Method for establishing TCP connection, target agent node and storage medium

By adding and parsing the client's public IP address in the second TCP message body during the TCP connection establishment process, the problem of IP address loss after load balancing is solved, and the effect of retaining the client's public IP address when the TCP connection is established is achieved.

CN120075276APending Publication Date: 2025-05-30HISENSE HOME APPLIANCES GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311644310.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-30
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

When establishing a TCP connection, the client's public IP address is often lost after load balancing, resulting in the work based on the client's public IP address cannot be carried out.

Method used

By adding the public IP address of the target client in the second TCP message body and parsing and binding the IP address on the target proxy node, a TCP connection between the target client and the target network element node is established to ensure that the public IP address is retained.

Benefits of technology

While load balancing, the public IP address of the target client is retained, reducing the intrusion in the process of establishing a TCP connection, and is suitable for container cloud platforms and virtual cloud platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120075276A_ABST
    Figure CN120075276A_ABST
Patent Text Reader

Abstract

The invention discloses a method for establishing TCP connection, a target agent node and a storage medium, and belongs to the technical field of networks. The method comprises the following steps: receiving a first connection establishment request sent by the flow inlet node, wherein the first connection establishment request follows a PROXY protocol; analyzing the first connection establishment request to obtain a public network IP address of the target client and the second TCP message body from the first TCP message body; and establishing TCP connection between the target client and a target network element node through the second TCP message body by adopting the public network IP address of the target client, the target network element node being a network element node communicating with the target proxy node in the plurality of network element nodes. According to the invention, the public network IP address of the target client is added in the second TCP message body, so that the public network IP address of the target client can be reserved while the load is balanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network technologies, and in particular, to a method for establishing a TCP connection, a target proxy node, and a storage medium. Background Art

[0002] Currently, when deploying a TCP (Transmission Control Protocol) service, a TCP connection needs to be established between a client and a network element of a server. When establishing the TCP connection, since multiple connection establishment requests sent by different clients all need to pass through the traffic entry node of the server, and the traffic entry node performs load balancing on the multiple connection establishment requests. However, after the load balancing, the public IP (Internet Protocol Address) of the client is often lost, resulting in the inability to perform operations based on the public IP address of the client. Therefore, there is an urgent need for a TCP connection establishment method that can retain the public IP address of the client. Summary of the Invention

[0003] This application provides a method for establishing a TCP connection, a target proxy node, and a storage medium, which can solve the problem of source IP loss in related technologies. The technical solutions are as follows:

[0004] On the one hand, a method for establishing a TCP connection is provided. The method is applied to a target proxy node in a target platform. The target platform includes a traffic entry node, multiple proxy nodes, and multiple network element nodes. The target proxy node is a proxy node selected by the traffic entry node from the multiple proxy nodes according to a load balancing policy. The method includes:

[0005] Receiving a first connection establishment request sent by the traffic entry node. The first connection establishment request follows the PROXY protocol. The first connection establishment request is obtained by the traffic entry node converting a second connection establishment request sent by a target client. The second connection establishment request follows the TCP protocol. The first connection establishment request carries a first TCP message body, and the first TCP message body is obtained by adding the public IP address of the target client to a second TCP message body. The second TCP message body is the TCP message body carried by the second connection establishment request;

[0006] Parsing the first connection establishment request to obtain the public IP address of the target client and the second TCP message body from the first TCP message body;

[0007] Use the public IP address of the target client to establish a TCP connection between the target client and the target network element node through the second TCP message body, where the target network element node is the network element node that communicates with the target proxy node among the multiple network element nodes.

[0008] Optionally, the target proxy node and the target network element node are located in the same service node, and the service node further includes a target network card;

[0009] The step of using the public IP address of the target client to establish a TCP connection between the target client and the target network element node through the second TCP message body includes:

[0010] Bind the public IP address of the target client to the target network card;

[0011] Use the target network card to send a third connection establishment request to the target network element node by calling the system kernel, where the third connection establishment request carries the public IP address of the target client and the second TCP message body;

[0012] Receive a connection establishment response sent by the target network element node through the target network card, where the connection establishment response is sent by the target network element node after querying the policy route of the target network card, and the policy route indicates that packets with the destination IP address being any IP address bound to the target network card are allowed to pass through the target network card;

[0013] Send the connection establishment response to the traffic entry node so that the traffic entry node sends the connection establishment response to the target client.

[0014] Optionally, before receiving the connection establishment response sent by the target network element node through the target network card, the method further includes:

[0015] Display a configuration interface for instructing a technician to input the policy route;

[0016] Obtain the policy route from the configuration interface and configure the policy route for the target network card.

[0017] Optionally, before receiving the first connection establishment request sent by the traffic entry node, the method further includes:

[0018] Set the internal network IP address and port number listened by the target proxy node to be the first internal network IP address and the first port number respectively, where the first internal network IP address and the first port number are the internal network IP address and port number originally listened by the target network element node;

[0019] Update the internal network IP address and port number listened by the target network element node to a second internal network IP address and a second port number. The second internal network IP address is an IP address within the network segment of the target network card, and the second port number is different from the first port number.

[0020] Optionally, the target network card is a loopback network card.

[0021] Optionally, the target platform is a container cloud platform, which includes multiple PODs, and the service node is one of the multiple PODs; or,

[0022] The target platform is a virtual cloud platform, which includes multiple virtual machines, and the service node is one of the multiple virtual machines.

