Message processing method and related equipment thereof
By using the modified protocol stack to embed and parse message headers in the cloud service system, the problem that the server cannot distinguish multiple VPC messages is solved, resource saving and efficient VPC perception are achieved, and large-scale VPC applications are supported.
Patent Information
- Application Number
- CN202410126248.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-22
- Filing Date
- 2024-01-29
- Publication Date
- 2025-06-24
AI Technical Summary
In the existing cloud service system, the server cannot distinguish packets from different virtual private clouds in multiple VPC scenarios, resulting in excessive resource overhead and insufficient scalability, and the existing packet processing architecture affects performance.
Using the modified protocol stack, by embedding and parsing message headers between cloud instances, the server application realizes the VPC information perception, and no additional port is required. The VXLAN header is used to indicate cloud instance information and perform message processing.
Save server resource overhead, improve application capabilities and scalability in multi-VPC scenarios, maintain packet processing efficiency, and support large-scale VPCs.
Smart Images

Figure CN120201025A_ABST
Abstract
Description
[0001] This application claims the priority of a Chinese patent application with the application number 202311785299.1 and the invention title "A Message Processing Method and a Message Processing System" submitted to the National Intellectual Property Administration on December 22, 2023, the entire content of which is incorporated herein by reference. Technical Field
[0002] Embodiments of this application relate to the field of cloud technology, and in particular, to a message processing method and related devices thereof. Background Art
[0003] With the continuous development of cloud technology, tenants have higher and higher requirements for the network security of cloud service systems. Virtual Private Cloud (VPC) technology can build exclusive independent networks for each tenant on the public network resources of cloud service systems, which can ensure a certain degree of privacy for tenants.
[0004] In related cloud service systems, when the server receives a message sent by a client in a certain VPC, the protocol stack of the server usually first unpacks the message to obtain the message header and the inner message of the message. Then, the protocol stack discards the message header and sends the inner message to the application processing of the server. Since the message header has been discarded, when the application processes the inner message, it cannot perceive the information of the VPC to which the client belongs, which will cause the server to be unable to distinguish messages from multiple VPCs in the scenario of multiple VPCs, thus limiting the service capabilities of the server in this scenario.
[0005] Based on this, multiple ports corresponding to multiple VPCs can be opened on the server. Therefore, the application on the server can distinguish messages from different VPCs based on the messages received by different ports. However, since the number of VPCs is often large, a large number of ports need to be created on the server, resulting in excessive software and hardware overhead. Summary of the Invention
[0006] Embodiments of this application provide a message processing method and related devices thereof. The server is provided with a modified protocol stack. Without adding additional ports, the application on the server can perceive multiple VPCs only with the existing ports, so as to distinguish messages sent by clients in different VPCs, which can save resource overhead on the server side.
[0007] The first aspect of the embodiments of this application provides a message processing method, which is applied to a cloud service system. The cloud service system includes a first cloud instance and a second cloud instance. The first cloud instance includes a first application, a first socket layer, and a first protocol stack. The method includes:
[0008] When the first cloud instance needs to communicate with the second cloud instance, the first application of the first cloud instance can generate a first packet header and a first inner packet, and embed the first packet header into the first inner packet to obtain first data. Then, the first application can call the first socket layer of the first cloud instance through the corresponding interface to send the first data to the first protocol stack of the first cloud instance through the first socket layer. Then, the first protocol stack can parse the first data to obtain the first packet header and the first inner packet. Then, the first protocol stack can encapsulate the first inner packet with the first packet header to obtain a first packet. Subsequently, the first protocol stack can send the first packet to the second cloud instance.
[0009] After obtaining the first packet, the second protocol stack of the second cloud instance can de-encapsulate the first packet to obtain the first packet header and the first inner packet. Then, the second protocol stack can embed the first packet header into the first inner packet to obtain first data. Then, the second protocol stack can store the first data in the second socket layer of the second cloud instance, so the second application of the second cloud instance can call the second socket layer through the corresponding interface to obtain the first data from the second socket layer. Subsequently, after obtaining the first data, the second application can parse the first data to obtain the first packet header and the first inner packet, and process the first inner packet.
[0010] It can be seen from the above method that: since both the first cloud instance and the second cloud instance are provided with modified protocol stacks, namely the first protocol stack and the second protocol stack, due to the existence of these two protocol stacks, the first inner packet generated by the first application is accompanied by the first packet header during the process of passing through the first application, the first protocol stack, the second protocol stack, and the second application in sequence. Therefore, the second application can obtain both the first packet header and the first inner packet at the same time. Since the first packet header can not only be used to indicate the communication channel with the first cloud instance as the source end and the second cloud instance as the destination end, but also be used to indicate the first cloud instance itself, the second application can determine the relevant information of the first cloud instance from which the first inner packet comes based on the first packet header. For example, when the first cloud instance is a client and the second cloud instance is a server, the second application can perceive the VPC where the first cloud instance is located. Thus, it can be seen that this embodiment proposes a new packet processing architecture. Since the server is provided with a modified protocol stack, the server does not need to add additional ports. With only the existing ports, the application on the server can also obtain information related to multiple VPCs to perceive these multiple VPCs, so as to distinguish the packets sent by clients in different VPCs. This can save the resource overhead on the server side and is beneficial to the application of the server in the multi-VPC scenario.
[0011] In a possible implementation, the method further includes: the first protocol stack receives a second message from the second cloud instance; the first protocol stack de-encapsulates the second message to obtain a second message header and a second inner message, and embeds the second message header into the second inner message to obtain second data. The second inner message is obtained by the second cloud instance processing the first inner message, and the second message header is obtained by the second cloud instance processing the first message header; the first protocol stack sends the second data to the first application, so that the first application obtains and processes the second inner message from the second data. In the foregoing process, after obtaining the second message, the first protocol stack can de-encapsulate the second message to obtain the second message header and the second inner message. Then, the first protocol stack can embed the second message header into the second inner message to obtain the second data. Then, the first protocol stack can store the second data in the first socket layer, so the first application can call the first socket layer through a corresponding interface to obtain the second data from the first socket layer. Subsequently, after obtaining the second data, the first application can parse the first data to obtain the second message header and the second inner message, and process the second inner message. Since the first message is a request message and the second message is a response message of the first message, in this way, a communication is completed between the first cloud instance and the second cloud instance.
[0012] In a possible implementation, there are a first Ethernet header (which can also be referred to as a first media access control (MAC) header), a first Internet Protocol (IP) header, a first user datagram protocol (UDP) header, and a first virtual extensible local area network (VXLAN) header. In the foregoing implementation, the first MAC header, the first IP header, and the first UDP header in the first message header may contain information such as the network address of the first cloud instance as the source end and the network address of the second cloud instance as the destination end. Therefore, the first MAC header, the first IP header, and the first UDP header can be used to indicate a communication channel with the first cloud instance as the source end and the second cloud instance as the destination end. The first VXLAN header in the first message header may contain information of the first cloud instance itself. Therefore, the first VXLAN header can be used to indicate the first cloud instance.
[0013] In a possible implementation, the second packet header includes a second MAC header, a second IP header, a second UDP header, and a second VXLAN header. Among them, the second MAC header, the second IP header, and the second UDP header are used to indicate a communication channel with the second cloud instance as the source end and the first cloud instance as the destination end, and the second VXLAN header is used to indicate the first cloud instance. In the foregoing implementation, the second MAC header, the second IP header, and the second UDP header in the second packet header may include information such as the network address of the second cloud instance as the source end and the network address of the first cloud instance as the destination end. Therefore, the first MAC header, the first IP header, and the first UDP header can be used to indicate a communication channel with the second cloud instance as the source end and the first cloud instance as the destination end. The second VXLAN header in the second packet header may include information about the first cloud instance itself. Therefore, the second VXLAN header can be used to indicate the first cloud instance.
