Cloud service access method, communication device and system
By processing ARP requests in the home gateway and generating forwarding rules for the layer 2 bridge channel, the problems of home network complexity and operation and maintenance costs in the prior art are solved, and the effect of simplifying deployment and reducing operation and maintenance costs is achieved.
Patent Information
- Application Number
- CN202311455275.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-02
- Publication Date
- 2025-05-06
AI Technical Summary
In the existing optical communication technology, the complexity of the home network and the operation and maintenance costs of the operator are relatively high. Especially during the cloud service access process, it is necessary to deploy VxLAN tunnel endpoints (VTEP) in the optical network terminals (ONTs) of the home network, which increases the complexity and operation and maintenance costs of the system.
By receiving ARP requests from terminal devices in the home gateway and sending ARP requests to the cloud service gateway, forwarding rules for the layer 2 bridge channel between the terminal device and the cloud service gateway are generated, which simplifies the deployment and operation and maintenance process of the home network.
This method does not require additional features on ONT, simplifies the deployment of home networks, reduces operator operation and maintenance costs, and improves the security of cloud services.
Smart Images

Figure CN119945834A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of optical communication technology, and in particular to a cloud service access method, communication device and system. Background Art
[0002] With the development of virtualization technology, operators have gradually increased the deployment of cloud computing resources to provide users with storage and computing services, such as home-oriented cloud network attached storage (NAS) and cloud desktop services. However, due to the limitation of physical location, devices in the home network need to go through access and metropolitan area networks to access the service devices in the data center virtual network. The networking is complex and involves many physical network elements.
[0003] Optical network terminal (ONT) is a network device that users use to access the operator's network through optical fiber. How users can efficiently and securely access cloud services through ONT has become a problem. Generally, the cloud access channel adopts the Layer 2 network message forwarding mode. The typical technology is to access cloud services based on the virtual extensible LAN (VxLAN) tunnel. In the current solution of using VxLAN tunnel to access cloud services, it is necessary to deploy VxLAN tunnel end point (VTEP) in the ONT of the home network, which increases the complexity of the home network and the operation and maintenance cost of the operator. Summary of the invention
[0004] The embodiments of the present application provide a cloud service access method, a communication device, and a system for reducing the complexity of a home network and reducing the operation and maintenance costs of an operator.
[0005] In the first aspect, an embodiment of the present application provides a cloud service access method, which is applied to a home gateway, including: receiving an Address Resolution Protocol ARP request from a terminal device, the ARP request carrying the IP address of the terminal device, the Media Access Control MAC address of the terminal device, and the virtual IP address of the cloud service to be accessed, and the virtual IP address is configured for the terminal device to access the cloud service; the ARP request is used to request the Media Access Control MAC address corresponding to the virtual IP address; sending the ARP request to a cloud service gateway; receiving an ARP response from the cloud service gateway, the ARP response carrying the MAC address of the cloud service gateway corresponding to the virtual IP address; generating a forwarding rule for a Layer 2 bridge channel for data transmission between the terminal device and the cloud service gateway according to the IP address of the terminal device, the Media Access MAC address of the terminal device, the virtual IP address of the cloud service to be accessed, and the MAC address of the cloud service gateway; and sending the ARP response to the terminal device.
[0006] In the above embodiments of the present application, there is no need to add additional functions on the ONT. A layer 2 bridge channel is created between the terminal device and the cloud service gateway by combining the virtual IP address for accessing the cloud service, so that the terminal device can use the virtual IP address allocated for the cloud service and the created layer 2 bridge channel, and access the cloud service through the ONT, which can simplify the deployment of the home network and reduce the operation and maintenance costs.
[0007] In a possible implementation, a virtual IP address used by a terminal device belonging to the home gateway to access the cloud service is associated with the home gateway.
[0008] In a possible implementation, the virtual IP addresses used by terminal devices belonging to the same home gateway to access the cloud service are the same, and the virtual IP addresses used by terminal devices belonging to different home gateways to access the cloud service are different.
[0009] In a possible implementation, the virtual IP addresses used by terminal devices belonging to the same home gateway to access the cloud service are the same, and the virtual IP addresses used by terminal devices belonging to different home gateways to access the cloud service are the same.
[0010] In the above method, the IP address of the cloud service seen by all households is the same IP address, which can further simplify the configuration of the operator's massive ONTs and further reduce operation and maintenance costs. In addition, the IP address of the cloud service seen by the vCPE corresponding to different home gateways is also the same IP address, which can further simplify the deployment of the operator's private cloud.
[0011] In a possible implementation, the virtual IP address is a private network IP address configured for a terminal device of the home gateway to access the cloud service.
[0012] In the above method, the IP addresses of the cloud services seen by all households are private IP addresses, and the real IP addresses of the cloud servers are no longer exposed to the outside world (i.e., terminal devices), which can improve the security of the cloud services.
[0013] In one possible implementation, the method also includes: receiving a first data packet from a terminal device, the first data packet being used to request access to the cloud service, the first data packet carrying the IP address of the terminal device, the MAC address of the terminal device, the virtual IP address, and the MAC address of the cloud service gateway; and sending the first data packet to the cloud service gateway according to the forwarding rule.
[0014] In the above method, all household user traffic accesses the cloud service using a virtual IP address and forwards the traffic through a Layer 2 bridge channel, simplifying ONT deployment and reducing operation and maintenance costs.
[0015] In a possible implementation, the cloud service gateway includes N virtual client devices vCPE that provide services for the N home gateways respectively, and the MAC address is the MAC address of the vCPE corresponding to the home gateway. In the above method, the ONT creates a layer 2 bridge channel between the terminal device and the vCPE corresponding to the home gateway to which the terminal device belongs, and forwards traffic through the layer 2 bridge channel, thereby simplifying the deployment of the ONT and reducing operation and maintenance costs.
[0016] In a possible implementation, sending the ARP request to the cloud service gateway includes:
[0017] The ARP request is sent to the vCPE corresponding to the home gateway through the optical access device; the ARP request also carries the user-side virtual local area network CVLAN tag to which the home gateway belongs; the CVLAN tag is used by the optical access device to forward the ARP request to the cloud service gateway.
[0018] In the above method, the optical access device can distinguish different households through CVLAN, so that users can forward the ARP or traffic of different households to the vSwitch of the cloud service gateway.
[0019] In a possible implementation, the method further includes: receiving a Dynamic Host Configuration Protocol DHCP request from the terminal device, the DHCP request being used to request the home gateway to allocate an IP address to the terminal device; sending the IP address of the terminal device to the terminal device; and the APR request also carrying the IP address of the terminal device.
[0020] In the above implementation, the terminal device inherits the original IP address acquisition behavior and obtains the address from the ONT local DHCP server. That is, the home gateway allocates the IP address to the terminal device.
[0021] In a possible implementation, the method further includes:
[0022] Receive the virtual IP address or virtual IP address segment of the cloud service indicated by the network management device;
[0023] The IP address of the terminal device is in the same network segment as the virtual IP address of the cloud service, and the IP address of the terminal device is an IP address in the IP address pool of the home gateway other than the virtual IP address or virtual IP address segment.
[0024] The network management device instructs the home gateway to reserve the virtual IP address (or virtual IP address segment) of the cloud service in advance to ensure that the home gateway will not allocate the virtual IP address (or virtual IP address segment) to the terminal device after allocating an IP address to the terminal device to prevent conflicts.
[0025] In a second aspect, an embodiment of the present application provides a cloud service access method, which is applied to an optical access device, including:
[0026] Receive an Address Resolution Protocol ARP request sent by a home gateway, the ARP request carries the IP address of a terminal device managed by the home gateway, the Media Access Control MAC address of the terminal device, and a virtual IP address of a cloud service to be accessed, the virtual IP address being configured for the terminal device managed by the home gateway to access the cloud service; the ARP request is used to request the MAC address corresponding to the virtual IP address; send the ARP request to a cloud service gateway; receive an ARP response from the cloud service gateway, the ARP response carries the MAC address corresponding to the virtual IP address; send the ARP response to the home gateway, the MAC address is used by the home gateway to generate forwarding rules for a Layer 2 bridge channel between the created terminal device and the cloud service gateway.
[0027] In the above design, the OLT provides services for the creation of a Layer 2 bridge channel between the terminal device and the cloud service gateway. In some embodiments, the OLT also generates forwarding rules for the Layer 2 bridge channel between the terminal device and the cloud service gateway. Thus, no additional functions need to be added to the ONT. Home users can access cloud services through the Layer 2 bridge channel, which can simplify the deployment of home networks and reduce operation and maintenance costs.
[0028] In one possible implementation, the cloud service gateway includes a virtual switch; the ARP request also carries a user-side virtual local area network CVLAN tag to which the home gateway belongs; sending the ARP request to the cloud service gateway includes: forwarding the ARP request to the virtual switch according to the CVLAN tag.
[0029] In the above design, different CVLAN tags are configured for different home gateways, and a transmission channel is created between the OLT and the virtual switch through the CVLAN tags.
[0030] In a possible implementation manner, forwarding the ARP request to the virtual switch according to the CVLAN tag includes:
[0031] Switch the CVLAN tag in the ARP request to an SVLAN tag of the service provider virtual local area network to which the virtual switch belongs to obtain an updated ARP request, and send the updated ARP request to the virtual switch; or
[0032] An SVLAN tag to which the vCPE corresponding to the home gateway belongs is added to the ARP request to obtain an updated ARP request, and the updated ARP request is sent to the virtual switch.
