Cross-domain networking method and system based on cloud gateway, electronic equipment and storage medium
By building a multi-point cross-domain networking system in the cloud gateway architecture, and rewriting virtual network information using the access gateway and SRv6 protocol, the problem of inability to communicate between home users and enterprise users is solved, and mutual access and interoperability of multi-home intranets and edge application sharing is realized.
Patent Information
- Application Number
- CN202510436044.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-22
AI Technical Summary
In the cloud gateway architecture, home users and enterprise users are deployed in isolated network environments, resulting in direct intranet interoperability, which affects business system collaboration, especially home users' dynamic IP and enterprise strict security strategies, which increase the difficulty of interoperability.
By building a multi-point cross-domain networking system, access gateways are used to forward data between different edge clouds, and SRv6 protocol and QinQ information rewriting technology are used to realize data interoperability between home terminals. The access gateway obtains home network access data, rewritten virtual network information and generates SRv6 messages, parses and forwards to the target home terminal, simulates local home access, and realizes logical access to the same network element for multiple homes.
It realizes data forwarding between different edge clouds and mutual access between home terminals, meets the needs of smart home, industrial Internet of Things and operator services, and meets the requirements of elastic expansion, nearby computing and secure isolation.
Smart Images

Figure CN120358184A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data communication technologies, and in particular, to a cross-domain networking method based on a cloud gateway, a multi-point cross-domain networking system, an electronic device, and a computer-readable storage medium. Background Art
[0002] In the current cloud gateway architecture, 2H (To Home, home users) and 2B (To Business, enterprise users) are usually deployed in mutually isolated network environments, such as different VPCs (Virtual Private Clouds) or security domains, resulting in the inability of the two to directly communicate through the internal network, affecting the collaboration of business systems. In the corresponding technologies, due to the inability to balance security, flexibility, and low cost, especially the dynamic IPs of home users and the strict security policies of enterprises, etc., further exacerbate the difficulty of communication. Summary of the Invention
[0003] Embodiments of the present invention provide a cross-domain networking method, system, electronic device, and computer-readable storage medium based on a cloud gateway to solve or partially solve the problem that different users in the cloud gateway cannot achieve internal network communication and business system communication.
[0004] Embodiments of the present invention disclose a cross-domain networking method based on a cloud gateway, which is applied to a multi-point cross-domain networking system. The multi-point cross-domain networking system at least includes several edge clouds, an access gateway located in the edge clouds, and a home terminal accessing the access gateway. Among them, the access gateway at least includes a first access gateway and a second access gateway, and the first access gateway and the second access gateway are respectively located in different edge clouds. The method includes:
[0005] The first access gateway obtains home network access data sent by a source home terminal. The home network access data at least includes an access request, first virtual network information, and a first IP identifier.
[0006] The first access gateway rewrites the first virtual network information into second virtual network information matching the first IP identifier, and generates a first SRv6 packet corresponding to the home network access data.
[0007] The second access gateway parses the first SRv6 packet sent by the first access gateway, and extracts the access request, the second virtual network information, and the first IP identifier in the first SRv6 packet.
[0008] The second access gateway sends the access request to a first target home terminal corresponding to the first IP identifier according to the second virtual network information and the first IP identifier.
[0009] In some feasible implementation manners, the first virtual network information is first QinQ information, the second virtual network information is second QinQ information, and the rewriting the first virtual network information into second virtual network information matching the first IP identifier and generating a first SRv6 packet corresponding to the home network access data includes:
[0010] Rewrite the first QinQ information into second QinQ information matching the first IP identifier, and generate a first SRv6 packet corresponding to the home network access data.
[0011] In some feasible implementation manners, the rewriting the first QinQ information into second QinQ information matching the first IP identifier and generating a first SRv6 packet corresponding to the home network access data includes:
[0012] Obtain an IP matching forwarding table, where the IP matching forwarding table includes a mapping relationship between an IP identifier, QinQ information, and a forwarding path identifier;
[0013] Match the first IP identifier with the mapping relationship in the IP matching forwarding table to determine the second QinQ information and the first target forwarding path corresponding to the first IP identifier;
[0014] Rewrite the first QinQ information in the home network access data into the second QinQ information;
[0015] Encapsulate the access request, the second QinQ information, and the first IP identifier into a first SRv6 packet, and send the first SRv6 packet to the second access gateway according to the first target forwarding path.
[0016] In some feasible implementation manners, the edge cloud further includes a service gateway communicatively connected to the access gateway, and at least one edge application communicatively connected to the service gateway; wherein, the access gateway further includes a third access gateway, and the method further includes:
[0017] The first access gateway obtains edge application usage data sent by a source home terminal, and the edge application usage data at least includes an access request, second virtual network information, and a second IP identifier;
[0018] The first access gateway rewrites the second virtual network information into third virtual network information matching the second IP identifier, and generates a second SRv6 packet corresponding to the edge application usage data;
[0019] The third access gateway analyzes the second SRv6 packet sent by the first access gateway, and extracts the access request, the third virtual network information, and the second IP identifier in the second SRv6 packet;
[0020] The third access gateway locates the target edge application corresponding to the third virtual network information and the second IP identifier, and sends the application usage request to the target edge application;
[0021] Wherein, the third access gateway, the target service gateway, and the target edge application are located in the same edge cloud.