[0014] In a possible implementation, the first data is of skb data structure or mbuf data structure. The first inner packet is set in the main area of the skb data structure or mbuf data structure, and the first packet header is set in the private data area of the skb data structure or mbuf data structure. In the foregoing implementation, the first application can obtain a pre-set skb data structure or mbuf data structure, and the pre-set skb data structure or mbuf data structure includes a main area and a private data area. After generating the first packet header and the first inner packet, the first application can insert the first inner packet into the main area of the pre-set skb data structure or mbuf data structure, and insert the first packet header into the private data area of the pre-set skb data structure or mbuf data structure. The set skb data structure or the set mbuf data structure is the first data.
[0015] In a possible implementation, the first cloud instance is any one of the following: physical server, bare metal server, virtual machine, container, and micro virtual machine.
[0016] In a possible implementation, the first cloud instance is a cloud management platform, and the second cloud instance is located in a virtual private cloud (VPC); or, the first cloud instance is located in the VPC, and the second cloud instance is a cloud management platform.
[0017] A second aspect of the embodiments of the present application provides a message processing method, which is applied to a cloud service system. The cloud service system includes a first cloud instance and a second cloud instance. The second cloud instance includes a second application and a second protocol stack. The method includes: the second protocol stack receives a first message from the first cloud instance; the second protocol stack unpacks the first message to obtain a first message header and a first inner message, and embeds the first message header into the first inner message to obtain first data; the second protocol stack sends the first data to the second application so that the second application can obtain and process the first inner message from the first data.
[0018] In a possible implementation manner, the method further includes: the second application parses the first data to obtain a first message header and a first inner message, and processes the first inner message to obtain a second inner message; the second application embeds the first message header into the second inner message to obtain third data, and sends the third data to the second protocol stack; the second protocol stack parses the third data to obtain a first message header and a second inner message, and processes the first message header to obtain a second message header; the second protocol stack encapsulates the second inner message based on the second message header to obtain a second message, and sends the second message to the first cloud instance.
[0019] In a possible implementation manner, the second protocol stack embedding the first message header into the first inner message to obtain first data includes: the second protocol stack obtains a preset message header from the buffer area, and detects whether the first message header is legal based on the preset message header. If the first message header is legal, the second protocol stack embeds the first message header into the first inner message to obtain first data, where the preset message header comes from a third message sent by the first cloud instance, and the third message and the first message are handshake messages required for the first cloud instance and the second cloud instance to establish a connection.
[0020] In a possible implementation manner, the method further includes: if the first message header is illegal, the second protocol stack stops operating; or, if the first message header is illegal, the second protocol stack processes the first message header to obtain a second message header, and processes the first inner message to obtain a third inner message, where the third inner message is used to indicate that the second cloud instance refuses to establish a connection with the first cloud instance; the second protocol stack encapsulates the third inner message based on the second message header to obtain a fourth message, and sends the fourth message to the first cloud instance.
[0021] In a possible implementation manner, the first message header includes a first MAC header, a first IP header, a first UDP header, and a first VXLAN header. Among them, the first MAC header, the first IP header, and the first UDP header are used to indicate a communication channel with the first cloud instance as the source end and the second cloud instance as the destination end, and the first VXLAN header is used to indicate the first cloud instance.
[0022] In a possible implementation manner, the second packet header includes a second MAC header, a second IP header, a second UDP header, and a second VXLAN header. Among them, the second MAC header, the second IP header, and the second UDP header are used to indicate a communication channel with the second cloud instance as the source end and the first cloud instance as the destination end, and the second VXLAN header is used to indicate the first cloud instance.
[0023] In a possible implementation manner, the first data is in the skb data structure or the mbuf data structure. The first inner packet is set in the main area of the skb data structure or the mbuf data structure, and the first packet header is set in the private data area of the skb data structure or the mbuf data structure.
[0024] The third aspect of the embodiments of the present application provides a cloud instance, which is used as the first cloud instance. The first cloud instance is deployed in a cloud service system, and the cloud service system further includes a second cloud instance. The first cloud instance includes a first application and a first protocol stack. The first application is used to generate a first packet header and a first inner packet, embed the first packet header into the first inner packet to obtain first data, and send the first data to the first protocol stack. The first protocol stack is used to parse the first data to obtain the first packet header and the first inner packet, and encapsulate the first inner packet based on the first packet header to obtain a first packet. The first protocol stack is further used to send the first packet to the second cloud instance.
[0025] In a possible implementation manner, the first protocol stack is further used to receive a second packet from the second cloud instance. The first protocol stack is further used to de-encapsulate the second packet to obtain a second packet header and a second inner packet, and embed the second packet header into the second inner packet to obtain second data. The second inner packet is obtained by the second cloud instance processing the first inner packet, and the second packet header is obtained by the second cloud instance processing the first packet header. The first protocol stack is further used to send the second data to the first application so that the first application can obtain and process the second inner packet from the second data.
[0026] In a possible implementation manner, the first packet header includes a first MAC header, a first IP header, a first UDP header, and a first VXLAN header. Among them, the first MAC header, the first IP header, and the first UDP header are used to indicate a communication channel with the first cloud instance as the source end and the second cloud instance as the destination end, and the first VXLAN header is used to indicate the first cloud instance.
[0027] In a possible implementation, the second packet header includes a second MAC header, a second IP header, a second UDP header, and a second VXLAN header. Among them, the second MAC header, the second IP header, and the second UDP header are used to indicate a communication channel with the second cloud instance as the source end and the first cloud instance as the destination end, and the second VXLAN header is used to indicate the first cloud instance.
[0028] In a possible implementation, the first data is in the skb data structure or the mbuf data structure. The first inner packet is set in the main area of the skb data structure or the mbuf data structure, and the first packet header is set in the private data area of the skb data structure or the mbuf data structure.
[0029] In a possible implementation, the first cloud instance is any one of the following: a physical server, a bare metal server, a virtual machine, a container, and a micro virtual machine.
[0030] In a possible implementation, the first cloud instance is a cloud management platform and the second cloud instance is located in the VPC; or, the first cloud instance is located in the VPC and the second cloud instance is a cloud management platform.
[0031] In a possible implementation, the second cloud instance is any one of the following: a physical server, a bare metal server, a virtual machine, a container, and a micro virtual machine.
[0032] In a possible implementation, the first cloud instance is a cloud management platform and the second cloud instance is located in the VPC; or, the first cloud instance is located in the VPC and the second cloud instance is a cloud management platform.
[0033] The fourth aspect of the embodiments of the present application provides a cloud instance. This cloud instance serves as the second cloud instance. The second cloud instance is deployed in a cloud service system, and the cloud service system further includes a first cloud instance. The second cloud instance includes a second application and a second protocol stack;
[0034] The second protocol stack is used to receive a first packet from the first cloud instance;
[0035] The second protocol stack is used to de-encapsulate the first packet to obtain a first packet header and a first inner packet, and embed the first packet header into the first inner packet to obtain first data;
[0036] The second protocol stack is further used to send the first data to the second application so that the second application can obtain and process the first inner packet from the first data.
[0037] In a possible implementation manner, a second application is used to parse first data to obtain a first message header and a first inner message, and process the first inner message to obtain a second inner message; the second application is further used to embed the first message header into the second inner message to obtain third data, and send the third data to a second protocol stack; the second protocol stack is further used to parse the third data to obtain a first message header and a second inner message, and process the first message header to obtain a second message header; the second protocol stack is further used to encapsulate the second inner message based on the second message header to obtain a second message, and send the second message to a first cloud instance.
[0038] In a possible implementation manner, a second protocol stack is used to obtain a preset message header from a buffer area, and detect whether the first message header is legal based on the preset message header. If the first message header is legal, the second protocol stack embeds the first message header into the first inner message to obtain first data, where the preset message header is from a third message sent by the first cloud instance, and the third message and the first message are handshake messages required for the first cloud instance and the second cloud instance to establish a connection.
[0039] In a possible implementation manner, the second protocol stack is further used to: if the first message header is not legal, stop the operation; or, if the first message header is not legal, process the first message header to obtain a second message header, and process the first inner message to obtain a third inner message, where the third inner message is used to instruct the second cloud instance to refuse to establish a connection with the first cloud instance; encapsulate the third inner message based on the second message header to obtain a fourth message, and send the fourth message to the first cloud instance.
