Data forwarding method and device, nonvolatile storage medium and electronic equipment

By inserting identifiers in the preset fields of the request packet in the UDP protocol load balancing scenario, and using the virtual switch's flow table and session tracking table mechanism, the problem that the server cannot recognize the client's real IP address is solved, and the security and flexibility of the network architecture are improved.

CN120499148APending Publication Date: 2025-08-15CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510480713.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-16
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the load balancing scenario of UDP protocol, the server cannot view the client's real IP address, resulting in reduced network architecture security.

Method used

By inserting a preset identifier in the preset field of the request message, and using the virtual switch's flow table and session tracking table mechanism, we ensure that the real IP address of the client is transparently transmitted during communication, and the server can identify the real IP address of the client.

Benefits of technology

In the load balancing scenario of UDP protocol, the server can view the real IP address of the client, thereby improving the security and flexibility of the network architecture.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120499148A_ABST
    Figure CN120499148A_ABST
Patent Text Reader

Abstract

The invention discloses a data forwarding method and device, a nonvolatile storage medium and electronic equipment. The method comprises the steps that a request message sent by a client through a monitor based on a user datagram protocol is received, and the request message at least comprises a first source IP address and a first destination IP address; converting the first destination IP address into an IP address of a server, inserting a preset identifier into a preset field of the request message to obtain a processed request message, and forwarding the processed request message to the server through the virtual switch; and receiving a response message, converting the second source IP address into a virtual IP address of the gateway device to obtain a processed response message, and forwarding the processed response message to the client. According to the method and the device, the technical problem that the security of a network architecture is reduced due to the fact that the real IP address of the client cannot be checked at the server in a load balancing scene of a UDP protocol is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of cloud computing networks, and more specifically, to a data forwarding method and device, a non-volatile storage medium, and an electronic device. Background Art

[0002] In modern cloud computing and data center environments, load balancing technology is widely used to improve service availability, scalability, and security. Specifically, load balancing strategies have been designed for different communication protocols, such as TCP and UDP. Due to its connection-oriented nature, the TCP protocol can easily maintain session continuity in load balancing scenarios and ensure that the server can identify the client's true IP address through methods such as the TOA (Tunnel of Awesome) plug-in in full NAT mode. However, the connectionless nature of the UDP protocol presents a series of challenges to load balancing technology, particularly the difficulty for the server to obtain the client's true IP address.

[0003] During UDP traffic load balancing, the server sees the virtual IP address (VIP) of the gateway device (load balancer) rather than the client's actual source IP address. This phenomenon creates a major problem: the server struggles to implement access control and security policies based on the client's IP address, such as firewall rules and DDoS protection measures, reducing the security of the entire network architecture.

[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention

[0005] The present application provides a data forwarding method and device, a non-volatile storage medium, and an electronic device to at least solve the technical problem of reduced security of the network architecture due to the inability to view the client's real IP address on the server side in the load balancing scenario of the UDP protocol.

[0006] According to one aspect of the present application, a data forwarding method is provided, comprising: receiving a request message sent by a client through a listener based on a user datagram protocol, wherein the request message includes at least: a first source IP address and a first destination IP address, and the first destination IP address is a virtual IP address of a gateway device; converting the first destination IP address into an IP address of a server, and inserting a preset identifier into a preset field of the request message to obtain a processed request message, and forwarding the processed request message to the server through a virtual switch, wherein the virtual switch is used to receive a flow table, and the flow table includes at least: a preconfigured identifier; the virtual switch is further used to match the preconfigured identifier in the flow table with the preset identifier in the request message, and if the match is successful, forwarding the first source IP address to the server. The virtual switch is further configured to write the P address, the virtual IP address of the gateway device and the preset identifier into the session tracking table; the virtual switch is further configured to receive a response message sent by the server in response to the request message, wherein the response message includes: a second source IP address, a second destination IP address and a preset identifier, and the second source IP address is the IP address of the server; the virtual switch is further configured to match the pre-configured identifier in the flow table with the preset identifier in the response message, and when the match is successful, determine the virtual IP address of the gateway device through the session tracking table, and send the response message to the gateway device based on the virtual IP address of the gateway device; receive the response message, convert the second source IP address into the virtual IP address of the gateway device, obtain a processed response message, and forward the processed response message to the client.

[0007] Optionally, the flow table is sent by a software-defined network controller, wherein the software-defined network controller is configured to generate a flow table and send the flow table to the virtual switch when service traffic data first arrives at the software-defined network controller.

[0008] Optionally, the software-defined network controller is also used to create a flow table entry corresponding to the target session when the first data packet of the target session arrives, and associate a dynamically updated timeout counter with the flow table entry, wherein the target session is the session where the request message is located; when a data packet matching the flow table entry is detected to pass, the timeout counter associated with the flow table entry is reset; when the timeout counter is not reset within a preset time period, the flow table entry is deleted.

