Configuration method, device and equipment of software defined network, medium and network

By obtaining service data in the SDN architecture and establishing a correspondence between the tunnel endpoint device and the tenant, it is sent to the storage system to reduce the number of configurations of VTEP devices, the problem of increasing processing pressure of SDN controllers and VTEP devices is solved, and higher stability and reliability are achieved.

CN120017618APending Publication Date: 2025-05-16BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510173932.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

Under the Software Defined Network (SDN) architecture, as the number of tenants increases, the flow table entries of VTEP devices increase, resulting in increased processing pressure of SDN controllers and VTEP devices.

Method used

By obtaining business data, a corresponding relationship between the tunnel endpoint device and the tenant is established, and this relationship and related logical configuration information are sent to the storage system, so that the tunnel endpoint device only obtains the configuration information it needs.

Benefits of technology

It effectively reduces the number of configurations of each tunnel endpoint device, reduces processing pressure, and improves overall stability and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017618A_ABST
    Figure CN120017618A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of software-defined networks, and discloses a software-defined network configuration method, device and equipment, a medium and a network, and the method comprises the following steps: obtaining service data; the service data comprises logic configuration information corresponding to virtual resources of each tenant and tunnel endpoint equipment corresponding to the virtual resources; establishing a corresponding relationship between the tunnel endpoint device and the tenant according to the service data, and determining logic configuration information associated with the tenant; and issuing the corresponding relationship between the tunnel endpoint device and the tenant and the logic configuration information associated with the tenant to a lower storage system to indicate the tunnel endpoint device to obtain the logic configuration information of the corresponding tenant from the storage system. According to the invention, the second controller of each tunnel endpoint device can only obtain the required configuration from the storage system, and does not need to issue the configuration of the total tenant to each tunnel endpoint device, so that the configuration number of each tunnel endpoint device can be effectively reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of software defined networks, and in particular to configuration methods, devices, equipment, media and networks for software defined networks. Background Art

[0002] With the development of cloud computing and virtualization technology, virtual machines and containers provide higher flexibility and resource utilization than physical machines. Overlay networks create virtual networks on top of physical networks through VXLAN (Virtual eXtensible Local Area Network) technology, allowing virtual machines and containers across hosts to communicate efficiently. Currently, SDN (Software-defined Networking) technology is a commonly used way to implement network virtualization, which is combined with virtual switches to achieve network virtualization capabilities.

[0003] Under the SDN architecture, the traditional SDN controller will send the flow table of all tenants to each VTEP device. However, as the number of tenants gradually increases, the number of flow table entries of each VTEP device will increase, resulting in increased processing pressure on the SDN controller and VTEP devices. Summary of the invention

[0004] In view of this, the present disclosure provides a configuration method, apparatus, device, medium and network of a software defined network to solve the problem of high processing pressure on the controller.

[0005] In a first aspect, the present disclosure provides a method for configuring a software defined network, which is applied to a first controller of the software defined network, and the method includes:

[0006] Acquire business data; the business data includes logical configuration information corresponding to the virtual resources of each tenant and the tunnel endpoint device corresponding to the virtual resources;

[0007] Establishing a correspondence between a tunnel endpoint device and a tenant according to the service data, and determining logical configuration information associated with the tenant;

[0008] The correspondence between the tunnel endpoint device and the tenant and the logical configuration information associated with the tenant are sent to the storage system at the lower layer to instruct the tunnel endpoint device to obtain the logical configuration information of the corresponding tenant from the storage system.

[0009] In a second aspect, the present disclosure provides a method for configuring a software defined network, which is applied to a second controller of a tunnel endpoint device, the method comprising:

[0010] According to the correspondence between the tunnel endpoint device and the tenant stored in the upper storage system, query the target tenant corresponding to the local tunnel endpoint device;

[0011] Acquire target logical configuration information associated with the target tenant from the storage system; the storage system stores logical configuration information associated with the tenant;

[0012] Generate corresponding flow table entries according to the target logical configuration information, and issue the flow table entries.

[0013] In a third aspect, the present disclosure provides a software defined network, including: a first controller, a storage system, and a plurality of tunnel endpoint devices; the tunnel endpoint device is provided with a second controller;

[0014] The first controller is used to execute the configuration method of the software defined network of the first aspect or any corresponding embodiment thereof;

[0015] The second controller is used to execute the software-defined network configuration method of the second aspect or any corresponding implementation manner thereof.

[0016] In a fourth aspect, the present disclosure provides a configuration device for a software defined network, which is applied to a first controller of the software defined network, and the device includes:

[0017] A data acquisition module, used to acquire business data; the business data includes logical configuration information corresponding to the virtual resources of each tenant and the tunnel endpoint device corresponding to the virtual resources;

[0018] A processing module, used to establish a corresponding relationship between the tunnel endpoint device and the tenant according to the service data, and determine the logical configuration information associated with the tenant;

[0019] The configuration sending module is used to send the corresponding relationship between the tunnel endpoint device and the tenant and the logical configuration information associated with the tenant to the lower-level storage system to instruct the tunnel endpoint device to obtain the logical configuration information of the corresponding tenant from the storage system.