[0040] In a possible implementation manner, the first message header includes a first MAC header, a first IP header, a first UDP header, and a first VXLAN header, where the first MAC header, the first IP header, and the first UDP header are used to indicate a communication channel with the first cloud instance as the source end and the second cloud instance as the destination end, and the first VXLAN header is used to indicate the first cloud instance.
[0041] In a possible implementation manner, the second message header includes a second MAC header, a second IP header, a second UDP header, and a second VXLAN header, where the second MAC header, the second IP header, and the second UDP header are used to indicate a communication channel with the second cloud instance as the source end and the first cloud instance as the destination end, and the second VXLAN header is used to indicate the first cloud instance.
[0042] In a possible implementation manner, the first data is in the skb data structure or the mbuf data structure. The first inner message is set in the main body area of the skb data structure or the mbuf data structure, and the first message header is set in the private data area of the skb data structure or the mbuf data structure.
[0043] In a possible implementation manner, the second cloud instance is any one of the following: a physical server, a bare metal server, a virtual machine, a container, and a micro virtual machine.
[0044] In a possible implementation manner, the first cloud instance is a cloud management platform, and the second cloud instance is located in the VPC; or, the first cloud instance is located in the VPC, and the second cloud instance is a cloud management platform.
[0045] The fifth aspect of the embodiments of the present application provides a computing device cluster, which includes at least one computing device, and each computing device includes a processor and a memory: the memory is used to store instructions; the processor is used to execute the method described in the first aspect, any possible implementation manner in the first aspect, the second aspect, or any possible implementation manner in the second aspect according to the instructions.
[0046] The sixth aspect of the embodiments of the present application provides a computer storage medium, which stores one or more instructions, and when the instructions are executed by one or more computers, the one or more computers implement the method described in the first aspect, any possible implementation manner in the first aspect, the second aspect, or any possible implementation manner in the second aspect.
[0047] The seventh aspect of the embodiments of the present application provides a computer program product, which is characterized in that the computer program product stores instructions, and when the instructions are executed by a computer, the computer implements the method described in the first aspect, any possible implementation manner in the first aspect, the second aspect, or any possible implementation manner in the second aspect.
[0048] In an embodiment of the present application, when a first cloud instance needs to communicate with a second cloud instance, a first application of the first cloud instance can generate a first packet header and a first inner packet, and embed the first packet header into the first inner packet to obtain first data. Then, the first application can send the first data to the first protocol stack of the first cloud instance. Next, the first protocol stack can parse the first data to obtain the first packet header and the first inner packet. Then, the first protocol stack can encapsulate the first inner packet using the first packet header to obtain a first packet. Subsequently, the first protocol stack can send the first packet to the second cloud instance. After obtaining the first packet, the second protocol stack of the second cloud instance can de-encapsulate the first packet to obtain the first packet header and the first inner packet. Then, the second protocol stack can embed the first packet header into the first inner packet to obtain first data. Next, the second protocol stack can send the first data to the second application of the second cloud instance. Subsequently, after obtaining the first data, the second application can parse the first data to obtain the first packet header and the first inner packet, and process the first inner packet. In the foregoing process, since both the first cloud instance and the second cloud instance are provided with modified protocol stacks, namely the first protocol stack and the second protocol stack, due to the existence of these two protocol stacks, the first inner packet generated by the first application is accompanied by the first packet header during the process of passing through the first application, the first protocol stack, the second protocol stack, and the second application in sequence. Therefore, the second application can obtain both the first packet header and the first inner packet at the same time. Since the first packet header can be used not only to indicate the communication channel with the first cloud instance as the source end and the second cloud instance as the destination end, but also to indicate the first cloud instance itself, the second application can determine relevant information of the first cloud instance from which the first inner packet comes based on the first packet header. For example, when the first cloud instance is a client and the second cloud instance is a server, the second application can perceive the VPC where the first cloud instance is located. Thus, it can be seen that this embodiment proposes a new packet processing architecture. Since the server is provided with a modified protocol stack, the server does not need to add additional ports. With only the existing ports, the application on the server can also obtain information related to multiple VPCs to perceive these multiple VPCs, so as to distinguish packets sent by clients in different VPCs. This can save resource overhead on the server side and is beneficial to the application of the server in a multi-VPC scenario. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 FIG. is a schematic structural diagram of a cloud service system provided by an embodiment of the present application;
[0050] Figure 2 FIG. is a schematic structural diagram of a server provided by an embodiment of the present application;
[0051] Figure 3 FIG. is a schematic diagram of a packet processing method provided by an embodiment of the present application;
[0052] Figure 4 Schematic diagram of an application example of the message processing method provided by an embodiment of the present application;
[0053] Figure 5 Schematic diagram of another application example of the message processing method provided by an embodiment of the present application;
[0054] Figure 6 Schematic diagram of another application example of the message processing method provided by an embodiment of the present application;
[0055] Figure 7 Schematic diagram of a structure of a cloud instance provided by an embodiment of the present application;
[0056] Figure 8 Schematic diagram of another structure of a cloud instance provided by an embodiment of the present application;
[0057] Figure 9 Schematic diagram of a structure of a computing device provided by an embodiment of the present application;
[0058] Figure 10 Schematic diagram of a structure of a computing device cluster provided by an embodiment of the present application;
[0059] Figure 11 Schematic diagram of the connection of computing devices in a computer cluster provided by an embodiment of the present application through a network. Detailed implementation manners
[0060] An embodiment of the present application provides a message processing method and related devices. The server is provided with a modified protocol stack. Without adding additional ports, the applications on the server can also perceive multiple VPCs with only the existing ports, so as to distinguish the messages sent by clients of different VPCs, which can save the resource overhead on the server side.
[0061] Terms such as "first" and "second" in the specification, claims and above-mentioned drawings of the present application are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinction adopted when describing objects with the same attributes in the embodiments of the present application. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device including a series of units does not have to be limited to those units, but may include other units not clearly listed or inherent to these process, method, product or device.
[0062] With the continuous development of cloud technology, tenants have higher and higher requirements for the network security of cloud service systems. The VPC technology can build exclusive independent networks for each tenant on the public network resources of the cloud service system, which can ensure a certain degree of privacy for the tenants.
[0063] In the cloud service system of related technologies, when the server receives a packet sent by a client in a certain VPC, the protocol stack of the server usually first de-encapsulates the packet to obtain the packet header of the packet and the inner packet of the packet. Then, the protocol stack can discard the packet header and send the inner packet to the application processing of the server. Since the packet header usually contains information about the VPC to which the client belongs, and the packet header has been discarded by the protocol stack, when the application processes the inner packet, it cannot perceive the information about the VPC to which the client belongs. This will cause the application on the server to be unable to distinguish packets from multiple VPCs in the scenario of multiple VPCs, thus restricting the capabilities that the application can exert in this scenario.
[0064] Based on this, multiple ports corresponding to multiple VPCs can be opened on the server. Therefore, the application on the server can distinguish packets from different VPCs based on the packets received by different ports. However, since the number of VPCs is often very large, a large number of ports need to be created on the server, resulting in excessive software and hardware overhead. It can be seen that the existing packet processing architecture has high requirements for resources and is difficult to apply in the multi-VPC scenario.
[0065] Furthermore, VPCs usually serve tenants. In actual application scenarios, the number of tenants will continue to increase, while the resources of the server are limited and cannot expand a sufficient number of ports, so it cannot support a relatively large number of VPCs. It can be seen that the scalability of the existing packet processing architecture is not strong and it is difficult to support large-scale VPCs.
[0066] Furthermore, some other related technologies provide a new packet processing architecture. For example, the server is supported to handle multiple VPCs through a mapping method. Since a mapping conversion needs to be performed in the middle during the packet processing, it will affect the efficiency of packet processing and result in poor performance of the server.
