Cloud computing gateway service implementation method and device, equipment and storage medium
By using NAT gateways in a cloud computing environment, the problems of insufficient security and high cost of cloud computing resources on the public network are solved, and low-cost and secure Internet access is achieved.
Patent Information
- Application Number
- CN202510296978.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-05-13
AI Technical Summary
In a cloud computing environment, cloud resources are directly facing the public network, resulting in insufficient security, and each cloud resource needs to purchase a public IP address separately, resulting in high costs.
By using NAT gateways in a cloud computing environment, we can reduce the use of public IP addresses and avoid direct exposure of cloud computing resources to the public network, improving security. The specific plan includes creating a NAT service management node in the target cloud computing platform, creating an initial NAT gateway, binding the elastic public network IP with the NAT gateway, and configuring the network address translation function according to the data transmission requirements of cloud resources.
It realizes low-cost and secure Internet access between cloud computing resources and the public network, reduces the use of public IP addresses, improves security, and simplifies the gateway deployment process.
Smart Images

Figure CN119996369A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet data communication technology, and in particular to a cloud computing gateway service implementation method, device, equipment and storage medium. Background Art
[0002] Cloud computing platform, also known as cloud platform, refers to services based on hardware resources and software resources that provide computing, network and storage capabilities.
[0003] Currently, in cloud computing environments, users usually assign public IP addresses (Internet Protocol Address) to cloud resources, such as ECS (Elastic Compute Service, a cloud server) or EBS (Elastic Block Storage, a cloud hard disk) for easy access. However, this approach has two significant disadvantages: on the one hand, it is not cost-effective because each cloud resource needs to purchase a public IP address separately, resulting in increased costs; on the other hand, it is not secure enough. Once cloud resources are assigned public IP addresses, they will directly face the Internet, increasing security risks. Therefore, how to achieve low-cost and high-reliability Internet access between cloud computing platforms and the public network has become a technical problem that needs to be solved. Summary of the invention
[0004] In view of this, the purpose of the present invention is to provide a cloud computing gateway service implementation method, device, equipment and storage medium, which reduces the usage of public network IP addresses by using a NAT gateway in a cloud computing environment, avoids direct exposure of cloud computing resources to the public network, and improves security. The specific scheme is as follows:
[0005] In a first aspect, the present application provides a method for implementing a cloud computing gateway service, including:
[0006] Creating a NAT service management node in the target cloud computing platform, and using the NAT service management node to create an initial NAT gateway corresponding to the target cloud computing platform;
[0007] Binding a target number of elastic public IPs to the initial NAT gateway, and associating target cloud computing resources in the target cloud computing platform with the elastic public IPs;
[0008] According to the data transmission requirements corresponding to the target cloud computing resources, the network address translation function is configured for the initial NAT gateway to obtain the corresponding target NAT gateway, and the target NAT gateway is used to control the data transmission between the target cloud computing resources and the public network with the associated elastic public IP.
[0009] Optionally, the step of using the NAT service management node to create an initial NAT gateway corresponding to the target cloud computing platform includes:
[0010] The target gateway deployment mode is determined according to the business volume in the target cloud computing platform, and the initial NAT gateway corresponding to the target cloud computing platform is created using the target gateway deployment mode and the NAT service management node; wherein the target gateway deployment mode includes a stand-alone mode and an active-standby mode.
[0011] Optionally, the cloud computing gateway service implementation method further includes:
[0012] Performing quantitative analysis on the importance of management data in the NAT service management node to obtain corresponding analysis results;
[0013] If the analysis result indicates that the importance of the management data is not less than a first preset importance threshold, real-time monitoring of changes in the management data is performed, and if the management data changes, the management data is automatically backed up;
[0014] If the analysis result indicates that the importance of the management data is less than a first preset importance threshold and not less than a second preset importance threshold, setting a target time interval, and performing a scheduled backup of the management data according to the target time interval;
[0015] If the analysis result indicates that the importance of the management data is less than a second preset importance threshold, the management data is manually backed up.