[0033] In one possible implementation, the cloud service gateway includes a virtual switch; a data transmission channel is established between the optical access device and the virtual switch, and the data transmission channel is a VxLAN channel or a segment routing SRV6 channel based on the IPv6 forwarding plane; sending the ARP request to the cloud service gateway includes: sending the ARP request to the virtual switch through the data transmission channel.
[0034] In the above design, a VxLAN channel or a segment routing SRV6 channel based on the IPv6 forwarding plane is created between the OLT and the virtual switch to increase the number of homes in the LAN Layer 2 supported in the network.
[0035] In a third aspect, an embodiment of the present application provides a cloud service access method, which is applied to a cloud service gateway, including:
[0036] Receiving an Address Resolution Protocol (ARP) request from a home gateway, the ARP request carrying an IP address of a terminal device managed by the home gateway, a MAC address of the terminal device, and a virtual IP address of a cloud service to be accessed, the virtual IP address being configured for the terminal device to access the cloud service; the ARP request is used to request a media access control MAC address corresponding to the virtual IP address;
[0037] An ARP response is sent to the home gateway, where the ARP carries a MAC address corresponding to the virtual IP address, and the MAC address is used by the home gateway to generate forwarding rules for a layer 2 bridge channel between the terminal device and the cloud service gateway created.
[0038] In one possible implementation, a first data packet is received from a terminal device through a Layer 2 bridge channel, the first data packet carrying the IP address of the terminal device and the virtual IP address of a cloud service to be accessed, the IP address of the terminal device serving as the source IP address, and the virtual IP address of the cloud service serving as the destination IP address; the source IP address in the first data packet is converted into the IP address of a cloud service gateway, and the destination IP address is converted into the IP address of a cloud server providing the cloud service to obtain an updated first data packet; and the updated first data packet is sent to the cloud server.
[0039] In the above method, the cloud service gateway forwards user traffic (i.e. data packets) to the cloud server through two NAPT technologies. For terminal devices and other cloud devices, there is no need to know the IP address of the cloud server. Other cloud-related devices only need to know the virtual IP address, which can improve the security of cloud services.
[0040] In one possible implementation, the method also includes: receiving a second data packet sent by the cloud server, the second data packet carrying the IP address of the cloud service gateway and the IP address of the cloud server of the cloud service; using the IP address of the cloud service gateway as the destination IP address and the IP address of the cloud server as the source IP address; converting the destination IP address in the second data packet into the virtual IP address of the cloud service, and converting the source IP address into the IP address of the terminal device to obtain an updated second data packet; and sending the updated second data packet to the terminal device through the Layer 2 bridging channel.
[0041] In a possible implementation, the cloud service gateway includes a plurality of vCPEs corresponding to different home gateways, and the IP address of the cloud service gateway is the IP address of the VCPE.
[0042] In the above method, the downlink traffic is also forwarded through the NAPT technology, and there will be no conflict between the traffic of different users.
[0043] In a fourth aspect, an embodiment of the present application provides a network system, including a first home gateway and a cloud service gateway;
[0044] The first home gateway is used for an address resolution protocol ARP request from a terminal device, the ARP request carries an IP address of the terminal device, a media access control MAC address of the terminal device, and a virtual IP address of a cloud service to be accessed, the virtual IP address being configured for the terminal device to access the cloud service; the ARP request is used to request a media access control MAC address corresponding to the virtual IP address; and the ARP request is sent to the cloud service gateway;
[0045] The cloud service gateway is used to send an ARP response to the first home gateway, where the ARP response carries the MAC address of the cloud service gateway corresponding to the virtual IP address;
[0046] The first home gateway is also used to generate forwarding rules for the Layer 2 bridge channel used for data transmission between the terminal device and the cloud service gateway based on the IP address of the terminal device, the media access MAC address of the terminal device, the virtual IP address of the cloud service to be accessed, and the MAC address of the cloud service gateway; and send the ARP response to the terminal device.
[0047] In one possible implementation, the virtual IP address used by terminal devices belonging to the same home gateway to access the cloud service is the same, and the virtual IP addresses used by terminal devices belonging to different home gateways to access the cloud service are different; or, the virtual IP address used by terminal devices belonging to the same home gateway to access the cloud service is the same, and the virtual IP addresses used by terminal devices belonging to different home gateways to access the cloud service are the same.
[0048] In one possible implementation, the network system also includes a second home gateway; the virtual IP address used by terminal devices belonging to the first home gateway to access the cloud service is different from the virtual IP address used by terminal devices belonging to the second home gateway to access the cloud service; or, the virtual IP address used by terminal devices belonging to the first home gateway to access the cloud service is the same as the virtual IP address used by terminal devices belonging to the second home gateway to access the cloud service.
[0049] In a possible implementation, the virtual IP address is a private network IP address configured for a terminal device of the first home gateway to access the cloud service.
[0050] In a possible implementation, the first home gateway is further used to receive a first data message from a terminal device, where the first data message is used to request access to the cloud service, and the first data message carries an IP address of the terminal device, a MAC address of the terminal device, the virtual IP address, and a MAC address of the cloud service gateway; and send the first data message to the cloud service gateway according to the forwarding rule;
[0051] The cloud service gateway is further used to receive the first data message.
[0052] In a possible implementation, the cloud service gateway includes a virtual customer premises equipment vCPE providing services for the first home gateway;
[0053] The vCPE is used to convert the source IP address in the first data message into the IP address of the cloud service gateway, and convert the destination IP address into the IP address of the cloud server providing the cloud service, so as to obtain an updated first data message;
[0054] Send the updated first data message to the cloud server.
[0055] In a possible implementation, the cloud service gateway includes a virtual customer premises equipment vCPE providing services for the first home gateway;
[0056] The vCPE is used to receive a second data message from the cloud server; the second data message carries the IP address of the vCPE and the IP address of the cloud server of the cloud service; the IP address of the vCPE is used as the destination IP address, and the IP address of the cloud server is used as the source IP address; the destination IP address in the second data message is converted into the virtual IP address of the cloud service, and the source IP address is converted into the IP address of the terminal device to obtain an updated second data message; and the updated second data message is sent to the first home gateway;
[0057] The first home gateway is further configured to send the updated second data message to the terminal device according to the forwarding rule.
[0058] In a possible implementation, the cloud service gateway includes N virtual client devices vCPE that respectively provide services for the N first home gateways, and the MAC address is the MAC address of the vCPE corresponding to the first home gateway.
[0059] In a possible implementation, the system further includes an optical access device, and the cloud service gateway includes a virtual switch;
[0060] The first home gateway is specifically used to send the ARP request to the optical access device, wherein the ARP request also carries a user-side virtual local area network CVLAN tag to which the first home gateway belongs;
[0061] The optical access device is used to forward the ARP request to the virtual switch according to the CVLAN tag.
[0062] In a possible implementation manner, the optical access device is specifically used to:
[0063] Switch the first CVLAN tag in the ARP request to the second VLAN tag to which the virtual switch belongs to obtain an updated ARP request, and send the updated ARP request to the virtual switch; or
[0064] A second VLAN tag to which the vCPE corresponding to the first home gateway belongs is added to the ARP request to obtain an updated ARP request, and the updated ARP request is sent to the virtual switch.
[0065] In a possible implementation, the system further includes an optical access device, and the cloud service gateway includes a virtual switch; a data transmission channel is established between the optical access device and the virtual switch, and the data transmission channel is a VxLAN channel or a segment routing SRV6 channel based on an IPv6 forwarding plane;
[0066] The first home gateway is specifically configured to send the ARP request to the optical access device;
[0067] The optical access device is used to send the ARP request to the virtual switch through a data transmission channel.
[0068] In a fifth aspect, an embodiment of the present application provides a communication device, applied to a home gateway, including:
[0069] A receiving unit, configured to receive an address resolution protocol ARP request from a terminal device, wherein the ARP request carries an IP address of the terminal device, a media access control MAC address of the terminal device, and a virtual IP address of a cloud service to be accessed, wherein the virtual IP address is configured for the terminal device to access the cloud service; and the ARP request is used to request a media access control MAC address corresponding to the virtual IP address;
[0070] A sending unit, configured to send the ARP request to the cloud service gateway;
[0071] The receiving unit is further configured to receive an ARP response from the cloud service gateway, wherein the ARP response carries a MAC address of the cloud service gateway corresponding to the virtual IP address;
[0072] a processing unit, configured to generate a forwarding rule for a layer 2 bridge channel for data transmission between the terminal device and the cloud service gateway according to an IP address of the terminal device, a media access MAC address of the terminal device, a virtual IP address of the cloud service to be accessed, and a MAC address of the cloud service gateway;
[0073] The sending unit is further used to send the ARP response to the terminal device.
[0074] In a possible implementation, the virtual IP addresses used by terminal devices belonging to the same home gateway to access the cloud service are the same, and the virtual IP addresses used by terminal devices belonging to different home gateways to access the cloud service are different.
[0075] In a possible implementation, the virtual IP addresses used by terminal devices belonging to the same home gateway to access the cloud service are the same, and the virtual IP addresses used by terminal devices belonging to different home gateways to access the cloud service are the same.