[0009] Optionally, the request message also includes: a first source port address; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the request message, and if the match is successful, the first source IP address, the virtual IP address of the gateway device, the preset identifier and the first source port address are written into the session tracking table; the second source IP address is converted into the virtual IP address of the gateway device, a processed response message is obtained, and the processed response message is forwarded to the client, including: determining the first source IP address and the first source port address that are associated with the preset identifier in the session tracking table, converting the second source IP address into the virtual IP address of the gateway device, obtaining the processed response message, and forwarding the processed response message to the first source IP address and the first source port address.

[0010] Optionally, the request message and the response message are messages in a virtual extended local area network; the request message and the response message further include: identification information of the virtual extended local area network; and the flow table further includes: identification information of the virtual extended local area network.

[0011] Optionally, the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the request message, and to match the identification information of the virtual extended LAN in the flow table with the identification information of the virtual extended LAN in the request message, and if the match is successful, write the first source IP address, the virtual IP address of the gateway device and the preset identifier into the session tracking table; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the response message, and to match the identification information of the virtual extended LAN in the flow table with the identification information of the virtual extended LAN in the response message, and if the match is successful, determine the virtual IP address of the gateway device through the session tracking table, and send the response message to the gateway device based on the virtual IP address of the gateway device.

[0012] Optionally, after receiving the response message, the method further includes: setting the preset identifier to a target character different from the preset identifier.

[0013] According to another aspect of the present application, a data forwarding device is also provided, including: a receiving module for receiving a request message sent by a client through a listener based on the user datagram protocol, wherein the request message includes at least: a first source IP address and a first destination IP address, and the first destination IP address is a virtual IP address of a gateway device; a forwarding module for converting the first destination IP address into the IP address of the server, and inserting a preset identifier into a preset field of the request message to obtain a processed request message, and forwarding the processed request message to the server through a virtual switch, wherein the virtual switch is used to receive a flow table, and the flow table includes at least: a preconfigured identifier; the virtual switch is also used to match the preconfigured identifier in the flow table with the preset identifier in the request message, and if the match is successful, The first source IP address, the virtual IP address of the gateway device and the preset identifier are written into the session tracking table; the virtual switch is also used to receive a response message sent by the server in response to the request message, wherein the response message includes: a second source IP address, a second destination IP address and a preset identifier, and the second source IP address is the IP address of the server; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the response message, and if the match is successful, the virtual IP address of the gateway device is determined through the session tracking table, and based on the virtual IP address of the gateway device, the response message is sent to the gateway device; the receiving module is used to receive the response message, convert the second source IP address into the virtual IP address of the gateway device, obtain a processed response message, and forward the processed response message to the client.

[0014] According to another aspect of the present application, a non-volatile storage medium is provided, which includes a stored program, wherein when the program is executed, the device where the storage medium is located is controlled to execute the above data forwarding method.

[0015] According to another aspect of the present application, an electronic device is provided, including: a memory and a processor, wherein the processor is configured to run a program stored in the memory, wherein the above data forwarding method is executed when the program is run.

[0016] According to yet another aspect of the present application, a computer program is provided, wherein when the computer program is executed by a processor, the above data forwarding method is implemented.

[0017] According to another aspect of the present application, a computer program product is provided, which includes a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the above data forwarding method is implemented.

[0018] In the present application, a request message is received from a client through a listener based on the User Datagram Protocol, wherein the request message includes at least: a first source IP address and a first destination IP address, and the first destination IP address is a virtual IP address of a gateway device; the first destination IP address is converted into the IP address of the server, and a preset identifier is inserted into a preset field of the request message to obtain a processed request message, and the processed request message is forwarded to the server through a virtual switch, wherein the virtual switch is used to receive a flow table, and the flow table includes at least: a pre-configured identifier; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the request message, and if the match is successful, the first source IP address, the virtual IP address of the gateway device and the preset identifier are written into a session tracking table; the virtual switch is also used to receive a response message sent by the server in response to the request message, wherein the response message includes: a first destination IP address and a first destination IP address, and the first destination IP address is converted into a virtual IP address of a server, and the first destination IP address is converted into a virtual IP address of a server Two source IP addresses, a second destination IP address and a preset identifier, the second source IP address is the IP address of the server; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the response message. When the match is successful, the virtual IP address of the gateway device is determined through the session tracking table, and the response message is sent to the gateway device based on the virtual IP address of the gateway device; the response message is received, the second source IP address is converted into the virtual IP address of the gateway device, and the processed response message is obtained, and the processed response message is forwarded to the client. In this way, the purpose of being able to view the real IP address of the client on the server side in the load balancing scenario of the UDP protocol is achieved, thereby realizing the technical effect of improving the security of the network architecture, and further solving the technical problem that the security of the network architecture is reduced due to the inability to view the real IP address of the client on the server side in the load balancing scenario of the UDP protocol. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0020] Figure 1 is a flow chart of a data forwarding method according to an embodiment of the present application;