[0016] Optionally, after using the target NAT gateway and the associated elastic public IP to control data transmission between the target cloud computing resource and the public network, the method further includes:
[0017] Determine whether the target cloud computing platform still has cloud computing resources corresponding to the elastic public IP. If the target cloud computing platform does not have cloud computing resources corresponding to the elastic public IP, unbind the elastic public IP bound to the target NAT gateway.
[0018] Bind the new elastic public IP to the target NAT gateway, and use the new elastic public IP to perform corresponding data transmission operations.
[0019] Optionally, the cloud computing gateway service implementation method further includes:
[0020] Monitor the NAT service management node and the target gateway server corresponding to the target NAT gateway, and obtain a corresponding server operation report according to the monitoring result, so as to evaluate the status of the NAT service management node and the target gateway server according to the server operation report; wherein the server operation report includes the server resource usage, task response time and system server load corresponding to the target gateway server.
[0021] Optionally, the cloud computing gateway service implementation method further includes:
[0022] If the target gateway server fails, the target gateway server is repaired using a fault repair method corresponding to the deployment mode of the target NAT gateway.
[0023] Optionally, repairing the target gateway server by using a fault repair method corresponding to the deployment mode of the target NAT gateway includes:
[0024] If the deployment mode of the target NAT gateway is the active-standby mode, the keepalived technology is used to perform active-standby switching on the target gateway server to repair the target gateway server;
[0025] If the deployment mode of the target NAT gateway is a stand-alone mode, a new gateway server is selected, and the backup information of the target gateway server is imported into the new gateway server to repair the target gateway server.
[0026] In a second aspect, the present application provides a cloud computing gateway service implementation device, including:
[0027] A gateway creation module, used to create a NAT service management node in the target cloud computing platform, and use the NAT service management node to create an initial NAT gateway corresponding to the target cloud computing platform;
[0028] An IP binding module is used to bind a target number of elastic public IPs to the initial NAT gateway, and associate a target cloud computing resource in the target cloud computing platform with the elastic public IPs;
[0029] The data transmission module is used to configure the network address translation function for the initial NAT gateway according to the data transmission requirements corresponding to the target cloud computing resources, so as to obtain the corresponding target NAT gateway, and use the target NAT gateway and the associated elastic public IP to control the data transmission between the target cloud computing resources and the public network.
[0030] In a third aspect, the present application provides an electronic device, including:
[0031] Memory, used to store computer programs;
[0032] A processor is used to execute the computer program to implement the aforementioned cloud computing gateway service implementation method.
[0033] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the aforementioned cloud computing gateway service implementation method.
[0034] In the present application, a NAT service management node is first created in the target cloud computing platform, and the NAT service management node is used to create an initial NAT gateway corresponding to the target cloud computing platform. Then, a target number of elastic public IPs are bound to the initial NAT gateway, and the target cloud computing resources in the target cloud computing platform are associated with the elastic public IP. Finally, a network address translation function is configured for the initial NAT gateway according to the data transmission requirements corresponding to the target cloud computing resources to obtain the corresponding target NAT gateway, and the target NAT gateway is used to control data transmission between the target cloud computing resources and the public network with the associated elastic public IP. It can be seen that this application uses a NAT gateway in a cloud computing environment to carry out data communication between the cloud computing platform and the public network, so that cloud computing resources are no longer directly exposed to the public network, but are accessed through the NAT gateway. Since the NAT gateway can be configured to open specific ports, the security of data communication is significantly improved; by closely integrating the NAT gateway service with the cloud computing platform, the software deployment of the NAT gateway is realized, which is easy to operate, quick to deploy, and easy to use. It avoids the deployment of physical gateways in the cloud platform, simplifies the gateway deployment process, and reduces communication costs; by using elastic public IP to bind the NAT gateway, users can use a small number of IP addresses to provide public network access services for multiple cloud resources, significantly reducing the use of public IP addresses, thereby reducing the cost of using cloud computing services. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.