[0020] In a fifth aspect, the present disclosure provides a configuration device for a software-defined network, which is applied to a second controller of a tunnel endpoint device, and the device includes:

[0021] A query module, used to query a target tenant corresponding to a local tunnel endpoint device according to a correspondence between the tunnel endpoint device and the tenant stored in an upper storage system;

[0022] A configuration acquisition module, configured to acquire target logical configuration information associated with the target tenant from the storage system; the storage system stores logical configuration information associated with the tenant;

[0023] The flow table sending module is used to generate corresponding flow table entries according to the target logical configuration information and send the flow table entries.

[0024] In a sixth aspect, the present disclosure provides a computer device, comprising: a memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method for configuring a software-defined network of the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0025] In a seventh aspect, the present disclosure provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the method for configuring a software-defined network of the first aspect or any corresponding embodiment thereof.

[0026] In an eighth aspect, the present disclosure provides a computer program product, including computer instructions, which are used to enable a computer to execute the method for configuring a software-defined network of the above-mentioned first aspect or any corresponding embodiment thereof.

[0027] The first controller in the present disclosure converts the upper-layer business data into the correspondence between the tunnel endpoint device and the tenant and the logical configuration information associated with the tenant, and sends this information to the storage system, so that the second controller of each tunnel endpoint device can only obtain the configuration required by itself from the storage system, and does not need to send the configuration of all tenants to each tunnel endpoint device, which can effectively reduce the number of configurations of each tunnel endpoint device. In addition, the logical decoupling of the two-layer controller is realized by using the storage system, which can improve the overall stability and reliability.

[0028] In addition, the second controller of the local tunnel endpoint device queries the correspondence between the tunnel endpoint device and the tenant in the storage system, and can determine the target tenant corresponding to itself, and then obtain the target logical configuration information associated with the target tenant from the storage system, so as to realize on-demand delivery of network configuration. The local tunnel endpoint device only needs to obtain the necessary target logical configuration information and does not need to obtain the configuration of all tenants. It can reduce the number of configurations of each tunnel endpoint device, reduce the load of each tunnel endpoint device, and alleviate processing pressure. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the specific embodiments of the present disclosure or the technical solutions in the related technologies, the drawings required for use in the specific embodiments or the related technical descriptions will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0030] Figure 1 This is an architectural diagram of traditional SDN;

[0031] Figure 2 is a schematic diagram of an architecture of a software defined network according to an embodiment of the present disclosure;

[0032] Figure 3 is a flowchart of a method for configuring a software defined network according to an embodiment of the present disclosure;

[0033] Figure 4 is a schematic diagram of a logical architecture of a first controller according to an embodiment of the present disclosure;

[0034] Figure 5 is a flowchart of another method for configuring a software defined network according to an embodiment of the present disclosure;

[0035] Figure 6 is a schematic diagram of a logical architecture of a second controller according to an embodiment of the present disclosure;

[0036] Figure 7 is a structural block diagram of a configuration device of a first controller according to an embodiment of the present disclosure;

[0037] Figure 8 is a structural block diagram of a configuration device of a second controller according to an embodiment of the present disclosure;

[0038] Fig. 9 It is a schematic diagram of the hardware structure of the computer device of the embodiment of the present disclosure. DETAILED DESCRIPTION

[0039] In order to make the purpose, technical solution and advantages of the embodiments of the present disclosure clearer, the technical solution in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present disclosure.

[0040] SDN (Software-Defined Networking) is an emerging network architecture model and a network virtualization and containerization method. In traditional network devices such as switches and routers, the data plane (responsible for the actual forwarding of data packets) and the control plane (determine how data flows) are tightly integrated in the hardware. This coupling makes network configuration and management complex and inflexible. The core concept of SDN is to separate the control plane from the network hardware and hand it over to the SDN controller for unified management, which can optimize network resources and quickly adjust the network to adapt to changing business needs, applications and traffic, thereby achieving more efficient network control and management.

[0041] Figure 1 A schematic diagram of the SDN architecture is shown. Figure 1 As shown in the figure, the SDN controller of the control plane is the brain of the SDN network, which is mainly responsible for issuing routing decisions and policies and managing the entire network traffic.

[0042] The northbound interface is the communication interface between the controller and the upper application plane, allowing applications to interact with network devices through APIs (application programming interfaces), which makes network management and application development more convenient and provides possibilities for network intelligence and automation.

[0043] The southbound interface is the communication interface between the controller and the network device. Through the southbound interface, the controller can send instructions to the network devices to tell them how to handle specific data flows and ensure that the data is transmitted according to predetermined rules. The communication protocol used by the southbound interface is generally OpenFlow (a network communication protocol), which allows the SDN controller to communicate directly with network devices (such as switches and routers), thereby realizing centralized management and dynamic configuration of network traffic. Through OpenFlow, the SDN controller can issue instructions to control how network devices process and forward data packets.

[0044] The data plane can include traditional network devices (such as switches and routers), whose main responsibility is to forward data packets. Under the SDN architecture, the data plane only needs to perform simple data forwarding operations according to the instructions of the SDN controller, without the need for complex routing decisions.

