Container network optimization method and system, electronic equipment and storage medium

By binding the container to the container bridge network and running UPNP proxy services in the container bridge network, the problem of insufficient multi-tasking capabilities of equipment in the prior art is solved, and the function of running multiple business programs for a single device is realized, which improves resource utilization and network penetration capabilities.

CN120200911AActive Publication Date: 2025-06-24BEIJING XIAOHAI GEEK CLOUD NETWORK TECHNOLOGY CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510183150.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-06-24
Estimated Expiration
2045-02-19

AI Technical Summary

Technical Problem

In the operation of multi-service processes, the container network mode limits the multi-tasking capability of the device, resulting in increased network penetration difficulty and low hardware and bandwidth resource utilization.

Method used

By binding each container to the container bridge network and running UPNP proxy services in the container bridge network, the gateway device's verification of UPNP service requests and the target NAT type are realized, thereby allowing multiple business programs to run on a single device.

Benefits of technology

Without affecting the target NAT type, the ability of a single device to run multiple business programs is improved, the utilization rate of hardware and bandwidth resources is improved, and the difficulty of network penetration is reduced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200911A_ABST
    Figure CN120200911A_ABST
Patent Text Reader

Abstract

The invention discloses a container network optimization method and system, electronic equipment and a storage medium, and relates to the technical field of container network optimization, and the method comprises the steps: binding each container with a container bridge network; when the target container initiates the UPNP service request, the UPNP proxy service is operated in the container bridge network, so that the gateway equipment verifies the UPNP service request, if the verification is successful, the target container uses the target NAT type provided by the container bridge network and accesses a server corresponding to the UPNP service request through the gateway equipment, and the target container is any one container. According to the method and the device, under the condition that the target NAT type is not influenced, the function that a single device, namely a server, runs a plurality of service programs is realized, the utilization rate of hardware resources and bandwidth resources is improved, and the single device obtains more service benefits.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] Currently, each device runs only one service process, or when a device runs multiple service processes, since most service programs have some ports using fixed ports, only one service process can be run through host installation or container host mode. If you run it in container bridge mode, you can run multiple service programs, but the bridge mode will have an extra layer of container network NAT forwarding, making the network more difficult to penetrate. Summary of the invention

[0003] The technical problem to be solved by the present invention is to address the deficiencies of the prior art and specifically provide a method, system, electronic device and storage medium for optimizing a container network, as follows:

[0004] 1) In the first aspect, the present invention provides a method for optimizing a container network, and the specific technical solution is as follows:

[0005] Bind each container to the container bridge network;

[0006] When the target container initiates a UPNP service request, the UPNP proxy service is run in the container bridge network so that the gateway device verifies the UPNP service request. If the verification is successful, the target container uses the target NAT type provided by the container bridge network and accesses the server corresponding to the UPNP service request through the gateway device, where the target container is any container.

[0007] The beneficial effects of the container network optimization method provided by the present invention are as follows:

[0008] Without affecting the target NAT type, the target container uses the target NAT type provided by the container bridge network, and accesses the server corresponding to the UPNP service request through the gateway device, thereby realizing the function of a single device (i.e., server) running multiple business programs (specifically, when the target container sends a business processing request to the server, the server runs the business program to solve the business processing request of the target container), thereby improving the utilization rate of hardware resources and bandwidth resources, and enabling a single device to obtain more business benefits.

[0009] Based on the above solution, the container network optimization method of the present invention can also be improved as follows.

[0010] Furthermore, it also includes:

[0011] When the target container accesses the server corresponding to the UPNP service request, the server associated with the server corresponding to the UPNP service request accesses the target container through the exposed port of the gateway device.

[0012] The beneficial effects of adopting the above further solution are as follows: it can effectively reduce the network penetration difficulty between the target container and the servers associated with the server corresponding to the UPNP service request, and improve the service processing efficiency.

[0013] Furthermore, each container is created through an edge computing device.