[0023] On the other hand, a device for establishing a TCP connection is provided, which is applied to a target proxy node in a target platform. The target platform includes a traffic entry node, multiple proxy nodes, and multiple network element nodes. The target proxy node is a proxy node selected by the traffic entry node from the multiple proxy nodes according to a load balancing policy; the device includes:

[0024] A receiving module, configured to receive a first connection establishment request sent by the traffic entry node. The first connection establishment request follows the PROXY protocol. The first connection establishment request is obtained by the traffic entry node converting a second connection establishment request sent by a target client. The second connection establishment request follows the TCP protocol. The first connection establishment request carries a first TCP message body, and the first TCP message body is obtained by adding the public network IP address of the target client to a second TCP message body. The second TCP message body is the TCP message body carried by the second connection establishment request;

[0025] A parsing module, configured to parse the first connection establishment request to obtain the public network IP address of the target client and the second TCP message body from the first TCP message body;

[0026] A connection establishment module, configured to use the public network IP address of the target client to establish a TCP connection between the target client and a target network element node through the second TCP message body. The target network element node is a network element node that communicates with the target proxy node among the multiple network element nodes.

[0027] Optionally, the target proxy node and the target network element node are located in the same service node, and the service node further includes a target network card;

[0028] The connection establishment module includes:

[0029] A binding sub-module, configured to bind the public IP address of the target client to the target network card;

[0030] A first sending sub-module, configured to send a third connection establishment request to the target network element node by using the target network card by calling the system kernel, where the third connection establishment request carries the public IP address of the target client and the second TCP message body;

[0031] A receiving sub-module, configured to receive a connection establishment response sent by the target network element node through the target network card, where the connection establishment response is sent by the target network element node after querying the policy route of the target network card, and the policy route indicates that data packets with the destination IP address being any IP address bound to the target network card are allowed to pass through the target network card;

[0032] A second sending sub-module, configured to send the connection establishment response to the traffic entry node, so that the traffic entry node sends the connection establishment response to the target client.

[0033] Optionally, the apparatus further includes:

[0034] A display module, configured to display a configuration interface, where the configuration interface is used to instruct a technician to input the policy route;

[0035] An obtaining module, configured to obtain the policy route from the configuration interface and configure the policy route for the target network card.

[0036] Optionally, the apparatus further includes:

[0037] A setting module, configured to set the internal network IP address and port number listened by the target proxy node to a first internal network IP address and a first port number respectively, where the first internal network IP address and the first port number are the internal network IP address and port number originally listened by the target network element node;

[0038] An updating module, configured to update the internal network IP address and port number listened by the target network element node to a second internal network IP address and a second port number, where the second internal network IP address is an IP address within the network segment of the target network card, and the second port number is different from the first port number.

[0039] Optionally, the target network card is a loopback network card.

[0040] Optionally, the target platform is a container cloud platform, the container cloud platform includes multiple PODs, and the service node is one of the multiple PODs; or,

[0041] The target platform is a virtual cloud platform, which includes multiple virtual machines, and the service node is one of the multiple virtual machines.

[0042] On the other hand, a target proxy node is provided. The target proxy node is located in a target platform, which includes a traffic entry node, multiple proxy nodes, and multiple network element nodes. The target proxy node is a proxy node selected by the traffic entry node from the multiple proxy nodes according to a load balancing policy; the target proxy node includes a transceiver and a processor.

[0043] The transceiver is configured to receive a first connection establishment request sent by the traffic entry node. The first connection establishment request complies with the PROXY protocol and is obtained by the traffic entry node converting a second connection establishment request sent by a target client. The second connection establishment request complies with the TCP protocol. The first connection establishment request carries a first TCP message body, which is obtained by adding the public network IP address of the target client to a second TCP message body, and the second TCP message body is the TCP message body carried by the second connection establishment request.

[0044] The processor is configured to parse the first connection establishment request to obtain the public network IP address of the target client and the second TCP message body from the first TCP message body.

[0045] The processor is further configured to use the public network IP address of the target client to establish a TCP connection between the target client and a target network element node through the second TCP message body. The target network element node is a network element node that communicates with the target proxy node among the multiple network element nodes.

[0046] On the other hand, a computer-readable storage medium is provided. A computer program is stored in the storage medium, and when the computer program is executed by a processor, the steps of the method for establishing a TCP connection described above are implemented.

[0047] On the other hand, a computer program product including instructions is provided. When the instructions run on a computer, the computer is caused to execute the steps of the method for establishing a TCP connection described above.

[0048] The technical solution provided by this application can at least bring the following beneficial effects:

[0049] By adding the public network IP address of the target client to the second TCP message body, it is possible to balance the load while retaining the public network IP address of the target client; moreover, in the embodiments of the present application, a target proxy node is added, and the target proxy node parses the first connection establishment request to obtain the public network IP address of the target client and the second TCP message body, and establishes a TCP connection between the target client and the target network element node through the second TCP message body, so that the target network element node can directly read the second TCP message body without modifying it, reducing the intrusion during the process of establishing the TCP connection. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following described drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0051] Figure 1 is a schematic structural diagram of an implementation environment provided by the embodiments of the present application;

[0052] Figure 2 is a flowchart of a method for establishing a TCP connection provided by the embodiments of the present application;

[0053] Figure 3 is a schematic structural diagram of a TCP packet provided by the embodiments of the present application;

[0054] Figure 4 is a schematic structural diagram of a service node provided by the embodiments of the present application;

[0055] Figure 5 is a schematic structural diagram of a device for establishing a TCP connection provided by the embodiments of the present application;

[0056] Figure 6 is a schematic structural diagram of a client provided by the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0057] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the drawings.

[0058] Before explaining the method for establishing a TCP connection provided by the embodiments of the present application in detail, the application scenarios and implementation environments involved in the embodiments of the present application will be introduced.

[0059] Currently, when deploying a TCP service, a TCP connection needs to be established between the network elements of the client and the server. When establishing a TCP connection, since multiple connection establishment requests sent by different clients all need to pass through the traffic entry node of the server, the traffic entry node performs load balancing on these multiple connection establishment requests. However, after load balancing, the public IP address of the client is often lost. For example, when the traffic entry node is nginx (engine x), due to the working principle of SANT (Source Network Address Translation) of nginx, the source IP address carried in the TCP message body of the connection establishment request (i.e., the public IP address of the client) will be modified to the internal network IP address of nginx, resulting in the loss of the public IP address of the client and preventing operations based on the public IP address of the client (such as user profile statistics based on the public IP address of the client) from being carried out.

