Communication method, system and device based on TUN interface and storage medium
By sharding and encapsulating data packets as packets that can be transmitted in the communication tunnel and using the TUN interface to transmit, the problem of insufficient compatibility of network virtualization solutions in cross-platform deployment is solved, and efficient and flexible network virtualization communication is achieved.
Patent Information
- Application Number
- CN202510375068.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-07-18
AI Technical Summary
The existing network virtualization solutions are insufficient in compatibility due to differences in vendor protocols during cross-platform deployment, making it difficult to flexibly adapt to various tunnel environments, resulting in limited transfer efficiency between physical networks and virtual networks.
By obtaining the original data packet to be processed, sharding and encapsulating it into messages that can be transmitted in the communication tunnel, and transmitting the messages to the communication tunnel through the TUN interface, dynamically adjusting the size and number of data units after sharding, adding tunnel protocol headers, supporting the deployment across heterogeneous network platforms, and establishing a data buffer management mechanism between user state and kernel state.
It significantly improves the communication efficiency between physical networks and virtual networks, realizes more efficient and flexible network virtualization communication, adapts to the requirements of different tunnel protocols, and overcomes the problem of limited delivery efficiency during cross-platform deployment.
Smart Images

Figure CN120342996A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and particularly to a communication method based on a TUN interface, a communication system based on a TUN interface, an electronic device, and a computer-readable storage medium. Background Art
[0002] With the wide application of network virtualization technologies, the communication requirements between physical networks and virtual networks are increasing. Existing network virtualization solutions typically use a tunnel (Tunnel, abbreviated as TUN) interface to implement the interaction between user space programs and the kernel network stack, and rely on tunnel protocols such as Generic Routing Encapsulation (GRE) or Virtual Extensible Local Area Network (VXLAN) to construct an overlay network to support the operation of multiple logical networks on the same physical infrastructure.
[0003] However, there are differences in protocol implementation and data processing methods among virtualization platforms provided by different vendors, resulting in insufficient compatibility when deploying network virtualization solutions across platforms. Existing methods mostly adopt a unified transmission process, making it difficult to flexibly adapt to various tunnel environments, and thus limiting the data transfer efficiency between physical networks and virtual networks. Summary of the Invention
[0004] In view of the above problems, embodiments of the present invention are proposed to provide a communication method based on a TUN interface, a communication system based on a TUN interface, an electronic device, and a computer-readable storage medium that overcome or at least partially solve the above problems.
[0005] To solve the above problems, embodiments of the present invention disclose a communication method based on a TUN interface, the method comprising:
[0006] Obtaining an original data packet to be processed;
[0007] Fragmenting and encapsulating the original data packet into a message that can be transmitted in a communication tunnel;
[0008] Transmitting the message to the communication tunnel through a TUN interface.
[0009] Optionally, the fragmenting and encapsulating the original data packet into a message that can be transmitted in a communication tunnel comprises:
[0010] Dynamically adjusting the size and quantity of the fragmented data units according to the bandwidth of the communication tunnel, and adding a tunnel protocol header to each data unit during encapsulation to generate the message.
[0011] Optionally, the fragmenting and encapsulating the original data packet into a message that can be transmitted in a communication tunnel includes:
[0012] Selecting a fragmentation strategy according to the type of the original data packet, and encapsulating the type identifier corresponding to the fragmentation strategy and the data unit into the message during encapsulation.
[0013] Optionally, before fragmenting and encapsulating the original data packet into a message that can be transmitted in a communication tunnel, the method further includes:
[0014] Performing content analysis on the original data packet, and marking the priority of the data unit according to the analysis result.
[0015] Optionally, transmitting the message to the communication tunnel through the TUN interface includes:
[0016] Transmitting the message to the TUN interface through a data buffer management mechanism established between the user space and the kernel space, and transmitting the message to the communication tunnel through the TUN interface.
[0017] Optionally, the communication tunnel supports deployment across heterogeneous network platforms and adapts to multiple virtualization environments through the TUN interface.
[0018] Optionally, obtaining the original data packet to be processed includes:
[0019] Receiving the original data packet from a user-space application, and preprocessing the original data packet.
