Access method, device and system for point-to-surface cloud cross-regional service
Obtaining the access request and service access address of cross-region services through the user gateway, and determining the corresponding cross-region service gateway among multiple service gateways, solving the problem that existing cloud services cannot achieve cross-region access and achieving efficient and stable cross-region service access.
Patent Information
- Application Number
- CN202311651074.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-04
- Publication Date
- 2025-06-06
AI Technical Summary
Existing cloud services cannot achieve cross-regional services access operations, resulting in inefficient access to cloud services.
The user gateway obtains the access request and service access address of the cross-region service, determines the corresponding cross-region service gateway among multiple service gateways, and performs cross-region service access operations through the gateway and service access address.
It realizes stable access operations for cross-region services, expands the scope of application of cloud services, improves users' access experience for cross-region services, and ensures the access quality and efficiency of cloud services.
Smart Images

Figure CN120110690A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network technology, and in particular to a method, device and system for accessing point-to-point cross-regional services on the cloud. Background Art
[0002] With the rapid development of cloud technology, cloud products are being used more and more widely. Among them, cloud platforms can publish some cloud services for users to call. At present, users often cannot access services across regions, and the service connections built are all point-to-point, that is, users can access published cloud services in the same region and the same available area. Since the access to cloud services is restricted by regions, the access operation of cloud services in cross-regional scenarios is complicated, which reduces the access efficiency of cloud services. Summary of the invention
[0003] The embodiments of the present application provide a method, device and system for publishing cross-regional services on the cloud, which can realize access operations of cross-regional services, thereby effectively ensuring the access quality and efficiency of cloud services.
[0004] In a first aspect, an embodiment of the present application provides a point-to-point method for accessing cross-region services on a cloud, including:
[0005] Obtaining, through a user gateway, an access request for a cross-region service and a service access address corresponding to the access request, wherein the user gateway is communicatively connected to a plurality of service gateways, the user gateway is located in a first virtual internet network, the plurality of service gateways are located in different second virtual internet networks, the first virtual internet network is communicatively connected to the second virtual internet network, and the region and address segment corresponding to the first virtual internet network are different from the region and address segment corresponding to the second virtual private network;
[0006] Determine, among the multiple service gateways, a cross-region service gateway corresponding to the access request;
[0007] The cross-region service access operation is performed through the cross-region service gateway and the service access address.
[0008] In a second aspect, an embodiment of the present application provides a point-to-point cloud cross-region service access system, including: a first virtual interconnection network component and a second virtual interconnection network component that are communicatively connected, wherein the region and address segment corresponding to the first virtual interconnection network component are different from the region and address segment corresponding to the second virtual interconnection network component; the first virtual interconnection network component and the second virtual interconnection network component both include:
[0009] A user gateway is used to obtain an access request for a cross-regional service and multiple service gateways that are communicatively connected to the user gateway; among the multiple service gateways, determine a cross-regional service gateway corresponding to the access request; determine a service access address corresponding to the access request; and perform a cross-regional service access operation through the cross-regional service gateway and the service access address.
[0010] In a third aspect, an embodiment of the present application provides an electronic device, comprising: a memory, a processor; wherein the memory is used to store one or more computer instructions, wherein when the one or more computer instructions are executed by the processor, the point-to-point cloud cross-regional service access method shown in the first aspect above is implemented.
[0011] In a fourth aspect, an embodiment of the present invention provides a computer storage medium for storing a computer program, wherein the computer program enables a computer to implement the point-to-point cloud cross-region service access method shown in the first aspect when executed.
[0012] In a fifth aspect, an embodiment of the present invention provides a computer program product, comprising: a computer program, which, when executed by a processor of an electronic device, causes the processor to execute the steps in the point-to-face cloud cross-regional service access method shown in the first aspect above.
[0013] The method, device and system for publishing point-to-point cross-regional services on the cloud provided by the embodiments of the present application obtain an access request for the cross-regional service and a service access address corresponding to the access request through a user gateway, and then determine a cross-regional service gateway corresponding to the access request among multiple service gateways, and perform an access operation on the cross-regional service through the cross-regional service gateway and the service access address. Since the cross-regional service gateway is any one of the multiple service gateways, the multiple service gateways can be located in a second virtual Internet network in different regions, so that the user can implement point-to-point cross-regional service access operations through the user gateway and the cross-regional service gateway. This not only can stably implement cross-regional service access operations, effectively expand the scope of application of cloud services, but also can improve the user's good experience in accessing cross-regional services, ensure the access quality and effect of cross-regional cloud services, and is conducive to market promotion and application. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0015] Figure 1 A schematic diagram of the principle of a method for accessing cross-region services on the cloud from point to point provided in an embodiment of the present application;
[0016] Figure 2 A flowchart of a method for accessing a point-to-point cross-regional cloud service provided in an embodiment of the present application;
[0017] Figure 3 A schematic diagram of the principle of deploying multiple service gateways provided in an embodiment of the present application;
[0018] Figure 4 A flowchart of another method for accessing cross-region services on the cloud from point to point provided in an embodiment of the present application;
[0019] Figure 5 A flowchart of another method for accessing a point-to-point cross-region service on the cloud provided in an embodiment of the present application;
[0020] Figure 6 A flowchart of another method for accessing cross-region services on the cloud from point to point provided in an embodiment of the present application;
[0021] Figure 7 A schematic diagram of the principle of a method for accessing cross-region services on the cloud from point to point provided in an application embodiment of the present application;
[0022] Figure 8 A schematic diagram of the structure of a point-to-point cloud cross-region service access system provided in an embodiment of the present application;
[0023] Fig. 9 For Figure 8 The illustrated embodiment is a schematic diagram of the structure of an electronic device corresponding to a point-to-point cloud cross-region service access system. DETAILED DESCRIPTION
[0024] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0025] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The singular forms of "a", "said", and "the" used in the embodiments of the present application and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings, and "multiple" generally includes at least two, but does not exclude the inclusion of at least one.
[0026] It should be understood that the term "and / or" used in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the character " / " in this article generally indicates that the associated objects before and after are in an "or" relationship.
[0027] As used herein, the words "if" and "if" may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)", depending on the context.
[0028] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a product or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such a product or system. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the product or system including the elements.
[0029] In addition, the step sequence in the following method embodiments is only an example and not a strict limitation.
[0030] Definition of terms:
[0031] Point-to-point connection: refers to the ability for users to access all services published to the virtual Internet plane through one access point, without the need to establish a dedicated connection for each service as in point-to-point connection.
[0032] Virtual Internet plane: The virtual Internet is a private network that connects all regions on the cloud. The private network communication connections between each region constitute an Internet plane.
[0033] Cross-region connection: refers to the network connection between applications in virtual private clouds (VPCs) distributed in two different regions.
[0034] Access point: an abstract concept used to connect service providers or users to the virtual Internet. In some instances, the user side can use the terminal node of a private link PrivateLink as an access point.
[0035] Service subscription: The user of the service accesses the service by subscription.
[0036] Reference Figure 1 As shown, this embodiment provides a method, device and system for accessing cross-regional services on the cloud from point to point, wherein the executor of the method for accessing cross-regional services on the cloud from point to point is an access device for accessing cross-regional services on the cloud from point to point, and the access device for accessing cross-regional services on the cloud from point to point may include: a user gateway located in a first virtual Internet network and a service gateway located in a second virtual Internet network, the user gateway may be communicatively connected to the customer service end, and the service gateway may be communicatively connected to the server corresponding to the service provider, so as to implement access operations for cross-regional services on the cloud.
[0037] Among them, the number of service gateways included in the point-to-point cloud cross-regional service access device can be one or more, and one or more service gateways can be located in one or more different virtual private networks. When different service gateways can be located in different second virtual Internet networks, the regions and address segments corresponding to different second virtual Internet networks are different. For example: the user gateway can be located in the first virtual Internet network in area 1, and it can be communicated and connected with the service gateway 1 in the second virtual Internet network in area 2, and it can also be communicated and connected with the service gateway 2 in the second virtual Internet network in area 3, and it can also be communicated and connected with the service gateway 3 in the second virtual Internet network in area 4 (which can be called a cross-regional service gateway for implementing cross-regional service access operations).