[0045] With the continuous development of cloud computing and virtualization technology, network virtualization has become one of the key technologies for building a flexible and scalable network architecture. As a powerful open source virtual switch, Open vSwitch (OVS) is widely used in cloud computing and virtualization environments.

[0046] OVS is a high-quality virtual switch that supports multi-layer data forwarding and is used in software-defined networks. It is based on the idea of ​​software-defined networks (SDN) and implements the functions of traditional hardware switches through software. Through virtualization technology, an independent network interface is provided for each virtual machine, thereby achieving network isolation and communication between multiple virtual machines on the same physical host.

[0047] VXLAN is a network virtualization technology. VTEP devices are edge devices of VXLAN networks and the starting and ending points of VXLAN tunnels. They are usually physical or virtual switches, servers, or other network devices that support VXLAN. The job of VTEP devices is to create and terminate tunnels between each other and to be responsible for the encapsulation and unpacking of VXLAN protocol messages, that is, to encapsulate the message header of VTEP communication on the virtual message, so as to realize the communication between virtual machines in different VTEP devices.

[0048] Currently, under the SDN architecture, all network configurations are statically issued, such as flow tables, VTEP (VXLANTunnel Endpoints) device information, etc. Traditional SDN controllers issue flow tables for all tenants for each VTEP device. However, as the number of VPC (Virtual Private Cloud) tenants (Tenants) in the network gradually increases, the number of virtual machines and containers of different tenants also gradually increases, and the cluster size gradually increases, which leads to an increase in the number of flow table entries of each device, resulting in increased processing pressure on SDN controllers and virtual switches, and longer recovery time for scenarios such as hot upgrades and failures.

[0049] Specifically, in the distributed deployment of traditional SDN architecture, resource management locking mechanisms for each VTEP device are necessary to prevent data inconsistency or conflict; however, locking competition will become more intense in large-scale clusters, resulting in performance degradation. Since each VTEP device sends the configuration of all tenants, there may be a large number of invalid configurations on each VTEP device. Since not all tenants will use all VTEP devices, these invalid configurations not only occupy device resources, but also reduce the performance of the entire cluster. In addition, if a single-machine single-point deployment mode is adopted, if the controller fails or is attacked, the entire SDN network may be affected, and the control disaster recovery capability is low, making it difficult to meet high availability requirements.

[0050] According to an embodiment of the present disclosure, an embodiment of a configuration method for a software-defined network is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0051] In this embodiment, a configuration method for a software-defined network is provided, which is applied to a controller in a software-defined network; wherein the controller in the software-defined network is deployed in two layers; and a storage system is provided between the two layers of controllers to achieve logical decoupling of the two layers of controllers. The two layers of controllers no longer interact directly, but store and obtain information through the storage system. The coupling degree between the two layers of controllers is greatly reduced. The storage system, as an intermediate buffer layer, can effectively solve the event storm problem in the cluster and improve the stability and maintainability of the system.

[0052] Figure 2 A schematic diagram of the software defined network architecture is shown in FIG. Figure 2 As shown, the software defined network includes: a first controller, a storage system and a plurality of tunnel endpoint devices; the tunnel endpoint device is provided with a second controller.

[0053] The first controller is a component for single-point deployment in the cluster, which is an upper-layer SDN controller. The first controller is connected to the storage system and is used to send corresponding configuration information to the storage system. The second controller is a control agent component (Agent) in each tunnel endpoint device, which is connected to the storage system and is used to obtain the configuration information required by itself. Figure 2 As shown, the tunnel endpoint device is specifically a VTEP device.

[0054] A configuration method for a software defined network provided in this embodiment can be applied to the first controller mentioned above. Figure 3 is a flowchart of a method for configuring a software defined network according to an embodiment of the present disclosure, such as Figure 3 As shown, the process includes the following steps.

[0055] Step S301, obtaining business data; the business data includes logical configuration information corresponding to the virtual resources of each tenant and the tunnel endpoint device corresponding to the virtual resources.

[0056] In this embodiment, tenants can create virtual resources they need on the application plane, and the virtual resources may be, for example, virtual machines, containers, etc.; and, by logically configuring the virtual resources, corresponding logical configuration information may be generated. For example, the logical configuration information may include: speed limit configuration, elastic network card configuration, bandwidth configuration, etc.

[0057] In addition, the virtual resources created by the tenants will be scheduled to the corresponding nodes, and the devices corresponding to the nodes are tunnel endpoint devices, such as VTEP devices. The application plane can record the logical configuration information corresponding to the virtual resources of each tenant and the tunnel endpoint devices corresponding to the virtual resources.

[0058] The first controller can obtain the service data of each tenant from the upper application plane, and the service data includes the logical configuration information corresponding to the virtual resources of the tenant recorded by the application plane and the tunnel endpoint device corresponding to the virtual resources. The first controller is provided with a northbound interface, and the service data can be obtained based on the northbound interface.

[0059] Step S302: Establish a correspondence between the tunnel endpoint device and the tenant according to the service data, and determine the logical configuration information associated with the tenant.

[0060] In this embodiment, in order to facilitate each tunnel endpoint device at the lower layer to obtain the valid information required by itself, the first controller converts the service data.