[0036] Figure 1 A flow chart of a method for implementing a cloud computing gateway service disclosed in this application;
[0037] Figure 2 A cloud computing gateway service system structure diagram disclosed in this application;
[0038] Figure 3 A functional schematic diagram of a component disclosed in this application;
[0039] Figure 4 A flow chart of a method for cloud computing resources to access a public network disclosed in this application;
[0040] Figure 5 A flow chart of a method for providing services to a public network using cloud computing resources disclosed in this application;
[0041] Figure 6 A schematic diagram of the structure of a cloud computing gateway service implementation device disclosed in this application;
[0042] Figure 7 This is a structural diagram of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0043] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0044] At present, in a cloud computing environment, public IP addresses are usually allocated to cloud resources for easy access, but this method has the problems of high data communication costs, and cloud computing resources are directly exposed to the public network, which leads to low data security. To this end, the present application provides a cloud computing gateway service implementation method, which reduces the use of public IP addresses by using a NAT gateway in a cloud computing environment, avoids direct exposure of cloud computing resources to the public network, and improves security.
[0045] See also Figure 1 As shown, an embodiment of the present invention discloses a method for implementing a cloud computing gateway service, including:
[0046] Step S11: Create a NAT service management node in the target cloud computing platform, and use the NAT service management node to create an initial NAT gateway corresponding to the target cloud computing platform.
[0047] In this embodiment, in order to solve the problem of difficult deployment of cloud computing gateways and low security of cloud computing resources, this embodiment integrates a NAT gateway (Network Address Translation Gateway, a network address translation device) service module in the cloud computing platform and introduces keepalived technology (a fault switching technology), thereby forming a new type of cloud computing service system, thereby achieving high efficiency, simplicity and high availability of NAT gateway services. The functional components of this system are as follows: Figure 2 As shown, it includes: a system management component, a business management component and a monitoring disaster recovery component; wherein the system management component is the basic functional component of the present invention, responsible for deploying the NAT gateway service system in the cloud computing platform, and is also responsible for the data backup of the NAT gateway service system.
[0048] The system management component includes a service deployment module and a data backup module, wherein the service deployment module is used to realize the automatic deployment function of the NAT gateway service system. This module automatically creates a NAT gateway service management node on the cloud computing platform. The NAT gateway service management node is deployed in the control network, and a single-point deployment mode or a high-availability deployment mode can be selected; the data backup module is used to realize the data backup function of the NAT gateway service system. The user can choose manual backup, scheduled automatic backup, automatic backup after important operations and other methods to back up the management data in the above-mentioned NAT gateway service management node. Specifically, the importance of the management data in the NAT service management node is quantitatively analyzed to obtain the corresponding analysis results; if the analysis result indicates that the importance of the management data is not less than the first preset importance threshold, the change of the management data is monitored in real time, and if the management data changes, the management data is automatically backed up; if the analysis result indicates that the importance of the management data is less than the first preset importance threshold and not less than the second preset importance threshold, a target time interval is set, and the management data is backed up regularly according to the target time interval; if the analysis result indicates that the importance of the management data is less than the second preset importance threshold, the management data is manually backed up, that is, this embodiment can select different backup methods to back up the data according to the importance of the data. In addition, in one specific implementation, this embodiment can also convert the computer-coded data in the NAT service node into a DNA sequence and back up the data in the form of a DNA molecule; in another specific implementation, this embodiment can be combined with blockchain technology to store the data hash value on the blockchain. The data itself can be stored in a distributed storage node, and the integrity and authenticity of the data can be ensured through the blockchain to prevent the data from being maliciously tampered with. Each backup operation will generate a new hash value and record it on the blockchain, which is convenient for verifying the integrity of the data at any time. It can be understood that the above process of creating a NAT service node is carried out through the service deployment module.