[0022] In some feasible implementation manners, the first virtual network information is the first QinQ information, the third virtual network information is the third QinQ information, and the rewriting the second virtual network information into the third virtual network information matching the second IP identifier and generating a second SRv6 packet corresponding to the edge application usage data includes:
[0023] Rewrite the first QinQ information into the third QinQ information matching the second IP identifier, and generate a second SRv6 packet corresponding to the edge application usage data.
[0024] In some feasible implementation manners, the rewriting the first QinQ information into the third QinQ information matching the second IP identifier and generating a second SRv6 packet corresponding to the edge application usage data includes:
[0025] Obtain an IP matching forwarding table, where the IP matching forwarding table includes the mapping relationship between the IP identifier, the QinQ information, and the forwarding line identifier;
[0026] Match the second IP identifier with the mapping relationship in the IP matching forwarding table to determine the third QinQ information and the second target forwarding line corresponding to the second IP identifier;
[0027] Rewrite the first QinQ information in the edge application usage data into the third QinQ information;
[0028] Encapsulate the application usage request, the third QinQ information, and the second IP identifier into a second SRv6 packet, and send the second SRv6 packet to the third access gateway according to the second target forwarding line.
[0029] In some feasible implementation manners, it further includes:
[0030] The access gateway assigns a corresponding IP identifier to the accessed home terminal;
[0031] Among them, different home terminals correspond to different IP identifiers, and the IP identifiers are not repeated with the IP identifiers corresponding to the edge applications in the edge cloud.
[0032] An embodiment of the present invention also discloses a multi-point cross-domain networking system. The multi-point cross-domain networking system at least includes a plurality of edge clouds, an access gateway located in the edge clouds, and home terminals accessing the access gateway; among them, the access gateway at least includes a first access gateway and a second access gateway, and the first access gateway and the second access gateway are respectively located in different edge clouds; among them,
[0033] The first access gateway is configured to obtain home network access data sent by a source home terminal. The home network access data at least includes an access request, first virtual network information, and a first IP identifier.
[0034] The first access gateway is configured to rewrite the first virtual network information into second virtual network information matching the first IP identifier, and generate a first SRv6 packet corresponding to the home network access data.
[0035] The second access gateway is configured to analyze the first SRv6 packet sent by the first access gateway, and extract the access request, the second virtual network information, and the first IP identifier in the first SRv6 packet.
[0036] The second access gateway is configured to send the access request to a first target home terminal corresponding to the first IP identifier according to the second virtual network information and the first IP identifier.
[0037] In some feasible implementation manners, the first virtual network information is first QinQ information, and the second virtual network information is second QinQ information; among them,
[0038] The first access gateway is configured to rewrite the first QinQ information into second QinQ information matching the first IP identifier, and generate a first SRv6 packet corresponding to the home network access data.
[0039] In some feasible implementation manners, the first access gateway is specifically configured to:
[0040] Obtain an IP matching forwarding table, where the IP matching forwarding table includes a mapping relationship between an IP identifier, QinQ information, and a forwarding line identifier;
[0041] Match the first IP identifier with the mapping relationship in the IP matching forwarding table to determine second QinQ information and a first target forwarding line corresponding to the first IP identifier;
[0042] Rewrite the first QinQ information in the home network access data as the second QinQ information;
[0043] Encapsulate the access request, the second QinQ information, and the first IP identifier into a first SRv6 packet, and send the first SRv6 packet to the second access gateway according to the first target forwarding path.
[0044] In some possible implementation manners, the edge cloud further includes a service gateway communicatively connected to the access gateway, and at least one edge application communicatively connected to the service gateway; wherein, the access gateway further includes a third access gateway; wherein,
[0045] The first access gateway is configured to obtain edge application usage data sent by a source home terminal, where the edge application usage data at least includes an access request, second virtual network information, and a second IP identifier;
[0046] The first access gateway is configured to rewrite the second virtual network information as third virtual network information matching the second IP identifier, and generate a second SRv6 packet corresponding to the edge application usage data;
[0047] The third access gateway is configured to parse the second SRv6 packet sent by the first access gateway, and extract the access request, the third virtual network information, and the second IP identifier in the second SRv6 packet;
[0048] The third access gateway is configured to locate a target edge application corresponding to the third virtual network information and the second IP identifier, and send the application usage request to the target edge application;
[0049] Wherein, the third access gateway, the target service gateway, and the target edge application are located in the same edge cloud.
[0050] In some possible implementation manners, the first virtual network information is first QinQ information, and the third virtual network information is third QinQ information; wherein,
[0051] The first access gateway is configured to rewrite the first QinQ information as third QinQ information matching the second IP identifier, and generate a second SRv6 packet corresponding to the edge application usage data.
[0052] In some possible implementation manners, the first access gateway is specifically configured to:
[0053] Obtain an IP matching forwarding table, where the IP matching forwarding table includes the mapping relationship between the IP identifier, QinQ information, and the forwarding path identifier;
[0054] Match the second IP identifier with the mapping relationship in the IP matching forwarding table to determine the corresponding third QinQ information and the second target forwarding path for the second IP identifier;
[0055] Rewrite the first QinQ information in the edge application usage data as the third QinQ information;
[0056] Encapsulate the application usage request, the third QinQ information, and the second IP identifier into a second SRv6 packet, and send the second SRv6 packet to the third access gateway according to the second target forwarding path.
[0057] In some possible implementation manners, it further includes:
[0058] The access gateway is used to allocate corresponding IP identifiers to the accessed home terminals;
[0059] Wherein, different home terminals correspond to different IP identifiers, and the IP identifiers do not repeat with the IP identifiers corresponding to the edge applications in the edge cloud.