[0014] Furthermore, the target NAT type is: full cone NAT, restricted cone NAT, port-restricted cone NAT or symmetric NAT.

[0015] 2) In the second aspect, the present invention also provides a system for optimizing container networks, and the specific technical solution is as follows:

[0016] It includes a binding module and an access module;

[0017] The binding module is used to: bind each container to the container bridge network;

[0018] The access module is used to: when the target container initiates a UPNP service request, run a UPNP proxy service in the container bridge network to enable the gateway device to verify the UPNP service request. If the verification is successful, the target container uses the target NAT type provided by the container bridge network and accesses the server corresponding to the UPNP service request through the gateway device, where the target container is any container.

[0019] Based on the above solution, the system for optimizing container networks of the present invention can also be improved as follows.

[0020] Furthermore, the access module is also used to:

[0021] After the target container accesses the server corresponding to the UPNP service request, enable the servers associated with the server corresponding to the UPNP service request to access the target container through the exposed port of the gateway device.

[0022] Furthermore, each container is created through an edge computing device.

[0023] Furthermore, the target NAT type is: full cone NAT, restricted cone NAT, port-restricted cone NAT or symmetric NAT.

[0024] 3) In the third aspect, the present invention also provides an electronic device. The electronic device includes a processor, the processor is coupled to a memory, and at least one computer program is stored in the memory. The at least one computer program is loaded and executed by the processor so that the electronic device implements any one of the above methods for optimizing container networks.

[0025] 4) Fourth aspect, the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the method for optimizing a container network as described in any one of the above is implemented.

[0026] It should be noted that for the technical solutions of the second to fourth aspects of the present invention and the corresponding possible implementation manners, the beneficial effects obtained can refer to the technical effects of the first aspect and its corresponding possible implementation manners described above, and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention:

[0028] Figure 1 It is a schematic flowchart of a method for optimizing a container network according to an embodiment of the present invention;

[0029] Figure 2 It is a schematic flowchart of a method for optimizing a container network according to an embodiment of the present invention;

[0030] Figure 3 It is a schematic structural diagram of a system for optimizing a container network according to an embodiment of the present invention;

[0031] Figure 4 It is a schematic structural diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0032] The principles and features of the present invention are described below, and the examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.

[0033] The technical solutions of the present invention and how the technical solutions of the present invention solve the above technical problems are described in detail below with specific embodiments. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present invention will be described below with reference to the drawings.

[0034] As Figure 1 shown, a method for optimizing a container network according to an embodiment of the present invention includes the following steps:

[0035] S1. Bind each container to the container bridge network;

[0036] Among them, the container bridge network is a virtual network inside a single host (the edge computing device in the present invention).

[0037] Among them, each container is created through an edge computing device.

[0038] Among them, the container can specifically be: a container for business processing, a container for online games, a container for video conferencing, a container for data requests, a container for communication requests, or a container for permission granting, which can be set according to actual situations.

[0039] Among them, the process of constructing a container is as follows:

[0040] ① Download and install a container (such as Docker, Lxc, etc.) engine on the edge computing device, and configure the daemon process of the container (such as Docker, Lxc, etc.) engine.

[0041] ② According to the requirements of business processing, online games, video conferencing, data requests, communication requests, permission granting, etc., select an adapted image from Docker Hub or other container image repositories.

[0042] ③ Use container creation (such as Docker run, Lxc create, etc.) commands to create a container, and specify configurations such as the name of the container, the running command, port mapping, environment variables, etc., and allocate necessary resources such as CPU, memory, disk space, etc. for each container.

[0043] Optionally, use a data volume (Volume) or a bind mount (Bind Mount) to persistently store container data.

[0044] Among them, the process of binding a container to a container bridge network is as follows:

[0045] Create a virtual bridge on the edge computing device, and by default, assign an IP address to this virtual bridge. When the edge computing device creates a container, assign a virtual network interface to each container, and assign a unique IP address inside each container. One end of this virtual network interface is connected to the network namespace of the container, and the other end is connected to the virtual bridge, realizing the binding between the container and the container bridge network.