[0076] In the above method, the IP address of the cloud service seen by all households is the same IP address, which can further simplify the configuration of the operator's massive ONTs and further reduce operation and maintenance costs. In addition, the IP address of the cloud service seen by the vCPE corresponding to different home gateways is also the same IP address, which can further simplify the deployment of the operator's private cloud.
[0077] In a possible implementation, the virtual IP address is a private network IP address configured for a terminal device of the home gateway to access the cloud service.
[0078] In the above method, the IP addresses of the cloud services seen by all households are private IP addresses, and the real IP addresses of the cloud servers are no longer exposed to the outside world (i.e., terminal devices), which can improve the security of the cloud services.
[0079] In one possible implementation, the receiving unit is also used to receive a first data packet from a terminal device, where the first data packet is used to request access to the cloud service, and the first data packet carries the IP address of the terminal device, the MAC address of the terminal device, the virtual IP address, and the MAC address of the cloud service gateway; the sending unit is also used to send the first data packet to the cloud service gateway according to the forwarding rule.
[0080] In a possible implementation, the processing unit includes N virtual client devices vCPE that respectively provide services for the N home gateways, and the MAC address is the MAC address of the vCPE corresponding to the home gateway.
[0081] In one possible implementation, the sending unit is used to send the ARP request to the vCPE corresponding to the home gateway through an optical access device; the ARP request also carries a user-side virtual local area network CVLAN tag to which the home gateway belongs; the CVLAN tag is used by the optical access device to forward the ARP request to the cloud service gateway.
[0082] In a possible implementation, the receiving unit is further used to receive a Dynamic Host Configuration Protocol DHCP request from the terminal device, the DHCP request being used to request the home gateway to allocate an IP address to the terminal device. The sending unit is further used to send the IP address of the terminal device to the terminal device; the APR request also carries the IP address of the terminal device.
[0083] In one possible implementation, the receiving unit is also used to receive the virtual IP address or virtual IP address segment of the cloud service indicated by the network management device; the IP address of the terminal device is the same as the network segment to which the virtual IP address of the cloud service belongs, and the IP address of the terminal device is an IP address in the IP address pool of the home gateway except the virtual IP address or virtual IP address segment.
[0084] In a sixth aspect, an embodiment of the present application provides a communication device, applied to an optical access device, including:
[0085] A receiving unit, used for receiving an Address Resolution Protocol ARP request sent by a home gateway, wherein the ARP request carries the IP address of a terminal device managed by the home gateway, the Media Access Control MAC address of the terminal device, and a virtual IP address of a cloud service to be accessed, wherein the virtual IP address is configured for the terminal device managed by the home gateway to access the cloud service; the ARP request is used to request the MAC address corresponding to the virtual IP address; a sending unit, used for sending the ARP request to a cloud service gateway; the receiving unit, further used for receiving an ARP response from the cloud service gateway, wherein the ARP response carries the MAC address corresponding to the virtual IP address; the sending unit, further used for sending the ARP response to the home gateway, wherein the MAC address is used by the home gateway to generate forwarding rules for a Layer 2 bridge channel between the created terminal device and the cloud service gateway.
[0086] In one possible implementation, the cloud service gateway includes a virtual switch; the ARP request also carries a user-side virtual local area network CVLAN tag to which the home gateway belongs; and a sending unit, used to send the ARP request to the cloud service gateway, includes: forwarding the ARP request to the virtual switch according to the CVLAN tag.
[0087] In a possible implementation, the processing unit is configured to switch the CVLAN tag in the ARP request to an SVLAN tag of a service provider virtual local area network to which the virtual switch belongs to obtain an updated ARP request. The sending unit is configured to send the updated ARP request to the virtual switch.
[0088] In a possible implementation, the processing unit is configured to add the SVLAN tag to which the vCPE corresponding to the home gateway belongs to the ARP request to obtain an updated ARP request. The sending unit is configured to send the updated ARP request to the virtual switch.
[0089] In a possible implementation, the cloud service gateway includes a virtual switch; a data transmission channel is established between the optical access device and the virtual switch, and the data transmission channel is a VxLAN channel or a segment routing SRV6 channel based on an IPv6 forwarding plane. A sending unit is configured to send the ARP request to the virtual switch through the data transmission channel.
[0090] In a seventh aspect, an embodiment of the present application provides a communication device, applied to a cloud service gateway, including:
[0091] A receiving unit is used to receive an address resolution protocol ARP request from a home gateway, wherein the ARP request carries the IP address of a terminal device managed by the home gateway, the MAC address of the terminal device, and the virtual IP address of a cloud service to be accessed, wherein the virtual IP address is configured for the terminal device to access the cloud service; the ARP request is used to request a media access control MAC address corresponding to the virtual IP address. A sending unit is used to send an ARP response to the home gateway, wherein the ARP carries the MAC address corresponding to the virtual IP address, and the MAC address is used by the home gateway to generate forwarding rules for a Layer 2 bridge channel between the terminal device and the cloud service gateway.
[0092] In one possible implementation, a receiving unit is used to receive a first data packet from a terminal device through a Layer 2 bridge channel, the first data packet carrying the IP address of the terminal device and the virtual IP address of a cloud service to be accessed, the IP address of the terminal device serving as the source IP address, and the virtual IP address of the cloud service serving as the destination IP address; a processing unit is used to convert the source IP address in the first data packet into the IP address of a cloud service gateway, and convert the destination IP address into the IP address of a cloud server providing the cloud service, so as to obtain an updated first data packet; and a sending unit is used to send the updated first data packet to the cloud server.
[0093] In a possible implementation, the receiving unit is used to receive a second data message sent by the cloud server, the second data message carries the IP address of the cloud service gateway and the IP address of the cloud server of the cloud service; the IP address of the cloud service gateway is used as the destination IP address, and the IP address of the cloud server is used as the source IP address. The processing unit is used to convert the destination IP address in the second data message into the virtual IP address of the cloud service, and convert the source IP address into the IP address of the terminal device, so as to obtain an updated second data message; the sending unit is used to send the updated second data message to the terminal device through the Layer 2 bridge channel.
[0094] In a possible implementation, the cloud service gateway includes a plurality of vCPEs corresponding to different home gateways, and the IP address of the cloud service gateway is the IP address of the VCPE.
[0095] Exemplarily, the above-mentioned communication device is applied to a cloud service gateway, and may be applied to a vCPE.
[0096] In some possible scenarios, the cloud service gateway further includes a virtual switch, which is used to continue to send the first data message to the vCPE of the home gateway through the layer 2 bridge channel.
[0097] In an eighth aspect, an embodiment of the present application provides a communication device, comprising: a processor and a memory; the memory stores a computer program; the processor is used to execute the computer program stored in the memory, so that the method described in the first aspect or any implementation of the first aspect is executed, or the method described in the second aspect or any implementation of the second aspect is executed, or the method described in the third aspect or any implementation of the third aspect is executed.
[0098] In the ninth aspect, an embodiment of the present application provides a computer-readable storage medium storing instructions, which, when executed by a processor, causes the method described in the first aspect or any implementation of the first aspect to be executed, or causes the method described in the second aspect or any implementation of the second aspect to be executed, or causes the method described in the third aspect or any implementation of the third aspect to be executed.
[0099] In the tenth aspect, an embodiment of the present application provides a computer program product. When the computer program product runs on a device, the device executes the method described in the first aspect or any implementation of the first aspect, or executes the method described in the second aspect or any implementation of the second aspect, or executes the method described in the third aspect or any implementation of the third aspect.
[0100] In the eleventh aspect, an embodiment of the present application provides a chip system, which includes at least one processor, a memory and an interface circuit, wherein the interface circuit is used to provide information input / output for the at least one processor, and the memory stores a computer program. When the computer program runs on one or more processors, the method described in the first aspect or any possible implementation of the first aspect is executed, or the method described in the second aspect or any possible implementation of the second aspect is executed, or the method described in the third aspect or any possible implementation of the third aspect is executed.
[0101] Based on the implementations provided in the above aspects, the present application can also be further combined to provide more implementations. BRIEF DESCRIPTION OF THE DRAWINGS
[0102] Figure 1 A schematic diagram of a network connection scenario provided in an embodiment of the present application;
[0103] Figure 2 A schematic diagram of the architecture of a network system provided in an embodiment of the present application;
[0104] Figure 3 A network connection diagram provided for an embodiment of the present application;
[0105] Figure 4 A schematic diagram of the architecture of a network system provided in an embodiment of the present application;
[0106] Figure 5 A schematic diagram of a cloud service access method flow provided in an embodiment of the present application;
[0107] Figure 6 A schematic diagram of a cloud service access process combined with a network system provided in an embodiment of the present application;
[0108] Figure 7 A schematic diagram of the structure of a communication device provided in an embodiment of the present application;
[0109] Figure 8 A schematic diagram of the structure of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0110] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0111] Among them, in the description of this application, unless otherwise specified, "multiple" means two or more than two. In addition, " / " indicates that the objects associated before and after are in an "or" relationship, for example, A / B can represent A or B; "and / or" in this application is only a kind of association relationship describing the associated objects, indicating that there can be three relationships, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. In addition, in order to facilitate the clear description of the technical solutions of the embodiments of the present application, in the embodiments of the present application, the words "first" and "second" are used to distinguish the same items or similar items with basically the same functions and effects. Those skilled in the art can understand that the words "first" and "second" do not limit the quantity and execution order, and the words "first" and "second" do not limit them to be different. It should also be noted that, unless otherwise specified, the specific description of some technical features in one embodiment can also be used to explain the corresponding technical features mentioned in other embodiments.