[0067] To solve the above problems, the embodiments of the present application provide a packet processing method, which can be implemented through a cloud service system. Figure 1 As shown in the following figure, which is a schematic structural diagram of the cloud service system provided by the embodiments of the present application. Figure 1 As shown, the cloud service system includes a cloud management platform and an infrastructure that provides cloud services. The cloud management platform and the infrastructure will be introduced separately below:
[0068] The cloud management platform can overall manage the infrastructure in the entire cloud service system (for example, among multiple physical servers included in the infrastructure, select a specific one or more physical servers for a tenant, and create user-exclusive cloud instances on these physical servers, and these cloud instances can form the tenant's VPC, etc.), and can also be open to tenants outside the cloud service system and respond to their requests. For example, the cloud management platform can provide various interfaces such as a login interface and a creation interface for the tenants' clients (for example, the terminal devices used by the tenants or browsers on the terminal devices, etc.) to access. Among them, the cloud management platform can authenticate the tenants' clients through the login interface, and after successful authentication, allow the tenants' clients to log in to the cloud management platform. Also, for example, the cloud management platform can also, through the creation interface, allow the tenants' clients to send a VPC creation request of the tenant to the cloud management platform. The cloud management platform can select a certain or certain physical servers from the physical server cluster based on the VPC creation request, and create tenant-exclusive cloud instances on these physical servers to form a tenant-exclusive VPC, so as to provide cloud services for the tenant.
[0069] A VPC usually contains multiple cloud instances. Communication connections can be achieved among the multiple cloud instances, and each cloud instance can also achieve a communication connection with the cloud management platform. Generally, a VPC usually belongs to one tenant, different VPCs belong to different tenants, and these VPCs can all achieve a communication connection with the cloud management platform, so as to achieve message transmission and message processing. It can be understood that for any cloud instance in any one of the multiple VPCs, this cloud instance can be used as a client, and the cloud management platform can be used as a server. Generally, the client can include the tenant's application and a modified protocol stack (it can also be a traditional protocol stack), and the server can include an application for implementing management and a modified protocol stack. When the application of the client and the application of the server need to establish a communication connection (the communication connection request can be initiated actively by any one of the two), the two can synchronize and verify the information of both parties through handshake messages, so as to achieve the communication connection between the two.
[0070] For the server, the structure of the modified protocol stack it contains is similar to the structure of the traditional protocol stack, but there are differences in their functions. The following combines Figure 2 to further introduce the modified protocol stack. Figure 2 This is a schematic structural diagram of the server provided by the embodiment of the present application. As Figure 2As shown in the figure, the server includes a hardware layer and a software layer. The hardware layer includes various types of hardware such as computing resources (e.g., central processing unit (CPU) and graphics processing unit (GPU), etc.), storage resources (e.g., memory and hard disk, etc.), and communication resources (e.g., network interface card (NIC), etc.). The software layer is implemented with the support of the hardware layer and may include a modified protocol stack, socket layer, and applications. Among them, the protocol stack of the server is set with virtual extensible local area network tunnel endpoints (VTEP). The VTEP can receive the request message actively sent by the client forwarded by the network card of the server, and de-encapsulate the message to obtain the message header of the request message and the inner message of the request message, and embed the message header of the request message into the inner message of the request message to obtain a special data, and send the data to the application of the server through the socket layer, so that the application of the server can parse the message header of the request message and the inner message of the request message from the data. Then, based on the message header of the request message, the application of the server can determine the information of the VPC where the client sending the inner message of the request message is located, that is, the application of the server can perceive the VPC where the client is located. Correspondingly, after the application of the server processes the inner message of the request message, it can obtain the processed inner message, and embed the message header of the request message into the processed inner message to obtain another special data, and send it to the protocol stack of the server through the socket layer, so that after the VTEP of the protocol stack of the server parses the data, it can obtain the message header of the request message and the processed inner message. Therefore, the VTEP of the protocol stack of the server can process the message header of the request message to obtain the message header of the response message, and use the message header of the response message to encapsulate the processed inner message to obtain the response message, and return the response message to the client through the network card of the server.
[0071] For the client, if the client also includes the modified protocol stack, it also includes the VTEP. When the application on the client needs to actively establish communication with the application on the server, the application on the client can generate the header of the request message and the inner message of the request message, embed the header of the request message into the inner message of the request message to obtain a special data, and send the data to the protocol stack of the client through the socket layer of the client. Then, the VTEP of the protocol stack of the client can parse the header of the request message and the inner message of the request message from the data, and use the header of the request message to encapsulate the inner message of the request message, thereby obtaining the request message, and send the request message to the server through the network card of the client. It should be noted that if the client includes a traditional protocol stack, then the application and protocol stack of the client can generate the request message in the traditional way, which will not be elaborated here.
[0072] It should be understood that the above is only an illustrative introduction with the client actively initiating a communication connection to the server as an example. In actual applications, the server can also actively initiate a communication connection to the client, and this process can refer to the aforementioned process, which will not be elaborated here. Similarly, after the client and the server establish a connection, if they have normal business requirements, they can subsequently send request messages and return response messages to each other, and this process can also refer to the aforementioned process, which will not be elaborated here.
[0073] Furthermore, both the server and the client can essentially be regarded as cloud instances in the infrastructure. Cloud instances can be presented in various ways. For example, a cloud instance can be a certain physical server, or a virtual machine (VM) created on a physical server through virtualization technology, or a container (docker) created on a physical server through virtualization technology, or a micro virtual machine (microVM) created on a physical server through virtualization technology, or a container (docker) created on a physical server through virtualization technology, or a bare metal server, and so on.
[0074] Even further, multiple cloud instances in a VPC are usually set in one or more sites. Sites can be presented in various forms. For example, one or more sites can be one or more regions in the infrastructure, or one or more availability zones in the infrastructure, or at least one edge site and at least one central cloud site in the infrastructure, and so on.
[0075] Based on the above cloud service system, it can be seen that the improved protocol stack enables the application on the server side to successfully perceive the VPC where the client is located. In this way, when the server side communicates in the scenario of multiple VPCs, it can effectively distinguish each VPC. Moreover, only one VTEP device, which is equivalent to a port, needs to be set in the improved protocol stack of the server side, and there is no need to additionally add new ports to match multiple VPCs. This can save the resources of the server side and use the remaining resources for other services, thereby improving the resource utilization rate. To further understand this process, the following will be combined with Figure 3 to further introduce this process, Figure 3 which is a schematic diagram of the message processing method provided by the embodiment of this application. As Figure 3 shown, this method can be implemented through the cloud service system as shown in Figure 1 . The cloud management platform includes the cloud management platform and the infrastructure for providing cloud services. The infrastructure includes the first cloud instance and the second cloud instance. Among them, the first cloud instance includes the first application, the first socket layer, and the first protocol stack, and the second cloud instance includes the second application, the second socket layer, and the second protocol stack. This method includes:
[0076] 301. The first application of the first cloud instance generates the first message header and the first inner message, and embeds the first message header into the first inner message to obtain the first data.
[0077] 302. The first application sends the first data to the first protocol stack of the first cloud instance.
[0078] In this embodiment, when the first cloud instance needs to establish a communication connection with the second cloud instance, the first application of the first cloud instance can generate the first message header (which can also be called the message header of the request message) and the first inner message (which can also be called the inner message of the request message) to be processed by the second application of the second cloud instance, and embed the first message header into the first inner message, thereby obtaining the first data. Among them, the first message header can not only be used to indicate the communication channel (which can also be called a tunnel) with the first cloud instance as the source end and the second cloud instance as the destination end, but also be used to indicate the first cloud instance itself.
[0079] After obtaining the first data, the first application can call the first socket layer of the first cloud instance through the corresponding application programming interface (API) or software development kit (SDK) to send the first data to the first protocol stack of the first cloud instance through the first socket layer.
[0080] Specifically, the relationship between the first cloud instance and the second cloud instance can be presented in the following multiple ways:
[0081] (1) When the first cloud instance is the server, the second cloud instance is the client. That is to say, the first cloud instance is the cloud management platform, and the second cloud instance is a cloud instance in a certain VPC. (2) When the first cloud instance is the client, the second cloud instance is the server. That is to say, the first cloud instance is a cloud instance in a certain VPC, and the second cloud instance is the cloud management platform.