[0021] Figure 2 is a schematic diagram of a data forwarding method according to an embodiment of the present application;

[0022] Figure 3 is a structural diagram of a data forwarding device according to an embodiment of the present application;

[0023] Figure 4This is a hardware structure block diagram of a computer terminal according to a data forwarding method of an embodiment of the present application. DETAILED DESCRIPTION

[0024] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0026] According to an embodiment of the present application, a method embodiment of a data forwarding method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0027] Figure 1 is a flow chart of a data forwarding method according to an embodiment of the present application, such as Figure 1 As shown, the method includes the following steps:

[0028] Step S102: Receive a request message sent by the client through a listener based on the User Datagram Protocol, wherein the request message includes at least: a first source IP address and a first destination IP address, and the first destination IP address is a virtual IP address of the gateway device.

[0029] It is understandable that when a client tries to access a service in the cloud, the request message first reaches the gateway, which identifies the request message and then forwards the request to the load balancer LB. The LB uses relevant algorithms to determine which backend server to assign the request to in order to achieve optimal resource utilization while ensuring high availability of the service and minimizing response time.

[0030] In step S102, the first source IP address is the real IP address of the client, assuming it is 192.24.8.8; the first destination IP address is the virtual IP address of the gateway device, assuming it is 192.24.10.5.

[0031] When a client (with the IP address 192.24.8.8) attempts to access an application deployed in a cloud environment, it sends a message directly to the virtual IP address (VIP 192.24.10.5) of the application's load balancer (LB). Initially, the client doesn't communicate directly with the application's backend servers, but rather with the LB. The LB not only manages traffic distribution but also ensures efficient and secure distribution of traffic to multiple backend servers while providing a stable interface for the client.

[0032] Step S104, converting the first destination IP address into the IP address of the server, and inserting a preset identifier into the preset field of the request message to obtain a processed request message, and forwarding the processed request message to the server through the virtual switch, wherein the virtual switch is used to receive a flow table, and the flow table includes at least: a pre-configured identifier; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the request message, and when the match is successful, write the first source IP address, the virtual IP address of the gateway device and the preset identifier into the session tracking table; the virtual switch is also used to receive a response message sent by the server in response to the request message, wherein the response message includes: a second source IP address, a second destination IP address and a preset identifier, and the second source IP address is the IP address of the server; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the response message, and when the match is successful, determine the virtual IP address of the gateway device through the session tracking table, and send the response message to the gateway device based on the virtual IP address of the gateway device.

[0033] After the load balancer, the request message will be processed by the gateway device (XGW) for the next step. One of the tasks of the gateway device is to perform address translation. The gateway device uses the Virtual Extended Local Area Network (VXLAN) protocol to keep the client's true source IP address information transparent throughout the communication process.

[0034] The gateway device transparently transmits the client's source IP address (192.24.8.8) without performing any network address translation (NAT) on it, which means the client's original real IP address is preserved. Simultaneously, the gateway device translates the request's destination address from the LB's VIP (192.24.10.5) to the backend server's IP address (RS IP, for example, 192.24.8.9). This ensures that the request reaches the correct backend server for processing.

[0035] It is worth noting that to identify the specific session, the XGW sets a unique identifier in the reserved field of the VXLAN packet header, such as the number 1234. This flag value will remain consistent throughout the communication process until it is cleared when the response packet returns to the XGW, providing a key clue for subsequent processing.

[0036] Furthermore, the SDN controller is responsible for unified control of the entire network, particularly for communications between the XGW and backend hosts (servers). The SDN controller dynamically issues same-source and same-destination flow tables (flow tables), which are used by the backend host's virtual switch to determine and manage how response packets are sent back to the XGW. One of the flow table rules configured by the SDN controller is to match a specific flag field (e.g., 1234) in VXLAN packets. When a request packet arrives, the virtual switch identifies and records the XGW's VTEP (virtual tunnel endpoint) address, source IP address (i.e., the client's IP address), and reserved flag value based on the flag value. This ensures a direct connection between the XGW and the client, as well as traceability for subsequent requests. When the backend server completes processing the request and prepares to send a response packet, the virtual switch again matches the source IP address and reserved flag address based on the flow table rules. If a match is successful, the response packet is encapsulated using the XGW's VTEP address, ensuring that the packet is correctly returned to the XGW.

[0037] Step S106: Receive the response message, convert the second source IP address into the virtual IP address of the gateway device, obtain a processed response message, and forward the processed response message to the client.

[0038] When the response message arrives at the XGW, the XGW will match the message with the previously saved session information. This process involves identifying the source address in the response message and ensuring that the source address in the response message matches the previously recorded client IP address.