[0060] Based on this, the embodiments of the present application provide a method for establishing a TCP connection, which can retain the public IP address of the client while load balancing TCP traffic.

[0061] Please refer to Figure 1 , Figure 1 FIG. is a schematic diagram of an implementation environment shown according to an exemplary embodiment. The implementation environment includes multiple clients 101 (illustrated schematically as one in the figure), a traffic entry node 102, multiple proxy nodes 103 (illustrated schematically as one in the figure), and multiple network element nodes 104 (illustrated schematically as one in the figure). The traffic entry node 102, the proxy nodes 103, and the network element nodes 104 are located in the same target platform, which can be referred to as the server of the TCP connection. The client 101 can communicate with the traffic entry node 102, the traffic entry node 102 can communicate with the proxy nodes 103, and the proxy nodes 103 can communicate with the network element nodes 104. The communication connection can be a wired or wireless connection, and the embodiments of the present application do not limit this.

[0062] The client 101 is used to send a connection establishment request. This connection establishment request follows the TCP protocol and carries the original TCP message body. The connection establishment request will reach the traffic entry node 102. The traffic entry node 102 converts this connection establishment request so that it follows the PROXY protocol. The converted connection establishment request will enter a certain proxy node 103 according to the load balancing policy. The proxy node 103 parses the converted connection establishment request to obtain the public network IP address of the client 101 and the original TCP message body. Then, using the public network IP address of the client 101, a TCP connection is established between the client 101 and the network element node 104 through this original TCP message body.

[0063] Among them, the client 101 can be any kind of electronic product that can perform human-computer interaction with users through one or more ways such as a keyboard, touchpad, touch screen, remote control, voice interaction, or handwriting device. For example, a PC (Personal Computer), mobile phone, smart phone, PDA (Personal Digital Assistant), wearable device, pocket PC (PPC), tablet computer, smart vehicle head unit, smart TV, smart speaker, etc.

[0064] The traffic entry node 102, proxy node 103, and network element node 104 can be any device capable of network communication. By way of example, the traffic entry node 102 and the network element node 104 can be network devices such as routers and switches. The proxy node 103 can be network devices such as routers and switches, and can also be components capable of network communication.

[0065] Those skilled in the art should understand that the above-mentioned client 101, traffic entry node 102, proxy node 103, and network element node 104 are only examples. Other existing or future possible clients, traffic entry nodes, proxy nodes, or network element nodes that are applicable to the embodiments of the present application should also be included within the protection scope of the embodiments of the present application and are hereby incorporated by reference.

[0066] It should be noted that the application scenarios and implementation environments described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those of ordinary skill in the art know that with the emergence of new application scenarios and the evolution of implementation environments, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0067] Next, a detailed explanation of the method for establishing a TCP connection provided by the embodiments of the present application will be given.

[0068] Figure 2 It is a flowchart of a method for establishing a TCP connection provided by an embodiment of the present application. This method is applied to a target proxy node in a target platform. The target platform includes a traffic entry node, multiple proxy nodes, and multiple network element nodes. The target proxy node is a proxy node selected by the traffic entry node from the multiple proxy nodes according to a load balancing policy; please refer to Figure 2 , and the method includes the following steps.

[0069] Step 201: Receive a first connection establishment request sent by the traffic entry node. The first connection establishment request follows the PROXY protocol. The first connection establishment request is obtained by the traffic entry node converting a second connection establishment request sent by the target client. The second connection establishment request follows the TCP protocol. The first connection establishment request carries a first TCP message body. The first TCP message body is obtained by adding the public network IP address of the target client to the second TCP message body. The second TCP message body is the TCP message body carried by the second connection establishment request.

[0070] That is to say, the target client sends a second connection establishment request to the traffic entry node. The second connection establishment request follows the TCP protocol and carries a second TCP message body. The traffic entry node receives the second connection establishment request, converts the second connection establishment request to obtain a first connection establishment request. The first connection establishment request follows the PROXY protocol and carries a first TCP message body. The first TCP message body is obtained by adding the public network IP address of the target client to the second TCP message body. Then, the traffic entry node selects a proxy node from the multiple proxy nodes as the target proxy node according to the load balancing policy and sends the first connection establishment request to the target proxy node. In this way, the target proxy node can receive the first connection establishment request sent by the traffic entry node.

[0071] Since the second connection establishment request is sent by the target client for establishing a TCP connection, the second TCP message body is the original TCP message body sent by the client, and the original TCP message body refers to the TCP message body that has not been modified.

[0072] The second connection establishment request can be a TCP packet, such as Figure 3 shown Figure 3It is a schematic structural diagram of a TCP packet. The TCP packet includes an IP header and a TCP message body. The IP header carries a source IP address and a destination IP address. The source IP address is used to indicate the public IP address of the client that sends the connection establishment request, that is, the public IP address of the target client. The destination IP address is used to indicate the public IP address of the network element node that receives the connection establishment request, that is, the public IP address of the target network element node. The TCP message body includes a TCP header and a TCP data part. Among them, the TCP header carries a source port number and a destination port number. The source port number is used to indicate the port number of the client that sends the connection establishment request, that is, the port number of the target client. The destination port number is used to indicate the port number of the network element node that receives the connection establishment request, that is, the port number of the target network element node.

[0073] Based on the above description, during load balancing, the traffic ingress node will modify the source IP address carried in the second connection establishment request from the public IP address of the target client to the internal network IP address of the traffic ingress node, thus losing the public IP address of the target client. Therefore, in the embodiments of the present application, the traffic ingress node needs to convert the second connection establishment request to retain the public IP address of the target client. For example, the traffic ingress node can add the public IP address of the target client in front of the TCP data part in the second TCP message body to obtain the first TCP message body. In this way, during load balancing, even if the traffic ingress node modifies the source IP address carried in the TCP packet to the internal network IP address of the traffic ingress node, it can still retain the public IP address of the target client.

