Data forwarding method, device and system, medium and product

Through the mechanism of multi-network card collaboration and stream table sharing, the business interruption problem caused by OvS hardware failure is solved, and the service uninterrupted in the event of hardware failure is achieved and the network card bandwidth is efficiently utilized, which improves the reliability and performance of the cloud platform.

CN120416151APending Publication Date: 2025-08-01HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410158183.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-02-01
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

The existing OvS hardware offloading solutions are prone to business interruption in the event of hardware failure, and the multi-host solutions have performance expansion and failure spreading problems, so they cannot effectively utilize network card bandwidth.

Method used

Through the mechanism of fast perception of multi-network card collaboration, stream table sharing and failover, the Smart NIC memory release mechanism is used to enable multiple Smart NICs to share stream table memory and bind network card ports to realize load balancing and failure switching. The OvS collaboration mechanism across multiple hosts provides reliability and network card bandwidth utilization.

Benefits of technology

In the event of hardware failure, the network card bandwidth utilization is improved, and the business continuity and load balancing of virtual machines or containers in the cloud platform are ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120416151A_ABST
    Figure CN120416151A_ABST
Patent Text Reader

Abstract

The invention relates to a data forwarding method, device and system, a computer readable storage medium and a computer program product. The first host comprises a plurality of network cards, the plurality of network cards comprise a first network card and a second network card, and both the first network card and the second network card have forwarding flow tables. The method comprises the following steps: a first network card receives a data message of a sender, and forwards the data message of the sender to an access target according to a forwarding flow table located in the first network card; and when the first network card fails, the second network card receives the subsequent data message of the user, and forwards the subsequent data message of the sender to the access target according to the forwarding flow table located in the second network card. By implementing the embodiment of the invention, the capability of not interrupting the service can be realized when the hardware fails.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technologies, and more particularly to a data forwarding method, device, system, computer-readable storage medium, and computer program product. Background Art

[0002] The Open vSwitch (OvS) is an important connection component of a cloud computing platform, acting as a switch in a cloud environment to connect communications between virtual machines (VMs) and between a VM and an external device. After several generations of technology evolution, to address problems such as high CPU occupancy and low bandwidth utilization rate of the purely software-implemented OvS, major manufacturers have proposed OvS hardware offloading solutions, but at the cost of some reliability, which is unacceptable in storage scenarios. Therefore, improving the reliability of the OvS hardware offloading solution is an urgent problem to be solved. Summary of the Invention

[0003] The present disclosure provides a data forwarding solution. This solution realizes the ability of the hardware failure storage service not to be interrupted during a hardware failure through a mechanism of multi-network card collaboration, flow table sharing, and fast fault switching perception. In some implementation manners, a load balancing ability between network cards is provided. In some implementation manners, through an OvS collaboration mechanism across multiple hosts, while providing reliability, the network card bandwidth can also be fully utilized, thus improving the utilization rate of the network card bandwidth.

[0004] In a first aspect of the present disclosure, a data forwarding method is provided. A first host includes multiple network cards, the multiple network cards include a first network card and a second network card, both the first network card and the second network card have forwarding flow tables, and the two flow tables are the same. The method includes: the first network card receives a data packet from a sender and forwards the data packet from the sender to an access target according to the forwarding flow table located on the first network card; and when the first network card fails, the second network card receives subsequent data packets from a user and forwards the subsequent data packets from the sender to the access target according to the forwarding flow table located on the second network card. According to the data forwarding method of the first aspect of the present disclosure, since each network card has its own forwarding flow table, even if a certain network card fails, it will not cause the loss of the forwarding flow table, or have to obtain the forwarding flow table from memory / hard disk. Instead, other network cards with forwarding flow tables can quickly take over the services of the failed network card. Through a mechanism of multi-network card collaboration, flow table sharing, and fast fault switching perception, the ability of the hardware failure storage service not to be interrupted during a hardware failure is realized.

[0005] In an implementation of the first aspect, the sender can be a computer communicating with the first host, or the sender can be a virtual machine running on the first host, or the sender can be a container running on the first host. In an implementation of the first aspect, the access target can be a virtual machine running on the first host, or the access target can be a container running on the first host. In this way, this solution can also be implemented in the cloud platform, so as to implement the ability of uninterrupted hardware failure storage service and load balancing in virtual machines or containers.

[0006] In an implementation of the first aspect, the first network card receives the data packet from the sender, which can specifically include: receiving the data packet from the sender through the first port of the first network card. The second network card forwards the subsequent data packets of the sender to the access target, which can specifically include: the first network card forwards the data packet of the sender to the fourth port bound to the third port in the access target. In this way, in case of a hardware failure, it can be imperceptible to the user.

[0007] In an implementation of the first aspect, the first network card forwards the data packet of the sender to the access target, which can specifically include: the first network card forwards the data packet of the sender to the third port of the access target; and the second network card forwards the subsequent data packets of the sender to the access target, which can specifically include: the first network card forwards the data packet of the sender to the fourth port bound to the third port in the access target. In this way, in case of a hardware failure, it can be imperceptible to the user.

[0008] In an implementation of the first aspect, the first host is located in the data center, and the forwarding flow table can be a forwarding flow table based on the Open vSwitch (OvS). In this way, the OvS coordination mechanism can be utilized to provide a reliable forwarding function.

[0009] In an implementation of the first aspect, the data center can also include a second host, and the second host and the first host can share the first network card and the second network card: when the first host fails, or the first host receives an instruction to stop forwarding data packets, the OvS function can be enabled; and the second host can continue to forward data packets using the second network card. In some embodiments, the CPU of the host sends the forwarding flow table to the first network card and the second network card; or the first network card and the second network card obtain the forwarding flow table from the host memory. In this way, through the OvS coordination mechanism across multiple hosts, while providing reliability, the network card bandwidth can also be fully utilized, so that the service can be ensured to be unaffected and the utilization rate of the network card bandwidth can be improved.