[0049] The service management component is the core functional module of the present invention, which aims to provide users with comprehensive NAT gateway services, such as Figure 3 As shown, the component consists of two submodules: a NAT gateway management module and a NAT gateway business module, wherein the function of the NAT gateway management module is implemented by the NAT gateway service management node, and the function of the NAT gateway business module is implemented by the NAT gateway server created by the NAT gateway management module, i.e., the target gateway server; accordingly, the above-mentioned process of using the NAT service management node to create the initial NAT gateway corresponding to the target cloud computing platform is completed by using the NAT gateway management module, which may specifically include: determining the target gateway deployment mode according to the traffic volume in the target cloud computing platform, and using the target gateway deployment mode and the NAT service management node to create the initial NAT gateway corresponding to the target cloud computing platform (a NAT gateway without a network address translation function); wherein the target gateway deployment mode includes a stand-alone mode and a master-slave mode. It should be noted that the NAT gateway management module is responsible for the user interaction of the NAT gateway service. The user issues instructions to the NAT gateway business module by operating the NAT gateway service management node, thereby realizing the management of the NAT gateway instance. The module includes instance management function, business management function, and data monitoring function.
[0050] The above instance management function is: users can manage NAT gateway instances through this module. Users can create NAT gateway instances according to their needs (select instance specifications according to business volume), that is, initial NAT gateways. Users can choose single-point deployment mode or high-availability deployment mode. For NAT gateway instances deployed in high-availability mode, the system will simultaneously create two servers located on different host machines as the primary and backup server groups to provide services to customers. In addition, it also provides operations such as query, deletion, and reconfiguration of instances.
[0051] The above data monitoring function is: users can monitor the NAT gateway instance in real time through this module. Users can view the real-time monitoring data of the NAT gateway instance, including outbound traffic, inbound traffic, total outbound packets, total inbound packets, and individual traffic data of each IP or cloud computing resource. In this embodiment, by creating a NAT gateway in the platform, the deployment of a physical gateway for the cloud voucher is avoided, thereby reducing the complexity of gateway deployment.
[0052] Step S12: Bind a target number of elastic public IPs to the initial NAT gateway, and associate target cloud computing resources in the target cloud computing platform with the elastic public IPs.
[0053] In this embodiment, it is necessary to bind the elastic public IP to the initial NAT gateway. This process is achieved by using the service management function in the above-mentioned NAT gateway management module; the above-mentioned service management function is: the user can manage the NAT gateway service through this module, and the user can send the NAT gateway configuration to the NAT gateway server to which the specific NAT gateway instance belongs by operating this module. The above-mentioned gateway configuration mainly includes the elastic public IP management function and the cloud computing resource management function; among which, the above-mentioned elastic public IP management function is: with the help of EIP (Elastic The present invention adopts the Elastic Public IP (EPIP, i.e. Elastic Public IP) cluster technology. Users can bind one or more Elastic Public IPs to a NAT gateway instance as the traffic entrance and exit of cloud computing resources on the public network, and can also unbind the Elastic Public IP bound to the NAT gateway instance. In a specific implementation, the AI model can be used to analyze historical traffic, user behavior, time period and other data to predict future traffic peaks or valleys, and automatically adjust the binding relationship between EIP and NAT gateway accordingly. For example, redundant EIPs can be released during low traffic to reduce costs, or more EIPs can be dynamically bound during peak traffic to improve performance. In another specific implementation, the present embodiment can deploy lightweight NAT gateways on edge computing nodes of the cloud platform and bind EIPs to these nodes. Through local processing of edge computing nodes, data transmission delay can be reduced and user experience can be improved.