[0039] The XGW replaces the source IP address of the response message with its own IP address (e.g., 192.24.10.5) to simulate the effect of the response being sent directly from the LB's VIP. As a result, the client sees the response as if it came directly from the VIP, without knowing which backend server actually processed the request. This is a core advantage of load balancing technology, which is to hide the details of the backend server and simplify the client's access process.

[0040] In the above steps, when the client sends a UDP request message, the request message contains the client's real IP address (first source IP address) and the VIP address of the target service (first destination IP address). When the load balancer receives the message, it does not modify the source IP address, but instead marks the session by inserting a preset identifier in the preset field of the network message (such as the tag field in the VXLAN message), ensuring that the original information of the source IP address is retained throughout the forwarding path. The load balancer then replaces the first destination IP address (VIP address) with the IP address of the backend server, but the source IP address remains unchanged. The request message processed in this way is forwarded to the virtual switch and finally delivered to the server. Since the source IP address remains unchanged, the first source IP address in the message received by the server is the client's real IP address.

[0041] The virtual switch receives a flow table from the SDN controller, which contains preconfigured identifiers that are bound to specific forwarding rules and session management policies. When a request packet arrives at the virtual switch, the identifier in its pre-set field is matched against the pre-configured identifier in the flow table. A successful match indicates a known session. The virtual switch then writes the source IP address, the gateway device's virtual IP address, and the pre-set identifier into the session tracking table, establishing a tracking record for the session and ensuring accurate association and identification of the source IP address information in subsequent communications.

[0042] After the server processes the request and generates a response message, the message contains the server's IP address (second source IP address) as the source address, and the client's real IP address (first source IP address) is retained in the request message through a preset identifier. The response message will also carry the preset identifier when it is returned to facilitate reverse identification. When the virtual switch receives the response message, it will use the preset identifier to match again and look for the corresponding record in the session tracking table. If the match is successful, the virtual switch can determine the client's real IP address and the virtual IP address of the gateway device, and accordingly send the response message to the gateway device correctly.

[0043] Based on the session tracking information, the gateway device converts the response message's second source IP address into the gateway's virtual IP address and sets the preset identifier to the preset characters, completing the response message processing. In this way, the response message with the virtual IP address as the source address is forwarded to the client, while the client's actual IP address information is protected and transmitted throughout the entire round-trip communication process.

[0044] The above steps, by inserting an identifier into a preset field in the UDP packet and coordinating it with the virtual switch's flow table management and session tracking mechanisms, ensure that regardless of how the packet is processed or forwarded within the network, the client's true source IP address is accurately recorded and delivered to the server. This allows the server to perform advanced functions such as access control, traffic statistics, and security policies based on the client's true IP address, even in complex load balancing environments, without relying on traditional NAT or TOA mechanisms, thereby improving the flexibility and security of the network architecture.

[0045] It's worth noting that steps S102 to S106 apply to a UDP-based load balancing scenario. The network architecture for this load balancing scenario includes a transport control layer, a network element service layer, and a resource access layer. The transport control layer serves as the entry point for the entire network and is responsible for connecting to external networks. The transport control layer handles traffic from the internet, storage area network (NAS) traffic, dedicated line access points (POPs), high-speed inter-cloud equipment, and virtual private network (VPN) devices. To ensure high availability, the transport control layer uses active-active access and deploys an access gateway (AGW) and a service gateway (SGW) in a distributed cluster. The AGW broadcasts CIDR blocks to the public network, while the SGW implements rate limiting policies for traffic. The network element service layer provides tenants with comprehensive network services from Layer 3 to Layer 7. These services include dedicated line connections, an internet gateway (IGW), network address translation (NAT), VPN access services, and a load balancer (LB). All components deployed within this area also adhere to the principles of a distributed cluster to enhance system stability and performance. The resource access layer supports the virtual network access needs of virtual machines, containerized applications, and servers. At the resource access layer, distributed virtual routers and smart network cards ensure that computing resources can be seamlessly connected to the constructed virtual network environment.

[0046] The following Figure 1 The steps shown are exemplified and explained.

[0047] According to some optional embodiments of the present application, the flow table is sent by a software-defined network controller, wherein the software-defined network controller is used to generate a flow table and send the flow table to the virtual switch when the business traffic data arrives at the software-defined network controller for the first time.

[0048] Furthermore, the software-defined network controller is also used to create a flow table entry corresponding to the target session when the first data packet of the target session arrives, and associate a dynamically updated timeout counter with the flow table entry, wherein the target session is the session in which the request message is located; when a data packet matching the flow table entry is detected to pass, the timeout counter associated with the flow table entry is reset; when the timeout counter is not reset within a preset time period, the flow table entry is deleted.