[0038] Specifically, the access device for the cross-regional service on the cloud across the point-to-point can be any programmable computing device with a certain access capability to the cross-regional service on the cloud across the point-to-point. In addition, the basic structure of the access device for the cross-regional service on the cloud across the point-to-point may include: at least one processor. The number of processors depends on the configuration and type of the access device for the cross-regional service on the cloud across the point-to-point. The access device for the cross-regional service on the cloud across the point-to-point may also include a memory, which may be volatile, such as RAM, or non-volatile, such as read-only memory (ROM), flash memory, etc., or may include both types at the same time. The memory usually stores an operating system (OS), one or more application programs, and may also store program data, etc. In addition to the processing unit and the memory, the access device for the cross-regional service on the cloud across the point-to-point also includes some basic configurations, such as: a network card chip, an IO bus, a display component, and some peripheral devices. Optionally, some peripheral devices may include, for example, a keyboard, a mouse, an input pen, a printer, etc. Other peripheral devices are well known in the art and will not be described in detail here.
[0039] In addition, the access device for the point-to-point cross-regional cloud service can be communicatively connected to the server corresponding to the client and the service provider to implement the access operation of the point-to-point cross-regional cloud service. The client can be implemented as at least one of the following: VR client, video client, vehicle terminal, smart wearable device, handheld terminal, tablet computer, personal computer, etc. The client / server and the access device for the point-to-point cross-regional cloud service can be connected to the network, and the network connection can be a wireless or wired network connection. If the client / server and the access device for the point-to-point cross-regional cloud service are communicatively connected, the network standard of the mobile network can be any one of 4G (LTE), 4G+ (LTE+), 5G, 5.5G, 6G, etc.
[0040] In an embodiment of the present application, the client is used by users to implement cross-regional service access operations. Specifically, the client can display an interactive interface, through which an access request for a cross-regional service can be generated and obtained. After obtaining the access request for the cross-regional service, in order to implement the cross-regional service access operation, the access request for the cross-regional service can be sent to an access device for the cross-regional service on the cloud opposite the point.
[0041] A point-to-point access device for cross-regional services on the cloud is used to obtain the access request for the cross-regional service sent by the client through the user gateway. In order to implement the access operation of the cross-regional service, after obtaining the access request for the cross-regional service, the service access address corresponding to the access request can be determined. Among them, the user gateway can be communicatively connected with multiple service gateways, the user gateway can be located in the first virtual Internet network, and the multiple service gateways can be located in the second virtual Internet network. Specifically, the multiple service gateways can be located in one or more second virtual Internet networks, the first virtual Internet network is communicatively connected with the second virtual Internet network, and the area and address segment corresponding to the first virtual Internet network are different from the area and address segment corresponding to the second virtual private network.
[0042] After obtaining the access request for the cross-regional service, in order to implement the point-to-point access operation of the cross-regional service on the cloud, the cross-regional service gateway corresponding to the access request can be determined from multiple service gateways; the cross-regional service gateway can be any gateway among the multiple service gateways that can provide the access operation of the cross-regional service, and then the cross-regional service access operation can be performed on the cross-regional service gateway and the service access address, which not only can stably implement the access operation of the cross-regional service, effectively expand the scope of application of the cloud service, but also can improve the user's good experience of accessing the cross-regional service.
[0043] Some embodiments of the present invention are described in detail below in conjunction with the accompanying drawings. In the case where there is no conflict between the embodiments, the following embodiments and the features in the embodiments can be combined with each other. In addition, the step sequence in the following method embodiments is only an example and not a strict limitation.
[0044] Figure 2 A flowchart of a method for accessing a point-to-point cross-regional cloud service provided in an embodiment of the present application; see Attachment Figure 2 As shown, this embodiment provides a method for accessing a point-to-point cross-regional service on the cloud. The executor of the method is a device for accessing a point-to-point cross-regional service on the cloud. It can be understood that the device for accessing a point-to-point cross-regional service on the cloud can be implemented as software, or a combination of software and hardware. Specifically, when the device for accessing a point-to-point cross-regional service on the cloud is implemented as hardware, it can be various electronic devices with the ability to access a point-to-point cross-regional service on the cloud. In some instances, the device for accessing a point-to-point cross-regional service on the cloud can be implemented as an access platform. When the device for accessing a point-to-point cross-regional service on the cloud is implemented as software, it can be installed in the above-mentioned electronic device; based on the above-mentioned device for accessing a point-to-point cross-regional service on the cloud, the access operation of the point-to-point cross-regional service on the cloud can be implemented. Specifically, the method for accessing a point-to-point cross-regional service on the cloud can include the following steps:
[0045] Step S201: Obtain an access request for a cross-region service and a service access address corresponding to the access request through a user gateway, wherein the user gateway is communicatively connected to multiple service gateways, the user gateway is located in a first virtual Internet network, the multiple service gateways are located in different second virtual Internet networks, the first virtual Internet network is communicatively connected to the second virtual Internet network, and the region and address segment corresponding to the first virtual Internet network are different from the region and address segment corresponding to the second virtual private network.
[0046] Step S202: Determine, among multiple service gateways, a cross-region service gateway corresponding to the access request.
[0047] Step S203: Performing an access operation for the cross-region service through the cross-region service gateway and the service access address.
[0048] The specific implementation process and effects of each of the above steps are described in detail below:
[0049] Step S201: Obtain an access request for a cross-region service and a service access address corresponding to the access request through a user gateway, wherein the user gateway is communicatively connected to multiple service gateways, the user gateway is located in a first virtual Internet network, the multiple service gateways are located in different second virtual Internet networks, the first virtual Internet network is communicatively connected to the second virtual Internet network, and the region and address segment corresponding to the first virtual Internet network are different from the region and address segment corresponding to the second virtual private network.
[0050] Among them, the access device for cross-regional services (hereinafter referred to as "access device") may include a user gateway and multiple service gateways communicatively connected to the user gateway. The above-mentioned user gateway may be located in the first virtual Internet network and is used to communicate and connect with user terminals in different regions. For example: the user terminal includes user terminal a located in region 1, user terminal b located in region 2, and user terminal c located in region 3. The above-mentioned user terminals a, b and c can be communicatively connected to the user gateway so that users in different regions can implement cross-regional service access operations through the access device.
[0051] For the service gateway in the access device, multiple service gateways may be located in at least one second virtual Internet network, and different second virtual Internet networks may correspond to different areas, and are used to communicate with servers corresponding to service providers located in different areas. For example, refer to the attached Figure 3As shown, the second virtual interconnection network a includes a service gateway a1 and a service gateway a2, and the service gateway a1 and the service gateway a2 can be connected to the server 1 corresponding to the service provider 1 in the area 1, so that the service provider 1 can communicate with the service gateway a1 and / or the service gateway a2 through the server 1 in the area 1 to implement the cross-region service publishing operation and the cross-region service access operation; the second virtual interconnection network b can include a service gateway b, and the service gateway b can be connected to the server 2 corresponding to the service provider 2 in the area 2, so that the service provider 2 can communicate with the service gateway b through the server 1 in the area 2 to implement the cross-region service. The second virtual Internet network c may include service gateways c1, c2, and c3, which may be connected in communication with server 3 corresponding to service provider 3 in region 3, so that service provider 3 in region 3 may communicate with server 3 and service gateway c (any one of service gateways c1, c2, and c3) to implement cross-region service publishing operations and cross-region service access operations, thereby effectively enabling service providers in different regions to perform cross-region service publishing and access operations.
[0052] Specifically, when a user has access requirements for cross-regional services on the cloud, a cross-regional service access request can be sent to an access device for the cross-regional service on the cloud at the point-to-point through the user terminal, so that the access device can obtain the cross-regional service access request. The access device can obtain the cross-regional service access request through the user gateway, thereby effectively ensuring the accuracy and reliability of obtaining the cross-regional service access request. In order to accurately implement the cross-regional service access operation on the cloud at the point-to-point, after obtaining the cross-regional service access request, the cross-regional service access request can be analyzed and processed, so as to obtain the service access address corresponding to the access request, and the service access address can be implemented as an IPv4 address, an IPv6 address, etc.
[0053] In some instances, in order to implement point-to-point access operations to cross-regional services on the cloud, the user gateway needs to be configured before obtaining an access request for a cross-regional service through the user gateway. At this time, the method in this embodiment may also include: obtaining a configuration request for the user gateway; based on the configuration request, determining user gateway configuration information corresponding to the user private network, the user gateway configuration information including at least: service domain name information, service access address, and port information; performing gateway configuration operations based on the user gateway configuration information to obtain a user gateway located in the virtual Internet.