[0020] An embodiment of the present invention also discloses a communication system based on a TUN interface, the system includes:
[0021] A data acquisition module, configured to acquire an original data packet to be processed;
[0022] A fragmentation and encapsulation module, configured to fragment and encapsulate the original data packet into a message that can be transmitted in a communication tunnel;
[0023] A message transmission module, configured to transmit the message to the communication tunnel through the TUN interface.
[0024] Optionally, the fragmentation and encapsulation module is configured to dynamically adjust the size and quantity of the fragmented data units according to the bandwidth of the communication tunnel, and add a tunnel protocol header to each data unit during encapsulation to generate the message.
[0025] Optionally, the fragmentation and encapsulation module is configured to select a fragmentation strategy according to the type of the original data packet, and encapsulate the type identifier corresponding to the fragmentation strategy and the data unit into the message during encapsulation.
[0026] Optionally, the system further includes:
[0027] A priority marking module, configured to perform content analysis on the original data packet before the fragmentation encapsulation module fragments and encapsulates the original data packet into a message that can be transmitted in the communication tunnel, and mark the priority of the data unit according to the analysis result.
[0028] Optionally, the message transmission module is configured to transmit the message to the TUN interface through a data buffer management mechanism established between the user space and the kernel space, and transmit the message to the communication tunnel through the TUN interface.
[0029] Optionally, the communication tunnel supports deployment across heterogeneous network platforms and adapts to multiple virtualization environments through the TUN interface.
[0030] Optionally, the data acquisition module is configured to receive the original data packet from a user space application and preprocess the original data packet.
[0031] An embodiment of the present invention also discloses an electronic device, including: one or more processors; and one or more machine-readable media storing instructions thereon, which when executed by the one or more processors cause the electronic device to execute the communication method based on the TUN interface as described above.
[0032] An embodiment of the present invention also discloses a computer-readable storage medium, the computer program stored thereon causing a processor to execute the communication method based on the TUN interface as described above.
[0033] The embodiment of the present invention has the following advantages:
[0034] The communication solution based on the TUN interface provided by the embodiment of the present invention obtains an original data packet to be processed; fragments and encapsulates the original data packet into a message that can be transmitted in the communication tunnel; and transmits the message to the communication tunnel through the TUN interface.
[0035] Compared with the background art, the embodiment of the present invention has the following beneficial effects:
[0036] In the embodiments of the present invention, by obtaining the original data packet to be processed, fragmenting it and encapsulating it into a message that can be transmitted in a communication tunnel, and transmitting it through the TUN interface, the communication efficiency between the physical network and the virtual network is significantly improved. Compared with the limitations in the background art, such as insufficient compatibility due to vendor protocol differences and the difficulty of adapting the unified transmission process to the tunnel environment, the embodiments of the present invention optimize the adaptability of the data packet through fragmentation processing, enabling it to flexibly meet the requirements of different tunnel protocols (such as GRE or VXLAN). At the same time, the TUN interface is used to efficiently transmit the message to the communication tunnel, overcoming the problem of limited transfer efficiency in the existing methods during cross-platform deployment, thus achieving more efficient and flexible network virtualization communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 is a flowchart of the steps of a communication method based on the TUN interface according to an embodiment of the present invention;
[0038] Figure 2 is a flowchart of the steps of a method for achieving efficient network virtualization using the TUN interface according to an embodiment of the present invention;
[0039] Figure 3 is a block diagram of the structure of a communication system based on the TUN interface according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0040] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0041] The embodiments of the present invention provide a communication solution based on the TUN interface. By obtaining the original data packet to be processed, fragmenting it and encapsulating it into a message that can be transmitted in a communication tunnel, and transmitting the message to the communication tunnel through the TUN interface, efficient communication between the physical network and the virtual network is achieved. When the embodiments of the present invention obtain the data packet, it is received from the user-space application and preprocessed. In the fragmentation and encapsulation stage, the size and quantity of the fragmented data units are dynamically adjusted according to the communication tunnel bandwidth, and the tunnel protocol header is added during encapsulation, or the fragmentation strategy is selected according to the data packet type and the corresponding type identifier is encapsulated. In the transmission stage, it is sent to the TUN interface through the data buffer management mechanism between the user space and the kernel space. In addition, the embodiments of the present invention support content analysis of the data packet before fragmentation and marking the priority of the fragmented data units, and adapting to the communication tunnel across heterogeneous network platforms, thereby improving communication flexibility and efficiency.