[0082] More specifically, the first packet header can be presented in the following manner:
[0083] The first packet header can include a first Ethernet header (which can also be referred to as the first MAC header), a first IP header, a first UDP header, and a first VXLAN header. Among them, the first MAC header, the first IP header, and the first UDP header can include information such as the network address of the first cloud instance as the source end and the network address of the second cloud instance as the destination end. Therefore, the first MAC header, the first IP header, and the first UDP header can be used to indicate the communication channel with the first cloud instance as the source end and the second cloud instance as the destination end. The first VXLAN header can include information of the first cloud instance itself (for example, when the first cloud instance is the client, this information is the information of the VPC where the first cloud instance is located, such as the identifier of this VPC, etc.). Therefore, the first VXLAN header can be used to indicate the first cloud instance.
[0084] For example, as Figure 4 shown ( Figure 4 is a schematic diagram of an application example of the packet processing method provided by an embodiment of the present application), assume that the client actively establishes a connection with the server, and this process includes multiple handshake processes. The application of the client can generate the packet header of the request packet (i.e., a certain handshake packet) and the inner packet of the request packet (i.e., Figure 4 the payload in it, including the data to be processed by the server). The packet header of the request packet includes a MAC header, an IP header, a UDP header, and a VXLAN header. Among them, the MAC header, the IP header, and the UDP header include information such as the network address of the client as the source end and the network address of the server as the destination end. The VXLAN header includes information such as the identifier of the VPC where the client is located.
[0085] More specifically, the first data can be presented in the following manner:
[0086] The first application can obtain a pre - configured skb data structure or a pre - configured mbuf data structure. The pre - configured skb data structure or the pre - configured mbuf data structure contains a main area and a private data area. After the first application generates a first packet header and a first inner packet, it can set the first inner packet in the main area of the pre - configured skb data structure or the pre - configured mbuf data structure, and set the first packet header in the private data area of the pre - configured skb data structure or the pre - configured mbuf data structure. The set skb data structure or the set mbuf data structure is the first data.
[0087] Still as in the above example, after the application on the client obtains the packet header of the request packet and the inner packet of the request packet, it can obtain the pre - set skb / mbuf data structure, store the inner packet of the request packet in the main area of the skb / mbuf data structure, and store the packet header of the request packet in the private_data area of the skb / mbuf data structure, so as to obtain the completed skb / mbuf data structure. Then, the application on the client can call the socket layer of the client through an interface to send the completed skb / mbuf data structure to the protocol stack of the client through the socket layer.
[0088] 303. The first protocol stack parses the first data to obtain a first packet header and a first inner packet, and encapsulates the first inner packet based on the first packet header to obtain a first packet.
[0089] 304. The first protocol stack sends the first packet to the second cloud instance.
[0090] After obtaining the first data, the first protocol stack can parse the first data to obtain a first packet header and a first inner packet. Then, the first protocol stack can use the first packet header to encapsulate the first inner packet to obtain a first packet. Subsequently, the first protocol stack can send the first packet to the second cloud instance.
[0091] Still as in the above example, after the protocol stack of the client obtains the completed skb / mbuf data structure, it can parse it through the VTEP of the protocol stack of the client to extract the packet header of the request packet and the inner packet of the request packet, and use the packet header of the request packet to encapsulate the inner packet of the request packet to obtain the request packet. Then, the VTEP of the protocol stack of the client can send the request packet to the server through the network card of the client.
[0092] 305. The second protocol stack of the second cloud instance unpacks the first packet to obtain a first packet header and a first inner packet, and embeds the first packet header into the first inner packet to obtain the first data.
[0093] 306. The second protocol stack sends the first data to the second application of the second cloud instance.
[0094] After obtaining the first message, the second protocol stack of the second cloud instance can de-encapsulate the first message to obtain the first message header and the first inner message. Then, the second protocol stack can embed the first message header into the first inner message to obtain the first data. Subsequently, the second protocol stack can store the first data in the second socket layer of the second cloud instance. Therefore, the second application of the second cloud instance can call the second socket layer through the API or SDK to obtain the first data from the second socket layer.
[0095] For example, as Figure 5 shown ( Figure 5 which is another application example diagram of the message processing method provided by the embodiments of the present application, Figure 5 drawn on the basis of Figure 4 ), after the network card of the server receives the request message, it can forward the request message to the protocol stack of the server. The VTEP of the protocol stack of the server can de-encapsulate the request message to obtain the message header and the inner message of the request message. Then, it can obtain the pre-set skb / mbuf data structure, store the inner message of the request message in the main area of the skb / mbuf data structure, and store the message header of the request message in the privata_data area of the skb / mbuf data structure to obtain the set-up skb / mbuf data structure. Then, the VTEP of the protocol stack of the server can set the set-up skb / mbuf data structure in the socket layer of the server. Therefore, the application of the server can call the socket layer through the interface to obtain the set-up skb / mbuf data structure.
[0096] Specifically, the second protocol stack can obtain the first data in the following way:
[0097] Suppose the first message is a non-first handshake message in the handshake process of establishing a connection between the first cloud instance and the second cloud instance, and the third message is the first handshake message in the process of establishing a connection between the first cloud instance and the second cloud instance. Therefore, after the first cloud instance sends the third message to the second cloud instance, the second protocol stack of the second cloud instance de-encapsulates the third message and can cache the third message header of the third message as a pre-set message header in the buffer for verification in the subsequent handshake process.
[0098] Based on this, after the second protocol stack receives the first message and decapsulates it to obtain the first message header and the first inner message, it can obtain the pre-set message header from the buffer area, and detect whether the first message header is legal based on the pre-set message header (for example, whether the pre-set message header matches the first message header). If the first message header is legal, the second protocol stack embeds the first message header into the first inner message to obtain the first data, and sends the first data to the second application.
[0099] If the first message header is illegal, there can be multiple situations for the second protocol stack: (1) The second protocol stack directly stops any operation, which is equivalent to interrupting the handshake process with the first cloud instance and no longer responding to the first cloud instance, which is equivalent to a failure in establishing a connection between the two. (2) The second protocol stack processes the first message header to obtain a second message header, and processes the first inner message to obtain a third inner message. Among them, the second message header can not only be used to indicate the communication channel with the first cloud instance as the destination and the second cloud instance as the source, but also be used to indicate the first cloud instance itself, while the third inner message is used to indicate that the second cloud instance refuses to establish a connection with the first cloud instance. Then, the second protocol stack encapsulates the third inner message based on the second message header to obtain a fourth message, and sends the fourth message to the first cloud instance. In this way, the first cloud instance can know that the second cloud instance refuses to establish a connection, and the connection between the two fails.
[0100] For example, as Figure 6 shown ( Figure 6 is another application example schematic diagram of the message processing method provided by the embodiment of the present application, Figure 6 is drawn on the basis of Figure 5 ), after the network card of the server receives the request message, it can forward the request message to the protocol stack of the server. The VTEP of the protocol stack of the server can decapsulate the request message to obtain the message header and the inner message of the request message. Then, the VTEP can obtain the message header cached during the previous handshake process from the buffer area (syncache) (this message header comes from the first request message sent by the client to the server before, and this request message is also a handshake message), and detect the message header of the request message based on the cached message header to determine whether the message header of the request message is legal.
[0101] If the message header of the request message is legal, the VTEP can obtain the pre-set skb / mbuf data structure, store the inner message of the request message in the main area of the skb / mbuf data structure, and store the message header of the request message in the private_data area of the skb / mbuf data structure, so as to obtain the completed skb / mbuf data structure. Then, the VTEP of the protocol stack on the server side can set the completed skb / mbuf data structure at the socket layer of the server side, so the application on the server side can call the socket layer through the interface to obtain the completed skb / mbuf data structure.