[0060] An embodiment of the present invention also discloses an electronic device, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus;
[0061] The memory is used to store a computer program;
[0062] When the processor is used to execute the program stored in the memory, it implements the method as described in the embodiment of the present invention.
[0063] An embodiment of the present invention also discloses a computer-readable storage medium, on which instructions are stored. When executed by one or more processors, the instructions cause the processors to execute the method as described in the embodiment of the present invention.
[0064] The embodiments of the present invention have the following advantages:
[0065] In an embodiment of the present invention, it is applied to a multi-point cross-domain networking system. The multi-point cross-domain networking system at least includes several edge clouds, an access gateway located in the edge cloud, and a home terminal connected to the access gateway. Among them, the access gateway at least includes a first access gateway and a second access gateway. The first access gateway and the second access gateway are respectively located in different edge clouds. During the process of multi-point cross-domain networking, when one home terminal conducts data interaction with another home terminal, the first access gateway obtains the home network access data sent by the source home terminal. The home network access data at least includes an access request, first virtual network information, and a first IP identifier, and rewrites the first virtual network information into second virtual network information that matches the first IP identifier, and generates a first SRv6 packet corresponding to the home network access data. Then, the first SRv6 packet is sent to the second access gateway. The second access gateway parses the first SRv6 packet sent by the first access gateway, extracts the access request, second virtual network information, and first IP identifier in the first SRv6 packet, and then sends the access request to the first target home terminal corresponding to the first IP identifier according to the second virtual network information and the first IP identifier. Thus, data forwarding can be performed between the access gateways of different edge clouds through SRv6, and when mutual access is performed between different home terminals, by rewriting the virtual network data, accessing is simulated as if it were a local home, realizing that multiple homes are logically connected to the same network element, building a multi-home internal network, and achieving mutual access and intercommunication. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] Figure 1 is a flowchart of the steps of a cross-domain networking method based on a cloud gateway provided in an embodiment of the present invention;
[0067] Figure 2 is a schematic diagram of the system architecture provided in an embodiment of the present invention;
[0068] Figure 3 is a schematic diagram of multi-home mutual access traffic provided in an embodiment of the present invention;
[0069] Figure 4 is a schematic diagram of multi-home shared edge application traffic provided in an embodiment of the present invention;
[0070] Figure 5 is a block diagram of the structure of a multi-point cross-domain networking system provided in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0071] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0072] As an example, in the current cloud gateway architecture, 2H and 2B are usually deployed in isolated network environments, such as different VPCs or security domains, resulting in the inability to directly communicate with each other within the intranet and affecting the coordination of business systems. In the corresponding technologies, due to the inability to balance security, flexibility, and low cost, especially the dynamic IPs of home users and the strict security policies of enterprises, etc., further exacerbate the difficulty of intercommunication.
[0073] In response to this, in the present invention, by constructing a multi-point cross-domain networking system, data intercommunication between different virtual local area networks can be achieved through this multi-point cross-domain networking system. Specifically, the multi-point cross-domain networking system at least includes several edge clouds, an access gateway located in the edge clouds, and a home terminal connected to the access gateway; wherein, the access gateway at least includes a first access gateway and a second access gateway, and the first access gateway and the second access gateway are respectively located in different edge clouds. During the process of multi-point cross-domain networking, when one home terminal conducts data interaction with another home terminal, the first access gateway obtains the home network access data sent by the source home terminal. The home network access data at least includes an access request, a first virtual network information, and a first IP identifier, and rewrites the first virtual network information into a second virtual network information that matches the first IP identifier, and generates a first SRv6 packet corresponding to the home network access data, and then sends the first SRv6 packet to the second access gateway. The second access gateway parses the first SRv6 packet sent by the first access gateway, extracts the access request, the second virtual network information, and the first IP identifier in the first SRv6 packet, and then sends the access request to the first target home terminal corresponding to the first IP identifier according to the second virtual network information and the first IP identifier. Thus, data forwarding can be performed between the access gateways of different edge clouds through SRv6, and when mutual access between different home terminals is carried out, by rewriting the virtual network data, it simulates local home access, realizes that multiple homes are logically connected to the same network element, constructs a multi-home intranet, and realizes mutual access and intercommunication.
[0074] To enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, some technical features involved in the embodiments of the present invention are explained and described below:
[0075] SRv6 (Segment Routing IPv6, segment routing based on the IPv6 forwarding plane) simply means SR (Segment Routing) + IPv6. It is a new generation of IP bearer protocol. It adopts the existing IPv6 forwarding technology and realizes network programmability through flexible IPv6 extension headers.
[0076] DHCP (Dynamic Host Configuration Protocol) is a network management protocol used to centrally manage and dynamically configure user IP addresses.
[0077] VLAN (Virtual Local Area Network) is a communication technology that logically divides a physical LAN into multiple broadcast domains.
[0078] QinQ (802.1Q-in-802.1Q), also known as VLAN Stacking or Double VLAN, is defined by the IEEE802.1ad standard. It is a technology for expanding VLAN space by adding another 802.1Q tag to the 802.1Q tagged message.