[0046] Optionally, it further includes: different containers communicate through the virtual bridge, and use the IP forwarding mechanism to forward data packets from one container to another container.

[0047] Optionally, the container can access the external network (the server corresponding to the UPNP service request in the present invention and the servers associated with the server corresponding to the UPNP service request). Specifically, the network address translation (NAT) technology can be used to map the private IP address of the container to a public IP address to realize the communication between the container and the external network.

[0048] S2. After the target container initiates a UPNP service request, run a UPNP proxy service in the container bridge network to enable the gateway device to verify the UPNP service request. If the verification is successful, the target container uses the target NAT type provided by the container bridge network and accesses the server corresponding to the UPNP service request through the gateway device, where the target container is any container.

[0049] Among them, the UPNP service refers to the Universal Plug and Play service, which is a collection of network protocols designed to automatically discover, configure, and connect containers, gateway devices, the server corresponding to the UPNP service request, and the servers associated with the server corresponding to the UPNP service request in the container bridge network. Specifically, the UPNP service supports dynamic port mapping and allows applications that access internal network resources from outside the Internet (such as online games, video conferencing, or business processing, etc.).

[0050] Among them, the UPNP service request can specifically be a UPNP service request for business processing, a UPNP service request for online games, a UPNP service request for video conferencing, a UPNP service request for data requests, a UPNP service request for communication requests, or a UPNP service request for permission granting, which can be set according to the actual situation.

[0051] After the target container initiates a UPNP service request, the UPNP proxy service running in the container bridge network will detect the UPNP service request and construct a UPNP mapping request based on the information in the UPNP service request and send it to the gateway device. The information in the UPNP service request includes: the authentication information of the target container, the business processing information associated with the UPNP service request, data request information, communication request information, etc. The gateway device verifies the legitimacy of the source of the UPNP service request based on the authentication information of the target container contained in the UPNP mapping request and the business processing information, data request information, communication request information, etc. associated with the UPNP service request. If the verification passes, the target container uses the target NAT type provided by the container bridge network and accesses the server corresponding to the UPNP service request through the gateway device.

[0052] Among them, the UPNP proxy service constructs a UPNP mapping request based on the information in the UPNP service request. The specific implementation process is as follows:

[0053] The UPNP proxy service detects gateway devices by sending broadcast messages. When a gateway device is detected, the gateway device will return information (response message) to the UPNP proxy service. The UPNP proxy service obtains the IP address of the gateway device and the data format of the UPNP service, etc. according to the response message returned by the gateway device. The UPNP proxy service converts the information in the UPNP service request according to the data format of the UPNP service in the response message to obtain a UPNP mapping request that can be recognized by the gateway device.

[0054] Among them, the target NAT type is: full cone NAT, restricted cone NAT, port restricted cone NAT or symmetric NAT.

[0055] Among them, enabling the target container to utilize the target NAT type provided by the container bridge network and access the server corresponding to the UPNP service request through the gateway device, the specific implementation process is as follows:

[0056] Load the kernel module of the target NAT type, modify the NAT rules in the container bridge network to the NAT rules of the target NAT type according to the target NAT type. The target container accesses the gateway device through the kernel module of the target NAT type, and then accesses the server corresponding to the UPNP service request through the gateway device.

[0057] Among them, the kernel module of the target NAT type mainly refers to the module that implements the NAT function of the target NAT type in the kernel (such as the Linux kernel). The kernel module allows the host to communicate with the external network in the private network without a public IP address. When the target container transmits the data packet sent by the gateway device, the kernel module of the target NAT type will perform address conversion on the data packet according to the defined NAT rules.

[0058] Among them, the NAT rules are a set of instructions configured on the gateway device to guide the device on how to perform address conversion on the passing data packets. These rules work based on information such as the source address, destination address, source port and destination port of the data packet, as well as the predefined conversion logic.