[0054] In this embodiment, after using the target NAT gateway and the associated elastic public IP to control the data transmission between the target cloud computing resources and the public network, it also includes: judging whether there are still cloud computing resources corresponding to the elastic public IP in the target cloud computing platform, if there are no cloud computing resources corresponding to the elastic public IP in the target cloud computing platform, then unbinding the elastic public IP bound to the target NAT gateway; binding the new elastic public IP to the target NAT gateway, and using the new elastic public IP to perform corresponding data transmission operations. By binding the NAT gateway to the elastic public IP, a small number of IPs and multiple cloud resources can be used to provide public network access services, avoiding the allocation of public IPs for each cloud computing resource, significantly reducing the use of public IP addresses, and thus reducing the cost of using cloud computing services.
[0055] Step S13: configure the network address translation function for the initial NAT gateway according to the data transmission requirements corresponding to the target cloud computing resources to obtain the corresponding target NAT gateway, and use the target NAT gateway and the associated elastic public IP to control data transmission between the target cloud computing resources and the public network.
[0056] In this embodiment, the process of configuring the network address translation function for the initial NAT gateway is implemented through the cloud computing resource management function in the NAT gateway management module, and the NAT gateway configured with the network address translation function is the target NAT gateway; wherein the above-mentioned cloud computing resource management function is: the user can select the cloud computing resources belonging to the same VPC (Virtual Private Cloud) as the NAT gateway instance, and associate it with the elastic public IP bound to the NAT gateway instance, that is, configure SNAT (Source Network Address Translation) or DNAT (Destination Network Address Translation) for the cloud computing resources, that is, the above-mentioned network address translation function, thereby realizing the public network access function of the cloud computing resources, and can also disassociate the associated cloud computing resources from the elastic public IP.
[0057] In this embodiment, after the network address translation function is initially configured for the target NAT gateway, the aforementioned NAT gateway service module is also required to implement the aforementioned network address translation function; the NAT gateway service module is the service core of the NAT gateway service. According to the command issued by the user in the NAT gateway management module, the NAT gateway service is configured on the NAT gateway server to realize the public network access requirements of cloud computing resources. It provides the following functions: SNAT function: that is, source network address translation. Figure 4 As shown, through SNAT, cloud computing resources (such as cloud servers, etc.) or subnets within the VPC that do not have a public IP can be provided with the ability to access the Internet. According to the SNAT configuration issued by the NAT gateway management module, SNAT mapping conversion is performed to provide public network access services for selected cloud servers in the VPC. These servers can use the elastic public IP bound to the NAT gateway server as the source IP address to access the public network, or they can choose to perform SNAT conversion for the subnet within the VPC. In this way, cloud computing resources in the entire subnet can access the public network through the NAT gateway service; 2) DNAT function: that is, destination network address conversion. As shown Figure 5 As shown in the figure, according to the DNAT configuration delivered by the NAT gateway management module, the EIP (elastic public IP) on the NAT gateway can be mapped to the cloud computing resources at the IP level or port level, so that the cloud computing resources can use the EIP to provide Internet services to the outside world.
[0058] It should be noted that the present embodiment can also monitor the target gateway server corresponding to the NAT service management node and the target NAT gateway, and obtain the corresponding server operation report according to the monitoring result, so as to evaluate the status of the NAT service management node and the target gateway server according to the server operation report; wherein, the server operation report includes the server resource usage, task response time and system server load corresponding to the target gateway server. The above monitoring process is realized by the real-time monitoring module in the aforementioned monitoring disaster recovery component, and the above real-time monitoring module is responsible for real-time monitoring of the operation status of the NAT gateway management node and the NAT gateway server, including but not limited to resource usage, response time and system load. Users can obtain detailed server operation reports through this module, so as to have an intuitive understanding of the health status of the system. It should be noted that the above monitoring disaster recovery component also includes a fault alarm module. When the real-time monitoring module detects that the NAT gateway management node or the NAT gateway server fails, such as server downtime or network anomaly, or the monitoring index exceeds the preset warning line, the module will immediately send an alarm message to the system administrator and relevant personnel. The alarm can be carried out in a variety of ways, including but not limited to email, SMS, telephone, etc., to ensure timely notification and response.