[0079] Specifically, refer to Figure 1 , shows a flow chart of steps of a cross-domain networking method based on a cloud gateway provided in an embodiment of the present invention, which is applied to a multi-point cross-domain networking system, wherein the multi-point cross-domain networking system includes at least a plurality of edge clouds, an access gateway located in the edge cloud, and a home terminal accessing the access gateway; wherein the access gateway includes at least a first access gateway and a second access gateway, wherein the first access gateway and the second access gateway are located in different edge clouds respectively, and specifically may include the following steps:
[0080] Step 101: The first access gateway obtains home network access data sent by a source home terminal, where the home network access data at least includes an access request, first virtual network information, and a first IP identifier;
[0081] In an embodiment of the present invention, the multi-point cross-domain networking system can be a distributed network architecture, which realizes cross-regional, multi-tenant low-latency interconnection and resource sharing by integrating edge cloud, access gateway and home terminals. Through this multi-point cross-domain networking system, the problem of data intercommunication between 2H and 2B can be effectively solved, and the needs of smart home, industrial Internet of Things, operator business and other scenarios for elastic expansion, local computing and secure isolation can be met.
[0082] Among them, the edge cloud can be deployed at a geographical location close to users (such as a metropolitan data center, the base station side, etc.) and is used to provide computing, storage, and network functions, such as the operator's MEC (Multi-access Edge Computing) platform, public cloud edge nodes, etc.; the access gateway can be the connection hub between the edge cloud and the home terminal, such as a virtualized or hardware device (such as vCPE, etc.), and is used for protocol conversion (compatible with various access methods of home terminals), service isolation (assigning independent network slices to different homes through VLAN / VXLAN), and security control (firewall, intrusion detection), etc.; the home terminal can be a device or subsystem on the user side, etc. The home terminal can be located in the home network, such as smart home, home gateway, personal terminal, etc. It can be connected to the access gateway in a direct connection (accessing the edge cloud gateway through 5G / Wi-Fi) or an indirect connection (aggregating through the home gateway and then uploading). The present invention does not limit this.
[0083] In some feasible implementation manners, for each home terminal in the multi-point cross-domain networking system, the access gateway can allocate corresponding IP identifiers to each home terminal connected to the access gateway, and distinguish different home terminals through these IP identifiers. Among them, different home terminals can correspond to different IP identifiers to avoid access conflicts. At the same time, there can be at least one edge application in the edge cloud, and different edge applications can also correspond to different IP identifiers. Then, in order to further avoid address conflicts between the home terminal and the edge application, the IP identifiers between the edge application and the home terminal are also different, so that there is no repetition between the IP identifier corresponding to the home terminal and the IP identifier of the edge application.
[0084] For the multi-point cross-domain networking system, cross-domain interconnection and mutual access can be achieved between different home terminals, and sharing of edge applications can also be achieved. For example, home terminal ① located in virtual local area network A can achieve interconnection and mutual access with home terminal ② in virtual local area network B through the multi-point cross-domain networking system; home terminal ① located in virtual local area network A, which is connected to access gateway 1 of edge cloud Ⅰ, can achieve access to edge application a in edge cloud Ⅱ through the multi-point cross-domain networking system, etc. The present invention does not limit this.
[0085] For the scenario of mutual access between multiple households, assume that the edge clouds involved in the mutual access are the first edge cloud and the second edge cloud. Among them, the household terminal that initiates the mutual access request is used as the source household terminal, and the household terminal to be accessed is used as the target household terminal. Then, the source household terminal can initiate a corresponding access request through the first access gateway in the first edge cloud. The first access gateway can obtain the home network access data sent by the source household terminal. The home network access data at least includes an access request, first virtual network information, and a first IP identifier, so as to process the home network access data.
[0086] It should be noted that the virtual network information can be used to isolate users in the operator network. It can be used to distinguish different users and can be used to isolate the virtual networks of different customers in a multi-tenant environment. In addition, the IP identifier can be an IP address and is used to determine the access address corresponding to the target object.
[0087] Step 102, the first access gateway rewrites the first virtual network information into second virtual network information that matches the first IP identifier, and generates a first SRv6 packet corresponding to the home network access data;
[0088] After the first access gateway extracts the first virtual network information corresponding to the source household terminal from the home network access data, it can rewrite it into second virtual network information that matches the first IP identifier. By rewriting the virtual network data, it simulates the access of the local household, realizes that multiple households are logically connected to the same network element, and then generates a corresponding first SRv6 packet to perform data communication in different edge clouds through the SRv6 protocol.
[0089] Among them, the first virtual network information can be the first QinQ information, and the second virtual network information can be the second QinQ information. Then, the first access gateway can rewrite the first QinQ information into the second QinQ information that matches the first IP identifier, and generate a first SRv6 packet corresponding to the home network access data, thereby simulating the access of the local household by rewriting the QinQ information, realizing that multiple households are logically connected to the same network element, and enabling cross-domain mutual access and interconnection between different household terminals.
[0090] It should be noted that QinQ (802.1Q-in-802.1Q) is a double VLAN tagging technology mainly used to expand the number of VLANs and achieve user service isolation in the carrier network. Its core principle is as follows: Outer tag (Service VLAN, S-Tag): Assigned by the carrier, identifying different customers or service types (such as home broadband, enterprise dedicated line); Inner tag (Customer VLAN, C-Tag): User-defined, used for VLAN division within the enterprise or home network; Encapsulation method: Another layer of carrier VLAN tag (S-Tag) is encapsulated outside the VLAN tag (C-Tag) of the original Ethernet frame, forming a structure of [outer S-Tag][inner C-Tag][data].