[0010] In a second aspect of the present disclosure, a host is provided. The host includes multiple network cards, and the host is used to execute the method described in the first aspect. With respect to the host according to the second aspect of the present disclosure, since each network card has its own forwarding flow table, even if a certain network card fails, it will not cause the loss of the forwarding flow table, nor will it be necessary to obtain the forwarding flow table from the memory / hard disk. Instead, other network cards with forwarding flow tables can quickly take over the services of the faulty network card. Through the mechanisms of multi-network card cooperation, flow table sharing, and fast fault-switching perception, the ability to keep the storage service uninterrupted during hardware failures is achieved.

[0011] According to a third aspect of the present disclosure, a computing device cluster is provided, including at least one computing device. Each computing device includes a processor and a memory. The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method described in the first aspect of the present disclosure.

[0012] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided. The computer-readable storage medium stores instructions that, when executed by a computing device, cause the computer to execute the method described in the first aspect of the present disclosure. In some implementation scenarios, the computer-readable storage medium may be non-transitory. The computer-readable storage medium includes, but is not limited to, volatile memory (e.g., random access memory), non-volatile memory (e.g., flash memory, hard disk drive (HDD), solid state drive (SSD), etc.).

[0013] According to a fifth aspect of the present disclosure, a computer program product is provided. The computer program product includes instructions that, when executed by a computing device, cause the computing device to execute the method described in the first aspect of the present disclosure. In some implementation scenarios, the computer program product may include one or more software installation packages. In cases where it is necessary to use the method provided by the aforementioned first aspect or its possible variations, the software installation package can be downloaded or copied and executed on the computing device.

[0014] It should be understood that the computing device cluster according to the third aspect of the present disclosure, the computer-readable storage medium according to the fourth aspect, or the computer program product according to the fifth aspect are used to execute the method described in the first aspect. Therefore, the explanations or descriptions regarding the first aspect also apply to the third aspect, the fourth aspect, and the fifth aspect. In addition, the beneficial effects that can be achieved by the third aspect, the fourth aspect, and the fifth aspect can refer to the beneficial effects in the corresponding method, which will not be elaborated here.

[0015] Note that the Summary of the Invention section is provided to introduce a series of concepts in a simplified form, which will be further described in the Detailed Description below. The Summary of the Invention section is not intended to identify the key features or essential features of the present disclosure, nor is it intended to limit the scope of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In conjunction with the accompanying drawings and with reference to the following detailed description, the above and other features, advantages, and aspects of the embodiments of the present disclosure will become more apparent.

[0017] In the drawings, the same or similar reference numerals denote the same or similar elements, wherein:

[0018] Figure 1 FIG. schematically shows a schematic diagram of an example environment in which the exemplary embodiments of the present disclosure can be implemented;

[0019] Figure 2 and Figure 3 FIG. schematically shows a schematic diagram of a hardware failure recovery solution related to the exemplary embodiments of the present disclosure;

[0020] Figure 4 and Figure 5 FIG. schematically shows a schematic diagram of a multi-host solution related to the exemplary embodiments of the present disclosure;

[0021] Figure 6 FIG. schematically shows a flowchart of a method for data forwarding in a cloud computing platform according to an exemplary embodiment of the present disclosure;

[0022] Figure 7 FIG. schematically shows a block diagram of a device for data forwarding in a cloud computing platform according to an exemplary embodiment of the present disclosure;

[0023] Figure 8 FIG. shows a schematic structural diagram of a computing device provided by an embodiment of the present application;

[0024] Figure 9 FIG. shows a schematic structural diagram of a computing device cluster provided by an embodiment of the present application; and

[0025] Figure 10 FIG. shows a schematic structural diagram of a computing device cluster connected through a network provided by an embodiment of the present application.

[0026] In all the drawings, the same or similar reference numerals represent the same or similar elements. DETAILED DESCRIPTION

[0027] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Instead, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not used to limit the protection scope of the present disclosure.

[0028] In the description of the embodiments of the present disclosure, the term "including" and its variants should be understood as open inclusion, that is, "including but not limited to". The term "based on" should be understood as "at least partially based on". The term "an embodiment" or "the embodiment" should be understood as "at least one embodiment". The terms "first", "second", etc. may refer to different or the same objects unless clearly indicated otherwise.

[0029] In a virtual switch, a Smart NIC, i.e., a smart network card, is a device that assists the CPU in processing network loads through an FPGA (Field Programmable Gate Array). It has the ability to program network interface functions and can support the customization of data plane and control plane functions through FPGA localization programming, thereby assisting the CPU in processing network loads. In addition, a Smart NIC usually contains multiple ports and an internal switch, can quickly forward data, and can be intelligently mapped to relevant applications based on network data packets, application sockets, etc. It can also detect and manage network traffic. A Smart NIC can improve application and virtualization performance and realize many advantages of software-defined networking (SDN) and network function virtualization (NFV). It removes network virtualization, load balancing, and other low-level functions from the server CPU to ensure the maximum processing capacity for applications. At the same time, the smart network card can also provide distributed computing resources, enabling users to develop their own software or provide access services, thereby accelerating specific applications.

[0030] In an OvS hardware offloading solution, when the first data packet enters the Smart NIC and fails to query the flow table information (for example, the query fails due to a network card failure), the packet is sent to OvS. OvS generates flow information according to the forwarding rules and sends it to the Smart NIC. At the same time, the packet is re-injected into the Smart NIC for forwarding. When subsequent packets enter the Smart NIC and successfully query the flow table information, the packets are edited in the Smart NIC according to the flow table information and then forwarded. Based on this solution, when the Smart NIC fails, the Smart NIC can be repaired. After successful repair, OvS offloading can be restarted, or the OvS offloading can be switched to the backup Smart NIC. The disadvantage of this is that it will cause service interruption during the fault recovery period. Without waiting for the time required for Smart NIC repair, no service can be provided during this period. The switching of the backup Smart NIC is complex and requires complex management plane reconfiguration or application awareness of the link switch, resulting in no service being provided for a period of time during the switching process.

[0031] For the multi-host solution, the Smart NIC can isolate resources for multiple hosts, and independent OvS processes can be deployed and run in multiple hosts to complete their respective OvS offloading. Based on this solution, there are performance scaling issues and fault spreading issues. The performance scaling issue is caused by the resource isolation of the Smart NIC for multiple hosts. In the case of non-full configuration or failure of the host, the Smart NIC cannot fully utilize all its performance. The fault spreading issue is that independent OvS processes are running in multiple hosts, and the backup capabilities of multiple hosts are not fully utilized. When the OvS in one of the hosts fails, that host can no longer provide services.