[0059] In addition, if the target gateway server fails, the target gateway server is repaired using a fault repair method corresponding to the deployment mode of the target NAT gateway. Specifically, if the deployment mode of the target NAT gateway is the primary-backup mode, the keepalived technology is used to switch the target gateway server between the primary and backup modes to repair the target gateway server; if the deployment mode of the target NAT gateway is the stand-alone mode, a new gateway server is selected, and the backup information of the target gateway server is imported into the new gateway server to repair the target gateway server. The above repair process is realized by monitoring the disaster recovery switching module in the disaster recovery component. The disaster recovery switching module is the key to the high availability of the system. When the NAT gateway service system encounters abnormal situations such as service interruption, the module can quickly execute the disaster recovery switching strategy. For the NAT gateway management node, if the single-point mode is adopted for deployment, the module will use the latest backup information, re-pull up a new NAT gateway management node, and take over the service. This situation will cause a temporary interruption of the service; if the high-availability mode is adopted, the backup machine will be directly converted to the host, and a new node will be pulled up as a backup machine to achieve the imperceptible troubleshooting of the NAT gateway service. For NAT gateway servers deployed in high-availability mode, when a host fails, the system will rely on keepalived technology to switch the NAT gateway server group between the primary and backup machines, use the original backup machine as the host to provide external services, and change the failed host to the backup machine. At the same time, the fault situation is notified to relevant personnel through the fault alarm module for troubleshooting. By introducing keepalived technology, this system realizes automatic troubleshooting in the case of abnormal NAT gateway services, shortens the time for fault recovery, and realizes high availability and higher stability of NAT gateway services.
[0060] It can be seen that this application uses a NAT gateway in a cloud computing environment to carry out data communication between the cloud computing platform and the public network, so that cloud computing resources are no longer directly exposed to the public network, but are accessed through the NAT gateway. Since the NAT gateway can be configured to open specific ports, the security of data communication is significantly improved; by closely integrating the NAT gateway service with the cloud computing platform, the software deployment of the NAT gateway is realized, which is easy to operate, quick to deploy, and easy to use. It avoids the deployment of physical gateways in the cloud platform, simplifies the gateway deployment process, and reduces communication costs; by using elastic public IP to bind the NAT gateway, users can use a small number of IP addresses to provide public network access services for multiple cloud resources, significantly reducing the use of public IP addresses, thereby reducing the cost of using cloud computing services.
[0061] See also Figure 6 As shown, the embodiment of the present invention discloses a cloud computing gateway service implementation device, including:
[0062] The gateway creation module 11 is used to create a NAT service management node in the target cloud computing platform, and use the NAT service management node to create an initial NAT gateway corresponding to the target cloud computing platform;
[0063] An IP binding module 12 is used to bind a target number of elastic public IPs to the initial NAT gateway, and associate a target cloud computing resource in the target cloud computing platform with the elastic public IPs;
[0064] The data transmission module 13 is used to configure the network address translation function for the initial NAT gateway according to the data transmission requirements corresponding to the target cloud computing resources to obtain the corresponding target NAT gateway, and use the target NAT gateway and the associated elastic public IP to control the data transmission between the target cloud computing resources and the public network.
[0065] It can be seen that this application uses a NAT gateway in a cloud computing environment to carry out data communication between the cloud computing platform and the public network, so that cloud computing resources are no longer directly exposed to the public network, but are accessed through the NAT gateway. Since the NAT gateway can be configured to open specific ports, the security of data communication is significantly improved; by closely integrating the NAT gateway service with the cloud computing platform, the software deployment of the NAT gateway is realized, which is easy to operate, quick to deploy, and easy to use. It avoids the deployment of physical gateways in the cloud platform, simplifies the gateway deployment process, and reduces communication costs; by using elastic public IP to bind the NAT gateway, users can use a small number of IP addresses to provide public network access services for multiple cloud resources, significantly reducing the use of public IP addresses, thereby reducing the cost of using cloud computing services.