[0061] Specifically, based on the service data, it can be determined which tenant or tenants each tunnel endpoint device corresponds to (i.e., the tunnel endpoint device can correspond to one or more tenants), so that a correspondence between the tunnel endpoint device and the tenant can be established. For example, tenant A creates a virtual machine 1, and this virtual machine 1 is scheduled to node B, which corresponds to VTEP device 2. Then the first controller can generate a correspondence between VTEP device 2 and tenant A.

[0062] Furthermore, according to the business data, corresponding tenants may be associated with the logical configuration information, so that each logical configuration information is associated with the tenant.

[0063] Step S303: Send the correspondence between the tunnel endpoint device and the tenant and the logical configuration information associated with the tenant to the lower-layer storage system to instruct the tunnel endpoint device to obtain the logical configuration information of the corresponding tenant from the storage system.

[0064] In this embodiment, the information generated by the first controller is not directly sent to each tunnel endpoint device, but is sent to the lower-level storage system, which records the correspondence between the tunnel endpoint device and the tenant and the logical configuration information associated with the tenant. That is, the storage system stores the configuration of all tenants, and each tunnel endpoint device subsequently obtains the corresponding logical configuration information from the storage system; wherein, since the information stored in the storage system includes the correspondence between the tunnel endpoint device and the tenant, and each logical configuration information is associated with the tenant, each tunnel endpoint device can obtain only the configuration information it needs, without the need for full information, thereby reducing the number of configurations of each tunnel endpoint device, and the process of the tunnel endpoint device obtaining the configuration is explained later.

[0065] Figure 4 A schematic diagram of a logical architecture of a first controller is shown. The first controller is a component for single-point deployment in a cluster, and its main functions are as follows:

[0066] (1) Northbound external interface layer: Based on the northbound HTTP interface service, the user plane can query the controller's business data, such as virtual machine specifications, device bandwidth, and other data.

[0067] (2) Mapping of northbound object model and southbound data configuration: The northbound object model is a virtual machine model, etc. By defining the model and verifying the object model attributes, the corresponding northbound object data is obtained, and then the northbound object data is converted into southbound data configuration. The southbound data configuration is the data that needs to be stored in the storage system, such as the correspondence between the tunnel endpoint device and the tenant and the logical configuration information associated with the tenant.

[0068] (3) Southbound logical processing layer: responsible for sending southbound data in batches to the storage system; and also used to process information reported by southbound devices, where the southbound device is the second controller in the tunnel endpoint device, and the information it reports includes, for example, the virtual machine status.

[0069] (4) Southbound interface layer: responsible for connecting to southbound channel components, such as channel components of storage systems.

[0070] In the configuration method of the software-defined network provided in this embodiment, the first controller converts the upper-layer business data into the correspondence between the tunnel endpoint device and the tenant and the logical configuration information associated with the tenant, and sends this information to the storage system, so that the second controller of each tunnel endpoint device can only obtain the configuration required by itself from the storage system, and does not need to send the configuration of the full tenant to each tunnel endpoint device, which can effectively reduce the number of configurations of each tunnel endpoint device. In addition, the logical decoupling of the two-layer controller is realized by using the storage system, which can improve the overall stability and reliability.

[0071] In some optional implementations, the index structure corresponding to the correspondence between the tunnel endpoint device and the tenant includes: a device identifier of the tunnel endpoint device at a first layer, and a tenant identifier at a second layer.

[0072] In this embodiment, the correspondence between the tunnel endpoint device and the tenant generated by the first controller is stored in the storage system according to a certain index structure. The first layer of the index structure is the device identifier of the tunnel endpoint device, such as the IP address of the tunnel endpoint device, and the second layer of the index structure is the tenant identifier, such as the tenant ID.

[0073] Storing the correspondence between tunnel endpoint devices and tenants based on the index structure is beneficial for tunnel endpoint devices to perform matching queries based on their respective device identifiers, such as prefix matching queries, so as to quickly obtain their corresponding tenant identifiers, and then obtain the logical configuration information associated with the tenant identifier. This process is described in detail later.

[0074] Optionally, the process of "determining logical configuration information associated with the tenant" in the above step S302 may include: determining logical configuration information associated with the tenant in a key-value storage format; the key of the logical configuration information associated with the tenant includes the tenant identifier.

[0075] In this embodiment, the storage system is a key-value storage system, such as ETCD; wherein ETCD is an open source distributed key-value storage system, which is mainly used to store and manage configuration information, service discovery, and coordinate data in distributed systems. ETC and D in ETCD come from the unix " / etc" folder and the distributed system "Distributed" respectively. The " / etc" folder is where a single system stores configuration data, and ETCD stores configuration information of large-scale distributed systems.

[0076] The logical configuration information associated with the tenant determined by the first controller is stored in the form of key-value storage, that is, the logical configuration information associated with the tenant stored in the storage system is a key-value pair. Among them, the key of the logical configuration information associated with the tenant includes at least the tenant identifier, and its value is the corresponding logical configuration information. Storing the logical configuration information associated with the tenant in the form of key-value storage facilitates the tunnel endpoint device to monitor it based on the tenant identifier, so as to obtain the required and updated logical configuration information in a timely manner. The monitoring process of the tunnel endpoint device is explained later.