[0049] In the above embodiment, when the service traffic data first arrives at the SDN controller, the SDN controller will dynamically generate flow table entries based on the network topology, service requirements and load status. These flow table entries not only include basic packet matching rules (such as source IP, destination IP, protocol type, etc.), but also establish associations with specific sessions. Specifically for the UDP listener scenario: the target session refers to the session established when the client first sends a request message to the virtual IP (VIP) of the load balancer LB. The SDN controller can identify the target session and create corresponding flow table entries. When the first data packet of the target session arrives, the SDN controller will create a flow table entry related to the session. The entry contains information such as the client source IP address (such as 192.24.8.8), the destination IP address (LB's VIP, such as 192.24.10.5), and the VXLAN Flag field value (for example, 1234). This entry is designed to guide OVS on how to process and forward all data packets related to the session.

[0050] To ensure efficient utilization of network resources and optimize network performance, the SDN controller introduces a dynamic flow table update and timeout mechanism: each generated flow table entry is associated with a dynamically updated timeout counter. The purpose of this counter is to track the active status of the session, and its initial value is usually set to a preset duration (for example, 60 seconds). Whenever OVS detects a packet that matches an entry in the flow table (whether it is a request packet or a response packet), it reports this match event to the SDN controller. The controller then resets the timeout counter associated with the flow table entry, extending its validity period to ensure that the entry remains valid in the active session. If the timeout counter is not reset due to a packet matching event within the preset duration, it means that the session has terminated or has been inactive for a long time. At this point, the SDN controller automatically deletes the corresponding flow table entry to free up network resources and improve network scalability and performance.

[0051] By dynamically generating and deleting flow table entries, static flow table entries are prevented from occupying too much memory resources. This mechanism significantly improves resource utilization, especially for short-lived sessions that are frequently created and destroyed.

[0052] According to other optional embodiments of the present application, the request message also includes: a first source port address; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the request message, and if the match is successful, the first source IP address, the virtual IP address of the gateway device, the preset identifier and the first source port address are written into the session tracking table; the second source IP address is converted into the virtual IP address of the gateway device, a processed response message is obtained, and the processed response message is forwarded to the client, including: determining the first source IP address and the first source port address that are associated with the preset identifier in the session tracking table, converting the second source IP address into the virtual IP address of the gateway device, obtaining the processed response message, and forwarding the processed response message to the first source IP address and the first source port address.

[0053] When a request message arrives at the virtual switch, it first checks the flow table for a pre-configured identifier (i.e., the VXLAN Flag value 1234) and matches it with the preset identifier carried in the message. If a match is successful, the virtual switch performs the following operations:

[0054] The client's first source IP address (e.g., 192.24.8.8), the gateway device's virtual IP address (VIP, e.g., 192.24.10.5), a preset identifier (VXLAN Flag value 1234), and the first source port address are written into the session tracking table. The session tracking table is a key data structure used to record session status and track the path of data packets. The virtual switch then forwards the request message to the backend server (RS) based on the rules in the flow table entry. That is, the destination IP address in the request message is converted to the IP address of the backend server (e.g., 192.24.8.9). When the backend server prepares to send a response message, the message's second source IP address (i.e., the RS's IP address) needs to be converted to ensure that the response can be returned to the client via the correct path. The response message processing flow is as follows: The virtual switch first searches the session tracking table for the first source IP address (e.g., 192.24.8.8) and first source port address associated with the preset identifier (1234). Next, the virtual switch converts the second source IP address in the response message (ie, RS's IP address 192.24.8.9) into the virtual IP address of the gateway device (LBVIP, such as 192.24.10.5), while retaining the first source port address unchanged, to construct the processed response message.

[0055] The processed response message is encapsulated and sent back to the XGW through the XGW's VTEP address. The XGW then replaces the source IP address of the message with its own IP address to simulate the effect that the response comes directly from the LB VIP, and then forwards the message to the client.

[0056] In some optional embodiments of the present application, the request message and the response message are messages in a virtual extended local area network; the request message and the response message also include: identification information of the virtual extended local area network; and the flow table also includes: identification information of the virtual extended local area network. Furthermore, the virtual switch is further configured to match a preconfigured identifier in the flow table with a preset identifier in the request message, and to match the identification information of the virtual extended local area network in the flow table with the identification information of the virtual extended local area network in the request message, and if a match is successful, write the first source IP address, the virtual IP address of the gateway device, and the preset identifier into a session tracking table; the virtual switch is further configured to match the preconfigured identifier in the flow table with the preset identifier in the response message, and to match the identification information of the virtual extended local area network in the flow table with the identification information of the virtual extended local area network in the response message, and if a match is successful, determine the virtual IP address of the gateway device through the session tracking table, and send the response message to the gateway device based on the virtual IP address of the gateway device.

[0057] Preferably, after receiving the response message, the following step may be further performed: the preset identifier is set to a target character different from the preset identifier. For example, the preset identifier is 1234 and the target character is 0000.