[0032] The solution proposed in this disclosure is different from the above solutions. Instead, it can utilize the Smart NIC memory free mechanism, where multiple Smart NICs share the flow table memory, enabling multiple cards to use the same flow table. In addition, the outgoing ports of the cards and the service network ports are bonded. When a hardware failure occurs, load balancing and fault failover are automatically completed. In some embodiments, the OvS in multiple hosts can also be backed up for each other, and all the forwarding rules of all hosts are configured. The Smart NIC selects the active OvS. The Smart NIC provides unified OvS offloading for all hosts. When the active OvS fails, another OvS of other hosts is re-selected, and the services of all hosts are not affected.

[0033] The Smart NIC memory free mechanism is a memory management mechanism within the Smart NIC that releases unused memory resources. This mechanism monitors memory usage on the Smart NIC and promptly releases unneeded memory resources. By regularly scanning memory, tracking memory allocations, and utilizing reference counting techniques, the mechanism accurately identifies which memory blocks can be safely freed. Once a memory block is determined to be unused, the mechanism triggers appropriate actions, marking it as available and returning it to the memory pool for subsequent memory allocation requests. The introduction of the Smart NIC memory free mechanism offers multiple benefits. First, it effectively manages memory resources on the Smart NIC, preventing memory leaks and waste. Second, by promptly releasing unused memory, the mechanism reduces the Smart NIC's memory usage, improving its processing power and performance.

[0034] Reference below Figures 1 to 10 It should be understood that these exemplary embodiments are provided only to enable those skilled in the art to better understand and implement the embodiments of the present disclosure, and are not intended to limit the scope of the present disclosure in any way.

[0035] Figure 1 1 is a diagram illustrating an example environment 100 in which methods and / or processes according to embodiments of the present disclosure may be implemented. Figure 1 As shown in the example, example environment 100 may represent a cloud computing platform, which includes host 102 and host 104. A cloud computing platform, also known as a cloud platform, is a service based on hardware and software resources that provides computing, networking, and storage capabilities. Cloud computing platforms can be categorized into different types based on their functions and features, such as storage-based cloud platforms primarily focused on data storage, computing-based cloud platforms primarily focused on data processing, and comprehensive cloud computing platforms that combine computing and data storage processing. Figure 1 The number and arrangement of components shown are provided as examples. Figure 1 Compared to those shown in FIG, example environment 100 may include additional components, fewer components, different components, or components arranged differently. For example, example environment 100 may include more hosts. It should be noted that the solutions provided by embodiments of the present invention are also applicable to non-cloud computing scenarios (e.g., a single host), as long as the host has multiple network interfaces capable of forwarding data packets according to a flow table.

[0036] The host 102 includes OvS 106 and one or more VMs (collectively or individually also referred to as VM 108). The host 104 includes OvS 110 and one or more VMs (collectively or individually also referred to as VM 112). Examples of the host 102 or the host 104 can be servers. In some embodiments, the host may also include containers to at least partially replace the functions of VMs. For the sake of simplicity, the VMs are used as examples in the drawings. The host in a cloud computing platform refers to a cloud host, which is an important part of cloud computing in infrastructure applications. A cloud host is a virtualization technology that virtualizes multiple parts similar to independent hosts on one host, enabling single machine multi-user. Each part can have a separate operating system, and the management method is the same as that of a host. A cloud host is virtualized from a group of cluster hosts, and there is an image of the cloud host on each host in the cluster, thus greatly improving the security and stability of the virtual host. Unless all the hosts in the cluster have problems, the cloud host will not be inaccessible. Generally speaking, the host in a cloud computing platform has characteristics such as virtualization, high availability, and elastic scalability, and can provide users with efficient, flexible, and secure computing services. In the present disclosure, the host can be understood as a server. It should be noted that OvS is just a specific implementation manner. In other embodiments, OvS may not be used, but other mechanisms with data packet forwarding functions can be used instead.

[0037] The host 102 includes OvS 106 and VM 108. The host 104 includes OvS 110 and VM 112. The VM in a cloud computing platform refers to a complete computer system with the functions of a complete hardware system simulated by software and running in a completely isolated environment. What can be done on a physical computer can be achieved in a virtual machine. When creating a virtual machine in a computer, a part of the hard disk and memory capacity of the physical machine needs to be used as the hard disk and memory capacity of the virtual machine. Each virtual machine has an independent CMOS, hard disk, and operating system, and the virtual machine can be operated like a physical machine. In cloud computing, virtual machines are usually provided to users as a service. Users can access these virtual machines through the Internet and use them for various computing tasks. A virtual machine can simulate actual hardware devices, including a central processing unit, memory, storage devices, etc., and different operating systems and software can be run on these virtual devices. A virtual machine is an important resource and service that can help users use and manage computing resources more efficiently, improving business efficiency and reliability. OvS is a high-quality virtual switch that supports multi-layer data forwarding and is mainly deployed on servers. Compared with traditional switches, OvS has good programming scalability and at the same time has the network isolation and data forwarding functions implemented by traditional switches. OvS runs on each physical machine that realizes virtualization and provides remote management. VM 108 and VM 112 are managed by VVM 107.

[0038] The VVM 107 can be used to partition the hardware platform into multiple virtual machines. The VMM 107 runs in privileged mode. Its main functions are to isolate and manage multiple virtual machines running on the upper layer, arbitrate their access to the underlying hardware, and virtualize a set of virtual hardware environments (including processors, memory, and I / O devices) independent of the actual hardware for each guest operating system. The VMM 107 uses a certain scheduling algorithm to share the CPU among various virtual machines, such as the round-robin scheduling algorithm. Virtualization is the process of hiding the underlying physical hardware in some way, enabling multiple operating systems to transparently use and share it.