[0091] In some feasible implementation manners, the first access gateway can obtain an IP matching forwarding table, which includes the mapping relationship between the IP identifier, QinQ information, and the forwarding line identifier. Then, it matches the first IP identifier with the mapping relationship in the IP matching forwarding table to determine the corresponding second QinQ information and the first target forwarding line, rewrite the first QinQ information in the home network access data as the second QinQ information, and then encapsulate the access request, the second QinQ information, and the first IP identifier into a first SRv6 packet, and send the first SRv6 packet to the second access gateway according to the first target forwarding line. Thus, by rewriting the QinQ information, it simulates local home access, realizes that multiple homes are logically connected to the same network element, and enables cross-domain interconnection and intercommunication between different home terminals.
[0092] Step 103: The second access gateway parses the first SRv6 packet sent by the first access gateway, and extracts the access request, the second virtual network information, and the first IP identifier in the first SRv6 packet.
[0093] In a specific implementation, after receiving the first SRv6 packet sent by the first access gateway, the second access gateway can parse the first SRv6 packet to extract the corresponding access request, second virtual network information, first IP identifier, etc., so as to further send the access request to the corresponding home terminal. Among them, the second virtual network information can be the second QinQ information.
[0094] Step 104: The second access gateway sends the access request to the first target home terminal corresponding to the first IP identifier according to the second virtual network information and the first IP identifier.
[0095] After parsing to obtain corresponding access requests, second QinQ information, first IP identifier and other information, the second access gateway can locate the first target home terminal accessing the second access gateway according to the second QinQ information and the first IP identifier, and then send the access request to the first target home terminal according to the corresponding communication link, so that data forwarding can be performed between the access gateways of different edge clouds through SRv6. When mutual access is performed between different home terminals, by rewriting the virtual network data, it simulates access from a local home, realizing that multiple homes are logically connected to the same network element, building a multi-home intranet, and achieving mutual access and intercommunication.
[0096] In addition, for the multi-home edge application sharing scenario, the edge cloud may further include a service gateway communicatively connected to the access gateway, and at least one edge application communicatively connected to the service gateway; wherein, the access gateway further includes a third access gateway. In the edge application sharing scenario, the first access gateway obtains edge application usage data sent by the source home terminal, and the edge application usage data at least includes an access request, second virtual network information, and a second IP identifier. Then, the second virtual network information is rewritten as third virtual network information matching the second IP identifier, and a second SRv6 packet corresponding to the edge application usage data is generated and sent to the third access gateway. The third access gateway parses the second SRv6 packet sent by the first access gateway, extracts the access request, third virtual network information, and second IP identifier in the second SRv6 packet, then locates the target edge application corresponding to the third virtual network information and the second IP identifier, and sends an application usage request to the target edge application. Among them, the third access gateway, the target service gateway, and the target edge application are located in the same edge cloud.
[0097] In a specific implementation, the first virtual network information may be the first QinQ information, and the third virtual network information may be the third QinQ information. Then, the first access gateway can rewrite the first QinQ information as the third QinQ information matching the second IP identifier, and generate a second SRv6 packet corresponding to the edge application usage data.
[0098] In some feasible implementation manners, the first access gateway may obtain an IP matching forwarding table, where the IP matching forwarding table includes the mapping relationship between the IP identifier, the QinQ information, and the forwarding path identifier. Then, the second IP identifier is matched with the mapping relationship in the IP matching forwarding table to determine the third QinQ information and the second target forwarding path corresponding to the second IP identifier. Next, the first QinQ information in the edge application usage data is rewritten as the third QinQ information. Then, the application usage request, the third QinQ information, and the second IP identifier are encapsulated into a second SRv6 packet, and the second SRv6 packet is sent to the third access gateway according to the second target forwarding path. Thus, data can be forwarded between the access gateways of different edge clouds through SRv6. When mutual access is performed between different home terminals, by rewriting the virtual network data, accessing is simulated as if it were a local home, enabling multiple homes to be logically connected to the same network element, building a multi-home internal network, and achieving mutual access and intercommunication.
[0099] It should be noted that the embodiments of the present invention include but are not limited to the above examples. It can be understood that those skilled in the art can also make settings according to actual requirements under the guidance of the ideas of the embodiments of the present invention, and the present invention places no restrictions thereon.
[0100] In the embodiments of the present invention, it is applied to a multi-point cross-domain networking system. The multi-point cross-domain networking system at least includes several edge clouds, access gateways located in the edge clouds, and home terminals connected to the access gateways. Among them, the access gateways at least include a first access gateway and a second access gateway. The first access gateway and the second access gateway are respectively located in different edge clouds. During the multi-point cross-domain networking process, when one home terminal performs data interaction with another home terminal, the first access gateway obtains the home network access data sent by the source home terminal. The home network access data at least includes an access request, first virtual network information, and a first IP identifier. Then, the first virtual network information is rewritten as second virtual network information that matches the first IP identifier, and a first SRv6 packet corresponding to the home network access data is generated. Then, the first SRv6 packet is sent to the second access gateway. The second access gateway parses the first SRv6 packet sent by the first access gateway, extracts the access request, the second virtual network information, and the first IP identifier in the first SRv6 packet, and then sends the access request to the first target home terminal corresponding to the first IP identifier according to the second virtual network information and the first IP identifier. Thus, data can be forwarded between the access gateways of different edge clouds through SRv6. When mutual access is performed between different home terminals, by rewriting the virtual network data, accessing is simulated as if it were a local home, enabling multiple homes to be logically connected to the same network element, building a multi-home internal network, and achieving mutual access and intercommunication.