[0074] The PROXY protocol is an Internet protocol. The purpose of the PROXY protocol is to add fields that can mark the initial information of the client, such as the source IP address, destination IP address, source port, and destination port, to the TCP packet, so as to transmit the information of the client.

[0075] It should be noted that the above is to convert the second connection establishment request into the first connection establishment request first and then perform load balancing. Of course, in actual applications, load balancing can also be performed first and then the second connection establishment request is converted into the first connection establishment request. That is to say, the embodiments of the present application do not limit the execution order of the conversion operation and the load balancing operation of the connection establishment request.

[0076] Based on the above description, during load balancing, the traffic entry node will modify the source IP address carried in the second connection establishment request from the public IP address of the target client to the internal network IP address of the traffic entry node, so as to facilitate the transmission of the second connection establishment request within the local area network of the target platform. In some embodiments, the traffic entry node may also modify the destination IP address carried in the second connection establishment request from the public IP address of the target network element node to the internal network IP address of the target network element node, so as to facilitate the sending of the first connection establishment request to the target network element node within the local area network of the target platform.

[0077] Step 202: Parse the first connection establishment request to obtain the public IP address of the target client and the second TCP message body from the first TCP message body.

[0078] Since the first TCP message body is obtained by adding the public IP address of the target client to the second TCP message body, that is, the original TCP message body has been modified. In this way, the network element nodes in the target platform cannot directly parse and use the first TCP message body. Therefore, in the embodiments of the present application, a target proxy node is added, and the target proxy node parses the first connection establishment request to intercept the public IP address of the target client in the first TCP message body and obtain the second TCP message body.

[0079] Step 203: Use the public IP address of the target client to establish a TCP connection between the target client and the target network element node through the second TCP message body. The target network element node is the network element node that communicates with the target proxy node among multiple network element nodes.

[0080] Since it is currently necessary to establish a TCP connection between the target client and the target network element node, and according to the basic network principle, a device cannot send requests externally using a non-local IP address. Therefore, in the embodiments of the present application, the target proxy node needs to bind the public IP address of the target client, so as to send the second TCP message body to the target network element node on behalf of the target client, thereby establishing a TCP connection between the target client and the target network element node.

[0081] In some embodiments, the target proxy node and the target network element node are located in the same service node, and the service node also includes a target network card; in this case, the TCP connection between the target client and the target network element node can be established through the following steps (1)-(4).

[0082] (1) Bind the public IP address of the target client to the target network card.

[0083] Based on the above description, the target proxy node can intercept the public IP address of the target client in the first TCP message body. Therefore, the public IP address of the target client can be bound to the target network card. The embodiments of the present application do not limit the manner of binding the public IP address of the target client to the target network card.

[0084] In some embodiments, the target network card is a loopback network card.

[0085] The loopback network card, also known as the lo (loopback) network card, is a logical network card. Here, loopback means that the receiving party sends back the electronic signal, data stream, etc. along the sending path to the sending party. Therefore, the loopback network card is mainly used for internal system communication and application testing, and its network segment is 127.0.0.1 / 8. Moreover, the number of public IP addresses of the clients bound to the loopback network card is only limited by the memory of the operating system. That is to say, the target proxy node can bind the public IP addresses of multiple clients to the loopback network card.

[0086] It should be noted that the target network card can not only be the above-mentioned loopback network card, but also a physical network card or other network cards that can enable the target proxy node and the target network element node to communicate. The embodiments of the present application do not limit this.

[0087] The service node is one of the multiple service nodes included in the target platform, and the target proxy node is a newly added component in this service node. The embodiments of the present application implement the function of retaining the public IP address of the target client when establishing a TCP connection through the target proxy node, without the need to modify the target network element node.

[0088] (2) By calling the system kernel, use the target network card to send a third connection establishment request to the target network element node. The third connection establishment request carries the public IP address of the target client and the second TCP message body.

[0089] Since the third connection establishment request carries the public IP address of the target client, the public IP address of the target client is a non-local IP address for the target proxy node, and the target proxy node cannot directly use a non-local IP address to send a request. However, for the operating system, it supports using a non-local IP address to send a request. Therefore, in the embodiments of the present application, the target proxy node calls the system kernel of the operating system to use the non-local IP address bound to the target network card to send a request, that is, by calling the system kernel, use the target network card to send a third connection establishment request to the target network element node.

[0090] As an example, the operating system supports using a socket to send requests for non-local IP addresses. Therefore, in the embodiments of the present application, the target proxy node sends a third connection establishment request to the target network element node by calling the system kernel of the operating system, and the system kernel of the operating system uses the socket method to send the third connection establishment request. Exemplarily, the operating system can use the socket option IP_TRANSPARENT to send the third connection establishment request. Of course, other methods can also be used to send the third connection establishment request to the target network element node, and the embodiments of the present application do not limit this.

[0091] A socket is a data structure in the operating system kernel and is the gateway for the target proxy node and the target network element node to communicate with each other. Therefore, after the socket is established, the target proxy node and the target network element node can communicate with each other.

[0092] IP_TRANSPARENT is a socket option. Using this option can turn off the source IP address check of the service node. Even if the source IP address carried in the connection establishment request is a non-local IP address, after using the IP_TRANSPARENT option, the target proxy node can still send a third connection establishment request to the target network element node.

[0093] It should be noted that the system kernel is the kernel of the operating system, and the operating system is the operating system in the service node. The operating system can be a Linux system or other operating systems, and the embodiments of the present application do not limit this.

[0094] Since the third connection establishment request carries the public network IP address of the target client, after the target network element node receives the third connection establishment request, it believes that the third connection establishment request is sent by the target client, and currently it is the target client that establishes a TCP connection with it, thereby ensuring the reliability of the TCP connection between the target client and the target network element node; at the same time, the third connection establishment request carries the second TCP message body, that is, the original TCP message body. Therefore, after the target network element node receives the third connection establishment request, it can directly read the second TCP message body without the situation of being unable to read.