[0039] The cloud computing platform also includes the kernel 114. The kernel 114 refers to the operating system kernel of the cloud computing platform and is one of the core components of the cloud computing platform. It is responsible for managing the resources of the cloud computing platform, including computing resources, storage resources, network resources, etc., and provides abstraction and scheduling of these resources. The kernel is also responsible for task allocation and management, as well as functions such as resource monitoring and alerting. The kernel in the cloud computing platform usually adopts open-source operating system kernels, such as the Linux kernel. After being customized and optimized, these kernels can better adapt to the characteristics and requirements of the cloud computing platform. In addition, the kernel provides a series of management tools and interfaces to enable users and administrators to better manage and monitor the running status and resource usage of the cloud computing platform. Generally speaking, the kernel in the cloud computing platform is one of the core components of the cloud computing platform, responsible for managing the resources of the cloud computing platform, providing functions such as task allocation and management, and is one of the key factors to ensure the stable and efficient operation of the cloud computing platform.

[0040] A flow table 116 for forwarding data packets is stored in the kernel 114. A flow table is a logical table used to implement network traffic control and forwarding. It is usually located in the central processor or network chip of a network device and is configured by software or hardware. The flow table determines how to process these data packets by matching the key information of the data packets (such as source IP address, destination IP address, protocol type, etc.), for example, routing to which port, discarding, or forwarding to the next device. In a network card, the flow table is used to determine the sending and receiving methods of data packets. The flow table consists of multiple flow table entries, and each flow table entry contains a matching field and a corresponding operation field. When a data packet arrives at the network card, the flow table matches according to the key information of the data packet and performs the corresponding operation. By using the flow table, the network card can process network traffic more efficiently, reducing network congestion and latency.

[0041] The cloud computing platform further includes network cards 118 and 122. It can be understood that network cards 118 and 112 are the Smart NICs discussed above. As an example, 2 network cards are shown in environment 100, but the cloud computing platform may include fewer or more network cards. A copy of flow table 116 is offloaded to the cache of the network cards. That is, flow table 120 is stored in network card 118, and flow table 124 is stored in network card 122. Flow tables 116, 118, and 124 have the same content and can be used as backups for each other.

[0042] When a data packet 126 (also referred to as a packet, frame, or data package, and these terms will not be distinguished hereinafter) is received by the port of network card 118, network card 118 queries in flow table 120 where data packet 126 should be forwarded. If data packet 126 is the first packet, the query in flow table 120 will fail. At this time, network card 118 reports to OvS 106. OvS 106 generates flow information according to the forwarding rules, sends it down to flow table 116 in the kernel, and notifies all network cards, namely network cards 118 and 122. At the same time, OvS 106 reinserts data packet 126 into any network card for forwarding. Subsequent data packets 126 enter any network card, the flow table information is successfully queried, and after being edited in the network card according to the flow table information, they are forwarded.

[0043] Similarly, when a data packet 128 is received by the port of network card 122, network card 118 queries in flow table 124 where data packet 128 should be forwarded. If data packet 128 is the first packet, the query in flow table 124 will fail. At this time, network card 122 reports to OvS 110. OvS 110 generates flow information according to the forwarding rules, sends it down to flow table 116 in the kernel, and notifies all network cards, namely network cards 118 and 122. At the same time, OvS 110 reinserts data packet 128 into any network card for forwarding. Subsequent data packets 128 enter any network card, the flow table information is successfully queried, and after being edited in the network card according to the flow table information, they are forwarded.

[0044] Figure 2 A schematic diagram of a hardware failure recovery scheme 200 related to an exemplary embodiment of the present disclosure is schematically shown. It should be noted that, in order to better describe the solution of the present disclosure, Figures 2 to 6 the structure related to the host or network card is simplified, such as omitting VVM. As Figure 2The shown hardware failure recovery solution 200 utilizes the Smart NIC memory free mechanism. Multiple Smart NICs share the flow table memory, enabling multiple cards to use the same flow table. Additionally, the outgoing ports of multiple network cards and the service network ports are bound. When a hardware failure occurs, load balancing and fault failover are automatically completed. For example, the outgoing ports of multiple smart NICs are grouped into a bond, and correspondingly, the Ethernet interfaces (ETH) generated by the virtual functions (VFs) in the VM are also grouped into a bond. The bond in the VM is a custom bond without bond negotiation, and the activation status of the member ports is updated according to the status of the outgoing bond. When the first packet enters any Smart NIC and fails to query the flow table information, the packet is sent to OvS. Based on the forwarding rules, OvS generates flow information and sends it to the kernel-level unified flow table, notifies all Smart NICs, and at the same time reinserts the packet into any Smart NIC for forwarding. When subsequent packets enter any Smart NIC and successfully query the flow table information, the packets are edited in the Smart NIC according to the flow table information and then forwarded. When a Smart NIC fails, it triggers an update of the status of the bound ports, automatically completing service switching.

[0045] As an example, Figure 2 The shown cloud computing platform includes a user 202 and a VM 204 installed on a host. The user 202 can offload the flow information in OvS 206 to the kernel 214 of the operating system, that is, store it as a flow table 216. This offloading process is achieved via path 234. The VM 204 includes an application 208 and a bond 210. The bond 210 can be regarded as a kind of logic, which is only shown here for illustrative purposes. The bond 210 can bind the network ports (VF-ETH and VF'-ETH) formed by the virtual functions (VFs) together, thus forming a single port 212 externally. The cloud computing platform also includes a network card 218 (also known as the first network card) and a network card 222 (also known as the second network card). The flow table 216 in the kernel 214 is also offloaded to the network card 218, that is, the flow table cache 220, and to the network card 222, that is, the flow table cache 224. The port 1 of the network card 218 and the port 2 of the network card 222 are also bound together, thus forming a unified port 226. The statuses between port 226 and port 212 are synchronized with each other for better load balancing.

