Data drainage device and data drainage method in virtual network
Through the coordinated design of intelligent network card hardware acceleration and dynamic service chain controller, high-performance, low-latency, and scalable data drainage in virtual networks is achieved, solving the problems of poor scalability and high latency in the existing technology, and improving the system throughput and CPU utilization.
Patent Information
- Application Number
- CN202510699816.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-07-29
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The data drainage schemes in existing virtual networks have problems such as poor scalability, high latency and high CPU usage, especially in high throughput scenarios.
The collaborative design of intelligent network card hardware offload and dynamic service chain controller is adopted, and the packet characteristics and labeling are accelerated through intelligent network card hardware. The topology is dynamically constructed with the secure service chain controller, and RDMA is used to realize data packet parallel processing and direct writing, avoiding the static flow table rules.
Line-speed traffic classification and microsecond-level delay data drainage are realized, which improves the system's scalability and throughput, reduces CPU usage, and solves the performance bottlenecks in the existing technology.
Smart Images

Figure CN120389900A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of cloud computing and network security, and specifically to a data drainage device and a data drainage method in a virtual network. Background Art
[0002] In a virtualized network environment, communication between virtual machines (east-west traffic) usually needs to go through security detection (such as firewalls, intrusion detection, etc.) to ensure compliance and security. Traditional solutions rely on software-defined virtual switches (such as Open vSwitch) or dedicated gateways to achieve traffic drainage.
[0003] For example, the data drainage device and data drainage method in a virtual network disclosed in the authorized announcement number CN110213181B. In the data drainage device, a first virtual machine, a second virtual machine, and a security service node are respectively connected to a virtual switch, and a flow table is used to indicate the routing rules for the virtual switch to transmit data. After adopting the above technical solution, the beneficial effect of the present invention is that when draining data through this data drainage device, there is no need to encapsulate data through a virtual machine gateway during the entire data drainage process, nor does the virtual machine need to perform data drainage through the method of memory transfer. In this way, for the security service node, there is no need to pre-define the protocol used by the virtual gateway to encapsulate data in advance, nor to pre-customize and develop an API interface that matches the memory of the virtual machine. Correspondingly, there is no need to perform a large number of adaptation operations on the security service node provided by a third party in advance, thereby improving the application flexibility of the data drainage device.
[0004] Although the above patent realizes data drainage through a virtual switch and a fixed flow table, this solution relies on pre-defined flow table rules to instruct the virtual switch to forward traffic to the security node, resulting in the need to manually update the entire network flow table every time a new type of security detection is added (such as adding an audit node), and the operation complexity is O(N) (N is the number of virtual machines); and its flow table matching depends on the soft processing of the host CPU. Actual measurements show that at a 40Gbps traffic, the forwarding delay of the virtual switch increases to more than 200 μs (compared with 20 μs of the hardware solution), and the CPU occupancy rate exceeds 70%, which cannot meet the requirements of high-throughput scenarios. Summary of the Invention
[0005] The purpose of the present invention is to provide a data drainage device and a data drainage method in a virtual network to solve the problems raised in the above background art.
[0006] To achieve the above purpose, the present invention provides the following technical solutions:
[0007] A data drainage device in a virtual network, comprising:
[0008] An intelligent network card, directly connected to the source virtual machine and the target virtual machine, for:
[0009] The feature information of the hardware-accelerated identification data packet is recognized, and the data packet is marked according to the preset rules;
[0010] The unmarked data packets are directly forwarded to the target virtual machine, and the marked data packets trigger the drainage operation;
[0011] The security service chain controller communicates with the intelligent network card and is used for:
[0012] Receiving the dynamic registration information of the security virtual machine and generating an extensible service chain topology;
[0013] Issuing a dynamic drainage instruction to the intelligent network card according to the data packet marking;
[0014] The security virtual machine pool includes at least one security service node, and each node is connected to the controller through a standard API interface, and is used for processing the data packets drained by the intelligent network card in parallel and returning the security judgment result.
[0015] In the present invention, the intelligent network card further includes:
[0016] A hardware traffic classification engine that recognizes data packets based on the five-tuple or application layer protocol;
[0017] A lightweight virtual switch that realizes the stateless execution of the drainage rule through an eBPF program;
[0018] An RDMA interface for directly writing data packets into the memory space of the security virtual machine.