[0112] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0113] VxLAN is a virtualized tunnel communication technology and also an overlay technology, which is used to eliminate the limitation of the number of VLANs in the virtualized network world and build a virtual layer 2 network through a three-layer network. VxLAN uses tunnel technology on the underlying physical network (underlay), and uses the user datagram protocol (UDP) layer to encapsulate the layer 2 Ethernet message into the UDP payload to achieve cross-domain access to the large layer 2 local area network. Combined with the background technology, the current solution is to access cloud services based on the virtual extensible LAN (VxLAN) tunnel. At present, it is necessary to deploy VTEP in the optical network terminal (ONT) of the home network. The process of users accessing the cloud service network and the Internet needs to be forwarded by the VTEP of the ONT into the cloud channel to the virtual residential gateway (vRG), and then diverted to different networks through the vRG. Adding VTEP on OTN will increase the complexity of the home network and increase the operation and maintenance costs of operators.
[0114] Based on this, the embodiments of the present application provide a method, device and system for accessing cloud services to simplify the deployment on the home network side, without the need to add VTEP to the current existing gateway, and can also enhance the security of cloud services.
[0115] See also Figure 1 As shown, it is a schematic diagram of a network connection scenario provided by an embodiment of the present application. The home gateway 100 connects and controls all networkable devices in the home and becomes the network connection center in the home. The home gateway 100 mainly plays the role of a router, network address translation, WIFI, and physical port access device, responsible for connecting the devices in the home and dialing to register in the operator network. The cloud service provided by the operator network can be accessed through the home gateway. At the same time, the home gateway 100 also provides management interfaces such as ONT management and control interface (OMCI) and TR069 to the operator management device, which is convenient for the operator to remotely manage it. All networkable devices in the home are connected to the external network through the home gateway 100. The home gateway itself can be an ONT, and can be connected to the optical access device 200 using the Ethernet passive optical network connection port. The optical access device 200 can be an optical line terminal (Optical Line Terminal, OLT). As an access point, the OLT can be connected to the data center network through a metropolitan area network. The data center network can include a gateway, which can be called a data center gateway (data central-gateway, DC-GW) 300. The data center network also includes at least one cloud service gateway (sGW) 400, which can also be called a cloud service gateway. The cloud service gateway can also replace the home gateway 100 to implement some access control functions. Home bandwidth users can access the cloud server 500 through the cloud service gateway 400. The cloud server 500 is used to provide some cloud services, such as cloud NAS, cloud desktop, etc.
[0116] Taking the home gateway itself as an ONT as an example, when a home broadband user needs to use cloud services through a terminal device, the ONT as the home gateway 100 can send an online request to the OLT, and then the OLT sends the online request to the DC-GW 300. The DC-GW 300 then forwards the request to the cloud service gateway 400 corresponding to the ONT. The cloud service gateway 400 forwards the request to the cloud server 500, so that the home broadband user can obtain cloud service resources through the terminal device.
[0117] The terminal devices involved in the embodiments of the present application may be, but are not limited to, home appliances such as smart TVs, smart cameras, smart speakers, smart projectors, smart routers, smart gateways, wearable devices such as smart bracelets and smart glasses, or other mobile phones, tablet computers, handheld computers, personal digital assistants (PDA), desktops, laptops, notebook computers, ultra mobile personal computers (UMPC), netbooks, smart screens and other devices.
[0118] In some embodiments, the OLT and different home gateways can be connected by bridging the wide area network (WAN) port. The OLT and DC-GW300 can communicate by establishing a data transmission channel. The data transmission channel, for example, can be a service provider virtual LAN (service VLAN, SVLAN) channel, QinQ channel, VxLAN channel, or segment routing (Segment Routing IPv6, SRV6) channel based on the IPv6 forwarding plane. QinQ (802.1Q-in-802.1Q), also called VLAN Stacking or Double VLAN, is defined by the IEEE 802.1ad standard and is a technology for expanding VLAN space. It achieves the purpose of expanding VLAN space by adding another layer of 802.1Q tags on the basis of 802.1Q tag messages. QinQ technology can be understood as adding a layer of SVLAN tags on the basis of CVLAN tags.
[0119] In the embodiments of the present application, when a terminal device accesses a cloud service, a virtual Internet Protocol (IP) address is used to complete the access to the cloud service through the cooperation of a home gateway + optical access device + cloud service gateway. In some embodiments, different types of cloud services use different virtual IP addresses. The virtual IP address can be a virtual IP address assigned to the cloud service by a network management device in advance when registering with the cloud service. In some possible implementation scenarios, different cloud service providers use different virtual IP addresses.
[0120] See also Figure 2 , which is a schematic diagram of the architecture of a network system provided in an embodiment of the present application. Figure 2 In the embodiment, the network system includes an optical access device and a cloud service gateway. The network system also includes a home gateway. It should be noted that the number of home gateways included in the network system is not limited in the embodiment of the present application. Figure 3As shown, when a home broadband user uses a terminal device to access the cloud through a home gateway, an address resolution protocol (ARP) is sent to the home gateway. The ARP request carries the virtual IP address of the cloud service to be accessed. The virtual address is configured to access cloud services, such as cloud NAS or cloud desktop. The ARP request is used to request the media access control (MAC) address corresponding to the virtual IP address. After receiving the ARP request, the home gateway forwards the ARP request to the optical access device. After receiving the ARP request, the optical access device sends the ARP request to the cloud service gateway. Thus, the cloud service gateway determines the MAC address corresponding to the virtual IP address according to the ARP request, and feeds back the ARP response to the optical access device, and the ARP response carries the MAC address corresponding to the virtual IP address. Then the optical access device sends the MAC address corresponding to the virtual IP address to the terminal device through the home gateway. Thus, the IP address of the terminal device, the virtual IP address of the cloud service, the MAC address of the terminal device, and the MAC address corresponding to the virtual IP address (such as the MAC address of the cloud service gateway) can be combined between the terminal device and the cloud service gateway to complete the creation of a Layer 2 bridge channel. The home gateway can combine the IP address of the terminal device, the virtual IP address of the cloud service, the MAC address of the terminal device, and the MAC address of the cloud service gateway corresponding to the virtual IP address to create a layer 2 bridge channel between the terminal device and the cloud service gateway to generate forwarding rules for the layer 2 bridge channel. In this way, home broadband users can access the cloud server based on the virtual IP address and MAC address to obtain the cloud services provided by the cloud server.
[0121] The embodiments of the present application do not specifically limit the method for creating a Layer 2 bridge channel between a terminal device and a cloud service gateway (vCPE corresponding to a home gateway), and any method that can support the creation of a Layer 2 bridge channel is applicable to the present application.
[0122] In some embodiments, the terminal device of the embodiment of the present application inherits the original IP address behavior and obtains the IP address from the home gateway. For example, the terminal device sends a dynamic host configuration protocol (DHCP) request to the home gateway, and the DHCP request is used to request the home gateway to assign an IP address to the terminal device. The home gateway thereby assigns an IP address to the terminal device. Exemplarily, the DHCP service (server) function is deployed locally on the ONT in the home gateway, so that the DHCP server of the ONT assigns an IP address to the terminal device. In one possible implementation, the network segment to which the IP address of the terminal device belongs is the same as the network segment to which the virtual IP address belongs. The ONT local DHCP server can reserve the virtual IP address of the cloud service from the address pool to prevent the ONT local DHCP server from using the virtual IP address of the cloud service when assigning an IP address to the terminal device. When requesting the MAC address of the virtual IP address, the terminal device can carry the IP address configured by the home gateway for the terminal device in the ARP request.
[0123] Exemplarily, the virtual IP address may be a private IP address configured for a terminal device of a home gateway to access a cloud service.
[0124] In one possible scenario, the network system includes multiple home gateways, and the network management device (or control device) configures the same virtual IP address for accessing the cloud service for different home gateways. That is, the virtual IP address used for terminal devices belonging to the same home gateway to access the cloud service is the same, and the virtual IP address used for terminal devices belonging to different home gateways to access the cloud service is the same. It can be understood that: a home gateway provides services for one or more terminal devices, or one or more terminal devices access (or connect to) the home gateway. Therefore, the virtual IP address for terminal devices accessing the same home gateway to access the cloud service is the same, and the virtual IP addresses for terminal devices accessing different home gateways to access the cloud service may also be the same.
[0125] In another possible scenario, the network system includes multiple home gateways, and the network management device (or control device) configures the same virtual IP address for accessing the cloud service for different home gateways. That is, the virtual IP address used for terminal devices belonging to the same home gateway to access the cloud service is the same, and the virtual IP addresses used for terminal devices belonging to different home gateways to access the cloud service are different. It can be understood that: a home gateway provides services for one or more terminal devices, or one or more terminal devices access (or connect) the home gateway. Therefore, the virtual IP addresses for terminal devices accessing the same home gateway to access the cloud service are different, and the virtual IP addresses for terminal devices accessing different home gateways to access the cloud service are the same. For example, the network system includes a first home gateway and a second home gateway, and the virtual IP address for the terminal device accessing the first home gateway to access the cloud service is different from the virtual IP address for the terminal device accessing the second home gateway to access the cloud service. The virtual IP addresses for terminal devices accessing the first home gateway to access the cloud service are the same. The virtual IP addresses for terminal devices accessing the second home gateway to access the cloud service are the same. It can also be understood that the virtual IP address of the terminal device belonging to the home gateway accessing the cloud service has an association relationship (or a corresponding relationship) with the home gateway, and different home gateways correspond to different virtual IP addresses of the cloud service.