[0042] Refer to Figure 1, which shows the step flowchart of a communication method based on the TUN interface according to an embodiment of the present invention. This communication method based on the TUN interface can be applied to systems such as communication systems and network systems (hereinafter simply referred to as systems). The communication method based on the TUN interface specifically may include the following steps:
[0043] Step 101, obtain the original data packet to be processed.
[0044] The original data packet refers to the initial data unit generated or received by the user-mode application program in the system and has not been fragmented and encapsulated. Its content may include various types of data such as text, image, audio, or video. Specifically, through the data acquisition mechanism in the system, these original data packets are captured from the output interface of the user-mode application program. For example, in a network system, the application program may be video stream service software, and the original data packets generated by it contain continuous video frame data. In a communication system, it may be text data packets generated by an instant messaging application. The capture process usually involves the application program writing the data to a specified memory area through a system call, and then the relevant module of the communication method reads these data. To ensure data integrity, a basic integrity check is performed on the original data packet during the acquisition process, such as checking whether the header information of the data packet conforms to the expected format. In addition, the source of the original data packet to be processed is not limited. It may be locally generated data or relay data received from an external network and forwarded to the system. After the acquisition is completed, the original data packet is temporarily stored in the buffer of the system.
[0045] Step 102, fragment and encapsulate the original data packet into a message that can be transmitted in the communication tunnel.
[0046] The fragmentation process first divides the original data packet into multiple smaller data units according to the size of the original data packet and the characteristics of the communication tunnel. Specifically, when fragmenting, the maximum transmission unit (MTU) of the communication tunnel is considered to ensure that each fragmented data unit does not exceed the MTU limit. For example, if the original data packet is a 10MB video file and the MTU of the communication tunnel is 1500 bytes, then the data packet will be divided into multiple data units less than or equal to 1500 bytes. After fragmentation, each data unit remains independent, facilitating separate processing during subsequent transmission. Next, the encapsulation process converts these fragmented data units into packets that can be transmitted in the communication tunnel. This process includes adding necessary header information to each data unit, such as a tunnel protocol header (e.g., GRE or VXLAN header), to identify the destination address, protocol type, and sequence number of the data unit, ensuring that it can be correctly routed and reassembled in the communication tunnel. The encapsulated packet not only contains the content of the original data unit but also includes additional metadata to adapt it to the transmission requirements of the communication tunnel. For example, in the VXLAN scenario, the encapsulation adds a VXLAN header to the data unit, containing the virtual network identifier (VXLAN Network Identifier, VNI for short), to support network isolation in a multi-tenant environment. The entire fragmentation and encapsulation process is completed in the user space or kernel space of the system, depending on the implementation method, but usually utilizes the network protocol stack provided by the system to ensure the efficiency and accuracy of the operation.
[0047] Step 103, transmit the packet to the communication tunnel through the TUN interface.
[0048] As a virtual network device, the TUN interface operates at the network layer (the third layer of the Open Systems Interconnection (OSI) model) and can bridge the communication between user-space applications and the kernel network stack. In specific operations, the system first writes the encapsulated packet from the user-space buffer into the TUN interface. This process is achieved through a system call. The user-space program passes the packet data to the file descriptor of the TUN device, and then the kernel takes over and processes it. After receiving the packet, the TUN interface treats it as an IP packet and routes it according to the configuration of the communication tunnel. For example, if the communication tunnel is based on the GRE protocol, the TUN interface will send the packet into the pre-established GRE tunnel, and the attached GRE header will guide the packet to reach the target virtual network node through the physical network. During the transmission process, the TUN interface does not modify the packet content but only injects it into the entrance of the communication tunnel to ensure that the packet is forwarded according to the requirements of the tunnel protocol. To support efficient transmission, the system may configure specific network parameters for the TUN interface, such as IP addresses and routing rules, to match the starting settings of the communication tunnel. In addition, this step supports multiple tunnel protocols (such as GRE or VXLAN), enabling the packet to adapt to different virtual network environments, such as the VXLAN overlay network in a data center. After the transmission is completed, the packet leaves the TUN interface, enters the communication tunnel, and is finally received and processed by the other end of the tunnel, completing the data interaction between the physical network and the virtual network. The whole process ensures the efficiency and compatibility of communication.