[0054] Specifically, when the user has a configuration requirement for the user gateway, the access device can obtain the configuration request of the user gateway. In some instances, the configuration request of the user gateway can be obtained through human-computer interaction operations. At this time, obtaining the configuration request of the user gateway may include: displaying a human-computer interaction interface; obtaining an execution operation input by the user in the human-computer interaction interface; and obtaining the configuration request of the user gateway based on the execution operation. In some other instances, the configuration request of the user gateway can be obtained not only through human-computer interaction operations, but also through a preset device. At this time, obtaining the configuration request of the user gateway may include: obtaining a preset device that is communicatively connected to the access device, and the preset device may include the configuration request of the user gateway; the configuration request of the user gateway may be actively or passively obtained through the preset device.
[0055] After obtaining the configuration request of the user gateway, the configuration request can be analyzed and processed to obtain the user gateway configuration information corresponding to the user private network, and the user gateway configuration information at least includes: service domain name information, service access address, and port information; after obtaining the user gateway configuration information, the gateway configuration operation can be performed based on the user gateway configuration information, so that the user gateway located in the virtual Internet network can be obtained. It should be noted that the number of user gateways is one, and the user gateway can be connected to all user terminals located in the same area. In this way, after the user gateway establishes a communication connection with the user terminal, the access operation of the cross-regional service can be realized through the established one-time communication link. In addition, for the user gateway, the first virtual private network can include a cloud server, and the configured user gateway can be deployed on the cloud server, which is conducive to ensuring the access operation of the cross-regional service based on the user gateway, and further ensuring the stability and reliability of the cross-regional service access operation.
[0056] It should be noted that, for the first virtual Internet network and the second virtual Internet network deployed in the access device, the first virtual Internet network is communicatively connected with the second virtual Internet network. In some instances, the first virtual Internet network can communicate with the second virtual Internet network through Cloud Enterprise Network (CEN) technology, VPC Peering technology, Virtual Private Network (VPN) technology, etc., and the region and address segment corresponding to the first virtual Internet network are different from the region and address segment corresponding to the second virtual private network to achieve cross-regional service access operations.
[0057] In some other instances, in order to enable access operations to cross-regional services on the cloud, the service gateway needs to be configured before obtaining access requests to cross-regional services through the user gateway. At this time, the method in this embodiment may also include: obtaining a configuration request for the service gateway; based on the configuration request, determining the service gateway configuration information, the service gateway configuration information includes at least: a network identifier of the service provider's private network, security group information for identifying service access rules, and a virtual switch for realizing information interaction; performing gateway configuration operations based on the service gateway configuration information to obtain a service gateway located in the virtual Internet network.
[0058] Specifically, when there is a configuration requirement for the service gateway, the access device can obtain the configuration request of the service gateway. In some instances, the configuration request of the service gateway can be obtained through human-computer interaction operations. In this case, obtaining the configuration request of the service gateway may include: displaying the human-computer interaction interface; obtaining the execution operation input by the user in the human-computer interaction interface; and obtaining the configuration request of the service gateway based on the execution operation. In some other instances, the configuration request of the service gateway can be obtained not only through human-computer interaction operations, but also through a preset device. In this case, obtaining the configuration request of the service gateway may include: obtaining a preset device that is communicatively connected to the access device, and the preset device may include the configuration request of the service gateway; the configuration request of the service gateway may be actively or passively obtained through the preset device.
[0059] After obtaining the configuration request of the service gateway, the configuration request can be analyzed and processed to obtain the service gateway configuration information, which includes at least: the network identifier of the service provider's private network, the security group information used to identify the service access rules, and the virtual switch used to implement information interaction. It should be noted that the service gateway configuration information can include not only the above information, but also other information. For example, the service gateway configuration information can also include: the IP address of the published service, the service port, etc. The technical personnel in this field can flexibly configure or flexibly adjust the service gateway configuration information according to the specific application scenario or application requirements.
[0060] After obtaining the service gateway configuration information, the gateway configuration operation can be performed based on the service gateway configuration information, so that the service gateway located in the virtual Internet can be obtained. It should be noted that a service provider's server can correspond to a service gateway, the IP addresses of servers of different service providers can be the same or different, and the service identifiers of servers of different service providers can be different. In addition, for the service gateway, the second virtual private network can include a cloud server, and the configured service gateway can be deployed on the cloud server, which is conducive to ensuring the access operation of cross-regional services based on the service gateway, and further ensuring the stability and reliability of the cross-regional service access operation.
[0061] Furthermore, for the service gateways in the second virtual internet network, users can add or delete the number of service gateways as needed. Specifically, after adding a service gateway, the added service gateway can be obtained, and then the added service gateway can be broadcasted in the first virtual internet network and the second virtual internet network, so that the user end or each service provider can be informed of the added service gateway in the virtual internet network. When deleting a service gateway, it can be detected whether the service gateway is associated with a client and a server. When the service gateway is associated with a client and a server, the deletion of the service gateway is prohibited; when the service gateway is not associated with a client and a server, the deletion of the service gateway is allowed.
[0062] Step S202: Determine, among multiple service gateways, a cross-region service gateway corresponding to the access request.
[0063] Since the access request of the cross-region service is used to implement the access operation to a certain cross-region service, in order to implement the access operation of the cross-region service, the cross-region service gateway corresponding to the access request can be determined among multiple service gateways. In some instances, the cross-region service gateway can be obtained based on the region to which the target service corresponding to the access request belongs. At this time, among multiple service gateways, determining the cross-region service gateway corresponding to the access request may include: obtaining the target service corresponding to the access request; determining the region to which the target service belongs; and among multiple service gateways, determining the cross-region service gateway corresponding to the access request that is located in the region to which the target service belongs, thereby effectively ensuring the accuracy and reliability of determining the cross-region service gateway.
[0064] In other instances, the cross-regional service gateway can be determined not only by the region to which the target service belongs, but also by a preset configuration information table. At this time, among multiple service gateways, determining the cross-regional service gateway corresponding to the access request may include: obtaining domain name information corresponding to the access request; determining a configuration information table for processing the domain name information, the configuration information table including a mapping relationship between the domain name information and the service gateway; based on the domain name information and the configuration information table, determining the cross-regional service gateway corresponding to the access request among multiple service gateways.
[0065] In some instances, multiple service gateways located in the second virtual interconnect network may correspond to different domain name information. In this case, the cross-region service gateway may be determined based on the different domain name information. Specifically, after obtaining the access request, the access request may be analyzed and processed, so that the domain name information corresponding to the access request may be obtained. In order to implement the access operation of the cross-region service, after obtaining the domain name information corresponding to the access request, a configuration information table for processing the domain name information may be determined. The configuration information table may include a mapping relationship between the domain name information and the service gateway. After obtaining the configuration information table and the domain name information, the cross-region service gateway corresponding to the access request may be determined among the multiple service gateways based on the domain name information and the configuration information table, thereby effectively ensuring the accuracy and reliability of the determination of the cross-region service gateway.
[0066] In other instances, multiple service gateways located in the second virtual Internet network may correspond to different service access addresses. In this case, the cross-regional service gateway may be determined based on the different service access addresses. Specifically, after obtaining the access request, the access request may be analyzed and processed so as to obtain the domain name information corresponding to the access request. In order to implement the cross-regional service access operation, after obtaining the domain name information corresponding to the access request, a configuration information table for processing the domain name information may be determined. The configuration information table may include a mapping relationship between the domain name information and the service access address. After obtaining the configuration information table and the domain name information, the service access address corresponding to the access request may be determined based on the domain name information and the configuration information table, and then the cross-regional service gateway corresponding to the access request may be determined among the multiple service gateways based on the service access address. This also ensures the accuracy and reliability of the determination of the cross-regional service gateway.
[0067] Step S203: Performing an access operation for the cross-region service through the cross-region service gateway and the service access address.
[0068] After obtaining the service access address and the cross-region service gateway corresponding to the access request, the cross-region service access operation can be performed through the cross-region service gateway and the service access address. In some instances, after obtaining the access request through the user gateway, the access request can be sent to the cross-region service gateway through the service access address. After the cross-region service gateway obtains the access request, the access request can be sent to the server corresponding to the service provider based on the service access address to implement the cross-region service access operation.
[0069] In other instances, an access instance for implementing access operations for cross-regional services may be configured in the cross-regional service gateway, and the access operations for cross-regional services may be implemented based on the access instances corresponding to the access requests. At this time, performing access operations for cross-regional services through the cross-regional service gateway and the service access address may include: obtaining multiple alternative access instances in the cross-regional service gateway; determining at least one target access instance corresponding to the access request among the multiple alternative access instances; and performing access operations for cross-regional services based on the at least one target access instance and the service access address.