[0019] In the present invention, the method for the security service chain controller to dynamically construct a service chain includes:
[0020] Assigning a unique capability label to each security service node;
[0021] Combining multiple security service nodes into a logical service chain according to the policy and assigning a globally unique ID to the chain;
[0022] When the load of the security service node exceeds the threshold, automatically scheduling a standby node to join the service chain.
[0023] In the present invention, when the nodes in the security virtual machine pool process data packets:
[0024] Adopting a scatter-gather model, the intelligent network card parallelly sends data packet copies to all security service nodes in the same service chain;
[0025] After each node processes independently, it returns the judgment result to the controller, and the controller aggregates the results and decides the final forwarding action.
[0026] A data drainage method in a virtual network, which is applied to the data drainage device, includes the following steps:
[0027] Step S1, service registration and chain construction. When the secure virtual machine starts, it registers the service type and capability tags with the controller. The controller generates a service chain according to the security policy and assigns a service chain ID.
[0028] Step S2, traffic classification and marking. The intelligent network card captures the data packets sent by the source virtual machine, matches the preset rules through hardware acceleration, and marks the corresponding service chain ID for the data packets to be drained.
[0029] Step S3, dynamic drainage and parallel processing. The intelligent network card sends the marked data packet information to the controller. The controller queries the corresponding list of security service nodes according to the service chain ID and instructs the intelligent network card to send the data packets to each node in parallel through RDMA.
[0030] Step S4, security judgment and forwarding. After each security service node processes the data packet, it returns a judgment result. The controller notifies the intelligent network card to forward, modify or discard the data packet according to the aggregation result.
[0031] In the present invention, in the said step S3, the parallel processing includes:
[0032] The intelligent network card injects the data packet into the memory of the secure virtual machine through the zero-copy technology;
[0033] If there are multiple security service nodes of the same type in the same service chain, the controller distributes the data packet copies according to the load balancing strategy.
[0034] In the present invention, it also includes
[0035] Step S5, the intelligent network card records the performance indicators of the drained traffic and feeds them back to the controller. The controller dynamically adjusts the service chain topology according to the indicators, including adding service nodes or removing faulty nodes.
[0036] In the present invention, the said preset rules include:
[0037] Traffic with the protocol type of HTTP / HTTPS needs to be detected by the firewall and IDS;
[0038] Traffic with the source IP belonging to the blacklist needs to be processed by the audit virtual machine.
[0039] A computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the steps of the said method.
[0040] An electronic device, including a memory, a processor and a computer program stored on the memory. When the processor executes the program, it implements the steps of the said method.
[0041] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0042] 1. By combining the hardware offloading of the intelligent network card with the dynamic scheduling of the service chain controller, the present invention achieves the effects of line-speed traffic classification and stateless traffic diversion, and solves the problem of poor scalability caused by the static flow table rules in the prior art.
[0043] 2. Through the collaborative design of RDMA direct write and parallel security processing, the present invention achieves the effects of microsecond-level latency and high-throughput traffic diversion, and solves the problems of high forwarding latency and high CPU occupancy rate of the virtual switch in the prior art. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 is the dynamic data traffic diversion flowchart of the present invention;
[0045] Figure 2 is the system architecture diagram of the present invention;
[0046] Figure 3 is the service chain dynamic construction flowchart of the present invention;
[0047] Figure 4 is the parallel processing timing diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0048] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0049] Embodiment 1
[0050] Aiming at the problems of performance bottleneck, complex configuration and poor scalability existing in the traditional data traffic diversion scheme in the virtual network, the present invention realizes high-performance, low-latency and scalable secure data traffic diversion through the hardware offloading of the intelligent network card and the dynamic service chain technology. Due to the collaborative control of hardware acceleration and software-defined network (SDN), the following technical goals need to be achieved relying on the hardware architecture:
[0051] Hardware-level traffic classification: Support 100Gbps line-speed processing, with a latency of less than 100 μs;
[0052] Dynamic service chain construction: Security nodes can be registered / unloaded in seconds, and the service chain topology is updated in real time;
[0053] Stateless traffic diversion execution: The intelligent network card only depends on the controller instructions to avoid flow table expansion.