[0095] In some embodiments, before receiving the first connection establishment request sent by the traffic ingress node, the internal network IP address and port number listened by the target proxy node can be set to the first internal network IP address and the first port number respectively, and the first internal network IP address and the first port number are the internal network IP address and port number originally listened by the target network element node; the internal network IP address and port number listened by the target network element node are updated to the second internal network IP address and the second port number, and the second internal network IP address is an IP address within the network segment of the target network card, and the second port number is different from the first port number.

[0096] Based on the above description, since the destination IP address of the first connection establishment request is the internal network IP address of the target network element node and the destination port number is the port number of the target network element node, after setting the internal network IP address and port number listened by the target proxy node to the first internal network IP address and the first port number originally listened by the target network element node, the first connection establishment request will first reach the target proxy node, so that the target proxy node can parse the first connection establishment request.

[0097] Since the target proxy node binds the public network IP address of the target client to the target network card, and the third connection establishment request is sent to the target network element node using the target network card, it is necessary to update the internal network IP address listened by the target network element node to an IP address within the network segment of the target network card, so as to use the target network card to realize the communication between the target proxy node and the target network element node.

[0098] For example, Figure 4 (a) is a schematic structural diagram of the service node when the target proxy node is not added and the loopback network card is not used for communication. From Figure 4 (a), it can be seen that the internal network IP address originally listened by the target network element node is 0.0.0.0, the port number is 8088, the internal network IP address of the loopback network card is 127.0.0.1, and this entry is the entry of this service node. Thus, generally, the connection establishment request will directly reach the target network element node through the entry of this service node. And Figure 4 (b) is a schematic diagram of the service node after adding the target proxy node and using the target network card for communication. From Figure 4 (b), it can be seen that the internal network IP address listened by the target proxy node is 0.0.0.0, and the port number is 8088, that is, the target proxy node listens on the original internal network IP address and port number of the target network element node, so that the connection establishment request first reaches the target proxy node. And after using the loopback network card for communication, the internal network IP address listened by the target network element node is updated to the internal network IP address of the loopback network card, that is, 127.0.0.1, and the port number is updated to a port number different from the originally listened port number (such as 8087).

[0099] (3) Receive the connection establishment response sent by the target network element node through the target network card. This connection establishment response is sent by the target network element node after querying the policy route of the target network card, and this policy route indicates that any data packet with the destination IP address being any IP address bound to the target network card is allowed to pass through the target network card.

[0100] After the target network element node receives the third connection establishment request, if it confirms to establish a connection with the target client, it can send a connection establishment response to the target proxy node through the target network card. Since this connection establishment response is sent from the target network element node to the target proxy node, the source IP address carried in this connection establishment response is the internal network IP address of the target network element node, that is, the IP address within the network segment of the target network card, and the destination IP address carried is the public network IP address of the target client.

[0101] By default, the operating system will directly discard or route the data packet with the destination IP address being a non-local IP address to other devices. In order to enable the target proxy node to establish a TCP connection with the target network element node on behalf of the target client in this application embodiment, the public network IP address of the target client is bound to the target network card. In this way, after the target proxy node receives the connection establishment response sent by the target network element, it compares the destination IP address carried in this connection establishment response with the IP address bound to the target network card. If there is an IP address in the IP addresses bound to the target network card that is the same as the destination IP address carried in this connection establishment response, it is confirmed that the destination IP address carried in this connection establishment response is a local IP address, and it will not be discarded or routed to other devices. Moreover, in order to enable this connection establishment response to return from the target network element node to the target proxy node, the policy route of the target network card can also be queried. If the policy route indicates that the data packets of any IP address bound to the target network card are allowed to pass through the target network card, this connection establishment response is sent to the target proxy node through the target network card.

[0102] Based on the above description, the connection establishment response can be sent from the target network element node to the target proxy node by querying the policy route of the target network card. Therefore, before receiving the connection establishment response sent by the target network element node through the target network card, a configuration interface can also be displayed. This configuration interface is used to instruct the technician to input the policy route; obtain the policy route from this configuration interface and configure this policy route for the target network card. That is, this policy route is input by the technician in the configuration interface in advance, and this policy route is configured for the target network card. Of course, this policy route can also be pre-configured when the target network card leaves the factory. This application embodiment does not make any limitations in this regard.

[0103] In order to configure the policy route for the target network card, the technician needs to have the cap_net_admin (allowing execution of network management tasks) permission and the cap_net_raw (allowing use of raw sockets) permission. At the same time, the target platform needs to enable the NET_ADMIN (network administrator) permission and the NET_RAW (raw sockets) permission accordingly.

[0104] In some embodiments, the target platform may be a container cloud platform or a virtual cloud platform. When the target platform is a container cloud platform, the container cloud platform includes multiple PODs, and the service node is one of the multiple PODs; or, when the target platform is a virtual cloud platform, the virtual cloud platform includes multiple virtual machines, and the service node is one of the multiple virtual machines.

[0105] A POD is the smallest scheduling unit of a container cloud platform. Containers are contained in a POD. There can be one or more containers in a POD. Containers in the same POD share storage and network and are uniformly arranged and scheduled.

[0106] A virtual machine is a complete computer system with complete hardware system functions simulated by software, and each virtual machine has an independent operating system.

[0107] When the target platform is a container cloud platform, in order for technicians to have deeper access rights to the containers in the POD, the technicians need to start the containers in the way of privileged = true; similarly, when the target platform is a virtual cloud platform, the technicians also need to start the virtual machines in the way of privileged = true.

[0108] It should be noted that the target platform can not only be the above-mentioned container cloud platform or virtual cloud platform, but also a public cloud platform, etc. The embodiments of the present application do not make any limitations in this regard.

[0109] (4) Send the connection establishment response to the traffic entry node, so that the traffic entry node sends the connection establishment response to the target client.