[0102] If the message header of the request message is illegal, the VTEP of the protocol stack on the server side can obtain the message header of the response message generated based on the message header of the request message (the source and destination information in the two message headers is swapped), and generate the inner message of the response message based on the inner message of the request message (that is, Figure 6 the payload shown), to notify the client that the server refuses to establish a connection. Subsequently, the VTEP of the protocol stack on the server side can encapsulate the inner message of the response message with the message header of the response message to obtain the response message, and return it to the client.
[0103] 307. The second application parses the first data to obtain the first message header and the first inner message, and processes the first inner message to obtain the second inner message.
[0104] 308. The second application embeds the first message header into the second inner message to obtain the third data, and sends the third data to the second protocol stack.
[0105] After obtaining the first data, the second application can parse the first data to obtain the first message header and the first inner message, and process the first inner message to obtain the second inner message (the second inner message can also be called the inner message of the response message. For example, if the first inner message is the data to be processed, the second inner message is the processed data, etc.). Then, the second application can embed the first message header into the second inner message to obtain the third data. Subsequently, the second application can call the second socket layer through the API or SDK to send the third data to the second protocol stack through the second socket layer.
[0106] Still as Figure 5 shown in the example, after obtaining the completed skb / mbuf data structure, the application on the server side can parse it to extract the message header of the request message and the inner message contained in the request, and process the inner message contained in the request to obtain the inner message of the response message (that is, Figure 5The payload shown in the figure is obtained, and the skb / mbuf data structure set in advance is acquired. The inner packet of the response message is stored in the main area of the skb / mbuf data structure, and the header of the request message is stored in the private_data area of the skb / mbuf data structure, thereby obtaining another completed skb / mbuf data structure. Then, the application on the server side can call the socket layer of the server through the interface to send the other completed skb / mbuf data structure to the protocol stack of the server through the socket layer.
[0107] 309. The second protocol stack parses the third data to obtain the first header and the second inner packet, and processes the first header to obtain the second header.
[0108] 310. The second protocol stack encapsulates the second inner packet based on the second header to obtain the second packet, and sends the second packet to the first cloud instance.
[0109] After obtaining the third data, the second protocol stack can parse the third data to obtain the first header and the second inner packet. Then, the second protocol stack can process the first header to obtain the second header, and use the second header to encapsulate the second inner packet to obtain the second packet. Subsequently, the second protocol stack can send the second packet to the first cloud instance. Among them, the second header can not only be used to indicate the communication channel with the first cloud instance as the destination and the second cloud instance as the source, but also be used to indicate the first cloud instance itself.
[0110] Still as Figure 5 In the example shown in the figure, after obtaining another completed skb / mbuf data structure, the VTEP of the protocol stack on the server side parses it to extract the header of the request message and the inner packet of the response message, and generates the header of the response message based on the header of the request message (the source and destination information in the two headers is swapped), and then uses the header of the response message to encapsulate the inner packet of the response message to obtain the response message. Then, the VTEP of the protocol stack on the server side can send the response message to the client through the network card of the server.
[0111] More specifically, the second header can be presented in the following ways:
[0112] The second packet header may include a second MAC header, a second IP header, a second UDP header, and a second VXLAN header. Among them, the second MAC header, the second IP header, and the second UDP header may include information such as the network address of the first cloud instance as the destination and the network address of the second cloud instance as the source. Therefore, the second MAC header, the second IP header, and the second UDP header can be used to indicate a communication channel with the second cloud instance as the source and the first cloud instance as the destination. The second VXLAN header may include information about the first cloud instance itself. Therefore, the second VXLAN header can be used to indicate the first cloud instance.
[0113] 311. The first protocol stack decapsulates the second packet to obtain the second packet header and the second inner packet, and embeds the second packet header into the second inner packet to obtain the second data.
[0114] 312. The first protocol stack sends the second data to the first application so that the first application can obtain and process the second inner packet from the second data.
[0115] For the introduction of steps 311 to 312, reference can be made to the relevant description parts of steps 305 to 307, which will not be elaborated here. It should be noted that the difference between the two is that in steps 311 to 312, the protocol stack of the client does not need to verify whether the second packet header is legal, while in steps 305 to 307, it is usually necessary to verify whether the first packet header is legal.
[0116] Steps 301 to 312 can be regarded as a handshake process between the first cloud instance and the second cloud instance. After multiple handshakes, when the first cloud instance and the second cloud instance establish a connection, the process of business packet transmission and processing between the two can also refer to steps 301 to 312, which will not be elaborated here.
[0117] In the embodiment of the present application, when the first cloud instance needs to communicate with the second cloud instance, the first application of the first cloud instance can generate a first packet header and a first inner packet, and embed the first packet header into the first inner packet to obtain the first data. Then, the first application can send the first data to the first protocol stack of the first cloud instance. Then, the first protocol stack can parse the first data to obtain the first packet header and the first inner packet. Then, the first protocol stack can encapsulate the first inner packet with the first packet header to obtain the first packet. Subsequently, the first protocol stack can send the first packet to the second cloud instance. After obtaining the first packet, the second protocol stack of the second cloud instance can de-encapsulate the first packet to obtain the first packet header and the first inner packet. Then, the second protocol stack can embed the first packet header into the first inner packet to obtain the first data. Then, the second protocol stack can send the first data to the second application of the second cloud instance. Subsequently, after obtaining the first data, the second application can parse the first data to obtain the first packet header and the first inner packet, and process the first inner packet. In the foregoing process, since both the first cloud instance and the second cloud instance are provided with modified protocol stacks, that is, the first protocol stack and the second protocol stack, due to the existence of these two protocol stacks, the first inner packet generated by the first application is accompanied by the first packet header during the process of passing through the first application, the first protocol stack, the second protocol stack, and the second application in sequence. Therefore, the second application can obtain both the first packet header and the first inner packet at the same time. Since the first packet header can not only be used to indicate the communication channel with the first cloud instance as the source end and the second cloud instance as the destination end, but also be used to indicate the first cloud instance itself, the second application can determine the relevant information of the first cloud instance from which the first inner packet comes based on the first packet header. For example, when the first cloud instance is a client and the second cloud instance is a server, the second application can perceive the VPC where the first cloud instance is located. Thus, it can be seen that the present embodiment proposes a new packet processing architecture. Since the server is provided with a modified protocol stack, the server does not need to add additional ports. With only the existing ports, the application on the server can also obtain information related to multiple VPCs to perceive these multiple VPCs, so as to distinguish the packets sent by clients in different VPCs. This can save the resource overhead on the server side and is beneficial to the application of the server in a multi-VPC scenario.
[0118] Furthermore, in the packet processing architecture provided by the embodiment of the present application, even if the number of VPCs is continuously increasing, due to the existence of the modified protocol stack, the server does not need to expand ports additionally. The application on the server can still perceive these new VPCs, which has strong scalability and is beneficial to the server to support a large number of VPCs.
[0119] Furthermore, in the packet processing architecture provided by the embodiments of the present application, the application on the server obtains the packet header and the inner packet from the protocol stack of the server through the socket layer, and then obtains the relevant information of the VPC from the packet header to achieve the perception of the VPC. In this process, no conversion operation needs to be performed, and the efficiency of packet processing is hardly affected, which can ensure the performance of the server.
[0120] The above is a detailed description of the packet processing method provided by the embodiments of the present application. The following will introduce the cloud instance provided by the embodiments of the present application. Figure 7 A structural schematic diagram of the cloud instance provided by the embodiments of the present application is shown in Figure 7 As shown, this cloud instance is the first cloud instance. The first cloud instance is deployed in the cloud service system, and the cloud service system also includes a second cloud instance. The first cloud instance includes a first application 701 and a first protocol stack 702;
[0121] The first application 701 is used to generate a first packet header and a first inner packet, embed the first packet header into the first inner packet to obtain first data, and send the first data to the first protocol stack;
[0122] The first protocol stack 702 is used to parse the first data to obtain a first packet header and a first inner packet, and encapsulate the first inner packet based on the first packet header to obtain a first packet;
[0123] The first protocol stack 702 is further used to send the first packet to the second cloud instance.