[0070] Among them, the access request can realize the access operation of the cross-regional service through one or more access instances, and multiple alternative access instances for realizing the access operation of the cross-regional service are stored in the cross-regional service gateway. Specifically, after obtaining the access request of the cross-regional service, multiple alternative access instances in the cross-regional service gateway can be obtained by accessing the preset area, and then at least one target access instance corresponding to the access request can be determined from the multiple alternative access instances. The at least one target access instance can be obtained by analyzing and processing multiple alternative access instances through a random algorithm or a load balancing algorithm. After obtaining at least one target access instance, the access operation of the cross-regional service can be performed based on the at least one target access instance and the service access address, thereby effectively realizing the stability and reliability of the cross-regional service access operation.
[0071] The point-to-point cross-regional service access method provided in this embodiment obtains the cross-regional service access request and the service access address corresponding to the access request through the user gateway, and then determines the cross-regional service gateway corresponding to the access request among multiple service gateways, and performs the cross-regional service access operation through the cross-regional service gateway and the service access address. Since the cross-regional service gateway is any one of the multiple service gateways, the multiple service gateways can be located in different regions, so that the user can implement the point-to-point cross-regional service access operation through the user gateway and the cross-regional service gateway. In this way, not only can the cross-regional service access operation be stably implemented, the application scope of the cloud service is effectively expanded, but also the user's good experience of accessing the cross-regional service can be improved, and the access quality and effect of the cross-regional cloud service can be guaranteed. In addition, since the user gateway and the service gateway are both deployed in the virtual Internet network, when the virtual Internet network is implemented as a virtual Internet private network, the private network access operation is implemented, thereby effectively ensuring the security and stability of service publishing and service access, which is conducive to market promotion and application.
[0072] Figure 4 A flowchart of another method for accessing cross-region services on a cloud from point to point provided in an embodiment of the present application; based on the above embodiment, refer to the attached Figure 4 As shown, after obtaining the service gateway located in the virtual Internet, in order to enable users to implement cross-region service access operations based on the service gateway, the cross-region service publishing operation can be performed through the service gateway. At this time, the method in this embodiment can also include:
[0073] Step S401: Obtain a service publishing request through a service gateway.
[0074] Step S402: Based on the service publishing request, determine the configuration information corresponding to the service to be published, where the configuration information at least includes: the IP address and port information of the service to be published.
[0075] Step S403: Based on the configuration information, a service publishing operation is performed in the virtual Internet corresponding to the service gateway to obtain the published service.
[0076] When a service provider has a service publishing demand, the service provider can send a service publishing request to the access device through the service gateway, so that the access device can obtain the service publishing request through the service gateway. After obtaining the service publishing request, the service publishing request can be analyzed and processed, so as to determine the configuration information corresponding to the service to be published, which at least includes the IP address and port information of the service to be published. It should be noted that the configuration information can include not only the IP address and port information of the service to be published, but also the service name information of the service to be published, the identity information of the service provider, the service version information, the service publishing time information, etc. The technicians in this field can flexibly configure or adjust the specific data included in the configuration information according to the specific application scenario or application requirements.
[0077] After obtaining the configuration information corresponding to the service to be published, the service publishing operation can be performed in the virtual Internet network corresponding to the service gateway based on the configuration information, so as to obtain the published service, wherein the obtained published service can be deployed in the first virtual Internet network and the second virtual Internet network, thereby effectively realizing the cross-region service publishing operation. After obtaining the published service, the published service and the corresponding service gateway can be associated and stored, and then the published service can be accessed based on the service gateway, thereby effectively ensuring the stability and reliability of the service access operation.
[0078] For example, when service provider 1 located in area 1 needs to publish a service, service provider 1 can send a service publishing request to the access device through service gateway 1. The access device determines the configuration information corresponding to the service to be published through the service publishing request, and then performs a service publishing operation in the virtual Internet network corresponding to service gateway 1 based on the configuration information, thereby obtaining published service 1. When service provider 2 located in area 2 needs to publish a service, service provider 2 can send a service publishing request to the access device through service gateway 2. The access device determines the configuration information corresponding to the service to be published through the service publishing request, and then performs a service publishing operation in the virtual Internet network corresponding to service gateway 2 based on the configuration information, thereby obtaining published service 2.
[0079] Since the virtual Internet network corresponding to service gateway 1 and the virtual Internet network corresponding to service gateway 2 can be different virtual Internet networks, service gateway 1 is communicatively connected with service gateway 2. When the service provider performs service publishing operations through a service gateway located in a certain area, cross-regional service publishing operations can be implemented, that is, the published service 1 published by service provider 1 can be accessed and called by users located in area 1 and area 2, and the published service 2 published by service provider 2 can be accessed and called by users located in area 1 and area 2. This effectively ensures the stability and reliability of the same-region or cross-regional access operations to the published services.
[0080] In some other instances, after obtaining the published service, a configuration information table corresponding to the published service can be generated. Specifically, the method in this embodiment may also include: obtaining service access attributes of the published service through the service gateway, the service access attributes including at least: domain name information, service access address and service port; associating and storing the service gateway and the service access attributes, and generating a configuration information table for analyzing and processing the domain name information.
[0081] Specifically, when obtaining a published service, the service access attributes corresponding to the published service can be stored in a preset area in the access device. Therefore, after obtaining the published service, in order to implement the service access operation, the service access attributes of the published service can be obtained through the service gateway. The service access attributes can at least include: domain name information, service access address and service port; after obtaining the service access attributes, the service gateway and the service access attributes can be associated and stored to generate a configuration information table for analyzing and processing the domain name information. The generated configuration information table can include a mapping relationship between the service gateway and the service access attributes, so that users can implement cross-region service access operations through the configuration information table.
[0082] In this embodiment, a service publishing request is obtained through a service gateway, and based on the service publishing request, configuration information corresponding to the service to be published is determined, and based on the configuration information, a service publishing operation is performed in the virtual Internet corresponding to the service gateway to obtain the published service, which effectively enables the service provider to perform service publishing operations through the service gateway, and then facilitates users to access cross-regional services through access devices.
[0083] Figure 5 A flowchart of another method for accessing a point-to-point cross-regional cloud service provided in an embodiment of the present application; based on any of the above embodiments, refer to the attached Figure 5 As shown, the method in this embodiment can flexibly adjust and control the number of access instances in the cross-region service gateway based on the access traffic. At this time, the method in this embodiment can also include:
[0084] Step S501: Obtain traffic information passing through the cross-region service gateway.
[0085] Step S502: Control the number of access instances in the cross-region service gateway based on traffic information.
[0086] Since the service access traffic in different application scenarios may be different, in order to ensure the stable operation of the service access operation, the traffic information passing through the cross-regional service gateway can be obtained. It should be noted that the traffic information passing through the cross-regional service gateway can be the actual traffic information passing through the cross-regional service gateway at the current moment, or the traffic information passing through the cross-regional service gateway can be the predicted traffic information passing through the cross-regional service gateway at a certain future moment predicted at the current moment.
[0087] In some instances, since the cross-regional service gateway can receive the service access traffic sent by the client through the user gateway, or the cross-regional service gateway can send the service access traffic to the server corresponding to the service provider, it can be seen from the above that the traffic information passing through the cross-regional service gateway can include inbound traffic and outbound traffic. In order to ensure the stable operation of the service access operation, the traffic information passing through the cross-regional service gateway can be manually or automatically obtained during the service access operation. At this time, obtaining the traffic information passing through the cross-regional service gateway can include: obtaining a human-computer interaction interface; determining a trigger operation input by the user in the human-computer interaction interface; based on the trigger operation, the traffic information passing through the cross-regional service gateway can be obtained, thereby effectively realizing that the traffic information passing through the cross-regional service gateway can be manually obtained. Alternatively, obtaining the traffic information passing through the cross-regional service gateway can include: obtaining an information collection period for determining the traffic information; obtaining the traffic information passing through the cross-regional service gateway based on the information collection period, thereby effectively realizing that the traffic information passing through the cross-regional service gateway can be automatically obtained.