[0110] Based on the above description, the destination IP address carried in the connection establishment response is the public IP address of the target client. Therefore, the target proxy node needs to send the connection establishment response to the traffic entry node, so that the traffic entry node can then send the connection establishment response to the target client.

[0111] After the target client receives the connection establishment response, it will also send a connection confirmation message to the traffic entry node. The traffic entry node forwards the connection confirmation message to the target proxy node, so that the target proxy node sends the connection confirmation message to the target network element node, thereby completing the step of establishing a TCP connection between the target client and the target network element node. The transmission method of the connection confirmation message is similar to that of the second connection establishment request. Please refer to the above content and will not be elaborated here.

[0112] In the embodiments of the present application, by adding the public network IP address of the target client to the second TCP message body, it is possible to balance the load while retaining the public network IP address of the target client; moreover, in the embodiments of the present application, a target proxy node is added, and the target proxy node parses the first connection establishment request to obtain the public network IP address of the target client and the second TCP message body, and establishes a TCP connection between the target client and the target network element node through the second TCP message body, so that the target network element node can directly read the second TCP message body without modifying it, reducing the intrusion during the process of establishing a TCP connection. At the same time, the method provided by the embodiments of the present application is applicable to container cloud platforms, virtual cloud platforms, etc., and has a wide range of applications.

[0113] Figure 5 It is a schematic structural diagram of a device for establishing a TCP connection provided by the embodiments of the present application. The device for establishing a TCP connection can be implemented by software, hardware, or a combination of both as part or all of the target proxy node, and the target proxy node can be the Figure 1 proxy node shown. Please refer to Figure 5 , and the device includes: a receiving module 501, a parsing module 502, and a connection establishment module 503.

[0114] The receiving module 501 is configured to receive a first connection establishment request sent by a traffic entry node. The first connection establishment request follows the PROXY protocol. The first connection establishment request is obtained by the traffic entry node converting a second connection establishment request sent by the target client. The second connection establishment request follows the TCP protocol. The first connection establishment request carries a first TCP message body, and the first TCP message body is obtained by adding the public network IP address of the target client to the second TCP message body. The second TCP message body is the TCP message body carried by the second connection establishment request.

[0115] The parsing module 502 is configured to parse the first connection establishment request to obtain the public network IP address of the target client and the second TCP message body from the first TCP message body.

[0116] The connection establishment module 503 is configured to use the public network IP address of the target client to establish a TCP connection between the target client and the target network element node through the second TCP message body. The target network element node is the network element node that communicates with the target proxy node among multiple network element nodes.

[0117] Optionally, the target proxy node and the target network element node are located in the same service node, and the service node further includes a target network card.

[0118] The connection establishment module 503 includes:

[0119] A binding sub-module, configured to bind the public IP address of a target client to a target network card;

[0120] A first sending sub-module, configured to send a third connection establishment request to a target network element node by using the target network card through calling the system kernel, where the third connection establishment request carries the public IP address of the target client and a second TCP message body;

[0121] A receiving sub-module, configured to receive a connection establishment response sent by the target network element node through the target network card, where the connection establishment response is sent by the target network element node after querying the policy route of the target network card, and the policy route indicates that data packets with a destination IP address being any IP address bound to the target network card are allowed to pass through the target network card;

[0122] A second sending sub-module, configured to send the connection establishment response to a traffic entry node, so that the traffic entry node sends the connection establishment response to the target client.

[0123] Optionally, the apparatus further includes:

[0124] A display module, configured to display a configuration interface for instructing a technician to input a policy route;

[0125] An obtaining module, configured to obtain the policy route from the configuration interface and configure the policy route for the target network card.

[0126] Optionally, the apparatus further includes:

[0127] A setting module, configured to set the internal network IP address and port number listened by a target proxy node to be a first internal network IP address and a first port number respectively, where the first internal network IP address and the first port number are the internal network IP address and port number originally listened by the target network element node;

[0128] An updating module, configured to update the internal network IP address and port number listened by the target network element node to be a second internal network IP address and a second port number, where the second internal network IP address is an IP address within the network segment of the target network card, and the second port number is different from the first port number.

[0129] Optionally, the target network card is a loopback network card.

[0130] Optionally, the target platform is a container cloud platform, the container cloud platform includes multiple PODs, and the service node is one of the multiple PODs; or,

[0131] The target platform is a virtual cloud platform, the virtual cloud platform includes multiple virtual machines, and the service node is one of the multiple virtual machines.

[0132] In the embodiments of the present application, by adding the public network IP address of the target client to the second TCP message body, it is possible to balance the load while retaining the public network IP address of the target client; moreover, the embodiments of the present application add a target proxy node, which parses the first connection establishment request to obtain the public network IP address of the target client and the second TCP message body, and establishes a TCP connection between the target client and the target network element node through the second TCP message body, so that the target network element node can directly read the second TCP message body without modifying it, reducing the invasiveness during the TCP connection establishment process. At the same time, the method provided by the embodiments of the present application is applicable to container cloud platforms, virtual cloud platforms, etc., with a wide range of applications.

[0133] It should be noted that: when the device for establishing a TCP connection provided in the above embodiment establishes a TCP connection, only the division of the above functional modules is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the device for establishing a TCP connection provided in the above embodiment and the method embodiment for establishing a TCP connection belong to the same concept. For the specific implementation process, please refer to the method embodiment, which will not be elaborated here.

[0134] Figure 6 It is a structural block diagram of a client 600 provided by the embodiments of the present application. The client 600 can be a portable mobile client, such as: a smart phone, a tablet computer, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 (Moving Picture Experts Group Audio Layer IV) player, a notebook computer or a desktop computer. The client 600 may also be referred to by other names such as user equipment, portable client, laptop client, desktop client, etc.

[0135] Generally, the client 600 includes: a processor 601 and a memory 602.