[0049] The communication solution based on the TUN interface provided by the embodiment of the present invention obtains the original packet to be processed; fragments and encapsulates the original packet into a packet that can be transmitted in the communication tunnel; and transmits the packet to the communication tunnel through the TUN interface.
[0050] Compared with the background technology, the embodiment of the present invention has the following beneficial effects:
[0051] By obtaining the original packet to be processed, fragmenting and encapsulating it into a packet that can be transmitted in the communication tunnel, and transmitting it through the TUN interface, the embodiment of the present invention significantly improves the communication efficiency between the physical network and the virtual network. Compared with the limitations in the background technology, such as insufficient compatibility caused by vendor protocol differences and the difficulty of adapting the unified transmission process to the tunnel environment, the embodiment of the present invention optimizes the adaptability of the packet through fragmentation processing, enabling it to flexibly meet the requirements of different tunnel protocols (such as GRE or VXLAN). At the same time, it uses the TUN interface to efficiently transmit the packet to the communication tunnel, overcoming the problem of limited transfer efficiency in the existing methods during cross-platform deployment, thus achieving more efficient and flexible network virtualization communication.
[0052] In an exemplary embodiment of the present invention, an implementation manner of fragmenting an original data packet and encapsulating it into a message that can be transmitted in a communication tunnel is as follows: Dynamically adjust the size and number of the fragmented data units according to the bandwidth of the communication tunnel, and add a tunnel protocol header to each data unit during encapsulation to generate a message.
[0053] The bandwidth of a communication tunnel refers to the available transmission capacity of the tunnel in the current network environment, which is usually limited by the link speed of the physical network or the configuration parameters of the virtual network. During actual application, the system will monitor the bandwidth status in real time. For example, when the bandwidth is high (such as 1 Gbps), the original data packet can be divided into a smaller number of large-sized data units to reduce the fragmentation overhead. When the bandwidth is limited (such as 100 Mbps), the number of fragments is increased and the size of each data unit is reduced to avoid congestion. For example, a 5 MB original data packet may be divided into 10 data units of 500 KB under high bandwidth, while it may be divided into 50 data units of 100 KB under low bandwidth. This dynamic adjustment ensures that the size and number of data units match the transmission capacity of the communication tunnel. Subsequently, the encapsulation process converts each fragmented data unit into a message that can be transmitted in the communication tunnel. The specific operation is to add a tunnel protocol header in front of each data unit, such as the header of GRE or the header of VXLAN. The tunnel protocol header contains information such as the destination address, protocol identifier, and sequence number, which is used to guide the routing and recombination of the message in the communication tunnel. For example, in the VXLAN scenario, the system adds a header containing the VNI to each data unit to support multi-tenant isolation. After encapsulation, all data units and their protocol headers together form a complete message, which is ready to be transmitted to the communication tunnel through the TUN interface.
[0054] In this implementation manner, dynamically adjusting the size and number of the fragmented data units can adapt to the real-time bandwidth changes of the communication tunnel, avoiding the transmission congestion or resource waste that may be caused by the fixed fragmentation method. Adding a tunnel protocol header to each data unit ensures the correct transmission and compatibility of the message in the communication tunnel, thereby improving the communication efficiency and flexibility.
[0055] In an exemplary embodiment of the present invention, an implementation manner of fragmenting an original data packet and encapsulating it into a message that can be transmitted in a communication tunnel is as follows: Select a fragmentation strategy according to the type of the original data packet, and encapsulate the type identifier corresponding to the fragmentation strategy into the message during encapsulation.
[0056] The type of the original data packet refers to the content characteristics it carries, such as video stream, audio data, text message, or file transfer data. Different types of data packets have different requirements for transmission latency and integrity. Specifically, the system analyzes the header information or metadata of the original data packet to determine its type and then selects a suitable fragmentation strategy accordingly. For example, for video stream data packets with high real-time requirements, the system may choose a small-size, high-frequency fragmentation strategy, splitting a 1MB video data packet into 100 data units of 10KB each to reduce transmission latency; while for text data packets of large files, it may adopt a large-size, low-frequency fragmentation strategy, dividing it into 5 data units of 200KB each to reduce fragmentation overhead. After fragmentation, it enters the encapsulation stage. The system encapsulates each fragmented data unit together with the type identifier corresponding to the fragmentation strategy into a message. The type identifier is an additional metadata field used to record the information of the selected fragmentation strategy, such as indicating whether the data unit comes from a video stream or file transfer, facilitating the identification and processing by the receiving end of the communication tunnel. Finally, the encapsulated message contains the data unit, type identifier, and protocol header, fully adapting to the transmission requirements of the communication tunnel.