[0058] Figure 2 is a schematic diagram of a data forwarding method according to an embodiment of the present application, such as Figure 2 As shown in Figure 2, in the VXLAN encapsulation protocol, the reserved fields in the packet header (usually bits 24-31) can be used to carry additional information that is crucial for network management and traffic control. By setting a unique identifier, such as the numbers 1234, true UDP traffic originating from the client can be marked, ensuring that this traffic can be correctly identified and processed throughout the communication link.

[0059] When a client wants to communicate with an application deployed in a cloud environment, it sends a UDP request to the load balancer's VIP. The VIP serves as the front-end entry point for cloud applications, hiding the specific information of the back-end servers and enabling intelligent traffic distribution. After receiving the client's request, the gateway device (XGW) first transparently transmits the client's source IP address—that is, it does not perform NAT and retains source IP information such as 192.24.8.8. It then translates the destination address from the VIP (e.g., 192.24.10.5) to the back-end server's IP address (RS IP, e.g., 192.24.8.9) and encapsulates this translated message into a VXLAN message. To distinguish these sessions, the XGW inserts Flag = 1234 in the reserved field of the VXLAN message header as an identifier. This flag identifier accompanies the UDP packet until it is processed and returned to the client.

[0060] The SDN controller is the brain of the network, managing the network's flow table rules and ensuring that packets are correctly processed and forwarded according to predefined policies. For UDP-based traffic, the SDN controller dynamically creates and maintains flow tables to adapt to changing communication needs. For inbound flow table rules, when a VXLAN-encapsulated UDP packet with Flag = 1234 arrives, the virtual switch (OVS) matches the flow table rule based on the Flag value, records the client's source IP address, the XGW's VTEP address, and the Flag value itself, and then forwards the packet to the designated backend server. For outbound flow table rules, when the backend server processes the request and prepares to send a response, the OVS again matches the Flag value, this time encapsulating the response packet with the XGW's VTEP address, restoring the packet's original path. The SDN controller uses its state tables (such as the CT table) to trace back to the original session, ensuring that the response packet is accurately returned to the client.

[0061] As a gateway device, the XGW not only handles traffic input and output but also decapsulates and recapsulates packets to ensure they return to the client along their original path. When the backend server's response packet reaches the XGW via OVS, the XGW clears the VXLAN packet's flag identifier and sets it to 0, restoring the packet's original format. The XGW then replaces the response packet's source IP address with its own, making it appear to the client that the response is coming directly from the VIP. This replacement strategy is crucial for maintaining transparency and consistency in the network architecture.

[0062] Preferably, the SDN controller will only generate a corresponding flow table entry when it detects the traffic of a specific session (i.e., the communication between the client and the back-end server) for the first time. Doing so can avoid the waste of resources caused by pre-setting a large number of flow table entries. Especially in the dynamic communication mode, the flow table can change as the actual demand changes, thereby improving the efficiency of resource utilization. Flow table entries are not permanently valid. In order to avoid outdated entries occupying memory resources, the SDN controller sets a timeout mechanism for the flow table. Once the flow table entry does not match any traffic again within a preset time (for example, 60 seconds), the entry will be automatically deleted to make room for new sessions and traffic. This mechanism not only reduces resource consumption, but also improves the response speed of the network and the scalability of the cluster.

[0063] The above process not only ensures the transparency of the client's real source IP address under the UDP listener configuration, but also fully utilizes the flexibility and intelligent features of SDN to provide strong support for traffic management and security control in complex network environments.

[0064] Figure 3 is a structural diagram of a data forwarding device according to an embodiment of the present application, such as Figure 3 As shown, the device includes:

[0065] The receiving module 32 is configured to receive a request message sent by the client via a listener based on the User Datagram Protocol, wherein the request message includes at least a first source IP address and a first destination IP address, and the first destination IP address is a virtual IP address of the gateway device.

[0066] The forwarding module 34 is used to convert the first destination IP address into the IP address of the server, and to insert a preset identifier into the preset field of the request message to obtain a processed request message, and forward the processed request message to the server through the virtual switch, wherein the virtual switch is used to receive a flow table, and the flow table includes at least: a pre-configured identifier; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the request message, and when the match is successful, write the first source IP address, the virtual IP address of the gateway device and the preset identifier into the session tracking table; the virtual switch is also used to receive a response message sent by the server in response to the request message, wherein the response message includes: a second source IP address, a second destination IP address and a preset identifier, and the second source IP address is the IP address of the server; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the response message, and when the match is successful, determine the virtual IP address of the gateway device through the session tracking table, and send the response message to the gateway device based on the virtual IP address of the gateway device.

[0067] The receiving module 36 is configured to receive the response message, convert the second source IP address into a virtual IP address of the gateway device, obtain a processed response message, and forward the processed response message to the client.