[0059] Optionally, in the above technical solution, it further includes:

[0060] S3. After the target container accesses the server corresponding to the UPNP service request, enable the server associated with the server corresponding to the UPNP service request to access the target container through the exposed port of the gateway device.

[0061] Among them, the exposed ports of the gateway device refer to the ports on the gateway device that can be accessed by the external network (in the present invention, in the gateway device, the ports that interact with the target container). The exposed ports are usually used to provide access entrances for specific network services or applications.

[0062] Among them, the server associated with the server corresponding to the UPNP service request refers to the server that has information interaction with the server corresponding to the UPNP service request and passes the security verification.

[0063] As Figure 2 shown, through another embodiment, the present invention is described, which specifically includes the following steps:

[0064] S101. The edge computing device creates multiple N containers and binds them to the container bridge network, where the N containers are respectively denoted as: Container 1 to Container N.

[0065] S102. Run the UPNP proxy service in the container bridge network. Specifically:

[0066] ① The UPNP proxy service detects the gateway device by sending a broadcast message. When the gateway device is detected, the gateway device will return information (response message) to the UPNP proxy service. The UPNP proxy service obtains the IP address of the gateway device and the data format of the UPNP service, etc. according to the response message returned by the gateway device.

[0067] ② The UPNP proxy service converts the information in the UPNP service request according to the data format of the UPNP service in the response message to obtain a UPNP mapping request that can be recognized by the gateway device.

[0068] ③ The gateway device verifies the legitimacy of the source of the UPNP service request according to the authentication information of the target container, the service processing information, data request information or communication request information, etc. associated with the UPNP service request included in the UPNP mapping request. If the verification is successful (passed), the next step is executed. If the verification fails (not passed), the subsequent steps are stopped.

[0069] ④ Load the kernel module of the target NAT type, and modify the NAT rules in the container bridge network to the NAT rules of the target NAT type. The target container accesses the gateway device through the kernel module of the target NAT type, and then accesses the server (the first server) corresponding to the UPNP service request through the gateway device.

[0070] ⑤ After the target container accesses the server corresponding to the UPNP service request, the server associated with the server corresponding to the UPNP service request (the second server) accesses the target container through the exposed port of the gateway device, specifically through the UPNP proxy service or the kernel module of the target NAT type.

[0071] In the above embodiments, although the steps are numbered S1, S2, etc., they are only specific embodiments given by the present invention. Those skilled in the art can adjust the execution order of S1, S2, etc. according to the actual situation, which is also within the protection scope of the present invention. It can be understood that in some embodiments, it may include some or all of the above embodiments.

[0072] As Figure 3 shown, a container network optimization system 200 according to an embodiment of the present invention includes a binding module 201 and an access module 202;

[0073] The binding module 201 is configured to: bind each container to the container bridge network;

[0074] The access module 202 is configured to: when the target container initiates a UPNP service request, run the UPNP proxy service in the container bridge network to enable the gateway device to verify the UPNP service request. If the verification is successful, the target container uses the target NAT type provided by the container bridge network and accesses the server corresponding to the UPNP service request through the gateway device, where the target container is any container.

[0075] Optionally, in the above technical solution, the access module 202 is further configured to:

[0076] After the target container accesses the server corresponding to the UPNP service request, the server associated with the server corresponding to the UPNP service request accesses the target container through the exposed port of the gateway device.

[0077] Optionally, in the above technical solution, each container is created through an edge computing device.

[0078] Optionally, in the above technical solution, the target NAT type is: full cone NAT, restricted cone NAT, port restricted cone NAT or symmetric NAT.

