to any one of claims 1 to 6.