[0088] In addition, for the traffic information passing through the cross-regional service gateway, it can be an inbound flow or an outbound flow. In some instances, the cross-regional service gateway can be communicatively connected to a traffic detection module, and the traffic information passing through the cross-regional service gateway can be obtained through the traffic detection module. The traffic information can be an inbound flow or an outbound flow. Specifically, obtaining the traffic information passing through the cross-regional service gateway can include: obtaining the inbound flow and outbound flow passing through the cross-regional service gateway; comparing the inbound flow with the outbound flow. When the inbound flow is greater than the outbound flow, the traffic information passing through the cross-regional service gateway can be regarded as the inbound flow; when the inbound flow is less than the outbound flow, the traffic information passing through the cross-regional service gateway can be regarded as the outbound flow.
[0089] After obtaining the traffic information passing through the cross-regional service gateway, the number of access instances in the cross-regional service gateway can be controlled based on the traffic information. In some instances, controlling the number of access instances in the cross-regional service gateway based on the traffic information can be achieved through a pre-trained machine learning model or neural network model. Alternatively, in other instances, the number of access instances in the cross-regional service gateway can be controlled directly by identifying whether the current number of access instances can meet the traffic demand. At this time, controlling the number of access instances in the cross-regional service gateway based on the traffic information can include: obtaining the current number of access instances in the cross-regional service gateway and the supportable traffic of a single access instance; determining the total supportable traffic of the cross-regional service gateway based on the current number and the supportable traffic; and controlling the number of access instances in the cross-regional service gateway based on the traffic information based on the total supportable traffic.
[0090] Among them, during the operation of the cross-regional service gateway, the cross-regional service gateway can record the access instances created for implementing data processing operations. In the process of service access and service publishing, in order to accurately control the access instances in the cross-regional gateway, the current number of access instances in the cross-regional service gateway can be obtained by timing or real-time through a counter or the serial number of the created access instance. For each access instance, the supportable flow corresponding to each access instance can be pre-configured, and the flow information can change based on the change of the configuration data of the access instance. After the access instance is determined, the supportable flow of a single access instance can be determined based on the attribute information and configuration information of the access instance.
[0091] After obtaining the current number and supportable traffic of access instances in the cross-regional service gateway, the total supportable traffic of the cross-regional service gateway can be determined by analyzing the current number and supportable traffic. The total supportable traffic is the sum of the supportable traffic of all access instances, that is, the total supportable traffic = current number * supportable traffic. When the supportable traffic corresponding to different access instances is different, the total supportable traffic = supportable traffic 1 + supportable traffic 2 + ..., thereby effectively ensuring the stability and reliability of determining the total supportable traffic.
[0092] After determining the total supported traffic of the cross-regional service gateway, the total supported traffic and traffic information can be analyzed and processed to control the number of access instances in the cross-regional service gateway based on the analysis and processing results; in some instances, the total supported traffic and traffic information can be analyzed and processed by a pre-trained machine learning model or neural network model, and the number of access instances in the cross-regional service gateway can be controlled. In other instances, the total supported traffic can be directly compared with the traffic size corresponding to the traffic information, and then the number of access instances in the cross-regional service gateway can be controlled based on the comparison result. At this time, controlling the number of access instances in the cross-regional service gateway based on the total supported traffic and the traffic information can include: when the total supported traffic is greater than or equal to the traffic size corresponding to the traffic information, it means that the current cross-regional service gateway can fully guarantee the normal operation of service access operations and service publishing operations, so the number of access instances in the cross-regional service gateway can be kept unchanged.
[0093] Correspondingly, when the total supportable traffic is less than the traffic size corresponding to the traffic information, it means that the current cross-regional service gateway cannot guarantee the normal implementation of service access operations and service publishing operations. Therefore, in order to ensure the stability and reliability of data transmission, it is necessary to expand the access instance in the cross-regional service gateway. In order to avoid waste of resources, when performing the expansion operation, you can first obtain the traffic difference between the traffic size and the total supportable traffic, and then control the number of access instances in the cross-regional service gateway based on the traffic difference. Specifically, controlling the number of access instances in the cross-regional service gateway based on the traffic difference can include: obtaining the ratio between the traffic difference and the supportable traffic of a single access instance; based on the ratio, determining the quantity information for increasing the access instance in the cross-regional service gateway, so as to expand the access instance based on the quantity information.
[0094] For example, when the supportable traffic of a single access instance is 1.5G, the current number of access instances included in the cross-regional service gateway is 2, and the traffic size passing through the cross-regional service gateway is 6G, it means that the 2 access instances in the cross-regional service gateway cannot guarantee stable and effective data processing operations, and then the total supportable traffic of the current cross-regional service gateway can be obtained, that is, 2*1.5=3G, and then the difference between the traffic size and the total supportable traffic is determined, that is, 6G-3G=3G, and the ratio between the traffic difference and the supportable traffic of a single access instance is determined, that is, 3G / 1.5G=2, and then the quantity information for increasing the access instances in the cross-regional service gateway can be determined based on the above ratio, that is, in the current case, it is necessary to add 2 access instances in the cross-regional service gateway, that is, to expand the number of access instances from 2 to 4, so as to ensure the stability and reliability of data processing.
[0095] It should be noted that when the ratio between the traffic difference and the supportable traffic of a single access instance is not an integer, the comparison value can be rounded up, and then the rounded value is determined as the quantity information for increasing the access instances in the cross-regional service gateway, which effectively realizes the flexible expansion of the access instances in the cross-regional service gateway according to traffic requirements. This not only ensures the stable progress of data processing, but also avoids the waste of resources caused by unlimited expansion of access instances, which is conducive to improving the utilization of data processing resources.
[0096] In this embodiment, by obtaining the traffic information passing through the cross-regional service gateway and then controlling the number of access instances in the cross-regional service gateway based on the traffic information, it is effectively possible to flexibly adjust and control the number of access instances in the cross-regional service gateway based on the traffic information, thereby effectively ensuring the stability and reliability of the cross-regional service access operation.
[0097] Figure 6 A flowchart of a method for accessing a point-to-point cross-regional cloud service provided in an embodiment of the present application; based on any of the above embodiments, refer to the attached Figure 6 As shown, the method in this embodiment can flexibly adjust and control the number of cloud servers located in the virtual Internet based on the access traffic. At this time, the method in this embodiment can also include:
[0098] Step S601: Obtain traffic information passing through a cloud server in a second virtual internet network, where a service gateway in the second virtual internet network is deployed on the cloud server.
[0099] Step S602: Control the number of cloud servers based on traffic information.
[0100] Since the service access traffic in different application scenarios may be different, in order to ensure the stable operation of the service access operation, the traffic information passing through the cloud server in the second virtual Internet network can be obtained, wherein the service gateways in the virtual Internet network are deployed on the cloud server. It should be noted that not only the service gateway can be deployed on the cloud server, but also other components, such as: load balancing components, security components, etc.
[0101] Specifically, during the service access process, the cloud server can receive the service access traffic sent by the client through the user gateway, or the cloud server can send the service access traffic to the server corresponding to the service provider. Therefore, the traffic information passing through the cloud server can include inbound traffic and outbound traffic. In order to ensure the stable operation of the service access operation, during the service access operation, the traffic information passing through the cloud server in the second virtual Internet network can be manually or automatically obtained. At this time, obtaining the traffic information passing through the cloud server in the second virtual Internet network can include: obtaining a human-computer interaction interface; determining a trigger operation input by a user in the human-computer interaction interface; based on the trigger operation, the traffic information passing through the cloud server in the second virtual Internet network can be obtained, thereby effectively realizing that the traffic information passing through the cloud server in the second virtual Internet network can be manually obtained. Alternatively, obtaining the traffic information passing through the cloud server in the second virtual Internet network can include: obtaining an information collection cycle for determining the traffic information; based on the information collection cycle, the traffic information passing through the cloud server in the second virtual Internet network is obtained, thereby effectively realizing that the traffic information passing through the cloud server in the second virtual Internet network can be automatically obtained.
[0102] In addition, for the traffic information passing through the cloud server, it can be inbound traffic or outbound traffic. In some instances, the cloud server can be communicatively connected to a traffic detection module, and the traffic information passing through the cloud server can be obtained through the traffic detection module. The traffic information can be inbound traffic or outbound traffic. Specifically, obtaining the traffic information passing through the cloud server in the second virtual Internet network can include: obtaining the inbound traffic and outbound traffic passing through the cloud server; comparing the inbound traffic with the outbound traffic. When the inbound traffic is greater than the outbound traffic, the traffic information passing through the cloud server can be regarded as the inbound traffic; when the inbound traffic is less than the outbound traffic, the traffic information passing through the cloud server can be regarded as the outbound traffic.