[0124] In a possible implementation manner, the first protocol stack 702 is further used to receive a second packet from the second cloud instance; the first protocol stack 702 is further used to de-encapsulate the second packet to obtain a second packet header and a second inner packet, and embed the second packet header into the second inner packet to obtain second data. The second inner packet is obtained by the second cloud instance processing the first inner packet, and the second packet header is obtained by the second cloud instance processing the first packet header; the first protocol stack 702 is further used to send the second data to the first application so that the first application can obtain and process the second inner packet from the second data.
[0125] In a possible implementation manner, the first packet header includes a first MAC header, a first IP header, a first UDP header, and a first VXLAN header. Among them, the first MAC header, the first IP header, and the first UDP header are used to indicate the communication channel with the first cloud instance as the source end and the second cloud instance as the destination end, and the first VXLAN header is used to indicate the first cloud instance.
[0126] In a possible implementation, the second packet header includes a second MAC header, a second IP header, a second UDP header, and a second VXLAN header. Among them, the second MAC header, the second IP header, and the second UDP header are used to indicate a communication channel with the second cloud instance as the source end and the first cloud instance as the destination end, and the second VXLAN header is used to indicate the first cloud instance.
[0127] In a possible implementation, the first data is in the skb data structure or the mbuf data structure. The first inner packet is set in the main area of the skb data structure or the mbuf data structure, and the first packet header is set in the private data area of the skb data structure or the mbuf data structure.
[0128] In a possible implementation, the first cloud instance is any one of the following: a physical server, a bare metal server, a virtual machine, a container, and a micro virtual machine.
[0129] In a possible implementation, the first cloud instance is a cloud management platform, and the second cloud instance is located in the VPC; or, the first cloud instance is located in the VPC, and the second cloud instance is a cloud management platform.
[0130] Figure 8 Another structural schematic diagram of the cloud instance provided by the embodiment of the present application is as Figure 8 shown. The cloud instance serves as the second cloud instance. The second cloud instance is deployed in the cloud service system, and the cloud service system further includes a first cloud instance. The second cloud instance includes a second application 801 and a second protocol stack 802;
[0131] The second protocol stack 802 is used to receive the first packet from the first cloud instance;
[0132] The second protocol stack 802 is used to de-encapsulate the first packet to obtain the first packet header and the first inner packet, and embed the first packet header into the first inner packet to obtain the first data;
[0133] The second protocol stack 802 is further used to send the first data to the second application 801 so that the second application 801 can obtain and process the first inner packet from the first data.
[0134] In a possible implementation manner, the second application 801 is used to parse the first data to obtain a first message header and a first inner message, and process the first inner message to obtain a second inner message; the second application 801 is further used to embed the first message header into the second inner message to obtain third data, and send the third data to the second protocol stack; the second protocol stack 802 is further used to parse the third data to obtain a first message header and a second inner message, and process the first message header to obtain a second message header; the second protocol stack 802 is further used to encapsulate the second inner message based on the second message header to obtain a second message, and send the second message to the first cloud instance.
[0135] In a possible implementation manner, the second protocol stack 802 is used to obtain a preset message header from the buffer area, and detect whether the first message header is legal based on the preset message header. If the first message header is legal, the second protocol stack embeds the first message header into the first inner message to obtain first data, where the preset message header comes from a third message sent by the first cloud instance, and the third message and the first message are handshake messages required for the first cloud instance and the second cloud instance to establish a connection.
[0136] In a possible implementation manner, the second protocol stack 802 is further used to: if the first message header is illegal, stop the operation; or, if the first message header is illegal, process the first message header to obtain a second message header, and process the first inner message to obtain a third inner message, where the third inner message is used to instruct the second cloud instance to refuse to establish a connection with the first cloud instance; encapsulate the third inner message based on the second message header to obtain a fourth message, and send the fourth message to the first cloud instance.
[0137] In a possible implementation manner, the first message header includes a first MAC header, a first IP header, a first UDP header, and a first VXLAN header. Among them, the first MAC header, the first IP header, and the first UDP header are used to indicate a communication channel with the first cloud instance as the source end and the second cloud instance as the destination end, and the first VXLAN header is used to indicate the first cloud instance.
[0138] In a possible implementation manner, the second message header includes a second MAC header, a second IP header, a second UDP header, and a second VXLAN header. Among them, the second MAC header, the second IP header, and the second UDP header are used to indicate a communication channel with the second cloud instance as the source end and the first cloud instance as the destination end, and the second VXLAN header is used to indicate the first cloud instance.
[0139] In a possible implementation, the first data is an skb data structure or an mbuf data structure. The first inner packet is set in the main area of the skb data structure or the mbuf data structure, and the first packet header is set in the private data area of the skb data structure or the mbuf data structure.
[0140] In a possible implementation, the second cloud instance is any one of the following: a physical server, a bare metal server, a virtual machine, a container, and a micro virtual machine.
[0141] In a possible implementation, the first cloud instance is a cloud management platform, and the second cloud instance is located in a VPC; or, the first cloud instance is located in a VPC, and the second cloud instance is a cloud management platform.
[0142] It should be noted that for the information interaction, implementation process, etc. between the above-mentioned device modules / units, since they are based on the same concept as the method embodiments of the present application, the technical effects brought by them are the same as those of the method embodiments of the present application. For the specific content, reference can be made to the description in the method embodiments shown above in the embodiments of the present application, and details are not described herein again.
[0143] Please refer to Figure 9 , Figure 9 which is a schematic structural diagram of a computing device provided by an embodiment of the present application. As Figure 9 shown, the computing device 900 (which can be used to present the aforementioned first cloud instance or second cloud instance) includes: a processor 901, a memory 902, a communication interface 903, and a bus 904. The processor 901, the memory 902, and the communication interface 903 are coupled through a bus (not labeled in the figure). The memory 902 stores instructions. When the execution instructions in the memory 902 are executed, the computing device 900 executes the method executed by the cloud management platform in the above-mentioned method embodiments.
[0144] The computing device 900 may be one or more integrated circuits configured to implement the above methods. For example, one or more application specific integrated circuits (ASICs), or one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For another example, when the units in the device can be implemented in the form of a processing element scheduler, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processors that can call programs. For another example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0145] The processor 901 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0146] The memory 902 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0147] Executable program code is stored in the memory 902, and the processor 901 executes the executable program code to respectively implement the functions of the foregoing first protocol stack and the first application (or, the second protocol stack and the second application), etc., so as to implement the foregoing message processing method. That is to say, instructions for executing the foregoing message processing method are stored on the memory 902.
[0148] The communication interface 903 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 900 and other devices or a communication network.
[0149] In addition to including a data bus, the bus 904 may further include a power bus, a control bus, a status signal bus, etc. The bus may be a peripheral component interconnect express (PCIe) bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc. The bus may be divided into an address bus, a data bus, a control bus, etc.
[0150] Please refer to Figure 10 , Figure 10 which is a schematic structural diagram of a computing device cluster provided by an embodiment of the present application. As Figure 10 shown, the computing device cluster 1000 includes at least one computing device 900.
[0151] As Figure 10 shown, the computing device cluster 1000 includes at least one computing device 900. Instructions for executing the above message processing method may be stored in the memories 902 of one or more of the computing devices 900 in the computing device cluster 1000.
[0152] In some possible implementation manners, partial instructions for executing the above message processing method may also be separately stored in the memories 902 of one or more of the computing devices 900 in the computing device cluster 1000. In other words, a combination of one or more computing devices 900 may jointly execute for executing the above message processing method.
[0153] It should be noted that the memories 902 in different computing devices 900 in the computing device cluster 1000 may store different instructions, which are respectively used to execute partial functions of the above cloud management platform. That is, the instructions stored in the memories 902 of different computing devices 900 may implement the functions of one or more modules in the first protocol stack and the first application (or the second protocol stack and the second application).
[0154] In some possible implementation manners, one or more computing devices 900 in the computing device cluster 1000 may be connected through a network. Among them, the network may be a wide area network, a local area network, etc.