[0077] Another configuration method of a software defined network provided in this embodiment can be applied to a controller in a tunnel endpoint device, that is, the second controller mentioned above. Figure 5is a flowchart of a method for configuring a software defined network according to an embodiment of the present disclosure, such as Figure 5 As shown, the process includes the following steps.

[0078] Step S501 : querying a target tenant corresponding to a local tunnel endpoint device according to a correspondence relationship between tunnel endpoint devices and tenants stored in an upper-layer storage system.

[0079] In this embodiment, as described above, the storage system stores the configuration of all tenants issued by the first controller, specifically including: the correspondence between the tunnel endpoint devices and the tenants and the logical configuration information associated with the tenants.

[0080] Among them, the correspondence between the tunnel endpoint device and the tenant indicates which tenant or tenants the tunnel endpoint device corresponds to; for the local tunnel endpoint device that executes the method, a query can be performed based on the correspondence between the tunnel endpoint device and the tenant to determine the tenant corresponding to the local tunnel endpoint device. For the sake of convenience of description, the tenant corresponding to the local tunnel endpoint device is called the target tenant.

[0081] It can be understood that, under normal circumstances, the tunnel endpoint device only has a corresponding relationship with some tenants, that is, only these tenants will be used as target tenants; in other words, tenants that are not related to the local tunnel endpoint device are invalid tenants, and for the local tunnel endpoint device, these invalid tenants will not be processed subsequently.

[0082] Step S502: Acquire target logical configuration information associated with a target tenant from a storage system; the storage system stores the logical configuration information associated with the tenant.

[0083] In this embodiment, after the second controller determines the corresponding target tenant, it can further obtain logical configuration information associated with the target tenant from the storage system, that is, the target logical configuration information. The target logical configuration information is the configuration required for the local tunnel endpoint device, so that all configurations sent to the local tunnel endpoint device are necessary and do not contain logical configuration information of invalid tenants; that is, the local tunnel endpoint device may not save the configuration of all tenants.

[0084] Step S503: Generate corresponding flow table entries according to the target logical configuration information, and issue the flow table entries.

[0085] In this embodiment, after the second controller obtains the necessary target logic configuration information, it can calculate the corresponding forwarding rules according to the target logic configuration information, thereby generating a flow table entry (Flow Entry). Each flow table entry can define a set of matching conditions and corresponding forwarding rules, and finally issue the flow table entry. Figure 2As shown, the second controller can send the flow table entry to the virtual switch through the OpenFlow protocol, and the virtual switch is, for example, OVS-dpdk (DataPlane Development Kit), so as to process the corresponding traffic based on the flow table entry to realize data forwarding.

[0086] In the software-defined network configuration method provided in this embodiment, the second controller of the local tunnel endpoint device queries the correspondence between the tunnel endpoint device and the tenant in the storage system, and can determine the target tenant corresponding to itself, and then obtain the target logical configuration information associated with the target tenant from the storage system, so as to realize on-demand delivery of network configuration. The local tunnel endpoint device only needs to obtain the necessary target logical configuration information and does not need to obtain the configuration of all tenants. It can reduce the number of configurations of each tunnel endpoint device, reduce the load of each tunnel endpoint device, and alleviate processing pressure.

[0087] In some optional implementations, as described above, the index structure corresponding to the correspondence between the tunnel endpoint device and the tenant includes: a device identifier of the tunnel endpoint device at the first layer, and a tenant identifier at the second layer.

[0088] Furthermore, the above step S501 "querying the target tenant corresponding to the local tunnel endpoint device according to the correspondence between the tunnel endpoint device and the tenant stored in the upper storage system" includes step a1.

[0089] Step a1: perform prefix matching query on the correspondence between the tunnel endpoint device and the tenant stored in the storage system according to the device identifier of the local tunnel endpoint device, and determine the tenant identifier of the target tenant.

[0090] In this embodiment, the index result of the corresponding relationship includes two layers, namely, the device identification of the tunnel endpoint device and the tenant identification. Specifically, the index structure can be a storage path, which is a hierarchically organized directory, the first layer of which is the device identification of the tunnel endpoint device, and the second layer is the tenant identification. Specifically, the format of the index structure can be expressed as: / <device identification of the tunnel endpoint device> / <tenant identification>.

[0091] For example, if the storage system is a key-value storage system such as ETCD, the index structure is the key of the corresponding relationship, and its value can include the tenant identifier corresponding to the corresponding tunnel endpoint device. Alternatively, if the tenant identifier in the second layer of the index structure is the same as the specific value, the corresponding tenant identifier can be directly determined based on the index structure.

[0092] Specifically, the local tunnel endpoint device knows its own device identifier, and can perform a prefix matching query on the index structure based on its own device identifier, that is, compare the device identifier of the first layer of the index structure with its own device identifier, so as to query the various tenant identifiers corresponding to its own device identifier. These tenant identifiers are the tenant identifiers of the target tenants.

[0093] In this embodiment, the correspondence between the tunnel endpoint device and the tenant is stored based on the index structure. The local tunnel endpoint device can perform a prefix matching query on the index result based on its own device identification, so that it can simply and quickly determine the various target tenants under its own device, and then obtain the relevant target logical configuration information based on subsequent steps.