[0103] After obtaining the traffic information passing through the cloud servers, the number of cloud servers can be controlled based on the traffic information. In some instances, controlling the number of cloud servers based on the traffic information can include: obtaining the current number of cloud servers in the virtual Internet; detecting whether the current number of cloud servers can meet the traffic information; when the current number of cloud servers can meet the traffic information, the cloud servers can be kept unchanged; when the current number of cloud servers cannot meet the traffic information, the number of cloud servers can be increased to meet the traffic information, thereby ensuring stable cross-regional service access.
[0104] In this embodiment, by obtaining the traffic information of the cloud servers passing through the second virtual Internet, the number of cloud servers is controlled based on the traffic information, which effectively realizes the flexible adjustment and control of the number of cloud servers based on the traffic information, thereby effectively ensuring the stability and reliability of cross-region service access operations.
[0105] For specific applications, refer to the attached Figure 7 As shown, this application embodiment provides a point-to-surface service publishing and service access method, the execution subject of the method can be a system capable of implementing point-to-surface service publishing and service access, wherein at least a first virtual internet network VPC and a second virtual internet network VPC with communication connection are deployed in the service publishing and service access system, and the number of the first virtual internet network VPC and the second virtual internet network VPC can be one or more; specifically, the first virtual internet network VPC and the second virtual internet network VPC can realize the communication connection between the internet networks VPC through CEN technology, VPC Peering technology and VPN technology to realize the construction operation of cross-region access links; the above-mentioned first virtual internet network VPC and the second virtual internet network can both include:
[0106] The user gateway Service GW is set on the first cloud server in the first virtual interconnection network VPC, and is used to communicate with at least one client in each region. In order to implement cross-region service access operations through the user gateway Service GW, the user gateway Service GW can be configured first. Specifically, the configuration data of the user gateway can be obtained, and the configuration data may include: service access domain name, service access point, service address, access port and other information. After obtaining the configuration data of the user gateway, the user gateway can be configured on the first cloud server based on the configuration data of the user gateway.
[0107] In some instances, the user gateway Service GW is a service gateway used to implement external user access. The user gateway Service GW can communicate with the client through a private network link PrivateLink, wherein a load balancing component SLB can be configured between the client and the user gateway Service GW, and the user gateway Service GW can be a one-way access gateway. A 7-layer forwarding service policy can also be configured in the user gateway Service GW. The user gateway Service GW can forward the obtained traffic to the cross-regional service gateway ISV GW of the service access, thereby realizing cross-regional data communication operations.
[0108] Multiple service gateways ISV GW are set on the second cloud server in the second virtual internet network VPC, and are used to communicate with the user gateway Service GW and the server corresponding to the service provider, wherein the address segments and regions corresponding to the first virtual internet network VPC and the second virtual internet network VPC are different, and the above-mentioned first virtual internet network VPC and the second virtual internet network VPC can access the server and client of the service provider, so as to realize the sharing operation of computing resources.
[0109] In order to enable the publication and access of cross-regional services through the service gateway ISV GW, the service gateway ISV GW can be configured first. Specifically, the configuration data of the service gateway ISV GW can be obtained, and the configuration data may include: the ID information of the virtual Internet VPC corresponding to the service provider, the security group information of the virtual Internet VPC corresponding to the service provider (used to limit information access rules, etc.), the virtual switch VSW, the IP address of the service to be published, and the access port and other information. After obtaining the configuration data of the service gateway ISV GW, the service gateway ISV GW can be configured on the second cloud server based on the configuration data of the service gateway ISV GW.
[0110] In some instances, the service gateway ISV GW is an internal component built to implement access to service provider services, wherein the service gateway ISV GW can be a one-way access gateway, and multiple instances of servers corresponding to the service provider can be built inside the service gateway ISV GW. High-availability service publishing operations and service access operations can be implemented through multiple instances.
[0111] It should be noted that the service publishing and service access system may include not only the user gateway Service GW and multiple service gateways ISV GW, but also a configuration unit that is in communication with the user gateway Service GW and multiple service gateways ISV GW. The configuration unit may implement configuration operations of the service catalog and domain name management operations:
[0112] The service catalog may include: the service gateway ISV GW corresponding to the registration service provider (i.e. corresponding to the ISV access point), the service address of the virtual Internet VPC where the service is located, service access domain name information, etc., which are used to perform address forwarding operations based on Network Address Translation (NAT) within the virtual Internet VPC plane.
[0113] The domain name management operation can register a service access domain name based on the wildcard domain name technology, in which the client's node address can be determined as the ground address of the subdomain name for accessing the service. In this way, for existing services and newly released services, users do not need to subscribe again to access the service, and can directly resolve the access domain name information. The cloud server, confirmation information (Acknowledgement, ACK), and Fibre Channel (FC) protocol resources in the virtual Internet VPC where the client is located can all access the services of the virtual Internet.
[0114] Based on the above service publishing and service access system, the automatic publishing operation of services in all regions and the access operation of services in all regions can be realized, so that users can access all published services once. The service publishing method in this embodiment may include the following steps:
[0115] Step 11: The service provider generates a service publishing request through the server, and the service publishing request may include the service identifier, service configuration data, service access address, service domain name, etc. of the service to be published;
[0116] Step 12: The service provider sends the generated service publishing request to the second virtual internet VPC through the server.
[0117] Step 13: Obtain a service publishing request through the service gateway ISV GW in the second virtual internet network VPC, and perform service publishing operations based on the service publishing request. Since any two service gateways ISV GW in the second virtual internet network VPC are communicatively connected, the services published by the service provider can be accessed by users in different regions, effectively enabling the service provider to implement cross-regional service publishing operations in a certain region.
[0118] The service access method in this embodiment may include the following steps:
[0119] Step 21: The user generates a service access request through the client.
[0120] The service access request may be access domain name information, which may be expressed as: msg.isv1.alicompnest.com, weather.isv1.alicompnest.com, location.isv1.alicompnest.com, and the like.
[0121] Step 22: The client may send a service access request to the first virtual internet VPC.
[0122] Step 23: The service access request can be obtained through the user gateway Service GW in the first virtual Internet VPC.
[0123] Among them, the client and the user gateway Service GW can achieve communication connection through a private network link PrivateLink, and a load balancing component for balancing service access requests can be configured between the client and the user gateway Service GW, so that when there are multiple service access requests that need to be processed, service access operations can be performed stably.
[0124] Step 24: The user gateway Service GW may perform domain name resolution processing on the service access request to obtain domain name information corresponding to the access request.
[0125] Step 25: The user gateway Service GW may obtain a service catalog for analyzing and processing the domain name information through a configuration unit. The service catalog includes four-tuple information. The four-tuple information may include <service domain name, service gateway, service address, access port> and the like.
[0126] Step 26: The user gateway uses the service directory to analyze and process the domain name information to obtain the service address and service gateway corresponding to the service access request.
[0127] Step 27: The user gateway in the first virtual internet network VPC sends the service access request to the service gateway in the second virtual internet network VPC through cross-region interconnection technology based on the determined service address and service gateway.
[0128] Step 28: The service gateway located in the second virtual internet VPC can obtain the service access request and send the service access request to the server corresponding to the service provider, thereby realizing the cross-region service access operation.
[0129] For example 1, when user a in Zhangjiakou wants to access the service application "msg" in Hangzhou, user a can generate a service access request a through the client, where the IP address of the client can be Zhangjiakou: 192.168.0.0 / 16, and the obtained service access request a can be msg.isv1.alicompnest.com. The user can send the obtained service access request a to the user gateway Service GW in the first virtual internet network VPC through the client, and the IP address of the above-mentioned first virtual internet network VPC can be Zhangjiakou: 10.3.0.0 / 16.
[0130] After the user gateway Service GW obtains the service access request a, it can obtain the service directory corresponding to the service access request through the configuration unit, and then use the service directory to analyze and process the service access request a, so as to obtain the service access address and service gateway ISV GW corresponding to the service access request a, wherein the service access address can be implemented as an IP address, for example: the IP address can be 172.16.1.1, and the above-mentioned service gateway ISV GW can be located in the second virtual Internet network VPC, and the IP address of the second virtual Internet network VPC can be Hangzhou: 10.2.0.0 / 16.
[0131] After determining the service access address and service gateway ISV GW corresponding to the service access request a, the user gateway can send the obtained service access request a to the service gateway ISV GW. After the service gateway ISV GW obtains the service access request a, it can send the service access request a to the server corresponding to the corresponding service provider a based on the service access address, wherein the IP address of the server corresponding to the service provider a can be the service access address corresponding to the service access request a, thereby realizing cross-regional access and calling operations of the msg application service.