[0101] To enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, the following provides exemplary descriptions through corresponding examples:
[0102] For a multi-point cross-domain networking system, access gateways in different edge clouds can communicate with each other through SRv6 forwarding. Specifically: The access gateway assigns different DHCP address pools corresponding to different network segments for the communicating households to ensure that IPs do not conflict when households access each other; the access gateway rewrites the source household QinQ to the destination household's QinQ and then forwards it through SRv6, and matches the forwarding path according to the destination IP; the peer access gateway parses the SRv6 packet, identifies the rewritten QinQ, and forwards it as local household traffic, applying the traffic forwarding service gateway, and forwarding the traffic to the local household side in the mutual access process; the service gateway receives the rewritten QinQ and forwards it as local household traffic, and the original service process remains unchanged. Optionally, the IP planning requirements are: The IPs assigned to terminals within a household cannot be repeated with the IPs in the MEC application pool; the application service IPs within the edge cloud are globally planned.
[0103] As an example, referring to Figure 2 , a schematic diagram of the system architecture provided in the embodiments of the present invention is shown. In a multi-point cross-domain networking system, there can be several Pod nodes and multiple edge clouds. The Pod nodes can include corresponding household terminals and related network elements (such as vbras, Sleaf, Spine, Aleaf, and DC-Leaf, etc.), and the edge clouds can include access gateways, service gateways, and application systems (edge applications), etc. Among them, for the data transmission route of household terminals, it can include accessing the Internet ( Figure 2 the solid line path shown), mutual access between multiple households ( Figure 2 the dotted line path shown), and accessing applications across edge clouds ( Figure 2 the bold line path shown), etc.
[0104] Among them, the path for a household terminal to access the Internet can be: household terminal - edge cloud (access gateway) - Internet; the path for mutual access between multiple households can be: household terminal ① - edge cloud Ⅰ (access gateway 1) - edge cloud Ⅱ (access gateway 2) - household terminal ②; the path for accessing applications across edge clouds can be: household terminal ① - edge cloud Ⅰ (access gateway 1) - edge cloud Ⅱ (access gateway 2) - edge cloud Ⅱ (service gateway) - application system, etc. Thus, access gateways between different edge clouds can forward data through SRv6, and when mutual access occurs between different household terminals, by rewriting the virtual network data, it simulates local household access, realizing that multiple households are logically connected to the same network element, building a multi-household internal network, and achieving mutual access and interconnection.
[0105] For example, referring to Figure 3As shown, it shows the schematic diagram of the traffic for multi-family interconnection and mutual access in the embodiments of the present invention. In the scenario of multi-family interconnection and mutual access, the corresponding traffic transmission can be as follows:
[0106] For the process from Home A - Terminal A to Home B - Terminal B:
[0107] ① The traffic reaches Access Gateway 1
[0108] Match the forwarding table according to the destination IP: The IP belongs to Home B, and the forwarding direction is loopback - IP1;
[0109] Search for the line identifier of Home B, rewrite the qinq as the qinq of Home B, and send it out from loopback - IP1.
[0110] ② The traffic reaches Access Gateway 2
[0111] Match the forwarding rule, and the outgoing IP direction is vpws - lan2.
[0112] For the process from Home B - Terminal B to Home A - Terminal A:
[0113] ① The traffic reaches Access Gateway 2
[0114] Match the forwarding table according to the destination IP: The IP belongs to Home A, and the forwarding direction is loopback - IP2;
[0115] Rewrite the qinq as the qinq of Home A, and send it out from loopback - IP2.
[0116] ② The traffic reaches Access Gateway 1
[0117] Match the forwarding rule, and the outgoing IP direction is vpws - lan1.
[0118] Correspondingly, referring to Figure 4 As shown, it shows the schematic diagram of the traffic for multi-family shared edge applications in the embodiments of the present invention. In the scenario of multi-family shared edge applications, the corresponding traffic transmission can be as follows:
[0119] For the process from Home A - Terminal A to Edge Cloud 2 - vNAS:
[0120] ① The traffic reaches Access Gateway 1
[0121] Match the forwarding table according to the destination IP: The IP belongs to Home B, and the forwarding direction is loopback (virtual network interface) - IP1;
[0122] Search for the line identifier of Home B, rewrite the qinq as the qinq of Home B, and send it out from loopback - IP1.
[0123] ② The traffic reaches the access gateway 2
[0124] Match the forwarding rule, and the outgoing IP direction is vxlan - mec.
[0125] ③ The traffic reaches the service gateway
[0126] The service gateway matches the forwarding rule and forwards the traffic to the vNAS system after NAT (Network Address Translation).
[0127] For the process from Edge Cloud 2 - vNAS to Home A - Terminal A:
[0128] ① The traffic reaches the service gateway
[0129] Forward the traffic to the access gateway according to the service configuration.
[0130] ② The traffic reaches the access gateway 2
[0131] Rewrite the qinq to the qinq of Home A, the forwarding direction is loopback - IP2, from loopback - IP2.
[0132] ③ The traffic reaches the access gateway 1
[0133] Match the forwarding rule, and the outgoing IP direction is vpws - lan1.
[0134] Through the above process, the access gateways between different edge clouds are forwarded through SRv6, and the access gateways allocate DHCP address pools with different network segments for the interconnected homes. When accessing each other, the local access gateway rewrites the user VLAN, simulates local home access, realizes that multiple homes are logically connected to the same network element, the peer access gateway recognizes the rewritten VLAN and forwards it as local home traffic, builds a multi - home logical internal network, and realizes mutual access and interconnection.
[0135] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequence, because according to the embodiments of the present invention, certain steps can be carried out in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.