[0136] The processor 601 may include one or more processing cores, such as a quad-core processor, an octa-core processor, etc. The processor 601 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor 601 may also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor 601 may be integrated with a GPU (Graphics Processing Unit), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 601 may further include an AI (Artificial Intelligence) processor, and the AI processor is used to process computational operations related to machine learning.

[0137] The memory 602 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 602 may further include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In some embodiments, the non-transitory computer-readable storage media in the memory 602 is used to store at least one instruction, and the at least one instruction is used to be executed by the processor 601 to communicate with the traffic inlet node to implement the method for establishing a TCP connection provided in the method embodiments of the present application.

[0138] In some embodiments, the client 600 may further optionally include: a peripheral device interface 603 and at least one peripheral device. The processor 601, the memory 602, and the peripheral device interface 603 may be connected through a bus or signal lines. Each peripheral device may be connected to the peripheral device interface 603 through a bus, signal lines, or a circuit board. Specifically, the peripheral devices include at least one of a radio frequency circuit 604, a touch display screen 605, a camera 606, an audio circuit 607, a positioning component 608, and a power supply 609.

[0139] The peripheral device interface 603 can be used to connect at least one I / O (Input / Output) related peripheral device to the processor 601 and the memory 602. In some embodiments, the processor 601, the memory 602, and the peripheral device interface 603 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 601, the memory 602, and the peripheral device interface 603 can be implemented on separate chips or circuit boards, and this embodiment does not limit this.

[0140] The radio frequency circuit 604 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The radio frequency circuit 604 communicates with a communication network and other communication devices through electromagnetic signals. The radio frequency circuit 604 converts an electrical signal into an electromagnetic signal for transmission, or converts a received electromagnetic signal into an electrical signal. Optionally, the radio frequency circuit 604 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a subscriber identity module card, and so on. The radio frequency circuit 604 can communicate with other clients through at least one wireless communication protocol. The wireless communication protocol includes but is not limited to: the World Wide Web, a metropolitan area network, an intranet, generations of mobile communication networks (2G, 3G, 4G, and 5G), a wireless local area network, and / or a WiFi (Wireless Fidelity) network. In some embodiments, the radio frequency circuit 604 may further include a circuit related to NFC (Near Field Communication), and this application embodiment does not limit this.

[0141] The display screen 605 is used to display the UI (User Interface). The UI may include graphics, text, icons, videos, and any combination thereof. When the display screen 605 is a touch display screen, the display screen 605 also has the ability to collect touch signals on or above the surface of the display screen 605. The touch signals can be input to the processor 601 as control signals for processing. At this time, the display screen 605 can also be used to provide virtual buttons and / or virtual keyboards, also known as soft buttons and / or soft keyboards. In some embodiments, there can be one display screen 605, which is set on the front panel of the client 600; in some other embodiments, there can be at least two display screens 605, which are respectively set on different surfaces of the client 600 or in a folding design; in still some other embodiments, the display screen 605 can be a flexible display screen, which is set on the curved surface or folding surface of the client 600. Even further, the display screen 605 can also be set as an irregular non-rectangular shape, that is, a special-shaped screen. The display screen 605 can be prepared using materials such as LCD (Liquid Crystal Display) and OLED (Organic Light-Emitting Diode).

[0142] The camera module 606 is used to collect images or videos. Optionally, the camera module 606 includes a front camera and a rear camera. Generally, the front camera is set on the front panel of the client, and the rear camera is set on the back of the client. In some embodiments, there are at least two rear cameras, which are any one of a main camera, a depth camera, a wide-angle camera, and a telephoto camera respectively, to implement functions such as the combination of the main camera and the depth camera to achieve the background blurring function, the combination of the main camera and the wide-angle camera to achieve panoramic shooting and VR (Virtual Reality) shooting functions or other combined shooting functions. In some embodiments, the camera module 606 can also include a flash. The flash can be a single-color temperature flash or a dual-color temperature flash. The dual-color temperature flash refers to the combination of a warm light flash and a cold light flash, which can be used for light compensation under different color temperatures.

[0143] The audio circuit 607 may include a microphone and a speaker. The microphone is used to collect sound waves of the user and the environment, convert the sound waves into electrical signals and input the electrical signals to the processor 601 for processing, or input the electrical signals to the radio frequency circuit 604 to implement voice communication. For the purpose of stereo collection or noise reduction, there may be multiple microphones, which are respectively arranged at different parts of the client 600. The microphone may also be an array microphone or an omnidirectional collection microphone. The speaker is used to convert the electrical signals from the processor 601 or the radio frequency circuit 604 into sound waves. The speaker may be a traditional thin film speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can not only convert the electrical signals into sound waves audible to humans, but also convert the electrical signals into sound waves inaudible to humans for uses such as ranging. In some embodiments, the audio circuit 607 may further include a headphone jack.

[0144] The positioning component 608 is used to locate the current geographical location of the client 600 to implement navigation or LBS (Location Based Service). The positioning component 608 may be a positioning component based on the GPS (Global Positioning System) of the United States, the Beidou system of China or the Galileo system of Russia.

[0145] The power supply 609 is used to supply power to each component in the client 600. The power supply 609 may be alternating current, direct current, a disposable battery or a rechargeable battery. When the power supply 609 includes a rechargeable battery, the rechargeable battery may be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery charged through a wired line, and a wireless rechargeable battery is a battery charged through a wireless coil. The rechargeable battery can also be used to support fast charging technology.

[0146] Those skilled in the art can understand that Figure 6 the structure shown in does not limit the client 600, and may include more or fewer components than shown in the figure, or combine certain components, or adopt different component arrangements.

[0147] In some embodiments, a computer-readable storage medium is further provided. A computer program is stored in the storage medium. When the computer program is executed by a processor, the steps of the method for establishing a TCP connection in the above embodiments are implemented. For example, the computer-readable storage medium may be a ROM, a RAM, a CD-ROM, a magnetic tape, a floppy disk and an optical data storage device, etc.

[0148] It should be noted that the computer-readable storage medium mentioned in the embodiments of the present application may be a non-volatile storage medium, in other words, it may be a non-transitory storage medium.