[0094] Optionally, the storage system includes storage and notification middleware; as the name implies, the storage and notification middleware has a notification function in addition to the storage function; for example, the storage system may be ETCD, through which ETCD acts as the storage and notification middleware.

[0095] Furthermore, the storage system is a key-value storage system, wherein the logical configuration information associated with the tenant is stored in a key-value format, and the key of the logical configuration information associated with the tenant includes the tenant identifier. The logical configuration information may specifically include a logical configuration type and an identifier (e.g., ID) corresponding to each configuration item, and the key of the logical configuration information associated with the tenant may specifically include: tenant identifier, logical configuration type, and configuration item identifier, and its storage format in the storage system is, for example: / <logical configuration type> / <tenant identifier> / <configuration item identifier>.

[0096] The above step S502 of “obtaining target logical configuration information associated with the target tenant from the storage system” includes steps b1 and b2.

[0097] Step b1, initiating a monitoring request to the storage and notification middleware; the monitoring request is used to monitor the tenant identifier of the target tenant.

[0098] Step b2, acquiring a monitoring event pushed by the storage and notification middleware when the value corresponding to the tenant identifier of the target tenant changes; the monitoring event includes target logic configuration information associated with the target tenant.

[0099] In this embodiment, after the second controller determines the tenant identifier of the target tenant, it can initiate a monitoring request to the storage and notification middleware to monitor the change of the value corresponding to the tenant identifier of the target tenant. When the value corresponding to the tenant identifier is created, updated, or deleted, the storage and notification middleware can generate a monitoring event including the changed value, which includes the target logical configuration information associated with the target tenant, and then push the monitoring event to the second controller, so that the second controller can obtain the required target logical configuration information in a timely manner based on the monitoring method.

[0100] Figure 6 A schematic diagram of the logical architecture of the second controller is shown. Each tunnel endpoint device is configured with a second controller, which is responsible for sending data plane configurations such as flow tables to the tunnel endpoint device. Its main functions are as follows:

[0101] (1) Northbound driver layer: responsible for monitoring changes in the corresponding tenant configuration in the storage system and performing subsequent processing.

[0102] (2) Northbound logic processing layer: used to provide functions such as parameter verification, permission verification, and internal orchestration logic of the second controller.

[0103] (3) Northbound data model and southbound flow table configuration mapping: responsible for converting the northbound data model into the southbound flow table configuration; the northbound data model is the model corresponding to the data obtained from the storage system, and the southbound flow table configuration is the flow table item that needs to be sent.

[0104] For example, the flow table configuration includes the definition and organization of the flow table configuration, and the converted flow table can also be persistently stored. In addition, the consistency check of northbound data and southbound flow tables can be performed based on the internal data reconciliation function to ensure the accuracy of the data.

[0105] (4) Bottom-level device abstraction layer: used for definition, verification, and persistence of bridge and interface devices.

[0106] (5) Southbound logic processing layer: responsible for sending batches of flow configuration data, and also used to process information reported by southbound devices; the southbound devices are virtual switches at the lower layer, etc.

[0107] (6) Southbound interface layer: responsible for connecting to southbound channel components, such as connecting to the virtual switch at the lower layer.

[0108] For ease of description, the overall configuration process is explained below using an embodiment, wherein the software defined network includes multiple VTEP devices, which serve as tunnel endpoint devices; and the storage system between the two layers of controllers uses ETCD.

[0109] by Figure 2 Taking the structure shown as an example, if tenant A creates a virtual machine 1, and this virtual machine 1 is scheduled to node B, and this node B corresponds to VTEP device 2; the first controller records which tenant's virtual machines or containers are running under each VTEP device, and creates a corresponding relationship between the VTEP device and the tenant according to the resource situation of the virtual machines or containers created by the tenant on the VTEP device, and stores it in ETCD. Its storage format is: / <VTEP device IP> / <tenant ID>.

[0110] For example, if the IP address of VTEP device 2 is 1.1.1.1 and the ID of tenant A is tenant_A, then it is recorded in ETCD as: / 1.1.1.1 / tenant_A, which is the corresponding index structure.

[0111] Moreover, the first controller creates the logical configuration information corresponding to each tenant, and each is associated with the corresponding tenant ID. The storage format of this information in ETCD is: / <logical configuration type> / <tenant ID> / <configuration item ID>. This storage format is specifically the storage path of the logical configuration information, representing the key of the logical configuration information, and the value corresponding to it is the specific configuration content.

[0112] For example, tenant A corresponds to a rate-limit configuration, and one of its configuration item IDs is config001, then the storage path of this logical configuration information can be: / rate-limit / tenant_A / config001.

[0113] For each VTEP device, after the second controller starts, it can query ETCD for all tenant information on this VTEP device. Since tenant A's virtual machine does not exist in VTEP device 1 and VTEP device 3, these two VTEP devices will not obtain any configuration regarding tenant A.