[0046] In the scenario where an external client accesses the VM of a host, if a data packet 228 is received on port 226 at this time, the data packet may enter network card 218 or network card 222, which can depend on the load balancing policy. The following will take the data packet 228 first entering network card 218 as a non-limiting example. If the data packet 228 is the first data packet, network card 218 cannot find in the flow table cache 220 where the data packet 228 should be forwarded to. Therefore, network card 218 sends the data packet (or its information) to OvS206 via path 230. OvS206 generates flow information according to the forwarding rules and sends it to the flow table 216 in the kernel (e.g., via path 234). The flow table 234 will also be synchronized to the flow table cache 220 of network card 218 and the flow table cache 224 of network card 222. OvS206 reinserts the data packet 228 into network card 218 via path 232 (it can also be randomly inserted into any network card or based on the load balancing policy). Network card 218 or network card 222 will forward the data packet 228 to the destination port 212 according to the flow table, e.g., via path 236. The destination port 212, as a bound port, after receiving the data packet 228, will parse and forward it to the corresponding VM.

[0047] Subsequent data packets can enter any network card. If any network card successfully queries the flow table information, after completing the packet editing in the network card according to the flow table information, it will be forwarded. When a network card fails, it triggers an update of the bound port status and automatically completes the service switch. For example, if network card 218 fails, the status of port 226 can be updated to indicate that network card 218 fails and cannot work, then subsequent data packets can enter network card 222, and then network card 222 will forward the subsequent data packets based on the forwarding flow table 224. The updated status of port 226 will also be synchronized to port 212 via path 236. Port 212 can then know the status of port 226 to complete the corresponding service switch. It can be understood that these shown paths are only for better describing this solution. The above description of this solution also applies to the access between different VMs or containers running on the same host, and will not be elaborated here for the sake of brevity.

[0048] Figure 3 A schematic diagram schematically shows a hardware failure recovery solution 300 related to an exemplary embodiment of the present disclosure. The hardware failure recovery solution 300 is similar to the hardware failure recovery solution 200, but for the sake of more clearly explaining and without loss of generality, Figure 3 more VMs and more network cards are shown. As Figure 3The cloud computing platform shown includes a user 302, a VM 306, and a VM 312 installed on a host. The user 302 can unload the process information in the OvS 304 to the kernel 320 of the operating system, that is, store it as a flow table 322. The VM 306 includes an application 308 and a binding 310. Similarly, the binding 310 can be regarded as a kind of logic. The binding 310 can bind the network ports (VF-ETH and VF’-ETH) formed by the virtual functions (VFs) in the VM 306 together, and form a port 318 externally. The VM 312 includes an application 314 and a binding 316. Similarly, the binding 316 binds multiple network ports of the network card 312 together, so a port 342 is formed externally.

[0049] The cloud computing platform further includes a network card 324, a network card 328, and a network card 332. The flow table 322 in the kernel 320 will also be unloaded to the network card 324, the network card 328, and the network card 332, that is, the flow table cache 326, the flow table cache 330, and the flow table cache 334. Port 1 of the network card 324, port 2 of the network card 328, and port 3 of the network card 332 can also be bound together, thus forming a unified port 336. The status between port 336 and port 318 will be synchronized with each other. The status between port 336 and port 342 will be synchronized with each other.

[0050] If the data packet 340 is received by port 336 at this time, the data packet 340 may enter the network card 324, the network card 328, or the network card 332, which can depend on the load balancing policy. The following will take the data packet 340 entering the network card 328 as a non-limiting example. If the data packet 340 is a first packet, the network card 328 cannot find in the flow table cache 330 where the data packet 340 should be forwarded. Therefore, the network card 328 sends the data packet (or its information) to the OvS 304. The OvS 304 generates process information according to the forwarding rules and sends it to the flow table 322 in the kernel. The flow table 322 will also be synchronized to the flow table cache 326 of the network card 324, the flow table cache 330 of the network card 328, and the flow table cache 334 of the network card 332. The OvS 304 reinserts the data packet 340 into any one of the network cards, such as any one of the network card 324, the network card 328, or the network card 332, randomly or based on the load balancing policy. The network card 324, the network card 328, or the network card 332 will forward the data packet 340 to the destination port 318 according to its own flow table. The destination port 318, as a binding port, after receiving the data packet 340, will parse and forward it to the corresponding VM, such as the VM 306 or the VM 312.

[0051] And Figure 2Similarly, subsequent data packets can enter any network card. If the flow table information is successfully queried on any network card, the packet editing is completed in the network card according to the flow table information and then the packet is forwarded. When a network card fails, the bound port status is updated, and the service switch is automatically completed. For example, if network card 328 fails, the status of port 336 can be updated to indicate that network card 328 fails and cannot work, and the updated status of port 336 will also be synchronized to port 318.

[0052] Figure 4 FIG. schematically shows a schematic diagram of a multi-host solution 400 related to an exemplary embodiment of the present disclosure. As Figure 4 shown in the multi-host solution 400, the same rules are configured in OvS in multiple hosts, which are backup to each other. Which host the packet is sent to through the Smart NIC determines which host's OvS is in the active state, without an additional activation process. All subsequent first packets of services on all hosts will be sent to the active OvS for flow table offloading and forwarding. When the active OvS or the host where it is located fails, the Smart NIC re-selects a host for activation to ensure that the service is not affected.

[0053] As an example, as Figure 4 shown, the cloud computing platform includes host 402 and host 404 installed on the host. Host 402 can offload the process information in OvS406 to the kernel 414 of the operating system. Host 404 can offload the process information in OvS 416 to the kernel 424 of the operating system. The OvS 406 of host 402 and the OvS 416 of host 404 are configured with the same process rules. In this example, the OvS of host 402 is activated, that is, OvS 406 will be used to manage the forwarding service together with host 402 and host 404.

[0054] With Figure 2 and Figure 3Similarly, the host also includes VMs and network ports. For example, host 402 includes VM 408, and host 404 includes VM 418. VM 408 includes application 410 and VF-ETH port 412. VM 418 includes application 420 and VF-ETH port 422. The flow table is offloaded to the cache of network card 426, i.e., flow table cache 428. Since OvS 406 in host 402 is active at this time, if data packet 430 is received at port 1 of network card 426 and data packet 430 is the first packet, network card 426 cannot find where to forward data packet 430 in flow table cache 428. Therefore, network card 426 sends the data packet (or its information) to OvS 406. OvS 406 generates flow information according to the forwarding rules and sends it to the flow table cache 428 of network card 426. Network card 426 will forward data packet 430 to the destination port according to its own flow table.