[0068] Optionally, the flow table is sent by a software-defined network controller, wherein the software-defined network controller is configured to generate a flow table and send the flow table to the virtual switch when service traffic data first arrives at the software-defined network controller.

[0069] Optionally, the software-defined network controller is also used to create a flow table entry corresponding to the target session when the first data packet of the target session arrives, and associate a dynamically updated timeout counter with the flow table entry, wherein the target session is the session where the request message is located; when a data packet matching the flow table entry is detected to pass, the timeout counter associated with the flow table entry is reset; when the timeout counter is not reset within a preset time period, the flow table entry is deleted.

[0070] Optionally, the request message also includes: a first source port address; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the request message, and if the match is successful, the first source IP address, the virtual IP address of the gateway device, the preset identifier and the first source port address are written into the session tracking table; the second source IP address is converted into the virtual IP address of the gateway device, a processed response message is obtained, and the processed response message is forwarded to the client, including: determining the first source IP address and the first source port address that are associated with the preset identifier in the session tracking table, converting the second source IP address into the virtual IP address of the gateway device, obtaining the processed response message, and forwarding the processed response message to the first source IP address and the first source port address.

[0071] Optionally, the request message and the response message are messages in a virtual extended local area network; the request message and the response message further include: identification information of the virtual extended local area network; and the flow table further includes: identification information of the virtual extended local area network.

[0072] Optionally, the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the request message, and to match the identification information of the virtual extended LAN in the flow table with the identification information of the virtual extended LAN in the request message, and if the match is successful, write the first source IP address, the virtual IP address of the gateway device and the preset identifier into the session tracking table; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the response message, and to match the identification information of the virtual extended LAN in the flow table with the identification information of the virtual extended LAN in the response message, and if the match is successful, determine the virtual IP address of the gateway device through the session tracking table, and send the response message to the gateway device based on the virtual IP address of the gateway device.

[0073] Optionally, after receiving the response message, the method further includes: setting the preset identifier to a target character different from the preset identifier.

[0074] It should be noted that the above Figure 3 The modules in the embodiment can be program modules (for example, a set of program instructions that implement a specific function) or hardware modules. For the latter, they can be expressed in the following forms, but are not limited to these: the expression form of each of the above modules is a processor, or the functions of each of the above modules are implemented by a processor.

[0075] It should be noted that Figure 3 The preferred implementation of the embodiment shown can be found in Figure 1 The relevant description of the illustrated embodiment will not be repeated here.

[0076] Figure 4 FIG1 shows a hardware structure block diagram of a computer terminal for implementing a data forwarding method. Figure 4 As shown, the computer terminal 40 may include one or more (402a, 402b, ..., 402n are shown in the figure) processors 402 (the processor 402 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 404 for storing data, and a transmission module 406 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that Figure 4 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 4 More or fewer components than shown, or with Figure 4 Different configurations shown.

[0077] It should be noted that the one or more processors 402 and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry." The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be incorporated in whole or in part into any of the other components of the computer terminal 40. As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).

[0078] The memory 404 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the data forwarding method in the embodiment of the present application. The processor 402 executes various functional applications and data processing by running the software programs and modules stored in the memory 404, that is, implementing the above-mentioned data forwarding method. The memory 404 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 404 may further include a memory remotely located relative to the processor 402, and these remote memories may be connected to the computer terminal 40 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0079] The transmission module 406 is configured to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by the communications provider of the computer terminal 40. In one embodiment, the transmission module 406 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission module 406 may be a radio frequency (RF) module, which is configured to communicate with the Internet wirelessly.

[0080] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 40 .

[0081] It should be noted that, in some optional embodiments, the above Figure 4 The computer terminal shown may include hardware elements (including circuits), software elements (including computer code stored on a computer-readable medium), or a combination of hardware elements and software elements. Figure 4This is merely one example of a particular embodiment and is intended to illustrate the types of components that may be present in the computer terminal described above.

[0082] It should be noted that Figure 4 The computer terminal shown is used to execute Figure 1 The data forwarding method shown, therefore the relevant explanations in the execution method of the above command are also applicable to the electronic device and will not be repeated here.

[0083] An embodiment of the present application further provides a non-volatile storage medium, which includes a stored program, wherein when the program is running, the device where the storage medium is located is controlled to execute the above data forwarding method.

[0084] A program for performing the following functions on a non-volatile storage medium: receiving a request message sent by a client through a listener based on the user datagram protocol, wherein the request message includes at least: a first source IP address and a first destination IP address, and the first destination IP address is a virtual IP address of a gateway device; converting the first destination IP address into the IP address of the server, and inserting a preset identifier into a preset field of the request message to obtain a processed request message, and forwarding the processed request message to the server through a virtual switch, wherein the virtual switch is used to receive a flow table, and the flow table includes at least: a pre-configured identifier; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the request message, and if the match is successful, the first source IP address, The virtual IP address and preset identifier of the gateway device are written into the session tracking table; the virtual switch is also used to receive a response message sent by the server in response to the request message, wherein the response message includes: a second source IP address, a second destination IP address and a preset identifier, and the second source IP address is the IP address of the server; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the response message, and if the match is successful, determine the virtual IP address of the gateway device through the session tracking table, and send the response message to the gateway device based on the virtual IP address of the gateway device; receive the response message, convert the second source IP address into the virtual IP address of the gateway device, obtain a processed response message, and forward the processed response message to the client.