[0057] This implementation mode of selecting a fragmentation strategy according to the type of the original data packet can optimize the fragmentation process according to different data characteristics, and encapsulating the type identifier into the message provides a strategy basis for subsequent transmission and reception, thus improving the adaptability of the communication tunnel and the pertinence of data processing.
[0058] In an exemplary embodiment of the present invention, an implementation mode before fragmenting the original data packet and encapsulating it into a message that can be transmitted in the communication tunnel is: performing content analysis on the original data packet and marking the priority of the data unit according to the analysis result.
[0059] The system analyzes the header information or payload content of the original data packet to extract key features. For example, an original data packet containing real-time video conferencing data may be identified as high-priority due to its low-latency requirements, while an original data packet for bulk file transfer may be classified as low-priority due to its lower timeliness requirements. The analysis process is usually completed in the user space of the system, relying on preset analysis algorithms or rule libraries to determine the attributes of the data packet and ensure the accuracy and consistency of the results. Next, based on the results of the content analysis, the system marks the priority for the fragmented data units. This marking is metadata preset for the original data packet before fragmentation, indicating the processing order of its subsequent fragmented data units during transmission. For example, for an original data packet marked as high-priority, its fragmented data units may be assigned a higher position in the transmission queue, while low-priority data units are arranged behind. The marking information is usually appended to the metadata of the original data packet in the form of a field, such as a priority value (e.g., 1 represents high-priority, 0 represents low-priority), and is passed to each data unit during fragmentation and encapsulation.
[0060] Through the content analysis and priority marking of the original data packet, this implementation method can preset the transmission order for the data units before fragmentation and encapsulation, thereby optimizing the resource allocation and data flow management in the communication tunnel.
[0061] In an exemplary embodiment of the present invention, an implementation method for transmitting a packet to a communication tunnel through a TUN interface is as follows: Through a data buffer management mechanism established between the user space and the kernel space, the packet is transmitted to the TUN interface, and the packet is transmitted to the communication tunnel through the TUN interface.
[0062] The user space refers to the layer where the system runs user applications, while the kernel space is the layer where the core network stack of the operating system runs. Data transfer between the two usually needs to be completed through system calls. The data buffer management mechanism is a preset memory management strategy used to coordinate the data flow between the packets generated by user space applications and the TUN interface in the kernel space. For example, the system may allocate a shared buffer in the user space to store the encapsulated packets, and then transfer the buffer data to the kernel space through an efficient memory mapping or queue mechanism, avoiding frequent context switches. Next, the TUN interface receives these packets and processes them as IP data packets. After receiving the packet, the TUN interface injects it into the entrance of the communication tunnel according to the configuration of the communication tunnel (such as the destination address and protocol type). For example, if the communication tunnel is based on VXLAN, the TUN interface will send the packet into the VXLAN tunnel, and the VXLAN header of the packet will guide it to reach the virtual network node through the physical network.
[0063] This embodiment optimizes the transmission path of packets through the data buffer management mechanism between the user space and the kernel space, reducing the overhead of data interaction. The efficient injection of the TUN interface ensures that packets smoothly enter the communication tunnel, thereby enhancing the stability and efficiency of the transmission process.
[0064] In an exemplary embodiment of the present invention, the communication tunnel supports deployment across heterogeneous network platforms and adapts to various virtualization environments through the TUN interface.