[0136] Refer to Figure 5, showing a structural block diagram of a multi-point cross-domain networking system provided in an embodiment of the present invention. The multi-point cross-domain networking system at least includes several edge clouds, an access gateway located in the edge clouds, and a home terminal accessing the access gateway. Among them, the access gateway at least includes a first access gateway and a second access gateway, and the first access gateway and the second access gateway are respectively located in different edge clouds. Among them,
[0137] The first access gateway is used to obtain home network access data sent by a source home terminal. The home network access data at least includes an access request, first virtual network information, and a first IP identifier.
[0138] The first access gateway is used to rewrite the first virtual network information into second virtual network information matching the first IP identifier, and generate a first SRv6 packet corresponding to the home network access data.
[0139] The second access gateway is used to parse the first SRv6 packet sent by the first access gateway, and extract the access request, the second virtual network information, and the first IP identifier in the first SRv6 packet.
[0140] The second access gateway is used to send the access request to a first target home terminal corresponding to the first IP identifier according to the second virtual network information and the first IP identifier.
[0141] In some feasible implementation manners, the first virtual network information is first QinQ information, and the second virtual network information is second QinQ information. Among them,
[0142] The first access gateway is used to rewrite the first QinQ information into second QinQ information matching the first IP identifier, and generate a first SRv6 packet corresponding to the home network access data.
[0143] In some feasible implementation manners, the first access gateway is specifically used for:
[0144] Obtain an IP matching forwarding table, where the IP matching forwarding table includes the mapping relationship between the IP identifier, the QinQ information, and the forwarding line identifier.
[0145] Match the first IP identifier with the mapping relationship in the IP matching forwarding table to determine the second QinQ information and the first target forwarding line corresponding to the first IP identifier.
[0146] Rewrite the first QinQ information in the home network access data into the second QinQ information.
[0147] Encapsulate the access request, the second QinQ information, and the first IP identifier into a first SRv6 packet, and send the first SRv6 packet to the second access gateway according to the first target forwarding path.
[0148] In some possible implementation manners, the edge cloud further includes a service gateway communicatively connected to the access gateway, and at least one edge application communicatively connected to the service gateway; wherein, the access gateway further includes a third access gateway; wherein,
[0149] The first access gateway is configured to obtain edge application usage data sent by a source home terminal, where the edge application usage data at least includes an access request, second virtual network information, and a second IP identifier;
[0150] The first access gateway is configured to rewrite the second virtual network information into third virtual network information matching the second IP identifier, and generate a second SRv6 packet corresponding to the edge application usage data;
[0151] The third access gateway is configured to parse the second SRv6 packet sent by the first access gateway, and extract the access request, the third virtual network information, and the second IP identifier in the second SRv6 packet;
[0152] The third access gateway is configured to locate a target edge application corresponding to the third virtual network information and the second IP identifier, and send the application usage request to the target edge application;
[0153] Wherein, the third access gateway, the target service gateway, and the target edge application are located in the same edge cloud.
[0154] In some possible implementation manners, the first virtual network information is first QinQ information, and the third virtual network information is third QinQ information; wherein,
[0155] The first access gateway is configured to rewrite the first QinQ information into third QinQ information matching the second IP identifier, and generate a second SRv6 packet corresponding to the edge application usage data.
[0156] In some possible implementation manners, the first access gateway is specifically configured to:
[0157] Obtain an IP matching forwarding table, where the IP matching forwarding table includes a mapping relationship between an IP identifier, QinQ information, and a forwarding path identifier;
[0158] Match the second IP identifier with the mapping relationship in the IP matching forwarding table to determine the third QinQ information and the second target forwarding path corresponding to the second IP identifier;
[0159] Rewrite the first QinQ information in the edge application usage data as the third QinQ information;
[0160] Encapsulate the application usage request, the third QinQ information, and the second IP identifier into a second SRv6 packet, and send the second SRv6 packet to the third access gateway according to the second target forwarding path.
[0161] In some possible implementation manners, it further includes:
[0162] The access gateway is used to allocate corresponding IP identifiers to the accessed home terminals;
[0163] Wherein, different home terminals correspond to different IP identifiers, and the IP identifiers do not repeat with the IP identifiers corresponding to the edge applications in the edge cloud.
[0164] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, please refer to the partial description of the method embodiment.
[0165] In addition, an embodiment of the present invention further provides an electronic device, including: a processor, a memory, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, it implements each process of the above-mentioned method embodiment of cross-domain networking based on a cloud gateway, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0166] An embodiment of the present invention further provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, it implements each process of the above-mentioned method embodiment of cross-domain networking based on a cloud gateway, and can achieve the same technical effect. To avoid repetition, it will not be elaborated here. Among them, the computer-readable storage medium, such as a read-only memory (ROM for short), a random access memory (RAM for short), a magnetic disk, or an optical disc, etc.
[0167] Each embodiment in this specification is described in a progressive manner. The key points of each embodiment are the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other.
[0168] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, an apparatus, or a computer program product. Therefore, the embodiments of the present invention can take the form of an all-hardware embodiment, an all-software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, EEPROM, Flash, and eMMC, etc.) that contain computer-usable program code.
[0169] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0170] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0171] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0172] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concepts. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0173] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising said element.