[0132] Example 2: When user b in Zhangjiakou wants to access the service application "weather" in Hangzhou, user b can generate a service access request b through the client, where the obtained service access request b can be weather.isv1.alicompnest.com. Similar to the access operation of the above service access request a, the service access request b can be sent to the server corresponding to the service provider through the user gateway and the service gateway in sequence, and the IP address of the server can be 172.16.1.2, thereby effectively realizing the access operation of cross-regional services. When user c in Zhangjiakou wants to access the service application "weather" in Hangzhou, user c can generate a service access request c through the client, where the obtained service access request c can be location.isv2.alicompnest.com. Similar to the access operation of the above service access request a, the service access request c can be sent to the server corresponding to the service provider through the user gateway and the service gateway in sequence, and the IP address of the server can be 172.16.0.0 / 16, thereby effectively realizing the access operation of cross-regional services.
[0133] It should be noted that in order to stably implement cross-region service publishing and access operations, traffic control operations can be performed on multiple nodes in the service access link. For user access points such as clients, traffic control can be performed based on the user access points of PrivateLink. For example, when the traffic range supported by the user access point is 100Mbps-3Gbps, the single user traffic passing through the user access point can be obtained. When the single user traffic exceeds 3Gbps, multiple user access points can be allocated. In addition, the communication connection between the terminal node and the private Internet network VPC is realized based on the private network link PrivateLink, which effectively ensures the elastic and high availability of the system.
[0134] For the servers corresponding to the service provider, traffic control operations can also be implemented. Specifically, for scenarios with extremely large traffic (more than tens of G) in a region, you can consider maintaining multiple service nodes and evenly distributing users to multiple service nodes to support large-traffic access operations.
[0135] For the user gateway, it can also be dynamically expanded according to the traffic information; the service gateway can include multiple instances for implementing service access and service publishing operations, and can dynamically expand multiple instances in the service gateway based on the total instance traffic of the service gateway. For example: the traffic corresponding to each instance is 1.5G, and the service traffic is estimated to be 6G. At this time, in order to ensure the quality and efficiency of service publishing and service access, at least 4 instances can be allocated to the service gateway, that is, the number of instances in the service gateway can be dynamically adjusted according to the real-time traffic of the service provider.
[0136] It should be noted that both the user gateway and the service gateway are configured in the cloud server in the virtual internet VPC. In order to ensure the quality and effect of service access operations and service publishing operations, the cloud servers in the virtual internet VPC can be dynamically scaled based on the traffic information passing through each cloud server, further improving the practicality of the system. In addition, as a key intermediate forwarding component, the user gateway can be designed with high elasticity and high availability based on k8s technology, and can perform rolling upgrades on the user gateway as required. As the entrance to service access, the service gateway can include multiple instances. Load balancing scheduling operations can be implemented within the virtual internet, and the number of instances in the service gateway can be dynamically scaled based on traffic information. In addition, in order to ensure the security and reliability of service access operations and service publishing operations, security control operations can be performed on the user gateway and the service gateway based on preset security components.
[0137] The technical solution provided by this application embodiment can realize efficient cross-regional access operations for services. For service providers, they can realize the publishing operation of services in the entire region by accessing any nearby region. Specifically, multiple virtual Internet VPC clusters in the entire region can be configured in the service publishing and service access system, and any two virtual Internet network VPCs included in the virtual Internet VPC cluster in the entire region are communicated and connected, and the IPv4 address and IPv6 address of each virtual Internet network VPC are communicated and connected. The IPv4 address and IPv6 address of the interconnected virtual Internet network VPC can be realized as the Internet network plane of the entire region. The user end can easily access the service publishing and service access system through a private network link, that is, it realizes point-to-point In addition, after accessing the virtual Internet, the user end does not need to build a point-to-point service connection for each private network service that needs to be accessed. Instead, the user end can access all services of the virtual Internet by creating an access point at one time and sharing the access point. Moreover, the user end does not need to subscribe to services separately and can directly access the services in the service catalog, thereby effectively simplifying the process of private network access and reducing the cost of service access. For service providers, service providers can publish multiple services through service access point access service publishing and service access system, so that users can access more cross-regional services. This effectively reduces the cost of service publishing and service access operations, which is conducive to market promotion and application.
[0138] Figure 8 A schematic diagram of a point-to-point cloud cross-region service access system provided in an embodiment of the present application; see Attachment Figure 8 As shown, this embodiment provides a point-to-point cloud cross-region service access system, which is used to perform the above Figure 2 The point-to-point access method for cross-region services on the cloud shown in the figure, specifically, the access system may include: a first virtual interconnection network component 11 and at least one second virtual interconnection network component 12 that are communicatively connected, wherein different second virtual interconnection network components 12 correspond to different regions, and the region and address segment corresponding to the first virtual interconnection network component 11 are different from the region and address segment corresponding to the second virtual interconnection network component 12; the first virtual interconnection network component 11 and the second virtual interconnection network component 12 both include:
[0139] The user gateway 100 is used to obtain an access request for a cross-regional service and multiple service gateways 200 that are communicatively connected to the user gateway 100; determine a cross-regional service gateway corresponding to the access request among the multiple service gateways 200; determine a service access address corresponding to the access request; and perform an access operation for the cross-regional service through the cross-regional service gateway and the service access address.
[0140] In some examples, the first virtual interconnect network component 11 and the second virtual interconnect network component 12 further include:
[0141] At least one service gateway 200 is used to obtain a service publishing request; based on the service publishing request, determine the configuration information corresponding to the service to be published, the configuration information at least includes: the IP address information and port information of the service; based on the configuration information, perform a service publishing operation in the virtual Internet corresponding to the service gateway to obtain the published service.
[0142] In some examples, the access system further includes: a configuration unit 13 in communication with the user gateway 100;
[0143] The configuration unit 13 is used to obtain the domain name information corresponding to the access request through the user gateway 100; determine a configuration information table for processing the domain name information, wherein the configuration information table includes: a mapping relationship between the domain name information and the service gateway 200, and send the configuration information table to the user gateway 100;
[0144] The user gateway 100 is used to determine the cross-region service gateway corresponding to the access request among the multiple service gateways 200 by using the configuration information table and the domain name information.
[0145] In some examples, the configuration unit 13 is further used to: obtain traffic information passing through the cross-region service gateway; and control the number of access instances in the cross-region service gateway based on the traffic information.
[0146] In some instances, when the configuration unit 13 controls the number of access instances in the cross-regional service gateway based on the traffic information, the configuration unit 13 is used to: obtain the current number of access instances in the cross-regional service gateway and the supportable traffic of a single access instance; determine the total supportable traffic of the cross-regional service gateway based on the current number and the supportable traffic; and control the number of access instances in the cross-regional service gateway based on the total supportable traffic and the traffic information.
[0147] In some instances, when the configuration unit 13 controls the number of access instances in the cross-regional service gateway based on the supportable total traffic and the traffic information, the configuration unit 13 is used to: when the supportable total traffic is greater than or equal to the traffic size corresponding to the traffic information, keep the number of access instances in the cross-regional service gateway unchanged; when the supportable total traffic is less than the traffic size corresponding to the traffic information, obtain the traffic difference between the traffic size and the supportable total traffic, and control the number of access instances in the cross-regional service gateway based on the traffic difference.
[0148] In some instances, when the configuration unit 13 controls the number of access instances in the cross-regional service gateway based on the traffic difference, the configuration unit 13 is used to: obtain the ratio between the traffic difference and the supportable traffic of a single access instance; based on the ratio, determine the quantity information for increasing the access instances in the cross-regional service gateway, so as to expand the access instances based on the quantity information.
[0149] Figure 8 The point-to-point access system for cross-region services on the cloud can be executed Figure 1-Figure 7 For the method of the embodiment shown in the figure, the part not described in detail in this embodiment can be referred to Figure 1-Figure 7 The implementation process and technical effects of this technical solution refer to Figure 1-Figure 7 The description in the illustrated embodiment will not be repeated here.
[0150] In one possible design, Figure 8 The structure of the point-to-point cloud cross-region service access system shown can be implemented as an electronic device. Fig. 9 As shown, the point-to-point cloud cross-region service access system in this embodiment can be implemented as an electronic device. Specifically, the electronic device may include: a first processor 31 and a first memory 32. The first memory 32 is used to store the corresponding electronic device to execute the above Figure 2 The program of the point-to-point cloud cross-region service access method provided in the illustrated embodiment, the first processor 31 is configured to execute the program stored in the first memory 32.