[0155] Please refer to Figure 11 , Figure 11A schematic diagram of the connection of computer devices in a computer cluster provided by an embodiment of the present application through a network. As Figure 11 shown, two computing devices 900A and 900B are connected through a network. Specifically, they are connected to the network through the communication interfaces in each computing device.
[0156] In a possible implementation, the memory in computing device 900A stores instructions for executing functions of modules such as a first protocol stack (or a second protocol stack), etc. At the same time, the memory in computing device 900B stores instructions for executing functions of modules such as a first application (or a second application), etc.
[0157] It should be understood that Figure 11 the functions of computing device 900A shown in
[0158] An embodiment of the present application also relates to a computer storage medium. The computer-readable storage medium stores a program for signal processing. When it runs on a computer, it causes the computer to execute the steps in the Figure 3 shown embodiment.
[0159] An embodiment of the present application also relates to a computer program product. The computer program product stores instructions. When the instructions are executed by a computer, it causes the computer to execute the steps in the Figure 3 shown embodiment.
[0160] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0161] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms.
[0162] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0163] In addition, each functional unit in various embodiments of the present application may be integrated into a processing unit, may exist separately as individual physical units, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0164] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.
Claims
1. A message processing method, characterized in that: The method is applied to a cloud service system, the cloud service system includes a first cloud instance and a second cloud instance, the first cloud instance includes a first application and a first protocol stack, and the method includes: The first application generates a first message header and a first inner message, embeds the first message header into the first inner message, obtains first data, and sends the first data to the first protocol stack; The first protocol stack parses the first data to obtain the first message header and the first inner message, and encapsulates the first inner message based on the first message header to obtain a first message; The first protocol stack sends the first message to the second cloud instance.
2. The method according to claim 1, characterized in that , the method further comprises: The first protocol stack receives a second message from the second cloud instance; The first protocol stack decapsulates the second message to obtain a second message header and a second inner message, and embeds the second message header into the second inner message to obtain second data, wherein the second inner message is obtained by the second cloud instance processing the first inner message, and the second message header is obtained by the second cloud instance processing the first message header; The first protocol stack sends the second data to the first application, so that the first application obtains and processes the second inner layer message from the second data.
3. The method according to claim 1 or 2, characterized in that The first message header includes a first Ethernet MAC header, a first network interconnection protocol IP header, a first user datagram protocol UDP header, and a first virtual extended local area network VXLAN header, wherein the first MAC header, the first IP header, and the first UDP header are used to indicate a communication channel with the first cloud instance as the source and the second cloud instance as the destination, and the first VXLAN header is used to indicate the first cloud instance.
4. The method according to claim 2 or 3, characterized in that The second message header includes a second MAC header, a second IP header, a second UDP header and a second VXLAN header, wherein the second MAC header, the second IP header and the second UDP header are used to indicate a communication channel with the second cloud instance as the source and the first cloud instance as the destination, and the second VXLAN header is used to indicate the first cloud instance.
5. The method according to any one of claims 1 to 4, characterized in that: The first data is a skb data structure or an mbuf data structure, the first inner layer message is set in a main area of the skb data structure or the mbuf data structure, and the first message header is set in a private data area of the skb data structure or the mbuf data structure.
6. The method according to any one of claims 1 to 5, characterized in that: The first cloud instance is any one of the following: a physical server, a bare metal server, a virtual machine, a container, and a micro virtual machine.
7. The method according to any one of claims 1 to 5, characterized in that: The first cloud instance is a cloud management platform, and the second cloud instance is located in a virtual private cloud VPC; or, The first cloud instance is located in the VPC, and the second cloud instance is a cloud management platform.
8. A message processing method, characterized in that: The method is applied to a cloud service system, the cloud service system includes a first cloud instance and a second cloud instance, the second cloud instance includes a second application and a second protocol stack, and the method includes: The second protocol stack receives a first message from the first cloud instance; The second protocol stack decapsulates the first message to obtain a first message header and a first inner message, and embeds the first message header into the first inner message to obtain first data; The second protocol stack sends the first data to the second application, so that the second application obtains and processes the first inner layer message from the first data.
9. The method according to claim 8, characterized in that , the method further comprises: The second application parses the first data to obtain the first message header and the first inner message, and processes the first inner message to obtain a second inner message; The second application embeds the first message header into a second inner layer message to obtain third data, and sends the third data to the second protocol stack; The second protocol stack parses the third data to obtain the first message header and the second inner message, and processes the first message header to obtain the second message header; The second protocol stack encapsulates the second inner layer message based on the second message header to obtain a second message, and sends the second message to the first cloud instance.
10. The method according to claim 8 or 9, characterized in that The second protocol stack embeds the first message header into the first inner message, and obtains the first data including: The second protocol stack obtains a preset message header from a cache area, and detects whether the first message header is legal based on the preset message header. If the first message header is legal, the second protocol stack embeds the first message header into the first inner layer message to obtain first data, wherein the preset message header comes from a third message sent by the first cloud instance, and the third message and the first message are handshake messages required by the first cloud instance and the second cloud instance in the process of establishing a connection.
11. The method according to claim 10, characterized in that , the method further comprises: If the first message header is illegal, the second protocol stack stops operating; or, If the first message header is illegal, the second protocol stack processes the first message header to obtain the second message header, and processes the first inner layer message to obtain a third inner layer message, where the third inner layer message is used to instruct the second cloud instance to refuse to establish a connection with the first cloud instance; The second protocol stack encapsulates the third inner layer message based on the second message header to obtain a fourth message, and sends the fourth message to the first cloud instance.
12. The method according to any one of claims 8 to 11, characterized in that The first message header includes a first MAC header, a first IP header, a first UDP header and a first VXLAN header, wherein the first MAC header, the first IP header and the first UDP header are used to indicate a communication channel with the first cloud instance as the source and the second cloud instance as the destination, and the first VXLAN header is used to indicate the first cloud instance.
13. The method according to any one of claims 9 to 11, characterized in that The second message header includes a second MAC header, a second IP header, a second UDP header and a second VXLAN header, wherein the second MAC header, the second IP header and the second UDP header are used to indicate a communication channel with the second cloud instance as the source and the first cloud instance as the destination, and the second VXLAN header is used to indicate the first cloud instance.
14. The method according to any one of claims 8 to 13, characterized in that: The first data is a skb data structure or an mbuf data structure, the first inner layer message is set in a main area of the skb data structure or the mbuf data structure, and the first message header is set in a private data area of the skb data structure or the mbuf data structure.
15. A cloud instance, characterized in that: The cloud instance is a first cloud instance, the first cloud instance is deployed in a cloud service system, the cloud service system further includes a second cloud instance, and the first cloud instance includes a first application and a first protocol stack; The first application is used to generate a first message header and a first inner message, embed the first message header into the first inner message, obtain first data, and send the first data to the first protocol stack; The first protocol stack is used to parse the first data to obtain the first message header and the first inner message, and encapsulate the first inner message based on the first message header to obtain the first message; The first protocol stack is further used to send the first message to the second cloud instance.
16. A cloud instance, characterized in that: The cloud instance serves as a second cloud instance, the second cloud instance is deployed in a cloud service system, the cloud service system further includes a first cloud instance, and the second cloud instance includes a second application and a second protocol stack; The second protocol stack is used to receive a first message from the first cloud instance; The second protocol stack is used to decapsulate the first message to obtain a first message header and a first inner message, and embed the first message header into the first inner message to obtain first data; The second protocol stack is further used to send the first data to the second application, so that the second application obtains and processes the first inner layer message from the first data.
17. A computing device cluster, characterized in that: The computing device cluster includes at least one computing device, each computing device including a processor and a memory: The memory is used to store instructions; The processor is configured to cause the computing device cluster to execute the method according to any one of claims 1 to 14 according to the instructions.
18. A computer storage medium, characterized in that: The computer storage medium stores one or more instructions, which, when executed by one or more computers, enable the one or more computers to implement the method of any one of claims 1 to 14.
19. A computer program product, characterized in that The computer program product stores instructions, which, when executed by a computer, enable the computer to implement the method according to any one of claims 1 to 14.