[0065] This embodiment emphasizes that the communication tunnel supports deployment across heterogeneous network platforms. Heterogeneous network platforms refer to network infrastructures built by different vendors or technical standards. For example, a data center may simultaneously include physical servers based on traditional IP networks and virtualization clusters based on cloud services. The communication tunnel encapsulates packets to cross these platforms, enabling data interconnection between the physical network and the virtual network. In implementation, the communication tunnel can adopt various tunnel protocols, such as GRE or VXLAN, to adapt to different network architectures. For example, a GRE tunnel may connect a local enterprise network to a remote branch office, while a VXLAN tunnel is used for large-scale virtual machine communication within a data center. Subsequently, the TUN interface is used to achieve adaptation to various virtualization environments. As a virtual network device, the TUN interface operates at the network layer and can process packets generated by user-space applications and inject them into the communication tunnel. During the adaptation process, the TUN interface adjusts the transmission parameters of the packets according to the requirements of the virtualization environment. For example, it adds a VNI to packets in the VXLAN environment or configures specific routing rules for the GRE environment. Multiple configuration files are preset on the TUN interface to match the protocol requirements of different virtualization platforms. For example, in a hybrid cloud scenario, the TUN interface may support the transmission of VXLAN packets to the public cloud and GRE packets to the private cloud simultaneously, ensuring seamless packet delivery to the corresponding communication tunnel.
[0066] The ability of the communication tunnel to be deployed across heterogeneous network platforms in this embodiment expands the applicable scope of the method, while the adaptation of the TUN interface to various virtualization environments ensures compatible transmission of packets in different network architectures, thereby improving the flexibility and reliability of communication.
[0067] In an exemplary embodiment of the present invention, an embodiment of obtaining the original packet to be processed is: receiving the original packet from a user-space application and preprocessing the original packet.
[0068] A user-space application refers to software running in the system's user space, such as a video stream service, an instant messaging client, or a file transfer tool. The original data packets generated or received by these applications are the objects to be processed by the communication method. The receiving process is usually completed through interfaces provided by the system. For example, the application writes the original data packets into a shared memory area or passes them to the processing module of the communication method through a socket. For example, in a video conferencing system, the user-space application may be video capture software, and the original data packets it generates contain real-time audio and video data; in an enterprise network, it may be batch transfer data generated by a file sharing tool. The received original data packets may have different formats and sizes, but the embodiments of the present invention do not specifically limit their content, only ensuring that the data packets are completely captured. Subsequently, preprocessing of the original data packets is performed, which involves basic checks and preparatory work on the data packets to ensure their suitability for subsequent processing. Preprocessing may include verifying the integrity of the data packets (such as checking the header checksum), removing redundant fields (such as duplicate metadata), or adjusting the structure of the data packets (such as unifying the header format). For example, for an original data packet containing multiple segments of audio, preprocessing may remove invalid padding bytes to make it more compact and facilitate fragmentation.
[0069] Receiving the original data packets from the user-space application in this embodiment ensures wide compatibility of the data source, while preprocessing lays the foundation for subsequent fragmentation and encapsulation by optimizing the structure and integrity of the data packets, thereby improving the processing efficiency and stability of the communication method.
[0070] Based on the above relevant description of an embodiment of a communication method based on the TUN interface, a method for implementing efficient network virtualization using the TUN interface is introduced below. One of the purposes is to improve the communication efficiency between the physical network and the virtual network by optimizing the data processing and transmission processes, support the deployment across heterogeneous network platforms, and meet the business requirements of enterprise extended network architectures. This method can be applied to communication systems or network systems (hereinafter referred to as systems), and specifically includes the following steps:
[0071] Refer to Figure 2 , which shows the step flow chart of a method for implementing efficient network virtualization using the TUN interface according to an embodiment of the present invention.
[0072] Step 201, configure the TUN interface.
[0073] At system startup, the TUN interface is first created and configured as a virtual network device for interaction between the user space and the kernel space. The configuration process includes assigning network parameters such as an IP address, subnet mask, and routing rules to the TUN interface. For example, in a data center network, the TUN interface may be configured with an IP address of 192.168.1.10, a subnet mask of 255.255.255.0, and a routing rule pointing to the target network segment of the virtual network. These parameters ensure that the TUN interface can correctly receive packets generated by user space applications and inject them into the communication tunnel. After configuration, the TUN interface is in a ready state and ready to process subsequent data streams.
[0074] Step 202, obtain the original packet to be processed.
[0075] The system receives the original packet to be processed from the user space application and preprocesses it. The user space application may be a video stream service, a file transfer tool, or an instant messaging client, and the generated original packet contains various types of data, such as real-time audio and video or bulk files. The receiving process is completed through a system interface. For example, the application writes the original packet into a shared memory area, which is then captured by the processing module. The preprocessing includes verifying the integrity of the packet (such as checking the header checksum) or adjusting the structure (such as removing redundant fields) to provide reliable input for subsequent operations. For example, an audio packet may remove invalid padding bytes during preprocessing to optimize its fragmentation efficiency.