[0066] In some specific embodiments, the gateway creation module 11 may specifically include:
[0067] A gateway creation unit is used to determine a target gateway deployment mode according to the traffic volume in the target cloud computing platform, and to create the initial NAT gateway corresponding to the target cloud computing platform using the target gateway deployment mode and the NAT service management node; wherein the target gateway deployment mode includes a stand-alone mode and an active-standby mode.
[0068] In some specific embodiments, the cloud computing gateway service implementation device further includes:
[0069] A data analysis unit, used to perform quantitative analysis on the importance of the management data in the NAT service management node to obtain corresponding analysis results;
[0070] A first data backup unit, configured to monitor changes in the management data in real time if the analysis result indicates that the importance of the management data is not less than a first preset importance threshold, and automatically back up the management data if the management data changes;
[0071] A second data backup unit, configured to set a target time interval and perform regular backup of the management data according to the target time interval if the analysis result indicates that the importance of the management data is less than a first preset importance threshold and not less than a second preset importance threshold;
[0072] The third data backup unit is configured to manually back up the management data if the analysis result indicates that the importance of the management data is less than a second preset importance threshold.
[0073] In some specific embodiments, the data transmission module 13 further includes:
[0074] An IP unbinding unit is used to determine whether there are still cloud computing resources corresponding to the elastic public IP in the target cloud computing platform. If there are no cloud computing resources corresponding to the elastic public IP in the target cloud computing platform, the elastic public IP bound to the target NAT gateway is unbound;
[0075] The IP binding unit is used to bind the new elastic public IP to the target NAT gateway and use the new elastic public IP to perform corresponding data transmission operations.
[0076] In some specific embodiments, the cloud computing gateway service implementation device further includes:
[0077] The server monitoring unit is used to monitor the target gateway server corresponding to the NAT service management node and the target NAT gateway, and obtain the corresponding server operation report according to the monitoring result, so as to evaluate the status of the NAT service management node and the target gateway server according to the server operation report; wherein, the server operation report includes the server resource usage, task response time and system server load corresponding to the target gateway server.
[0078] In some specific embodiments, the cloud computing gateway service implementation device further includes:
[0079] The server repair submodule is used to repair the target gateway server by using a fault repair method corresponding to the deployment mode of the target NAT gateway if a fault occurs to the target gateway server.
[0080] In some specific embodiments, the server repair submodule may specifically include:
[0081] The first server repair unit is used to perform active-standby switching of the target gateway server by using keepalived technology if the deployment mode of the target NAT gateway is the active-standby mode, so as to repair the target gateway server;
[0082] The second server repair unit is used to select a new gateway server if the deployment mode of the target NAT gateway is a stand-alone mode, and import the backup information of the target gateway server into the new gateway server to repair the target gateway server.
[0083] Furthermore, the present application also discloses an electronic device. Figure 7 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be regarded as any limitation on the scope of use of the present application.
[0084] Figure 7 A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the cloud computing gateway service implementation method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0085] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0086] In addition, the memory 22 as a carrier for storing resources may be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be temporary storage or permanent storage.
[0087] The operating system 221 is used to manage and control the hardware devices and computer program 222 on the electronic device 20, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the cloud computing gateway service implementation method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.
[0088] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the aforementioned disclosed cloud computing gateway service implementation method is implemented. The specific steps of the method can refer to the corresponding contents disclosed in the aforementioned embodiments, and will not be repeated here.
[0089] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0090] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0091] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0092] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0093] The technical solution provided by the present application is introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for general technicians in this field, according to the idea of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A method for implementing a cloud computing gateway service, characterized in that: include: Creating a NAT service management node in the target cloud computing platform, and using the NAT service management node to create an initial NAT gateway corresponding to the target cloud computing platform; Binding a target number of elastic public IPs to the initial NAT gateway, and associating target cloud computing resources in the target cloud computing platform with the elastic public IPs; According to the data transmission requirements corresponding to the target cloud computing resources, the network address translation function is configured for the initial NAT gateway to obtain the corresponding target NAT gateway, and the target NAT gateway is used to control the data transmission between the target cloud computing resources and the public network with the associated elastic public IP.