[0151] The program includes one or more computer instructions, wherein the one or more computer instructions can implement the following steps when executed by the first processor 31: obtaining an access request for a cross-regional service and a service access address corresponding to the access request through a user gateway, wherein the user gateway is communicatively connected to multiple service gateways, the user gateway is located in a first virtual Internet network, the multiple service gateways are located in different second virtual Internet networks, the first virtual Internet network is communicatively connected to the second virtual Internet network, and the area and address segment corresponding to the first virtual Internet network are different from the area and address segment corresponding to the second virtual private network; among the multiple service gateways, determining the cross-regional service gateway corresponding to the access request; and performing cross-regional service access operations through the cross-regional service gateway and the service access address.
[0152] Furthermore, the first processor 31 is also used to execute the aforementioned Figure 2 All or part of the steps in the illustrated embodiment. The structure of the electronic device may further include a first communication interface 33, which is used for the electronic device to communicate with other devices or a communication network.
[0153] In addition, an embodiment of the present invention provides a computer storage medium for storing computer software instructions used by electronic devices, which includes instructions for executing the above Figure 2 The procedures involved in the point-to-point method for accessing cross-region services on the cloud in the method embodiment shown.
[0154] In addition, an embodiment of the present invention provides a computer program product, including: a computer program, when the computer program is executed by a processor of an electronic device, the processor executes Figure 2 The method for accessing cross-region services on the cloud point-to-point in the method embodiment shown.
[0155] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0156] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, i.e., they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Those of ordinary skill in the art may understand and implement it without creative effort.
[0157] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by adding a necessary general hardware platform, and of course can also be implemented by combining hardware and software. Based on such an understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a computer product, and the present application can be in the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0158] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable device to generate a machine, so that the instructions executed by the processor of the computer or other programmable device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0159] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable device to work in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 These computer program instructions can also be loaded onto a computer or other programmable device so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide the functions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0160] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory. The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0161] Computer readable media include permanent and non-permanent, removable and non-removable media that can be used to store data by any method or technology. Data can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store data that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0162] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A point-to-point method for accessing cross-region services on the cloud. It is characterized in that include: Obtaining, through a user gateway, an access request for a cross-region service and a service access address corresponding to the access request, wherein the user gateway is communicatively connected to a plurality of service gateways, the user gateway is located in a first virtual internet network, the plurality of service gateways are located in different second virtual internet networks, the first virtual internet network is communicatively connected to the second virtual internet network, and the region and address segment corresponding to the first virtual internet network are different from the region and address segment corresponding to the second virtual private network; Determine, among the multiple service gateways, a cross-region service gateway corresponding to the access request; The cross-region service access operation is performed through the cross-region service gateway and the service access address.
2. The method according to claim 1, It is characterized in that Determining, among the multiple service gateways, a cross-region service gateway corresponding to the access request includes: Obtaining domain name information corresponding to the access request; Determine a configuration information table for processing the domain name information, wherein the configuration information table includes a mapping relationship between the domain name information and the service gateway; Based on the domain name information and the configuration information table, a cross-region service gateway corresponding to the access request is determined among the multiple service gateways.
3. The method according to claim 1, It is characterized in that Before obtaining the access request for the cross-region service through the user gateway, the method further includes: Get the configuration request of the service gateway; Based on the configuration request, determine the service gateway configuration information, the service gateway configuration information at least including: a network identifier of a service provider's private network, security group information for identifying service access rules, and a virtual switch for implementing information interaction; A gateway configuration operation is performed based on the service gateway configuration information to obtain a service gateway located in the virtual internet network.
4. The method according to claim 3, It is characterized in that After obtaining the service gateway located in the virtual internetwork, the method further includes: Obtaining a service publishing request through the service gateway; Based on the service publishing request, determine the configuration information corresponding to the service to be published, the configuration information at least including: the IP address and port information of the service to be published; Based on the configuration information, a service publishing operation is performed in the virtual Internet corresponding to the service gateway to obtain a published service.
5. The method according to claim 4, It is characterized in that After obtaining the published service, the method further includes: Acquire the service access attribute of the published service through the service gateway, wherein the service access attribute at least includes: domain name information, service access address and service port; The service gateway and the service access attribute are associated and stored, and a configuration information table for analyzing and processing the domain name information is generated.
6. The method according to claim 1, It is characterized in that Before obtaining the access request for the cross-region service through the user gateway, the method further includes: Get the configuration request of the user gateway; Based on the configuration request, determine the user gateway configuration information corresponding to the user private network, the user gateway configuration information at least including: service domain name information, service access address, port information; A gateway configuration operation is performed based on the user gateway configuration information to obtain a user gateway located in the virtual internet network.
7. The method according to any one of claims 1 to 6, It is characterized in that The access operation of the cross-region service is performed through the cross-region service gateway and the service access address, including: Acquire multiple candidate access instances in the cross-region service gateway; Determine at least one target access instance corresponding to the access request among a plurality of candidate access instances; An access operation of a cross-region service is performed based on the at least one target access instance and the service access address.
8. The method according to claim 7, It is characterized in that The method further comprises: Obtaining traffic information passing through the cross-region service gateway; The number of access instances in the cross-region service gateway is controlled based on the traffic information.
9. The method according to claim 8, It is characterized in that Controlling the number of access instances in the cross-region service gateway based on the traffic information includes: Obtaining the current number of access instances in the cross-region service gateway and the supportable traffic of a single access instance; Based on the current number and the supportable traffic, determine the total supportable traffic of the cross-region service gateway; The number of access instances in the cross-region service gateway is controlled based on the total supportable traffic and the traffic information.
10. The method according to claim 9, It is characterized in that Controlling the number of access instances in the cross-region service gateway based on the total supportable traffic and the traffic information includes: When the total supported traffic is greater than or equal to the traffic size corresponding to the traffic information, the number of access instances in the cross-region service gateway is kept unchanged; When the total supportable traffic is less than the traffic size corresponding to the traffic information, the traffic difference between the traffic size and the total supportable traffic is obtained, and the number of access instances in the cross-region service gateway is controlled based on the traffic difference.
11. The method according to claim 10, It is characterized in that Controlling the number of access instances in the cross-region service gateway based on the traffic difference includes: Obtaining a ratio between the flow difference and the supportable flow of a single access instance; Based on the ratio, quantity information for increasing the access instance in the cross-region service gateway is determined, so as to perform a capacity expansion operation on the access instance based on the quantity information.
12. The method according to any one of claims 1 to 6, It is characterized in that The method further comprises: Acquire traffic information passing through a cloud server in a virtual internet network, wherein a service gateway in the second virtual internet network is deployed on the cloud server; The number of the cloud servers is controlled based on the traffic information.
13. A point-to-point cloud cross-region service access system, It is characterized in that include: A first virtual interconnect network component and at least one second virtual interconnect network component that are communicatively connected, wherein the area and address segment corresponding to the first virtual interconnect network component are different from the area and address segment corresponding to the second virtual interconnect network component; the first virtual interconnect network component and the second virtual interconnect network component both include: A user gateway is used to obtain an access request for a cross-regional service and multiple service gateways that are communicatively connected to the user gateway; among the multiple service gateways, determine a cross-regional service gateway corresponding to the access request; determine a service access address corresponding to the access request; and perform a cross-regional service access operation through the cross-regional service gateway and the service access address.
14. The system according to claim 13, It is characterized in that The first virtual interconnect network component and the second virtual interconnect network component further include: At least one service gateway is used to obtain a service publishing request; based on the service publishing request, determine the configuration information corresponding to the service to be published, the configuration information at least includes: the IP address information and port information of the service; based on the configuration information, perform a service publishing operation in the virtual Internet corresponding to the service gateway to obtain the published service.
15. The system according to claim 13, It is characterized in that The access system further comprises: a configuration unit communicatively connected to the user gateway; The configuration unit is used to obtain the domain name information corresponding to the access request through the user gateway; determine a configuration information table for processing the domain name information, wherein the configuration information table includes: a mapping relationship between the domain name information and the service gateway, and send the configuration information table to the user gateway; The user gateway is used to determine the cross-region service gateway corresponding to the access request among the multiple service gateways by using the configuration information table and the domain name information.
16. An electronic device, It is characterized in that include: A memory, a processor; wherein the memory is used to store one or more computer instructions, wherein the one or more computer instructions, when executed by the processor, implement the method as described in any one of claims 1-12.