[0076] Step 203, perform content analysis on the original packet and mark the priority.
[0077] Before fragmentation and encapsulation, the system performs content analysis on the original packet and marks the priority of the data units after fragmentation according to the analysis results. The content analysis checks the type, timeliness, or business importance of the packet. For example, a real-time video packet is identified as high priority, and a file transfer packet is identified as low priority. The marking is attached in the form of metadata fields. For example, a value of "1" represents high priority, and "0" represents low priority. This priority information is passed to each data unit during subsequent fragmentation to provide a basis for the transmission order in the communication tunnel.
[0078] Step 204, fragment and encapsulate the original packet into a message that can be transmitted in the communication tunnel.
[0079] Dynamically adjust the size and quantity of the fragmented data units according to the bandwidth of the communication tunnel, and add the tunnel protocol header to each data unit during encapsulation to generate a message. Bandwidth monitoring evaluates the transmission capacity of the communication tunnel in real time. For example, at a 1Gbps bandwidth, a 5MB data packet is divided into 10 data units of 500KB, and at 100Mbps, it is divided into 50 data units of 100KB. During encapsulation, the tunnel protocol header of GRE or VXLAN is added to each data unit, containing information such as the destination address and sequence number. In addition, the system selects a fragmentation strategy according to the type of the original data packet (e.g., small-size and high-frequency fragmentation for video data packets), and encapsulates the data unit together with the type identifier corresponding to the fragmentation strategy into the message, such as the type field identifying the video stream, to support the receiving end to identify.
[0080] Step 205, establish a communication tunnel and implement security measures.
[0081] The system uses a tunnel protocol (such as GRE or VXLAN) through the TUN interface to establish a communication tunnel between the physical network and the virtual network. The appropriate protocol is selected during the establishment process. For example, VXLAN is used for the multi-tenant scenario in the data center, and GRE is used for enterprise VPN. Subsequently, encryption and authentication mechanisms are enabled for the communication tunnel, such as encrypting the message using the IPSec protocol, or using certificate verification to ensure that only authorized entities can access the data, ensuring secure transmission.
[0082] Step 206, transmit the message to the communication tunnel through the TUN interface.
[0083] The system transmits the message to the TUN interface through the data buffer management mechanism established between the user space and the kernel space. The buffer mechanism efficiently transfers the user-space message to the kernel space through shared memory or a queue, avoiding the overhead of context switching. After receiving the message, the TUN interface injects it into the tunnel entrance according to the configuration of the communication tunnel (such as the IP address and routing rules). For example, the VXLAN message is sent to the virtual network node in the data center. The communication tunnel supports deployment across heterogeneous network platforms and adapts to various virtualization environments through the TUN interface, such as the hybrid architecture of public and private clouds.
[0084] Step 207, traffic control and Quality of Service (QoS) settings.
[0085] During the message transmission process, the system sets the queue management rules based on priorities, arranges the data units according to priorities, and the high-priority data units are transmitted first. At the same time, apply the rate limit strategy to prevent a single data stream from occupying too much bandwidth. For example, limit the video data stream rate to 500Mbps to ensure the balanced distribution of mixed traffic.
[0086] Step 208, monitoring and maintenance.
[0087] The system continuously monitors the status of the communication tunnel, including traffic patterns, error rates, and latency. For example, if the detected latency exceeds 100 ms, an alarm is triggered. The security policy is updated regularly (such as changing the encryption key) and the network configuration is optimized (such as adjusting the TUN interface routing) to maintain efficient operation.
[0088] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.
[0089] Referring to Figure 3 , a structural block diagram of a communication system based on a TUN interface according to an embodiment of the present invention is shown. The communication system based on the TUN interface may specifically include the following modules.
[0090] A data acquisition module 31, configured to acquire the original data packets to be processed;
[0091] A fragmentation encapsulation module 32, configured to fragment and encapsulate the original data packets into packets that can be transmitted in the communication tunnel;
[0092] A packet transmission module 33, configured to transmit the packets to the communication tunnel through the TUN interface.