2. The cloud computing gateway service implementation method according to claim 1, characterized in that: The step of using the NAT service management node to create an initial NAT gateway corresponding to the target cloud computing platform includes: The target gateway deployment mode is determined according to the business volume in the target cloud computing platform, and the initial NAT gateway corresponding to the target cloud computing platform is created using the target gateway deployment mode and the NAT service management node; wherein the target gateway deployment mode includes a stand-alone mode and an active-standby mode.
3. The cloud computing gateway service implementation method according to claim 1, characterized in that: Also includes: Performing quantitative analysis on the importance of management data in the NAT service management node to obtain corresponding analysis results; If the analysis result indicates that the importance of the management data is not less than a first preset importance threshold, real-time monitoring of changes in the management data is performed, and if the management data changes, the management data is automatically backed up; If the analysis result indicates that the importance of the management data is less than a first preset importance threshold and not less than a second preset importance threshold, setting a target time interval, and performing a scheduled backup of the management data according to the target time interval; If the analysis result indicates that the importance of the management data is less than a second preset importance threshold, the management data is manually backed up.
4. The cloud computing gateway service implementation method according to claim 1, characterized in that: After using the target NAT gateway and the associated elastic public IP to control data transmission between the target cloud computing resource and the public network, the method further includes: Determine whether the target cloud computing platform still has cloud computing resources corresponding to the elastic public IP. If the target cloud computing platform does not have cloud computing resources corresponding to the elastic public IP, unbind the elastic public IP bound to the target NAT gateway. Bind the new elastic public IP to the target NAT gateway, and use the new elastic public IP to perform corresponding data transmission operations.
5. The method for implementing a cloud computing gateway service according to any one of claims 1 to 4, characterized in that: Also includes: Monitor the NAT service management node and the target gateway server corresponding to the target NAT gateway, and obtain a corresponding server operation report according to the monitoring result, so as to evaluate the status of the NAT service management node and the target gateway server according to the server operation report; wherein the server operation report includes the server resource usage, task response time and system server load corresponding to the target gateway server.
6. The cloud computing gateway service implementation method according to claim 5, characterized in that: Also includes: If the target gateway server fails, the target gateway server is repaired using a fault repair method corresponding to the deployment mode of the target NAT gateway.
7. The cloud computing gateway service implementation method according to claim 6, characterized in that: The method of repairing the target gateway server by using a fault repair method corresponding to the deployment mode of the target NAT gateway includes: If the deployment mode of the target NAT gateway is the active-standby mode, the keepalived technology is used to perform active-standby switching on the target gateway server to repair the target gateway server; If the deployment mode of the target NAT gateway is a stand-alone mode, a new gateway server is selected, and the backup information of the target gateway server is imported into the new gateway server to repair the target gateway server.
8. A cloud computing gateway service implementation device, characterized in that: include: A gateway creation module, used to create a NAT service management node in the target cloud computing platform, and use the NAT service management node to create an initial NAT gateway corresponding to the target cloud computing platform; An IP binding module is used to bind a target number of elastic public IPs to the initial NAT gateway, and associate a target cloud computing resource in the target cloud computing platform with the elastic public IPs; The data transmission module is used to configure the network address translation function for the initial NAT gateway according to the data transmission requirements corresponding to the target cloud computing resources, so as to obtain the corresponding target NAT gateway, and use the target NAT gateway and the associated elastic public IP to control the data transmission between the target cloud computing resources and the public network.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the cloud computing gateway service implementation method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: Used to store a computer program, which, when executed by a processor, implements the cloud computing gateway service implementation method according to any one of claims 1 to 7.