[0126] Exemplarily, the virtual IP address can be reserved by the network management device (or control device) notifying the home gateway of the virtual IP address. The home gateway (ONT) receives the virtual IP address or virtual IP address segment of the cloud service indicated by the network management device (or control device), so that when the ONT allocates an IP address to the terminal device, it selects an unused IP address from the IP address pool except the virtual IP address or virtual IP address segment and allocates it to the terminal device. That is, the IP address of the terminal device is the same as the network segment to which the virtual IP address of the cloud service belongs, and the IP address of the terminal device is an IP address in the IP address pool of the home gateway except the virtual IP address or virtual IP address segment.
[0127] In some application scenarios, the cloud service gateway is used to provide services for terminal devices. Exemplarily, multiple cloud service gateways are deployed in a network system to form a resource pool to provide services for terminal devices. The cloud service gateway may include one or more virtual customer premises equipment (vCPE) and one or more virtualised switches (vSwitch). The virtual switch is used to receive and forward user traffic through the local area network (local area network) side and the wide area network WAN (Wide Area Network) side. The virtual customer terminal equipment vCPE is connected to the vSwitch to process the user's business requirements.
[0128] Exemplarily, the cloud service gateway may be a virtual machine or container running on a physical node. Optionally, the virtual client terminal device and the virtual switch may also be virtual machines or containers running on a physical node. For example, if the network system includes N home gateways, the cloud service gateway may include N vCPEs that provide services for the N home networks respectively.
[0129] See also Figure 4 , which is a schematic diagram of the architecture of another network system provided in an embodiment of the present application. Figure 4 The cloud services provided include cloud NAS and cloud desktop as an example. Figure 4 In the example, two cloud service gateways are deployed in the network system. The two cloud service gateways are sGW1 and sGW2. sGW1 is connected to the cloud server that provides cloud NAS, and sGW2 is connected to the cloud server that provides cloud desktop. sGW1 includes vSwitch1 and two vCPEs, namely vCPE1 and vCPE2. sGW2 includes vSwitch2 and two vCPEs, namely vCPE3 and vCPE4. Optionally, the cloud server can be a physical node, or a virtual machine or container running on a physical node. Different vCPEs are used to provide services for different home gateways. See Figure 3 As shown, a network system includes two home networks as an example. Each home network includes an ONT. For ease of description, the ONTs of the two home networks are referred to as ONT1 and ONT2.
[0130] In some embodiments, the traffic of home users processed by the OLT may include a CVLAN tag or QINQ information (CVLAN tag + SVLAN tag). The OLT and DC-SW are connected by a VxLAN tunnel. The traffic processed by the OLT may include a VXLAN header after entering the DC-SW. The VXLAN header may include a virtual local area network identity VNI (VXLAN ID to distinguish users). QINQ and VNI constitute the identification information of the user traffic. In some embodiments, the DC-SW may be connected to the vSwitch via VXLAN or SRV6. For example, a home gateway (such as an ONU) accesses the network in a VXLAN networking manner. The home gateway can be connected to the OLT device in a bridging manner. After processing by the OLT device, the home message (traffic) carries a CVLAN tag or QINQ information. At this time, different home messages will carry different CVLAN tags or QINQ information; then the home message enters the DC-SW device and is encapsulated in a VXLAN header and sent out. At this time, messages from different families may be encapsulated in different VXLAN headers, that is, messages from different families may have different VNIs; the message is sent to the vSwitch of the virtual edge cloud service gateway via the LAN side VXLAN network. The VNI+QINQ information carried by different home messages arriving at the vSwitch of the edge cloud service gateway is different, and the VNI+QINQ information corresponds one-to-one to the home. VNI+QINQ can be called the LAN side message identification information.
[0131] In some other embodiments, an SRv6 tunnel is used to connect the OLT and the DC-SW. The user traffic processed by the OLT includes a CVLAN tag or QINQ information (or CVLAN+SVLAN tag), and the traffic processed by the OLT is encapsulated in an SRv6 header, and the SRv6 header includes a signaling identifier SID, and the QINQ (or CVLAN tag) and the SID constitute the identification information of the user traffic. The DC-SW can be connected to the vSwitch in an SRv6 networking mode. The home gateway (such as ONT) accesses the network in an SRv6 networking mode. The home gateway is connected to the OLT device in a bridging manner. After processing by the OLT device, the home message carries QINQ information (or CVLAN tag). At this time, different home messages will carry different QINQ information (or CVLAN tag); then the home message OLT device encapsulates the SRv6 header and sends it out. At this time, messages from different families may be encapsulated in different SRv6 headers, that is, they have different segment routing headers (SRH) headers; the message is sent to the virtual edge cloud service gateway via the LAN side SRv6 network. The signaling identifier (SID) + QINQ information carried by different home messages arriving at the edge cloud gateway is different, and the SID + QINQ information corresponds one-to-one to the home user. SID + QINQ can be called the identification information of the home message.
[0132] The following describes in detail the cloud service access method process provided in the embodiment of the present application in combination with the structure of the network system.
[0133] See also Figure 5 FIG. 1 is a flow chart of a cloud service access method provided in an embodiment of the present application. The terminal device accesses the cloud service on the cloud.
[0134] 501, the terminal device sends an ARP request to the home gateway. The ARP request carries the virtual IP address of the cloud service to be accessed. The virtual IP address is configured to access the cloud service. The ARP request is used to request the MAC address corresponding to the virtual IP address, such as the MAC address of the vCPE in the cloud service gateway corresponding to the home gateway. The ARP also carries the IP address of the terminal device and the MAC address of the terminal device. For example, the IP address of the terminal device is 192.168.1.2.
[0135] The IP address of the terminal device may be assigned by the ONT to the terminal device. When the terminal device initially establishes a connection with the ONT or the terminal device registers with the ONT, the terminal device may send a DHCP request to the ONT. Thus, after receiving the DHCP request, the ONT assigns an IP address to the terminal device. In some embodiments, the IP address assigned by the ONT to the terminal device belongs to the same network segment as the virtual IP address of the cloud service. For example, see Figure 5 As shown, the IP address allocated by the ONT to the terminal device is 192.168.1.2, and the virtual IP address of the cloud service is 192.168.1.4. In some embodiments, the ARP request also carries a tag of the user-side virtual local area network to which the home gateway belongs, that is, a CVLAN tag.
[0136] 502. After receiving the ARP request, the ONT forwards the ARP request to the OLT.
[0137] After receiving the ARP request, the OLT forwards the ARP request to the vSwitch through the DC-GW.
[0138] In some embodiments, the OLT and the vSwitch may be deployed in a manner of switching from CVLAN to SVLAN.
[0139] 503. After receiving the ARP request, the OLT updates the CVLAN tag in the ARP request to a public VLAN tag (or adds a public VLAN tag). For example, the VLAN tag (e.g., CVLAN) is 100, and the public VLAN tag is VLAN 101. In some embodiments, the CVLAN tag in the ARP request is updated to a QINQ tag. The QINQ tag can also be understood as encapsulating the CVLAN tag in the public VLAN tag, that is, CVLAN tag + SVLAN tag. The CVLAN tag carried in the ARP request is called a CVLAN tag. The public VLAN tag can also be understood as the VLAN tag of the vSwitch in the cloud service gateway, that is, the SVLAN tag. In one example, the OLT switches the first CVLAN tag in the ARP request to the updated ARP request of the vSwitch in the cloud service gateway, and sends the updated ARP request to the virtual switch. In another example, the OLT adds the VLAN tag of the vSwitch, that is, the SVLAN tag (which can be understood as SVLAN tag + SVLAN tag, that is, QINQ information) to the ARP request to obtain an updated ARP request, and sends the updated ARP request to the virtual switch.
[0140] In some other embodiments, the OLT and the vSwitch are connected by a VxLAN tunnel. The OLT includes a VXLAN header in the ARP request, wherein the VXLAN header includes a virtual local area network identity VNI (VXLAN ID for distinguishing users), and the VNI constitutes the label information of the user traffic.
[0141] In some other embodiments, the OLT and the vSwitch may be connected using SRv6 networking. The OLT may encapsulate the SRv6 header in the ARP request and then send it. In some embodiments, messages from different households may be encapsulated in different SRv6 headers, that is, they have different SRHs (Segment Routing Headers). The SRH header includes a signaling identifier (SID), and the SID constitutes the identification information of the user traffic.
[0142] In some of the above scenarios, using VxLAN tunnels or SRv6 tunnels between OLT and vSwitch can increase the number of home gateways in the large Layer 2 LAN supported by the network.
[0143] 504, the OLT forwards the updated ARP request to the vSwitch through the DC-GW.
[0144] In some embodiments, the OLT and DC-GW are connected by VxLAN tunnel or SRV6 tunnel networking, and the DC-GW and vSwitch can be connected by VxLAN tunnel or SRV6 tunnel networking. The networking methods between OLT and DC-GW, and between DC-GW and vSwitch can be the same or different.
[0145] 505, the vSwitch forwards the updated ARP request to the vCPE. Specifically, the vSwitch may continue to forward the updated ARP request to the vCPE through the Layer 2 bridge channel.