[0114] For VTEP device 2, its second controller can initiate a query to ETCD based on its own IP address, and can determine the tenant identifier tenant_A belonging to itself through the method of prefix matching query. Further, VTEP device 2 can assemble the ETCD prefix listening configuration according to this tenant identifier tenant_A, and then monitor the logical configuration information it needs.

[0115] For example, a prefix similar to " / * / tenant_A / " can be assembled, where * represents a wildcard and represents any logical configuration type. Through this prefix, VTEP device 2 can tell ETCD that it is interested in all configuration changes belonging to tenant "tenant_A" under all logical configuration types. When any configuration in ETCD that matches the prefix path changes (whether it is a new configuration, a modified configuration, or a deleted configuration), ETCD will send a notification to the second controller of VTEP device 2, that is, listen for events.

[0116] The second controller of VTEP device 2 can obtain specific logical configurations based on the configuration change notification sent by ETCD. For example, the specific value of the speed limit, the network interface of the application, and other information. In this way, the second controller can promptly obtain the logical configuration changes related to the tenant ID corresponding to itself, and then send these changes to the relevant network devices to ensure that the flow table of the network device is consistent with the tenant logical configuration stored in ETCD, so as to achieve accurate management of tenant network resources.

[0117] The configuration method of the software-defined network provided in this embodiment adopts an index-based two-layer controller separation architecture. The upper-layer first controller is mainly responsible for abstraction and computing logic configuration. Resources competing for resources within the cluster can also be well handled because of the single computing capability of the first controller. The tunnel endpoint device only obtains relevant logical configuration information, that is, it is only responsible for resource management under its own device, and realizes on-demand distribution of network configuration. It can effectively screen and filter invalid resources and configurations, avoid sending useless configurations to the data plane, effectively reduce the load of the second controller and the data plane, and is conducive to expanding the scale of the entire cluster.

[0118] In this embodiment, a configuration device for a software-defined network is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" may be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0119] This embodiment provides a configuration device for a software defined network, which is applied to a first controller of the software defined network, such as Figure 7 As shown, the device comprises:

[0120] The data acquisition module 701 is used to acquire business data; the business data includes the logical configuration information corresponding to the virtual resources of each tenant and the tunnel endpoint device corresponding to the virtual resources;

[0121] A processing module 702, configured to establish a correspondence between a tunnel endpoint device and a tenant according to the service data, and determine logical configuration information associated with the tenant;

[0122] The configuration sending module 703 is used to send the correspondence between the tunnel endpoint device and the tenant and the logical configuration information associated with the tenant to the lower-level storage system to instruct the tunnel endpoint device to obtain the logical configuration information of the corresponding tenant from the storage system.

[0123] In some optional implementations, the index structure corresponding to the correspondence between the tunnel endpoint device and the tenant includes: a device identifier of the tunnel endpoint device at a first layer, and a tenant identifier at a second layer.

[0124] In some optional implementations, the processing module 702 determines the logical configuration information associated with the tenant, including:

[0125] Determine logical configuration information associated with the tenant in a key-value storage format; the key of the logical configuration information associated with the tenant includes a tenant identifier.

[0126] This embodiment provides a configuration device for a software defined network, which is applied to a second controller of a tunnel endpoint device, such as Figure 8 As shown, the device comprises:

[0127] A query module 801, configured to query a target tenant corresponding to a local tunnel endpoint device according to a correspondence relationship between tunnel endpoint devices and tenants stored in an upper storage system;

[0128] The configuration acquisition module 802 is used to acquire the target logical configuration information associated with the target tenant from the storage system; the storage system stores the logical configuration information associated with the tenant;

[0129] The flow table sending module 803 is used to generate corresponding flow table entries according to the target logical configuration information and send the flow table entries.

[0130] In some optional implementations, the index structure corresponding to the correspondence between the tunnel endpoint device and the tenant includes: a device identifier of the tunnel endpoint device at the first layer, and a tenant identifier at the second layer;

[0131] The query module 801 queries the target tenant corresponding to the local tunnel endpoint device according to the correspondence between the tunnel endpoint device and the tenant stored in the upper storage system, including:

[0132] A prefix matching query is performed on the index structure corresponding to the correspondence between the tunnel endpoint device and the tenant stored in the storage system according to the device identifier of the local tunnel endpoint device to determine the tenant identifier of the target tenant.

[0133] In some optional implementations, the storage system includes storage and notification middleware; the logical configuration information associated with the tenant is stored in a key-value storage format, and the key of the logical configuration information associated with the tenant includes a tenant identifier;

[0134] The configuration acquisition module 802 acquires target logical configuration information associated with the target tenant from the storage system, including:

[0135] Initiate a monitoring request to the storage and notification middleware; the monitoring request is used to monitor the tenant identifier of the target tenant;

[0136] Acquire a monitoring event pushed by the storage and notification middleware when a value corresponding to the tenant identifier of the target tenant changes; the monitoring event includes target logic configuration information associated with the target tenant.

[0137] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0138] The configuration device of the software-defined network in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, including a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0139] The present disclosure also provides a computer device having the above Figure 7 or Figure 8 A configuration apparatus for a software defined network is shown.

[0140] See also Fig. 9 , Fig. 9 is a schematic diagram of a computer device provided by an optional embodiment of the present disclosure, such as Fig. 9As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Fig. 9 A processor 10 is taken as an example.