[0055] If network card 426 fails, host 404 can be activated to replace host 402, thus realizing service switching. For host 402 or host 404, the switching is seamless. Because which host's OvS is in the active state is determined by the packets sent up by the network card, and no additional activation process is required.

[0056] Figure 5 FIG. schematically shows a schematic diagram of a multi-host solution 500 related to an exemplary embodiment of the present disclosure. The multi-host solution 500 is similar to the hardware multi-host solution 400, but for the sake of clearer illustration and without loss of generality, Figure 5 more hosts are shown. As Figure 5 shown, the cloud computing platform includes hosts 502, 514, and 526 installed on hosts. The flow information in OvS 504 of host 502 can be offloaded to the kernel 512 of the operating system. The flow information in OvS 516 of host 514 can be offloaded to the kernel 524 of the operating system. The flow information in OvS 528 of host 526 can be offloaded to the kernel 536 of the operating system. OvS 504 of host 502, OvS 516 of host 514, and OvS 528 of host 526 are configured with the same flow rules. In this example, initially, the OvS of host 502 is active, i.e., OvS 504 will be used to manage the forwarding services of hosts 502, 514, and 526.

[0057] With Figure 4Similarly, the host also includes VMs and network ports. For example, host 502 includes VM 506, host 514 includes VM 518, and host 526 includes VM 530. VM 506 includes application 508 and VF-ETH port 510. VM 518 includes application 520 and VF-ETH port 522. VM 530 includes application 532 and VF-ETH port 534. The flow table is offloaded to network card 538, i.e., flow table cache 540. Initially, since OvS 504 in host 502 is active at this time, if a data packet 542 is received on port 1 of network card 538 and data packet 542 is the first packet, network card 538 cannot find in flow table cache 540 where data packet 542 should be forwarded to. Therefore, network card 538 sends data packet (or its information) to OvS 504 via path 544. OvS 504 generates flow information according to the forwarding rules and sends it to flow table cache 540 of network card 538. Network card 538 will forward data packet 542 to the destination port according to its own flow table. In some embodiments, while providing extreme reliability for 4 out of 4 (4 host scenarios), the network card bandwidth can also be 100% utilized in a single host scenario.

[0058] If host 502 fails at this time, or path 544 fails, network card can send data packet 542 to host 514 via path 546. When host 514 receives data packet 542, it means it is activated. Therefore, OvS 516 of host 514 generates flow information according to the forwarding rules and sends it to flow table cache 540 of network card 538. Network card 538 will forward data packet 542 to the destination port according to its own flow table. This is the OvS collaboration mechanism across multiple hosts, which provides reliability while also making full use of network card bandwidth, enhancing the reliability of OvS offloading based on multiple smart NICs or multi-hosts in the storage scenario. Schemes 200, 300, 400, or 500 can be directly combined and used, and can also be extended to other stateless offloading features, such as IPsec offloading, etc.

[0059] Figure 6A flowchart of a data forwarding method 600 according to an exemplary embodiment of the present disclosure is schematically shown. The first host includes multiple network cards, and the multiple network cards include a first network card and a second network card. Both the first network card and the second network card have forwarding flow tables. The method 600 includes: at 602, the first network card receives a data packet from the sender and forwards the data packet from the sender to the access target according to the forwarding flow table located in the first network card. At 604, when the first network card fails, the second network card receives the subsequent data packets from the user and forwards the subsequent data packets from the sender to the access target according to the forwarding flow table located in the second network card. According to the data forwarding method of the first aspect of the present disclosure, since each network card has its own forwarding flow table, even if a certain network card fails, it will not cause the loss of the forwarding flow table, or have to obtain the forwarding flow table from the memory / hard disk. Instead, other network cards with forwarding flow tables can quickly take over the services of the failed network card. Through the mechanisms of multi-network card cooperation, flow table sharing, and fast detection of fault switching, the ability to keep the storage service uninterrupted during hardware failures is achieved.

[0060] In some embodiments, the sender may be a computer communicating with the first host, or the sender may be a virtual machine running on the first host, or the sender may be a container running on the first host. In one implementation of the first aspect, the access target may be a virtual machine running on the first host, or the access target may be a container running on the first host. In this way, this solution can also be implemented in the cloud platform, so as to achieve the ability to keep the storage service uninterrupted and load balance in the virtual machine or container.

[0061] In some embodiments, the first network card receiving the data packet from the sender may specifically include: receiving the data packet from the sender through the first port of the first network card. The second network card forwarding the subsequent data packets from the sender to the access target may specifically include: the first network card forwarding the data packet from the sender to the fourth port bound to the third port in the access target. In this way, it can be made imperceptible to the user during hardware failures.

[0062] In some embodiments, the first network card forwarding the data packet from the sender to the access target may specifically include: the first network card forwarding the data packet from the sender to the third port of the access target; and the second network card forwarding the subsequent data packets from the sender to the access target may specifically include: the first network card forwarding the data packet from the sender to the fourth port bound to the third port in the access target. In this way, it can be made imperceptible to the user during hardware failures.

[0063] In some embodiments, the first host may be located in a data center, and the forwarding flow table may be a forwarding flow table based on the Open vSwitch (OvS). In this way, the reliable forwarding function can be provided by using the OvS cooperation mechanism.

[0064] In some embodiments, the data center may further include a second host, and the second host and the first host may share a first network card and a second network card: when the first host fails, or the first host receives an instruction to stop forwarding data packets, the OVS function may be enabled; and the second host may continue to forward data packets using the second network card. In some embodiments, the CPU of the host sends forwarding flow tables to the first network card and the second network card; or the first network card and the second network card obtain the forwarding flow tables from the host memory. In this way, through the OvS coordination mechanism across multiple hosts, while providing reliability, the network card bandwidth can also be fully utilized, so that the service can be ensured to be unaffected and the utilization rate of the network card bandwidth can be improved.