[0054] Based on the above technical requirements, this embodiment adopts the three-layer architecture of "intelligent network card - controller - security pool" as shown in Figure 1 Figure:
[0055] The intelligent network card hardware layer is implemented based on the NVIDIA BlueField-2 DPU, integrating a traffic classification engine, an eBPF virtual switch, and an RDMA interface. It is connected to the host through the PCIe bus, and the physical network interface is directly connected to the virtual machine network. Among them, the traffic classification engine matches the five-tuple (source / destination IP, port, protocol) through TCAM hardware, and the matching rules are as follows:
[0056]
[0057] The eBPF virtual switch marks the service chain ID or forwards directly according to the matching result.
[0058] In this embodiment, the intelligent network card realizes 100Gbps line speed matching through the hardware traffic classification engine (TCAM), avoiding the performance bottleneck of the host CPU soft processing.
[0059] The service chain control layer is implemented based on Kubernetes Operator, including a service registration module, a policy engine, and a load balancer. It communicates with the intelligent network card through gRPC and interacts with the security virtual machine pool through the API. Among them, the service registration module receives security node metadata (such as type, capability label), constructs a service chain topology graph G=(V,E), where the vertex V represents the security node, and the edge E represents the logical relationship between nodes. The policy engine generates a mapping function from the service chain ID to the node list according to the security policy:
[0060] f(chain_id)={v1,v2,…,v n},v i ∈V
[0061] In this embodiment, the service chain controller dynamically generates the service chain ID according to the security policy and updates the node list in real time. When adding a new security detection type, only the node needs to be registered, and there is no need to manually update the whole network flow table, reducing the operation complexity from O(N) to O(1).
[0062] The security virtual machine pool contains heterogeneous security nodes (firewall, IDS, audit, etc.). Each node deploys a standard gRPC interface and is directly connected to the intelligent network card RDMA channel through the virtual network. Among them, the node directly reads the data packet from the intelligent network card memory through RDMA, and returns the judgment result y i ∈{0 (reject), 1 (allow)}; the controller aggregates the results If Y = 1, it is released, otherwise it is discarded.
[0063] In this embodiment, the data packet is directly written into the memory of the secure virtual machine through RDMA, bypassing the host protocol stack, reducing the single-write latency from 200 μs (software solution) to 0.3 μs; the secure nodes process the data packet copies in parallel, and the aggregation decision time is controlled within 1 ms, reducing the cumulative latency (N × processing latency) of the serial processing by more than 80%, and the CPU occupancy rate is always lower than 20%.
[0064] As Figures 2-3 shown, the specific process of the dynamic data drainage method executed on this architecture includes:
[0065] Step S1: Service registration and topology construction. After the secure virtual machine is started, it sends a registration request to the controller, including the service type T and the set of capability tags L;
[0066] The controller updates the service chain topology graph G and assigns a unique ID to each service chain. The calculation of its hash value is as follows:
[0067] H(chain_id) = SHA-256(T1||L1||T2||L2||…)
[0068] Step S2: Traffic classification and marking. The intelligent network card receives the data packet p and extracts the five-tuple feature vector X = (x1,…,x5);
[0069] Judge whether to drain the traffic through the hardware rule matching function R(x):
[0070]
[0071] where w i represents the protocol weight, and θ represents the matching threshold.
[0072] Step S3: Parallel security processing. The intelligent network card writes the data packet copy into the memory addresses a = (a1,…,a n ) of each secure node through RDMA. The writing efficiency model is:
[0073]
[0074] where B i represents the RDMA bandwidth of the i-th node.
[0075] Each node returns the judgment result within the delay constraint t max = 1 ms.
[0076] Step S4: Aggregation judgment and forwarding. The controller calculates the comprehensive judgment Y:
[0077]
[0078] The intelligent network card performs forwarding or discarding actions according to the Y value.
[0079] Embodiment 2
[0080] As Figure 4 shown, assume that a certain financial cloud platform needs to perform real-time auditing and intrusion detection on the HTTPS transaction traffic between virtual machines.
[0081] Service chain construction:
[0082] The firewall node (v1) registers the capability label L1 = {HTTPS, TLS, 1.3};
[0083] The IDS node (v2) registers the label L2 = {SQLi, XSS};
[0084] The controller generates the service chain ID = 202, and the mapping function f(202) = (v1, v2).