[0079] It should be noted that the beneficial effects of the system 200 for optimizing container networks provided in the above embodiments are the same as those of the method for optimizing container networks described above, and will not be elaborated here. In addition, when the system provided in the above embodiments realizes its functions, only the division of the above function modules is used for illustration. In practical applications, the above functions can be allocated to different function modules according to needs, that is, the system can be divided into different function modules according to the actual situation to complete all or part of the functions described above. In addition, the system and method embodiments provided in the above embodiments belong to the same concept. For the specific implementation process, please refer to the method embodiments and will not be elaborated here.

[0080] Among them, the system for optimizing container networks of the present invention can be a computer program (including program code) running in a computer device. For example, the system for optimizing container networks of the present invention is an application software and can be used to execute the corresponding steps in the method for optimizing container networks of the present invention.

[0081] In some embodiments, the system for optimizing container networks of the present invention can be implemented in a combination of software and hardware. As an example, the system for optimizing container networks of the present invention can be a processor in the form of a hardware decoding processor, which is programmed to execute the method for optimizing container networks of the present invention. For example, a processor in the form of a hardware decoding processor can adopt one or more application specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field programmable gate arrays (FPGAs) or other electronic components.

[0082] Among them, the modules described in the embodiments of the present invention can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the module itself in some cases.

[0083] An electronic device according to an embodiment of the present invention includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements any one of the above methods for optimizing container networks. That is to say, an electronic device according to an embodiment of the present invention may include, but is not limited to: a processor and a memory; the memory is used to store a computer program; the processor is used to execute the method for optimizing container networks shown in any embodiment of the present invention by calling the computer program.

[0084] In an alternative embodiment, an electronic device is provided, such as Figure 4 as shown, Figure 4 the electronic device 4000 shown in Figure 4 includes: a processor 4001 and a memory 4003. Among them, the processor 4001 and the memory 4003 are connected, such as being connected through a bus 4002. Optionally, the electronic device 4000 may further include a transceiver 4004, and the transceiver 4004 can be used for data interaction between this electronic device and other electronic devices, such as data transmission and / or data reception, etc. It should be noted that in practical applications, the transceiver 4004 is not limited to one, and the structure of the electronic device 4000 does not constitute a limitation to the embodiments of the present invention.

[0085] The processor 4001 can be a CPU (Central Processing Unit, central processor), a general-purpose processor, a DSP (Digital Signal Processor, data signal processor), an ASIC (Application Specific Integrated Circuit, application-specific integrated circuit), an FPGA (Field Programmable Gate Array, field programmable gate array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in connection with the disclosure of the present invention. The processor 4001 can also be a combination that realizes computing functions, such as a combination including one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0086] The bus 4002 may include a path for transmitting information between the above components. The bus 4002 can be a PCI (Peripheral Component Interconnect, peripheral component interconnect standard) bus or an EISA (Extended Industry Standard Architecture, extended industry standard architecture) bus, etc. The bus 4002 can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 4 only a thick line is used to represent the bus 4002 in Figure 4 , but it does not mean that there is only one bus or one type of bus.

[0087] The memory 4003 can be a ROM (Read Only Memory), or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory), or other types of dynamic storage devices that can store information and instructions. It can also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0088] The memory 4003 is used to store the application program code (computer program) for executing the solution of the present invention and is controlled by the processor 4001 for execution. The processor 4001 is used to execute the application program code stored in the memory 4003 to implement the content shown in the foregoing method embodiments.

[0089] Among them, the electronic device can also be a terminal device, and the terminal device can be any device on which an application can be installed, including at least one of a smart phone, a tablet computer, a notebook computer, a desktop computer, a smart speaker, a smart watch, a smart TV, and a smart vehicle device.

[0090] It should be noted that Figure 4 The electronic device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present invention.

[0091] A computer-readable storage medium according to an embodiment of the present invention has a computer program stored thereon, and when the computer program is executed by a processor, it implements the method for optimizing any one of the above container networks.

[0092] Optionally, the computer-readable storage medium can be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), magnetic tape, floppy disk, and optical data storage device, etc.

[0093] In an exemplary embodiment, a computer program product or a computer program is further provided. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes any one of the above methods for optimizing container networks.