[0146] 506. After receiving the updated ARP request, the vCPE obtains the MAC address corresponding to the virtual IP address and sends an ARP response to the vSwitch. The ARP response carries the MAC address corresponding to the virtual IP address, that is, the MAC address of the vCPE.
[0147] Specifically, the ARP response is sent to the terminal device along the reverse path of the ARP request path.
[0148] 507, the vSwitch sends an ARP response to the OLT through the DC-GW.
[0149] 508. The OLT forwards the ARP response to the ONT.
[0150] 509. The ONT generates a forwarding rule for a Layer 2 bridge channel for data transmission between the terminal device and the cloud service gateway (i.e., the vCPE corresponding to the home gateway) according to the IP address of the terminal device, the media access MAC address of the terminal device, the virtual IP address of the cloud service to be accessed, and the MAC address of the cloud service gateway; and sends an ARP response to the terminal device.
[0151] 510, the terminal device generates user traffic and sends a first data message to the cloud service gateway (vCPE) through a layer 2 bridge channel. Specifically, the first data message is sent to the ONT through a layer 2 bridge channel. The first data message includes the IP address of the terminal device, the virtual IP address of the cloud service, the MAC address of the terminal device, the MAC address corresponding to the virtual IP address (i.e., the MAC address of the vCPE corresponding to the home gateway), and the CVLAN tag to which the home gateway belongs. The IP address of the terminal device is used as the source IP address, and the virtual IP address of the cloud service is used as the destination IP address. The MAC address of the terminal device is used as the source MAC address, and the MAC address of the vCPE corresponding to the home gateway is used as the destination MAC address.
[0152] Exemplarily, the source IP address and the destination IP address may be added to the user traffic in a five-tuple manner. The five-tuple includes the source IP address, the source port number, the destination IP address, the destination port number, and the transport layer protocol. In some embodiments, the destination IP address and the destination port number may be obtained during the process of the terminal device registering the cloud service.
[0153] 511, the ONT forwards the first data message to the cloud service gateway according to the forwarding rule of the layer 2 bridge channel, and the first data message first passes through the OLT.
[0154] 512, the OLT switches the CVLAN tag in the first data message to the SVLAN tag belonging to the vSwitch in the cloud service gateway to obtain an updated first data message, and the OLT forwards the updated first data message to the virtual switch vSwitch through the DC-GW.
[0155] Figure 4In the example, the OLT switches CVLAN to SVLAN to forward the cloud service traffic that is not accessible to the home to the vSwitch. In some scenarios, the OLT adds an SVLAN tag (which can be understood as QINQ information) to the first data message to obtain an updated first data message, and sends the updated first data message to the virtual switch. The second VLAN tag is used by the virtual switch to forward the updated first data message to the vCPE corresponding to the home gateway. In some other scenarios, if the OLT and the vSwitch in the cloud service gateway adopt a networking method of creating a VxLAN tunnel and / or an SRv6 tunnel, the OLT can send the first data message to the vSwitch through the created VxLAN tunnel and / or SRv6 tunnel.
[0156] 513. The virtual switch vSwitch forwards the updated first data message to the vCPE corresponding to the home gateway.
[0157] 514, the vCPE corresponding to the home gateway converts the source IP address in the first data packet into the IP address of the vCPE, and converts the destination IP address into the IP address of the cloud server providing cloud services to obtain the first data packet to be forwarded, and the cloud server sends the first data packet to be forwarded.
[0158] The vCPE corresponding to the home gateway uses two NAT technologies, which can be Source Network Address Translation (SNAT) + Destination Network Address Translation (DNAT), to forward the user's traffic to the cloud server.
[0159] SNAT is a network communication in which when a host on the internal network sends a data packet to an external network, the source IP address of the data packet will be modified to a public IP address, so that the external network cannot directly access the real IP address of the internal network. The main function of SNAT is to hide the real IP address of the internal network, thereby enhancing the security of the network. DNAT is a network communication in which when a host on the external network sends a data packet to the internal network, the destination IP address of the data packet will be modified to the IP address of a host on the internal network, thereby achieving data packet routing. The main function of DNAT is to route requests from the external network to a host on the internal network, thereby achieving access to network services.
[0160] In the embodiment of the present application, the conversion order of SNAT and DNAT is not specifically limited. SNAT may be performed first and then DNAT, or DNAT may be used first and then SNAT.
[0161] See also Figure 6 As shown, the IP address assigned by the ONT to the terminal device of home 1 is 192.168.1.2, and the IP address assigned to the terminal device of home 2 is 192.168.1.3. The port number of the terminal device of home 1 is 1000, and the port number of the terminal device of home 2 is 2000. For example, both home 1 and home 2 access the cloud NAS service. For example, the virtual IP address of the cloud service is 192.168.1.4. vCPE1 corresponds to home 1, and vCPE2 corresponds to home 2. The IP address of vCPE1 is 10.1.1.2, and the IP address of vCPE2 is 10.1.1.3. The IP address of the cloud server is 10.1.1.4. Figure 5 In the example, the terminal device is located in home 1. The home gateway of home 1 corresponds to vCPE1.
[0162] See also Figure 6 As shown in the figure, after two conversions, the uplink / downlink traffic of household 1 and household 2 meets the following requirements:
[0163] Upstream traffic of household 1:
[0164] 192.168.1.2(sip)+1000(sport)+192.168.1.4(dip)+8080(dport)+TCP<->10.1.1.2(sip)+x(sport)+10.1.1.4(dip)+8080(dport)+TCP.
[0165] Upstream traffic of household 2:
[0166] 192.168.1.2(sip)+2000(sport)+192.168.1.4(dip)+8080(dport)+TCP<->10.1.1.3(sip)+y(sport)+10.1.1.4(dip)+8080(dport)+TCP.
[0167] The protocol used in the above example 1 is TCP protocol, and other protocols may also be used, which is not specifically limited in the present embodiment. SIP represents the source IP address, sport represents the source port number, dip represents the destination IP address, and dport represents the destination port number.
[0168] It can be seen from the above that no matter whether it is upstream traffic or downstream traffic, the double conversion technology is used and no conflict will occur in forwarding.
[0169] In the embodiments of the present application, there is no need to add additional functions to the ONT, such as the function of VTEP, which can simplify the deployment of the home network and reduce maintenance costs. For the same cloud service, the virtual IP address of the cloud service known to different families can be the same private IP address, which can further simplify the configuration of the operator's massive ONTs and further reduce maintenance costs. In the same cloud service gateway, the virtual IP address of the cloud service seen by different vCPEs can also be the same private IP address, which can also simplify the deployment of the operator's proprietary cloud services. In addition, since the IP addresses of the cloud services seen by each home network are the same virtual IP address (i.e., private IP address), it is no longer necessary to expose the real IP address of the cloud server to the outside world (users), which can improve the security of the cloud service. The cloud-related network node deployment does not need to see the public IP address belonging to the cloud service.
[0170] Combination of the above Figures 1 to 6 The access scheme of the cloud service of the embodiment of the present application is described in detail. The embodiment of the present application also provides a communication device, such as Figure 7 As shown, the communication device includes: a sending unit 701, a receiving unit 702 and a processing unit 703. The communication device can be a node, or a device in the node, such as a chip or an integrated circuit. The node can be a home gateway or an OLT or a cloud service gateway (vCPE or vSwitch in the cloud service gateway).
[0171] In a possible application scenario, the communication device is applied to a home gateway.
[0172] The receiving unit 702 is used to receive an address resolution protocol ARP request from a terminal device, where the ARP request carries an IP address of the terminal device, a media access control MAC address of the terminal device, and a virtual IP address of a cloud service to be accessed, where the virtual IP address is configured for the terminal device to access the cloud service; the ARP request is used to request a media access control MAC address corresponding to the virtual IP address;
[0173] The sending unit 701 is used to send the ARP request to the cloud service gateway;
[0174] The receiving unit 702 is further configured to receive an ARP response from the cloud service gateway, wherein the ARP response carries a MAC address of the cloud service gateway corresponding to the virtual IP address;
[0175] The processing unit 703 is used to generate a forwarding rule for a layer 2 bridge channel for data transmission between the terminal device and the cloud service gateway according to the IP address of the terminal device, the media access MAC address of the terminal device, the virtual IP address of the cloud service to be accessed, and the MAC address of the cloud service gateway;
[0176] The sending unit 701 is further configured to send the ARP response to the terminal device.
[0177] In a possible implementation, a virtual IP address used by a terminal device belonging to the home gateway to access the cloud service is associated with the home gateway.
[0178] In the above method, the IP address of the cloud service seen by all households is the same IP address, which can further simplify the configuration of the operator's massive ONTs and further reduce operation and maintenance costs. In addition, if the IP address of the cloud service seen by the vCPE corresponding to different home gateways is also the same IP address, the deployment of the operator's private cloud can be further simplified.
[0179] In a possible implementation, the virtual IP address is a private network IP address configured for a terminal device of the home gateway to access the cloud service.
[0180] In the above method, the IP addresses of the cloud services seen by all households are private IP addresses, and the real IP addresses of the cloud servers are no longer exposed to the outside world (i.e., terminal devices), which can improve the security of the cloud services.