[0174] The above has introduced in detail a cross-domain networking method and a cross-domain networking device based on a cloud gateway provided by the present invention. Specific examples are used in this text to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A cross-domain networking method based on a cloud gateway, characterized in that Applied to a multi-point cross-domain networking system, the multi-point cross-domain networking system at least includes several edge clouds, an access gateway located in the edge clouds, and a home terminal accessing the access gateway; wherein, the access gateway at least includes a first access gateway and a second access gateway, the first access gateway and the second access gateway are respectively located in different edge clouds, and the method includes: The first access gateway obtains home network access data sent by a source home terminal, and the home network access data at least includes an access request, first virtual network information, and a first IP identifier; The first access gateway rewrites the first virtual network information into second virtual network information matching the first IP identifier, and generates a first SRv6 packet corresponding to the home network access data; The second access gateway parses the first SRv6 packet sent by the first access gateway, and extracts the access request, the second virtual network information, and the first IP identifier in the first SRv6 packet; The second access gateway sends the access request to a first target home terminal corresponding to the first IP identifier according to the second virtual network information and the first IP identifier.
2. The method according to claim 1, characterized in that, The first virtual network information is first QinQ information, the second virtual network information is second QinQ information, and the rewriting the first virtual network information into second virtual network information matching the first IP identifier, and generating a first SRv6 packet corresponding to the home network access data includes: Rewriting the first QinQ information into second QinQ information matching the first IP identifier, and generating a first SRv6 packet corresponding to the home network access data.
3. The method according to claim 2, wherein The rewriting the first QinQ information into second QinQ information matching the first IP identifier, and generating a first SRv6 packet corresponding to the home network access data includes: Obtaining an IP matching forwarding table, where the IP matching forwarding table includes a mapping relationship between an IP identifier, QinQ information, and a forwarding line identifier; Matching the first IP identifier with the mapping relationship in the IP matching forwarding table to determine second QinQ information and a first target forwarding line corresponding to the first IP identifier; Rewriting the first QinQ information in the home network access data into the second QinQ information; Encapsulating the access request, the second QinQ information, and the first IP identifier into a first SRv6 packet, and sending the first SRv6 packet to the second access gateway according to the first target forwarding line.
4. The method according to claim 1, wherein The edge cloud further includes a service gateway communicatively connected to the access gateway, and at least one edge application communicatively connected to the service gateway; wherein, the access gateway further includes a third access gateway, and the method further includes: The first access gateway obtains edge application usage data sent by a source home terminal, and the edge application usage data at least includes an access request, second virtual network information, and a second IP identifier; The first access gateway rewrites the second virtual network information into third virtual network information that matches the second IP identifier, and generates a second SRv6 packet corresponding to the edge application usage data; The third access gateway analyzes the second SRv6 packet sent by the first access gateway, and extracts the access request, the third virtual network information, and the second IP identifier in the second SRv6 packet; The third access gateway locates the target edge application corresponding to the third virtual network information and the second IP identifier, and sends the application usage request to the target edge application; Wherein, the third access gateway, the target service gateway, and the target edge application are located in the same edge cloud.
5. The method according to claim 4, wherein The first virtual network information is first QinQ information, and the third virtual network information is third QinQ information. The rewriting of the second virtual network information into third virtual network information that matches the second IP identifier, and generating a second SRv6 packet corresponding to the edge application usage data includes: Rewriting the first QinQ information into third QinQ information that matches the second IP identifier, and generating a second SRv6 packet corresponding to the edge application usage data.
6. The method according to claim 5, characterized in that The rewriting of the first QinQ information into third QinQ information that matches the second IP identifier, and generating a second SRv6 packet corresponding to the edge application usage data includes: Obtain an IP matching forwarding table, where the IP matching forwarding table includes the mapping relationship between the IP identifier, the QinQ information, and the forwarding line identifier; Match the second IP identifier with the mapping relationship in the IP matching forwarding table to determine the third QinQ information and the second target forwarding line corresponding to the second IP identifier; Rewrite the first QinQ information in the edge application usage data into the third QinQ information; Encapsulate the application usage request, the third QinQ information, and the second IP identifier into a second SRv6 packet, and send the second SRv6 packet to the third access gateway according to the second target forwarding line.
7. The method according to any one of claims 1 to 6, characterized in that, It further includes: The access gateway assigns a corresponding IP identifier to the accessed home terminal; Wherein, different home terminals correspond to different IP identifiers, and the IP identifiers do not repeat with the IP identifiers corresponding to the edge applications in the edge cloud.
8. A multi-point cross-domain networking system, characterized in that The multi-point cross-domain networking system at least includes several edge clouds, access gateways located in the edge clouds, and home terminals accessing the access gateways; wherein, the access gateways at least include a first access gateway and a second access gateway, and the first access gateway and the second access gateway are respectively located in different edge clouds; wherein, The first access gateway is used to obtain home network access data sent by a source home terminal, and the home network access data at least includes an access request, first virtual network information, and a first IP identifier; The first access gateway is configured to rewrite the first virtual network information into second virtual network information that matches the first IP identifier, and generate a first SRv6 packet corresponding to the home network access data; The second access gateway is configured to parse the first SRv6 packet sent by the first access gateway, and extract the access request, the second virtual network information, and the first IP identifier in the first SRv6 packet; The second access gateway is configured to send the access request to a first target home terminal corresponding to the first IP identifier according to the second virtual network information and the first IP identifier.
9. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus; The memory is used to store computer programs; When the processor is used to execute the program stored on the memory, it implements the method described in any one of claims 1-7.
10. A computer-readable storage medium, on which instructions are stored. When the instructions are executed by one or more processors, the processors are caused to execute the method described in any one of claims 1-7.