[0065] Figure 7 A block diagram of a data forwarding device 700 according to an exemplary embodiment of the present disclosure is schematically shown. The first host includes a plurality of network cards, and the plurality of network cards include a first network card and a second network card, and both the first network card and the second network card have forwarding flow tables. The device 700 includes a first module 702 configured to receive a data packet from a sender by the first network card and forward the data packet from the sender to an access target according to the forwarding flow table located in the first network card. The device 700 further includes a second module 704 configured to, when the first network card fails, the second network card receives subsequent data packets from a user and forwards the subsequent data packets from the sender to the access target according to the forwarding flow table located in the second network card. According to the data forwarding device of the second aspect of the present disclosure, since each network card has its own forwarding flow table, even if a certain network card fails, the loss of the forwarding flow table will not occur, or it is not necessary to obtain the forwarding flow table from the memory / hard disk. Instead, the services of the failed network card can be quickly taken over by other network cards with forwarding flow tables. Through the mechanisms of multi-network card coordination, flow table sharing, and quick detection of fault switching, the ability to keep the storage service uninterrupted during a hardware failure is achieved.

[0066] In some embodiments, the sender may be a computer communicating with the first host, or the sender may be a virtual machine running on the first host, or the sender may be a container running on the first host. In one implementation of the first aspect, the access target may be a virtual machine running on the first host, or the access target may be a container running on the first host. In this way, this solution can also be implemented in a cloud platform, so as to achieve the ability to keep the storage service uninterrupted and perform load balancing in a virtual machine or a container.

[0067] In some embodiments, the first module 702 may also be configured to receive data packets from a sender through a first port of a first network card. The second module 704 may also be configured to forward the data packets from the sender by the first network card to a fourth port bound to a third port in an access target. In this way, when a hardware failure occurs, it can be made imperceptible to the user.

[0068] In some embodiments, the first module 702 may also be configured to forward data packets from a sender by the first network card to a third port of an access target; and the second module 704 may also be configured to forward data packets from the sender by the first network card to a fourth port bound to the third port in the access target. In this way, when a hardware failure occurs, it can be made imperceptible to the user.

[0069] In some embodiments, the first host may be located in a data center, and the forwarding flow table may be a forwarding flow table based on an Open vSwitch (OvS). In this way, the OvS cooperation mechanism can be utilized to provide a reliable forwarding function.

[0070] In some embodiments, the data center may further include a second host, and the second host and the first host may share a first network card and a second network card. The apparatus 700 may further include a third module configured to enable the OvS function when the first host fails or the first host receives an instruction to stop forwarding data packets, and the second host continues to forward data packets using the second network card. In some embodiments, the apparatus 700 may further include a fourth module configured to cause the CPU of the host to send the forwarding flow table to the first network card and the second network card; or cause the first network card and the second network card to obtain the forwarding flow table from the host memory. In this way, through the OvS cooperation mechanism across multiple hosts, while providing reliability, the network card bandwidth can also be fully utilized, so that the service can be ensured to be unaffected and the utilization rate of the network card bandwidth can be improved.

[0071] Figure 8 A schematic block diagram of an exemplary computing device 800 that may be used to implement the exemplary implementations of the present disclosure is shown. As Figure 8 shown, the computing device 800 includes: a bus 802, a processor 804, a memory 806, and a communication interface 808. The processor 804, the memory 806, and the communication interface 808 communicate with each other through the bus 802. The computing device 800 may be a server, a storage device with computing capabilities, or a terminal device. It should be understood that the present disclosure does not limit the number of processors and memories in the computing device 800.

[0072] The bus 802 can be a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 only one line is used in Figure 8 , but it does not mean that there is only one bus or one type of bus. The bus 802 can include a path for transmitting information between various components of the computing device 800 (e.g., the memory 806, the processor 804, the communication interface 808).

[0073] The processor 804 can include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0074] The memory 806 can include volatile memory, such as random access memory (RAM). The processor 804 can also include non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0075] The memory 806 stores executable program code, and the processor 804 executes the executable program code to respectively implement the functions of one or more of the foregoing receiving first module 702 and second module 704, thereby implementing the update method for a database system according to an embodiment of the present disclosure. That is, the memory 806 stores instructions for executing the update of the database system according to an embodiment of the present disclosure.

[0076] Alternatively, the memory 806 stores executable code, and the processor 804 executes the executable code to respectively implement the functions of the foregoing device 700, thereby implementing the update method for a database system according to an embodiment of the present disclosure. That is, the memory 806 stores instructions for executing the update method for a database system according to an embodiment of the present disclosure.

[0077] The communication interface 808 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 800 and other devices or a communication network.

[0078] The embodiments of the present disclosure also provide a computing device cluster, such as a database system. Figure 9 A schematic block diagram of an example computing device cluster 900 that can be used to implement exemplary implementations of the present disclosure is shown. The computing device cluster 900 includes at least one computing device. The computing device can be a server, such as a central server, an edge server, a storage device with computing capabilities, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.

[0079] like Figure 9 As shown, the computing device cluster 900 includes at least one computing device 800. The memory 806 in one or more computing devices 800 in the computing device cluster 900 may store the same instructions for executing the updating method for a database system according to an embodiment of the present disclosure.

[0080] In some possible implementations, the memory 806 of one or more computing devices 800 in the computing device cluster 900 may also store partial instructions for executing the update method for a database system according to an embodiment of the present disclosure. In other words, the combination of one or more computing devices 800 can jointly execute instructions for executing the update method for a database system according to an embodiment of the present disclosure.

[0081] It should be noted that the memory 806 in different computing devices 800 in the computing device cluster 900 may store different instructions, each for executing part of the functions of the apparatus 700. In other words, the instructions stored in the memory 806 in different computing devices 800 may implement the functions of one or more of the aforementioned receiving modules 702 and 704.

[0082] In some possible implementations, one or more computing devices in computing device cluster 900 may be connected via a network, which may be a wide area network or a local area network. Figure 10 A possible implementation is shown. Figure 10As shown, two computing devices 800A and 800B are connected via a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this possible implementation, the memory 806 in computing device 800A stores instructions for executing the functions of the receiving first module 702 and the second module 704. The memory 806 in computing device 800B stores instructions for executing the functions of the receiving first module 702 and the second module 704.

[0083] It should be understood that Figure 10 the functions of computing device 800A shown in can also be completed by multiple computing devices 800. Similarly, the functions of computing device 800B can also be completed by multiple computing devices 800.