[0181] In one possible implementation, the receiving unit 702 is also used to receive a first data packet from a terminal device, where the first data packet is used to request access to the cloud service, and the first data packet carries the IP address of the terminal device, the MAC address of the terminal device, the virtual IP address, and the MAC address of the cloud service gateway; the sending unit 701 is also used to send the first data packet to the cloud service gateway according to the forwarding rule.
[0182] In a possible implementation, the processing unit 703 includes N virtual client devices vCPEs that respectively provide services for the N home gateways, and the MAC address is the MAC address of the vCPE corresponding to the home gateway.
[0183] In one possible implementation, the sending unit 701 is used to send the ARP request to the vCPE corresponding to the home gateway through the optical access device; the ARP request also carries a user-side virtual local area network CVLAN tag to which the home gateway belongs; the CVLAN tag is used by the optical access device to forward the ARP request to the cloud service gateway.
[0184] In a possible implementation, the receiving unit 702 is further configured to receive a Dynamic Host Configuration Protocol (DHCP) request from the terminal device, wherein the DHCP request is used to request the home gateway to allocate an IP address to the terminal device. The sending unit 701 is further configured to send the IP address of the terminal device to the terminal device; the APR request also carries the IP address of the terminal device.
[0185] In one possible implementation, the receiving unit 702 is also used to receive the virtual IP address or virtual IP address segment of the cloud service indicated by the network management device; the IP address of the terminal device is the same as the network segment to which the virtual IP address of the cloud service belongs, and the IP address of the terminal device is an IP address in the IP address pool of the home gateway except the virtual IP address or virtual IP address segment.
[0186] In yet another possible application scenario, the communication device is applied to optical access equipment.
[0187] The receiving unit 702 is used to receive an address resolution protocol ARP request sent by a home gateway, wherein the ARP request carries the IP address of a terminal device managed by the home gateway, the media access control MAC address of the terminal device, and the virtual IP address of a cloud service to be accessed, wherein the virtual IP address is configured for the terminal device managed by the home gateway to access the cloud service; the ARP request is used to request the MAC address corresponding to the virtual IP address; the sending unit 701 is used to send the ARP request to the cloud service gateway; the receiving unit 702 is also used to receive an ARP response from the cloud service gateway, wherein the ARP response carries the MAC address corresponding to the virtual IP address; the sending unit 701 is also used to send the ARP response to the home gateway, wherein the MAC address is used by the home gateway to generate forwarding rules for a Layer 2 bridge channel between the created terminal device and the cloud service gateway.
[0188] In one possible implementation, the cloud service gateway includes a virtual switch; the ARP request also carries a user-side virtual local area network CVLAN tag to which the home gateway belongs; the sending unit 701 is used to send the ARP request to the cloud service gateway, including: forwarding the ARP request to the virtual switch according to the CVLAN tag.
[0189] In a possible implementation, the processing unit 703 is configured to switch the CVLAN tag in the ARP request to the SVLAN tag of the service provider virtual local area network to which the virtual switch belongs to obtain an updated ARP request. The sending unit 701 is configured to send the updated ARP request to the virtual switch.
[0190] In a possible implementation, the processing unit 703 is configured to add the SVLAN tag to which the vCPE corresponding to the home gateway belongs to the ARP request to obtain an updated ARP request. The sending unit 701 is configured to send the updated ARP request to the virtual switch.
[0191] In a possible implementation, the cloud service gateway includes a virtual switch; a data transmission channel is established between the optical access device and the virtual switch, and the data transmission channel is a VxLAN channel or a segment routing SRV6 channel based on an IPv6 forwarding plane. A sending unit 701 is configured to send the ARP request to the virtual switch through the data transmission channel.
[0192] In another possible application scenario, the communication device is applied to a cloud service gateway.
[0193] The receiving unit 702 is used to receive an address resolution protocol ARP request from a home gateway, wherein the ARP request carries the IP address of a terminal device managed by the home gateway, the MAC address of the terminal device, and the virtual IP address of the cloud service to be accessed, wherein the virtual IP address is configured for the terminal device to access the cloud service; the ARP request is used to request the media access control MAC address corresponding to the virtual IP address. The sending unit 701 is used to send an ARP response to the home gateway, wherein the ARP carries the MAC address corresponding to the virtual IP address, and the MAC address is used by the home gateway to generate forwarding rules for the Layer 2 bridge channel between the terminal device and the cloud service gateway created.
[0194] In one possible implementation, the receiving unit 702 is used to receive a first data packet from a terminal device through a Layer 2 bridge channel, the first data packet carrying the IP address of the terminal device and the virtual IP address of the cloud service to be accessed, the IP address of the terminal device serving as the source IP address, and the virtual IP address of the cloud service serving as the destination IP address; the processing unit 703 is used to convert the source IP address in the first data packet into the IP address of a cloud service gateway, and convert the destination IP address into the IP address of a cloud server providing the cloud service, so as to obtain an updated first data packet; the sending unit 701 is used to send the updated first data packet to the cloud server.
[0195] In a possible implementation, the receiving unit 702 is used to receive a second data message sent by the cloud server, the second data message carries the IP address of the cloud service gateway and the IP address of the cloud server of the cloud service; the IP address of the cloud service gateway is used as the destination IP address, and the IP address of the cloud server is used as the source IP address. The processing unit 703 is used to convert the destination IP address in the second data message into the virtual IP address of the cloud service, and convert the source IP address into the IP address of the terminal device to obtain an updated second data message; the sending unit 701 is used to send the updated second data message to the terminal device through the layer 2 bridge channel.
[0196] In a possible implementation, the cloud service gateway includes a plurality of vCPEs corresponding to different home gateways, and the IP address of the cloud service gateway is the IP address of the VCPE.
[0197] Exemplarily, the above-mentioned communication device is applied to a cloud service gateway, and may be applied to a vCPE.
[0198] In some possible scenarios, the cloud service gateway also includes a virtual switch. The virtual switch is used to continue to send the first data packet to the vCPE of the home gateway through the Layer 2 bridge channel. Specifically, the receiving unit 702 in the virtual switch can be used to receive an APR request or a first data packet or an APR response or a second data packet. The sending unit 701 can be used to send an APR request or a first data packet to the vCPE; or to send an ARP response or a second data packet to the OLT. The processing unit 703 can control the receiving unit 702 and the sending unit 701, or identify the data packet and process the packet header.
[0199] It should be noted that the division of modules in the embodiments of the present application is schematic and is only a logical function division. There may be other division methods in actual implementation. In addition, each functional unit in each embodiment of the present application may be integrated into a processing unit, or may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0200] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) or a processor (processor) to perform all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.
[0201] See also Figure 8 , Figure 8 800 is a schematic diagram of a communication device provided in an embodiment of the present application. The communication device 800 may include at least one memory 801 and at least one processor 802. Optionally, a bus 803 may also be included. Further optionally, a communication interface 804 may also be included, wherein the memory 801, the processor 802 and the communication interface 804 are connected via the bus 803.
[0202] The memory 801 is used to provide a storage space, and the storage space can store data such as an operating system and a computer program. The memory 801 can be a random access memory (RAM), a read only memory (ROM), an erasable programmable read only memory (EPROM), or a portable read only memory (CD ROM), etc., or a combination of multiple thereof.
[0203] The processor 802 is a module that performs arithmetic operations and / or logical operations, and can specifically be a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor unit (MPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), a complex programmable logic device (CPLD), and other processing modules, or a combination of multiple thereof.
[0204] The communication interface 804 is used to receive data sent externally and / or send data externally, and may be a wired link interface such as an Ethernet cable, or a wireless link (Wi-Fi, Bluetooth, general wireless transmission, etc.) interface. Optionally, the communication interface 804 may also include a transmitter (such as a radio frequency transmitter, an antenna, etc.) coupled to the interface, or a receiver, etc.
[0205] The communication device 800 may be a node, or a device in the node, such as a chip or an integrated circuit, etc. The node may be a home gateway, an OLT, or a cloud service gateway (vCPE or vSwitch in the cloud service gateway).
[0206] In a possible application scenario, the communication device is applied to a home gateway, and the processor 802 in the communication device 800 is used to read the computer program stored in the memory 801 to execute the method executed by the aforementioned home gateway, for example Figure 3 or Figure 5 The method executed by the home gateway in any method embodiment.
[0207] In another possible application scenario, the communication device is applied to an OLT, and the processor 802 in the communication device 800 is used to read the computer program stored in the memory 801 to execute the method executed by the aforementioned OLT, for example Figure 3 or Figure 5 The method executed by the OLT in any one of the method embodiments.
[0208] In another possible application scenario, the communication device is applied to a vCPE in a home gateway, and the processor 802 in the communication device 800 is used to read the computer program stored in the memory 801 to execute the method executed by the aforementioned vCPE, for example Figure 3 or Figure 5 The method performed by the vCPE in any one of the method embodiments.
[0209] In another possible application scenario, the communication device is applied to a vSwitch in a home gateway, and the processor 802 in the communication device 800 is used to read the computer program stored in the memory 801 to execute the method executed by the aforementioned vSwitch, for example Figure 3 or Figure 5 The method performed by the vSwitch in any one of the method embodiments.
[0210] It should be noted that the implementation of each module can also refer to Figure 1-Figure 6 Corresponding description of each component in the illustrated embodiment.
[0211] The present application also provides a computer-readable storage medium in which a computer program is stored. When the computer program is executed on one or more processors, Figure 1-Figure 6 The methods executed by various devices in the illustrated embodiments.