[0094] Computer program code for performing the operations of the present invention may be written in one or more programming languages or combinations thereof. The above programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0095] It should be understood that the flowcharts and block diagrams in the drawings illustrate the possible architectures, functions, and operations of the methods and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0096] The computer-readable storage medium provided by the embodiments of the present invention may be, but is not limited to, a system, device or component of electricity, magnetism, light, electromagnetic, infrared ray, or semiconductor, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EEPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, device or component.

[0097] The above computer-readable storage medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device is caused to execute the method shown in the above embodiments.

[0098] The above description is only a preferred embodiment of the present invention and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present invention is not limited to the technical solution formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, a technical solution formed by mutually replacing the above features with (but not limited to) technical features having similar functions disclosed in the present invention.

[0099] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application are used to distinguish similar objects, and represent a limitation on a specific order or sequence. In appropriate cases, the use order of similar objects may be interchanged so that the embodiments of the present application described herein can be implemented in an order other than the illustrated or described order.

[0100] Those skilled in the art know that the present invention can be implemented as a system, method or computer program product. Therefore, the present invention can be specifically implemented in the following forms, that is: it can be completely hardware, can also be completely software (including firmware, resident software, microcode, etc.), and can also be a form of combination of hardware and software, which is generally referred to as "circuit", "module" or "system" in this article. In addition, in some embodiments, the present invention can also be implemented in the form of a computer program product in one or more computer-readable media, and the computer-readable media contains computer-readable program code.

[0101] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.

Claims

1. A method for optimizing a container network, characterized in that: include: Bind each container to the container bridge network; When the target container initiates a UPNP service request, a UPNP proxy service is run in the container bridge network so that the gateway device verifies the UPNP service request. If the verification is successful, the target container uses the target NAT type provided by the container bridge network and accesses the server corresponding to the UPNP service request through the gateway device, wherein the target container is any container.

2. A method for optimizing a container network according to claim 1, characterized in that: Also includes: After the target container accesses the server corresponding to the UPNP service request, the server associated with the server corresponding to the UPNP service request accesses the target container through the exposed port of the gateway device.

3. A method for optimizing a container network according to claim 1 or 2, characterized in that: Each container is created by an edge computing device.

4. A method for optimizing a container network according to claim 1 or 2, characterized in that: The target NAT type is: full cone NAT, restricted cone NAT, port restricted cone NAT or symmetric NAT.

5. A system for optimizing container networks, characterized in that: Includes binding module and access module; The binding module is used to: bind each container to the container bridge network; The access module is used to: when the target container initiates a UPNP service request, run the UPNP proxy service in the container bridge network so that the gateway device verifies the UPNP service request. If the verification is successful, the target container uses the target NAT type provided by the container bridge network and accesses the server corresponding to the UPNP service request through the gateway device, wherein the target container is any container.

6. A container network optimization system according to claim 5, characterized in that: The access module is also used for: After the target container accesses the server corresponding to the UPNP service request, the server associated with the server corresponding to the UPNP service request accesses the target container through the exposed port of the gateway device.

7. A container network optimization system according to claim 5 or 6, characterized in that: Each container is created by an edge computing device.

8. A container network optimization system according to claim 5 or 6, characterized in that: The target NAT type is: full cone NAT, restricted cone NAT, port restricted cone NAT or symmetric NAT.

9. An electronic device, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, a method for optimizing a container network as described in any one of claims 1 to 4 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for optimizing a container network according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Cross-router terminal communication method and device

    CN111800341A

  • Container public network bandwidth limiting method based on selectable field of IP protocol

    CN113067719A

  • Application task implementation method, system and device based on edge computing

    CN114039977A

  • Method and device for realizing ETCD double-node high availability based on VRRP (Virtual Router Redundancy Protocol)

    CN114390052A

  • Method and device for providing automatic port mapping service, cloud gateway equipment and medium

    CN115987937A