[0084] Embodiments of the present disclosure also provide another computing device cluster. The connection relationships between the computing devices in this computing device cluster can be similarly referred to Figure 8 and Figure 9 the connection manner of the computing device cluster 900. The difference is that the memory 806 in one or more computing devices 800 in this computing device cluster may store the same instructions for executing the update method for a database system according to the embodiments of the present disclosure.

[0085] In some possible implementations, the memory 806 in one or more computing devices 800 in this computing device cluster may also separately store partial instructions for executing the update method for a database system according to the embodiments of the present disclosure. In other words, a combination of one or more computing devices 800 can jointly execute the instructions for executing the update method for a database system according to the embodiments of the present disclosure.

[0086] Embodiments of the present disclosure also provide a computer program product containing instructions. The computer program product can be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, it causes at least one computing device to execute the methods and functions in any one of the above embodiments.

[0087] Embodiments of the present disclosure also provide a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive), etc. The computer-readable storage medium includes instructions that direct a computing device to execute the methods and functions in any one of the above embodiments.

[0088] In general, the various embodiments of the present disclosure may be implemented in hardware or special-purpose circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software, which may be executed by a controller, a microprocessor, or other computing devices. Although the various aspects of the embodiments of the present disclosure are shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that the blocks, devices, systems, techniques, or methods described herein may be implemented as, by way of non-limiting example, hardware, software, firmware, special-purpose circuits or logic, general-purpose hardware or controllers or other computing devices, or some combination thereof.

[0089] The present disclosure also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions, such as instructions included in program modules, which are executed in a device on a target real or virtual processor to perform the processes / methods as referred to the accompanying drawings above. Generally, program modules include routines, programs, libraries, objects, classes, components, data structures, etc. that perform specific tasks or implement specific abstract data types. In various embodiments, the functions of program modules may be combined or divided as needed. The machine-executable instructions for program modules may be executed within a local or distributed device. In a distributed device, program modules may be located in local and remote storage media.

[0090] The computer program code for implementing the methods of the present disclosure may be written in one or more programming languages. The computer program code may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data forwarding devices, such that when the program code is executed by the computer or other programmable data forwarding devices, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code may be executed entirely on the computer, partially on the computer, as a stand-alone software package, partially on the computer and partially on a remote computer, or entirely on a remote computer or server.

[0091] In the context of the present disclosure, the computer program code or related data may be carried by any suitable carrier so that the device, apparatus, or processor can perform the various processes and operations described above. Examples of carriers include signals, computer-readable media, and the like. Examples of signals may include electrical, optical, radio, acoustic, or other forms of propagated signals, such as carrier waves, infrared signals, etc.

[0092] A computer-readable medium can be any tangible medium that contains or stores a program for or relating to an instruction execution system, apparatus, or device, or a data storage device such as a data center that contains one or more available media. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. A computer-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. More specific examples of computer-readable storage media include electrical connections with one or more wires, portable computer disks, hard disks, random access memories (RAMs), read-only memories (ROMs), erasable programmable read-only memories (EPROMs or flash memories), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0093] In addition, although the operations of the methods of the present disclosure are described in a particular order in the drawings, this is not required or implied to perform these operations in that particular order, or that all of the illustrated operations must be performed to achieve the desired result. Instead, the steps depicted in the flowcharts can be changed in the order of execution. Additionally or alternatively, some steps can be omitted, multiple steps can be combined into one step for execution, and / or one step can be decomposed into multiple steps for execution. It should also be noted that the features and functions of two or more devices according to the present disclosure can be embodied in one device. Conversely, the features and functions of one device described above can be further divided and embodied by multiple devices.

[0094] The various implementations of the present disclosure have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed implementations. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention. Many modifications and variations are obvious to those of ordinary skill in the art without departing from the scope and spirit of the described implementations. The selection of the terms used herein is intended to best explain the principles of the implementations, practical applications, or improvements to the technologies in the market, or to enable other ordinary skill in the art to understand the various implementation manners disclosed herein.

Claims

1. A data forwarding method, characterized in that, The first host includes multiple network cards, the multiple network cards include a first network card and a second network card, and both the first network card and the second network card have forwarding flow tables. The method includes: The first network card receives data packets from a sender and forwards the data packets from the sender to an access target according to the forwarding flow table located in the first network card; and When the first network card fails, the second network card receives subsequent data packets of the user and forwards the subsequent data packets from the sender to the access target according to the forwarding flow table located in the second network card.

2. The method according to claim 1, wherein: The sender is a computer communicating with the first host; or The sender is a virtual machine running on the first host; or The sender is a container running on the first host.

3. The method according to claim 1, wherein: The access target is a virtual machine running on the first host, or The access target is a container running on the first host.

4. The method according to claim 1, wherein: The first network card receives data packets from a sender, specifically including: receiving the data packets from the sender through the first port of the first network card; and The second network card receives subsequent data packets of the user, specifically including: continuing to receive data packets subsequently sent by the sender through a second port bound to the first port of the first network card, and the second port is located in the second network card.

5. The method according to claim 1, wherein: The first network card forwards the data packets from the sender to the access target, specifically including: the first network card forwards the data packets from the sender to the third port of the access target; and The second network card forwards subsequent data packets from the sender to the access target, specifically including: the first network card forwards the data packets from the sender to the fourth port bound to the third port in the access target.

6. The method according to claim 1, characterized in that: The first host is located in a data center, and the forwarding flow table is a forwarding flow table based on the Open vSwitch (OvS).

7. The method according to claim 6, wherein: The data center further includes a second host, and the second host shares the first network card and the second network card with the first host: When the first host fails, or the first host receives an instruction to stop forwarding data packets, the OVS function is enabled; and The second host uses the second network card to continue data packet forwarding.

8. The method according to claim 6, wherein, It further includes: The CPU of the host sends the forwarding flow table to the first network card and the second network card; or The first network card and the second network card obtain the forwarding flow table from the host memory.

9. A host, the host includes multiple network cards, and the host is used to execute the method according to any one of claims 1-7.

10. A computing device cluster includes multiple hosts according to claim 9.