[0149] It should be understood that all or part of the steps of implementing the above embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. The computer instructions can be stored in the above computer-readable storage medium.

[0150] That is, in some embodiments, a computer program product containing instructions is also provided. When it runs on a computer, it causes the computer to execute the steps of the method for establishing a TCP connection described above.

[0151] It should be understood that the "at least one" mentioned herein refers to one or more, and the "multiple" refers to two or more. In the description of the embodiments of the present application, unless otherwise specified, " / " means "or". For example, A / B can mean A or B; the "and / or" herein is merely a description of the association relationship of the associated objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, words such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. Those skilled in the art can understand that the words such as "first" and "second" do not limit the quantity and execution order, and the words such as "first" and "second" do not necessarily limit to be different.

[0152] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals involved in the embodiments of the present application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data need to comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0153] The above are the embodiments provided by the present application, which are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for establishing a TCP connection, characterized in that, it is applied to a target proxy node in a target platform, the target platform includes a traffic entry node, multiple proxy nodes and multiple network element nodes, and the target proxy node is a proxy node selected by the traffic entry node from the multiple proxy nodes according to a load balancing policy; the method includes: Receiving a first connection establishment request sent by the traffic entry node, the first connection establishment request follows the PROXY protocol, the first connection establishment request is obtained by the traffic entry node converting a second connection establishment request sent by a target client, the second connection establishment request follows the TCP protocol, the first connection establishment request carries a first TCP message body, and the first TCP message body is obtained by adding the public IP address of the target client to a second TCP message body, and the second TCP message body is the TCP message body carried by the second connection establishment request; Parsing the first connection establishment request to obtain the public IP address of the target client and the second TCP message body from the first TCP message body; Using the public IP address of the target client, establishing a TCP connection between the target client and a target network element node through the second TCP message body, and the target network element node is a network element node that communicates with the target proxy node among the multiple network element nodes.

2. The method according to claim 1, characterized in that, the target proxy node and the target network element node are located in the same service node, and the service node further includes a target network card; The step of using the public IP address of the target client to establish a TCP connection between the target client and the target network element node through the second TCP message body includes: Binding the public IP address of the target client to the target network card; Sending a third connection establishment request to the target network element node by using the target network card by calling the system kernel, and the third connection establishment request carries the public IP address of the target client and the second TCP message body; Receiving a connection establishment response sent by the target network element node through the target network card, and the connection establishment response is sent by the target network element node after querying the policy route of the target network card, and the policy route indicates that data packets with the destination IP address being any IP address bound to the target network card are allowed to pass through the target network card; Sending the connection establishment response to the traffic entry node so that the traffic entry node sends the connection establishment response to the target client.

3. The method according to claim 2, characterized in that, before receiving the connection establishment response sent by the target network element node through the target network card, the method further includes: Displaying a configuration interface for instructing a technician to input the policy route; Obtaining the policy route from the configuration interface and configuring the policy route for the target network card.

4. The method according to claim 2, characterized in that, Before receiving the first connection establishment request sent by the traffic entry node, the method further includes: Setting the internal network IP address and port number listened by the target proxy node to be the first internal network IP address and the first port number respectively, where the first internal network IP address and the first port number are the internal network IP address and port number originally listened by the target network element node; Updating the internal network IP address and port number listened by the target network element node to be the second internal network IP address and the second port number, where the second internal network IP address is an IP address within the network segment of the target network card, and the second port number is different from the first port number.

5. The method according to any one of claims 2-4, Characterized in that, The target network card is a loopback network card.

6. The method according to any one of claims 2-4, Characterized in that, The target platform is a container cloud platform, the container cloud platform includes multiple PODs, and the service node is one of the multiple PODs; or, The target platform is a virtual cloud platform, the virtual cloud platform includes multiple virtual machines, and the service node is one of the multiple virtual machines.

7. A target proxy node, Characterized in that, The target proxy node is located in a target platform, the target platform includes a traffic entry node, multiple proxy nodes and multiple network element nodes, and the target proxy node is a proxy node selected by the traffic entry node from the multiple proxy nodes according to a load balancing policy; The target proxy node includes: A transceiver for receiving the first connection establishment request sent by the traffic entry node, the first connection establishment request follows the PROXY protocol, the first connection establishment request is obtained by the traffic entry node converting a second connection establishment request sent by a target client, the second connection establishment request follows the TCP protocol, the first connection establishment request carries a first TCP message body, and the first TCP message body is obtained by adding the public network IP address of the target client to a second TCP message body, and the second TCP message body is the TCP message body carried by the second connection establishment request; A processor for parsing the first connection establishment request to obtain the public network IP address of the target client and the second TCP message body from the first TCP message body; The processor is further configured to use the public network IP address of the target client to establish a TCP connection between the target client and a target network element node through the second TCP message body, and the target network element node is a network element node that communicates with the target proxy node among the multiple network element nodes.

8. The target proxy node according to claim 7, Characterized in that, The target proxy node and the target network element node are located in the same service node, and the service node further includes a target network card; The processor is further configured to: Bind the public network IP address of the target client to the target network card; Send a third connection establishment request to the target network element node using the target network card by invoking the system kernel, where the third connection establishment request carries the public IP address of the target client and the second TCP message body; Receive a connection establishment response sent by the target network element node through the target network card. The connection establishment response is sent by the target network element node after querying the policy route of the target network card, and the policy route indicates that data packets with the destination IP address being any IP address bound to the target network card are allowed to pass through the target network card; Send the connection establishment response to the traffic entry node so that the traffic entry node sends the connection establishment response to the target client.

9. The target proxy node according to claim 8, wherein, the processor is further configured to: display a configuration interface for instructing a technician to input the policy route; obtain the policy route from the configuration interface and configure the policy route for the target network card.

10. A computer-readable storage medium, wherein, a computer program is stored in the storage medium, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1-6 are implemented.