[0093] In an exemplary embodiment of the present invention, the fragmentation encapsulation module 32 is configured to dynamically adjust the size and quantity of the fragmented data units according to the bandwidth of the communication tunnel, and add a tunnel protocol header to each of the data units during encapsulation to generate the packets.
[0094] In an exemplary embodiment of the present invention, the fragmentation encapsulation module 32 is configured to select a fragmentation strategy according to the type of the original data packets, and encapsulate the type identifier corresponding to the fragmentation strategy of the data units into the packets during encapsulation.
[0095] In an exemplary embodiment of the present invention, the system further includes:
[0096] A priority marking module, configured to perform content analysis on the original data packets before the fragmentation encapsulation module 32 fragments and encapsulates the original data packets into packets that can be transmitted in the communication tunnel, and mark the priority of the data units according to the analysis results.
[0097] In an exemplary embodiment of the present invention, the packet transmission module 33 is configured to transmit the packet to the TUN interface through a data buffer management mechanism established between the user space and the kernel space, and transmit the packet to the communication tunnel through the TUN interface.
[0098] In an exemplary embodiment of the present invention, the communication tunnel supports deployment across heterogeneous network platforms and adapts to various virtualization environments through the TUN interface.
[0099] In an exemplary embodiment of the present invention, the data acquisition module 31 is configured to receive the original data packet from a user space application and preprocess the original data packet.
[0100] For the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For the relevant parts, refer to the partial description of the method embodiment.
[0101] Each embodiment in this specification is described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.
[0102] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0103] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, and the combination of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processors of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0104] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the functions specified in one process Figure 1 or more processes and / or blocks Figure 1 or more blocks.
[0105] These computer program instructions may also be loaded onto a computer or other programmable data processing terminal device, such that a series of operational steps are performed on the computer or other programmable terminal device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one process Figure 1 or more processes and / or blocks Figure 1 or more blocks.
[0106] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention.
[0107] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the element.
[0108] The above has introduced in detail a method for transmitting display content and a system for transmitting display content provided by the present invention. Specific examples are used in this text to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A communication method based on a TUN interface, characterized in that, The method includes: Obtain an original data packet to be processed; Fragment and encapsulate the original data packet into a message that can be transmitted in a communication tunnel; Transmit the message to the communication tunnel through a TUN interface.
2. The method according to claim 1, characterized in that, The fragmenting and encapsulating the original data packet into a message that can be transmitted in a communication tunnel includes: Dynamically adjust the size and quantity of the fragmented data units according to the bandwidth of the communication tunnel, and add a tunnel protocol header to each of the data units during encapsulation to generate the message.
3. The method according to claim 2, wherein The fragmenting and encapsulating the original data packet into a message that can be transmitted in a communication tunnel includes: Select a fragmentation strategy according to the type of the original data packet, and encapsulate a type identifier corresponding to the fragmentation strategy of the data unit into the message during encapsulation.
4. The method according to claim 2, characterized in that Before the fragmenting and encapsulating the original data packet into a message that can be transmitted in a communication tunnel, the method further includes: Perform content analysis on the original data packet, and mark the priority of the data units according to the analysis result.
5. The method according to claim 1, characterized in that, The transmitting the message to the communication tunnel through a TUN interface includes: Transmit the message to the TUN interface through a data buffer management mechanism established between the user space and the kernel space, and transmit the message to the communication tunnel through the TUN interface.
6. The method according to claim 1, wherein The communication tunnel supports deployment across heterogeneous network platforms and adapts to multiple virtualization environments through the TUN interface.
7. The method according to any one of claims 1 to 6, characterized in that, The obtaining an original data packet to be processed includes: Receive the original data packet from a user space application and preprocess the original data packet.
8. A communication system based on a TUN interface, characterized in that, The system includes: A data acquisition module for obtaining an original data packet to be processed; A fragmentation and encapsulation module for fragmenting and encapsulating the original data packet into a message that can be transmitted in a communication tunnel; A message transmission module for transmitting the message to the communication tunnel through a TUN interface.
9. An electronic device, characterized in that, Includes: One or more processors; And One or more machine-readable media storing instructions that, when executed by the one or more processors, cause the electronic device to execute the communication method based on a TUN interface according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer program stored therein causes the processor to execute the communication method based on a TUN interface according to any one of claims 1 to 7.