[0212] The embodiment of the present application also provides a chip system, the chip system includes at least one processor, a memory and an interface circuit, the interface circuit is used to provide information input / output for the at least one processor, the at least one memory stores a computer program, when the computer program is run on one or more processors, the execution Figure 1-Figure 6 The methods executed by various devices in the illustrated embodiments.
[0213] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, optical storage, etc.) that contain computer-usable program code.
[0214] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0215] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. A cloud service access method, characterized in that: Applied to home gateways, including: Receiving an Address Resolution Protocol (ARP) request from a terminal device, the ARP request carrying an IP address of the terminal device, a Media Access Control (MAC) address of the terminal device, and a virtual IP address of a cloud service to be accessed, the virtual IP address being configured for the terminal device to access the cloud service; the ARP request is used to request a Media Access Control (MAC) address corresponding to the virtual IP address; Sending the ARP request to the cloud service gateway; Receiving an ARP response from the cloud service gateway, the ARP response carrying a MAC address of the cloud service gateway corresponding to the virtual IP address; Generate a forwarding rule for a layer 2 bridge channel for data transmission between the terminal device and the cloud service gateway according to the IP address of the terminal device, the media access MAC address of the terminal device, the virtual IP address of the cloud service to be accessed, and the MAC address of the cloud service gateway; Send the ARP response to the terminal device.
2. The method according to claim 1, characterized in that The virtual IP address used for the terminal device belonging to the home gateway to access the cloud service is associated with the home gateway.
3. The method according to claim 1 or 2, characterized in that The virtual IP address is a private network IP address configured for the terminal device of the home gateway to access the cloud service.
4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: Receive a first data message from a terminal device, where the first data message is used to request access to the cloud service, and the first data message carries an IP address of the terminal device, a MAC address of the terminal device, the virtual IP address, and a MAC address of a cloud service gateway; The first data packet is sent to the cloud service gateway according to the forwarding rule.
5. The method according to any one of claims 1 to 4, characterized in that: The cloud service gateway includes N virtual client devices vCPE that provide services for the N home gateways respectively, and the MAC address is the MAC address of the vCPE corresponding to the home gateway.
6. The method according to any one of claims 1 to 5, characterized in that ; Sending the ARP request to the cloud service gateway includes: Sending the ARP request to the vCPE corresponding to the home gateway through an optical access device; The ARP request also carries a user-side virtual local area network CVLAN tag to which the home gateway belongs; the CVLAN tag is used by the optical access device to forward the ARP request to the cloud service gateway.
7. The method according to any one of claims 1 to 6, characterized in that: The method further comprises: Receiving a Dynamic Host Configuration Protocol DHCP request from the terminal device, wherein the DHCP request is used to request the home gateway to allocate an IP address to the terminal device; Sending the IP address of the terminal device to the terminal device; The APR request also carries the IP address of the terminal device.
8. The method according to claim 7, characterized in that The method further comprises: Receive the virtual IP address or virtual IP address segment of the cloud service indicated by the network management device; The IP address of the terminal device is in the same network segment as the virtual IP address of the cloud service, and the IP address of the terminal device is an IP address in the IP address pool of the home gateway other than the virtual IP address or virtual IP address segment.
9. A cloud service access method, characterized in that: Applied to optical access equipment, including: Receiving an Address Resolution Protocol ARP request sent by a home gateway, the ARP request carrying an IP address of a terminal device managed by the home gateway, a Media Access Control MAC address of the terminal device, and a virtual IP address of a cloud service to be accessed, the virtual IP address being configured for the terminal device managed by the home gateway to access the cloud service; the ARP request is used to request a MAC address corresponding to the virtual IP address; Sending the ARP request to the cloud service gateway; Receiving an ARP response from the cloud service gateway, the ARP response carrying a MAC address corresponding to the virtual IP address; The ARP response is sent to the home gateway, and the MAC address is used by the home gateway to generate forwarding rules for the layer 2 bridge channel between the created terminal device and the cloud service gateway.
10. The method according to claim 9, characterized in that The cloud service gateway includes a virtual switch; the ARP request also carries a user-side virtual local area network CVLAN tag to which the home gateway belongs; Sending the ARP request to the cloud service gateway includes: The ARP request is forwarded to the virtual switch according to the CVLAN tag.
11. The method according to claim 10, characterized in that The step of forwarding the ARP request to the virtual switch according to the CVLAN tag includes: Switch the CVLAN tag in the ARP request to an SVLAN tag of the service provider virtual local area network to which the virtual switch belongs to obtain an updated ARP request, and send the updated ARP request to the virtual switch; or An SVLAN tag to which the vCPE corresponding to the home gateway belongs is added to the ARP request to obtain an updated ARP request, and the updated ARP request is sent to the virtual switch.
12. The method according to claim 9, characterized in that The cloud service gateway includes a virtual switch; a data transmission channel is established between the optical access device and the virtual switch, and the data transmission channel is a VxLAN channel or a segment routing SRV6 channel based on the IPv6 forwarding plane; Sending the ARP request to the cloud service gateway includes: The ARP request is sent to the virtual switch through a data transmission channel.
13. A cloud service access method, characterized in that: Applied to cloud service gateway, including: Receiving an Address Resolution Protocol (ARP) request from a home gateway, the ARP request carrying an IP address of a terminal device managed by the home gateway, a MAC address of the terminal device, and a virtual IP address of a cloud service to be accessed, the virtual IP address being configured for the terminal device to access the cloud service; the ARP request is used to request a media access control MAC address corresponding to the virtual IP address; An ARP response is sent to the home gateway, where the ARP carries the MAC address corresponding to the virtual IP address, and the MAC address is used by the home gateway to generate forwarding rules for the layer 2 bridge channel between the terminal device and the cloud service gateway created.
14. The method according to claim 13, characterized in that The method further comprises: receiving a first data packet from a terminal device through the layer 2 bridge channel, wherein the first data packet carries an IP address of the terminal device and a virtual IP address of a cloud service to be accessed, the IP address of the terminal device being used as a source IP address, and the virtual IP address of the cloud service being used as a destination IP address; Convert the source IP address in the first data message into the IP address of the cloud service gateway, and convert the destination IP address into the IP address of the cloud server providing the cloud service, so as to obtain an updated first data message; Send the updated first data message to the cloud server.
15. The method according to claim 13, characterized in that The method further comprises: Receive a second data message sent by the cloud server, the second data message carrying the IP address of the cloud service gateway and the IP address of the cloud server of the cloud service; the IP address of the vCPE is used as the destination IP address, and the IP address of the cloud server is used as the source IP address; Convert the destination IP address in the second data message into the virtual IP address of the cloud service, and convert the source IP address into the IP address of the terminal device to obtain an updated second data message; The updated second data message is sent to the terminal device through the layer 2 bridge channel.
16. A network system, characterized in that: Including the first home gateway and cloud service gateway; The first home gateway is used for an address resolution protocol ARP request from a terminal device, the ARP request carries an IP address of the terminal device, a media access control MAC address of the terminal device, and a virtual IP address of a cloud service to be accessed, the virtual IP address being configured for the terminal device to access the cloud service; the ARP request is used to request a media access control MAC address corresponding to the virtual IP address; and the ARP request is sent to the cloud service gateway; The cloud service gateway is used to send an ARP response to the first home gateway, where the ARP response carries the MAC address of the cloud service gateway corresponding to the virtual IP address; The first home gateway is also used to generate forwarding rules for the Layer 2 bridge channel used for data transmission between the terminal device and the cloud service gateway based on the IP address of the terminal device, the media access MAC address of the terminal device, the virtual IP address of the cloud service to be accessed, and the MAC address of the cloud service gateway; and send the ARP response to the terminal device.
17. The system of claim 16, wherein: Also included is a second home gateway; The virtual IP address used by a terminal device belonging to the first home gateway to access the cloud service is different from the virtual IP address used by a terminal device belonging to the second home gateway to access the cloud service; Alternatively, the virtual IP address used by the terminal device belonging to the first home gateway to access the cloud service is the same as the virtual IP address used by the terminal device belonging to the second home gateway to access the cloud service.
18. The system according to claim 16 or 17, characterized in that The system further comprises an optical access device, and the cloud service gateway comprises a virtual switch; The first home gateway is specifically used to send the ARP request to the optical access device, wherein the ARP request also carries a user-side virtual local area network CVLAN tag to which the first home gateway belongs; The optical access device is used to forward the ARP request to the virtual switch according to the CVLAN tag.
19. A communication device, characterized in that: include: Processor and memory; The memory stores a computer program; The processor is used to execute the computer program stored in the memory, so that the method according to any one of claims 1 to 8 is executed, or the method according to any one of claims 9 to 12 is executed, or the method according to any one of claims 13 to 15 is executed.
20. A communication device, characterized in that: The method comprises one or more modules or units for implementing the method steps described in any one of claims 1 to 15.
21. A computer-readable storage medium, characterized in that: Instructions are stored, and when the instructions are executed by a processor, the method according to any one of claims 1 to 8 is executed, or the method according to any one of claims 9 to 12 is executed, or the method according to any one of claims 13 to 15 is executed.
22. A computer program product, characterized in that When the computer program product runs on a device, the device is enabled to execute the method according to any one of claims 1 to 8, the method according to any one of claims 9 to 12, or the method according to any one of claims 13 to 15.