[0141] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.

[0142] The memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.

[0143] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0144] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.

[0145] The computer device further comprises a communication interface 30 for the computer device to communicate with other devices or a communication network.

[0146] The embodiments of the present disclosure also provide a computer-readable storage medium. The above-mentioned method according to the embodiments of the present disclosure can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium and downloaded through a network, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.

[0147] A part of the present disclosure may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present disclosure through the operation of the computer. Those skilled in the art should understand that the existence of computer program instructions in computer-readable media includes, but is not limited to, source files, executable files, installation package files, etc., and accordingly, the way in which computer program instructions are executed by a computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to the computer.

[0148] Although the embodiments of the present disclosure are described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations should all be included in the protection scope of the present disclosure.

Claims

1. A method for configuring a software defined network, characterized in that: A first controller applied to a software defined network, the method comprising: Acquire business data; the business data includes logical configuration information corresponding to the virtual resources of each tenant and the tunnel endpoint device corresponding to the virtual resources; Establishing a correspondence between a tunnel endpoint device and a tenant according to the service data, and determining logical configuration information associated with the tenant; The correspondence between the tunnel endpoint device and the tenant and the logical configuration information associated with the tenant are sent to the storage system at the lower layer to instruct the tunnel endpoint device to obtain the logical configuration information of the corresponding tenant from the storage system.

2. The method according to claim 1, characterized in that The index structure corresponding to the correspondence between the tunnel endpoint device and the tenant includes: a device identifier of the tunnel endpoint device at the first layer, and a tenant identifier at the second layer.

3. The method according to claim 1 or 2, characterized in that: The determining of the logical configuration information associated with the tenant includes: Determine logical configuration information associated with the tenant in a key-value storage format; the key of the logical configuration information associated with the tenant includes a tenant identifier.

4. A method for configuring a software defined network, characterized in that: A second controller applied to a tunnel endpoint device, the method comprising: According to the correspondence between the tunnel endpoint device and the tenant stored in the upper storage system, query the target tenant corresponding to the local tunnel endpoint device; Acquire target logical configuration information associated with the target tenant from the storage system; the storage system stores logical configuration information associated with the tenant; Generate corresponding flow table entries according to the target logical configuration information, and issue the flow table entries.

5. The method according to claim 4, characterized in that The index structure corresponding to the correspondence between the tunnel endpoint device and the tenant includes: a device identifier of the tunnel endpoint device at the first layer, and a tenant identifier at the second layer; The querying of the target tenant corresponding to the local tunnel endpoint device according to the correspondence between the tunnel endpoint device and the tenant stored in the upper storage system includes: A prefix matching query is performed on the index structure corresponding to the correspondence between the tunnel endpoint device and the tenant stored in the storage system according to the device identifier of the local tunnel endpoint device to determine the tenant identifier of the target tenant.

6. The method according to claim 4 or 5, characterized in that: The storage system includes storage and notification middleware; the logical configuration information associated with the tenant is stored in a key-value storage format, and the key of the logical configuration information associated with the tenant includes a tenant identifier; The acquiring, from the storage system, target logical configuration information associated with the target tenant includes: Initiate a monitoring request to the storage and notification middleware; the monitoring request is used to monitor the tenant identifier of the target tenant; Acquire a monitoring event pushed by the storage and notification middleware when a value corresponding to the tenant identifier of the target tenant changes; the monitoring event includes target logic configuration information associated with the target tenant.

7. A software defined network, characterized in that: include: A first controller, a storage system and a plurality of tunnel endpoint devices; the tunnel endpoint devices are provided with a second controller; The first controller is used to execute the configuration method of the software defined network according to any one of claims 1 to 3; The second controller is used to execute the software defined network configuration method according to any one of claims 4 to 6.

8. A configuration device for a software defined network, characterized in that: A first controller applied to a software defined network, the device comprising: A data acquisition module, used to acquire business data; the business data includes logical configuration information corresponding to the virtual resources of each tenant and the tunnel endpoint device corresponding to the virtual resources; A processing module, used to establish a corresponding relationship between the tunnel endpoint device and the tenant according to the service data, and determine the logical configuration information associated with the tenant; The configuration sending module is used to send the corresponding relationship between the tunnel endpoint device and the tenant and the logical configuration information associated with the tenant to the lower-level storage system to instruct the tunnel endpoint device to obtain the logical configuration information of the corresponding tenant from the storage system.

9. A configuration device for a software defined network, characterized in that: A second controller applied to a tunnel endpoint device, the device comprising: A query module, used to query a target tenant corresponding to a local tunnel endpoint device according to a correspondence between the tunnel endpoint device and the tenant stored in an upper storage system; A configuration acquisition module, configured to acquire target logical configuration information associated with the target tenant from the storage system; the storage system stores logical configuration information associated with the tenant; The flow table sending module is used to generate corresponding flow table entries according to the target logical configuration information and send the flow table entries.

10. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method for configuring a software defined network according to any one of claims 1 to 6 by executing the computer instructions.

11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method for configuring a software-defined network according to any one of claims 1 to 6.