[0085] Traffic processing:
[0086] The intelligent network card captures the HTTPS packet (X = (IP A , IP B , 433, TCP, TLS1.3)), and calculates the matching score:
[0087]
[0088] The packet copy is written to v1 and b2 in parallel through RDMA, and the bandwidth B1 = B2 = 40 Gbps, and the write time:
[0089]
[0090] Security decision:
[0091] The firewall node decrypts and returns y1 = 1 (allowed);
[0092] The IDS node detects a SQL injection attack and returns y2 = 0 (rejected);
[0093] The controller aggregates the result Y = 0, triggers packet loss and alarms. Compared with the traditional cascaded drainage scheme, the throughput of HTTPS traffic processing in this embodiment is increased from 15 Gbps to 85 Gbps, and the latency is reduced from 500 μs to 60 μs.
[0094] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device.
[0095] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A data drainage device in a virtual network, characterized in that: Comprising: An intelligent network card, directly connected to the source virtual machine and the target virtual machine, for: Hardware-accelerating the identification of the feature information of data packets and marking the data packets according to preset rules; Directly forwarding the unmarked data packets to the target virtual machine and triggering a drainage operation for the marked data packets; A security service chain controller, communicating with the intelligent network card, for: Receiving the dynamic registration information of the security virtual machine and generating an extensible service chain topology; Issuing a dynamic drainage instruction to the intelligent network card according to the data packet marking; A security virtual machine pool, including at least one security service node, each node being connected to the controller through a standard API interface, for parallel processing of the data packets drained by the intelligent network card and returning a security judgment result.
2. The data drainage device in a virtual network according to claim 1, characterized in that: The intelligent network card further includes: A hardware traffic classification engine, identifying data packets based on a five-tuple or an application layer protocol; A lightweight virtual switch, implementing stateless execution of drainage rules through an eBPF program; An RDMA interface, for directly writing data packets into the memory space of the security virtual machine.
3. The data drainage device and data drainage method in a virtual network according to claim 1, characterized in that: The manner in which the security service chain controller dynamically constructs a service chain includes: Assigning a unique capability label to each security service node; Combining multiple security service nodes into a logical service chain according to a policy and assigning a globally unique ID to the chain; When the load of a security service node exceeds a threshold, automatically scheduling a standby node to join the service chain.
4. A data drainage device and a data drainage method in a virtual network according to claim 1, characterized in that: When the nodes in the security virtual machine pool process data packets: Adopting a scatter-gather model, the intelligent network card parallelly sending data packet copies to all security service nodes in the same service chain; After each node independently processes the data packets, returning the judgment result to the controller, and the controller aggregating the results and making a decision on the final forwarding action.
5. A data drainage method in a virtual network, characterized in that, Applied to the data drainage device according to any one of claims 1-4, including the following steps: Step S1, service registration and chain construction. When the security virtual machine starts, it registers the service type and the capability label with the controller, and the controller generates a service chain according to the security policy and assigns a service chain ID; Step S2, traffic classification and marking. The intelligent network card captures the data packets sent by the source virtual machine, matches the preset rules through hardware acceleration, and marks the corresponding service chain ID for the data packets to be drained; Step S3, dynamic drainage and parallel processing. The intelligent network card sends the marked data packet information to the controller, and the controller queries the corresponding list of security service nodes according to the service chain ID, and instructs the intelligent network card to parallelly send the data packets to each node through RDMA; Step S4, security judgment and forwarding. After each security service node processes the data packets, it returns the judgment result, and the controller notifies the intelligent network card to forward, modify, or discard the data packets according to the aggregated result.
6. The method according to claim 5, characterized in that: In the step S3, the parallel processing includes: The intelligent network card injecting the data packets into the memory of the security virtual machine through a zero-copy technology; If there are multiple security service nodes of the same type in the same service chain, the controller distributes the data packet copies according to a load balancing policy.
7. The method according to claim 5, wherein: Also including Step S5, the intelligent network card records the performance metrics of the drained traffic and feeds them back to the controller, and the controller dynamically adjusts the service chain topology according to the metrics, including adding service nodes or removing faulty nodes.
8. The method according to claim 5, wherein: The preset rules include: Traffic with the protocol type of HTTP / HTTPS needs to be detected by the firewall and IDS; Traffic with the source IP belonging to the blacklist needs to be processed by the audit virtual machine.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, the steps of any one of claims 5-8 are implemented.
10. An electronic device, comprising a memory, a processor, and a computer program stored on the memory, characterized in that, When the processor executes the program, the steps of any one of claims 5-8 are implemented.
Citation Information
Patent Citations
Data diversion devices and methods in virtual networks
CN110213181B