[0085] An embodiment of the present application further provides an electronic device, including: a memory and a processor, wherein the processor is configured to run a program stored in the memory, wherein the above data forwarding method is executed when the program is run.

[0086] The processor is used to run a program that performs the following functions: receiving a request message sent by a client through a listener based on the user datagram protocol, wherein the request message includes at least: a first source IP address and a first destination IP address, and the first destination IP address is a virtual IP address of the gateway device; converting the first destination IP address into the IP address of the server, and inserting a preset identifier into a preset field of the request message to obtain a processed request message, and forwarding the processed request message to the server through a virtual switch, wherein the virtual switch is used to receive a flow table, and the flow table includes at least: a preconfigured identifier; the virtual switch is also used to match the preconfigured identifier in the flow table with the preset identifier in the request message, and if the match is successful, the first source IP address, The virtual IP address and preset identifier of the gateway device are written into the session tracking table; the virtual switch is also used to receive a response message sent by the server in response to the request message, wherein the response message includes: a second source IP address, a second destination IP address and a preset identifier, and the second source IP address is the IP address of the server; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the response message, and if the match is successful, determine the virtual IP address of the gateway device through the session tracking table, and send the response message to the gateway device based on the virtual IP address of the gateway device; receive the response message, convert the second source IP address into the virtual IP address of the gateway device, obtain a processed response message, and forward the processed response message to the client.

[0087] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0088] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0089] In the above-mentioned embodiments of the present application, the collected information is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary protection measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0090] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0091] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0092] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0093] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the relevant technology or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0094] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A data forwarding method, characterized in that: include: Receiving a request message sent by a client through a listener based on a user datagram protocol, wherein the request message includes at least: a first source IP address and a first destination IP address, and the first destination IP address is a virtual IP address of a gateway device; The first destination IP address is converted into the IP address of the server, and a preset identifier is inserted into the preset field of the request message to obtain a processed request message, and the processed request message is forwarded to the server through the virtual switch, wherein the virtual switch is used to receive a flow table, and the flow table at least includes: a pre-configured identifier; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the request message, and if the match is successful, write the first source IP address, the virtual IP address of the gateway device and the preset identifier into a session tracking table; the virtual switch is also used to receive a response message sent by the server in response to the request message, wherein the response message includes: a second source IP address, a second destination IP address and the preset identifier, and the second source IP address is the IP address of the server; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the response message, and if the match is successful, determine the virtual IP address of the gateway device through the session tracking table, and send the response message to the gateway device based on the virtual IP address of the gateway device; Receive the response message, convert the second source IP address into the virtual IP address of the gateway device, obtain a processed response message, and forward the processed response message to the client.

2. The method according to claim 1, characterized in that The flow table is sent by a software-defined network controller, wherein the software-defined network controller is used to generate the flow table and send the flow table to the virtual switch when business traffic data arrives at the software-defined network controller for the first time.

3. The method according to claim 2, characterized in that The software-defined network controller is further configured to, upon arrival of a first data packet of a target session, create a flow table entry corresponding to the target session, and associate a dynamically updated timeout counter with the flow table entry, wherein the target session is the session in which the request message is located; Resetting the timeout counter associated with the flow table entry when detecting that a data packet matching the flow table entry passes through; If the timeout counter is not reset within a preset time period, the flow table entry is deleted.

4. The method according to claim 1, wherein The request message also includes: a first source port address; the virtual switch is further configured to match the pre-configured identifier in the flow table with the preset identifier in the request message, and if a match is successful, write the first source IP address, the virtual IP address of the gateway device, the preset identifier, and the first source port address into a session tracking table; Converting the second source IP address into a virtual IP address of the gateway device to obtain a processed response message, and forwarding the processed response message to the client, including: Determine the first source IP address and the first source port address that are associated with the preset identifier in the session tracking table, convert the second source IP address into the virtual IP address of the gateway device, obtain a processed response message, and forward the processed response message to the first source IP address and the first source port address.

5. The method according to claim 1, wherein The request message and the response message are messages in a virtual extended local area network; The request message and the response message further include: identification information of the virtual extended local area network; the flow table further includes: identification information of the virtual extended local area network.

6. The method according to claim 5, characterized in that The virtual switch is further configured to match the preconfigured identifier in the flow table with the preset identifier in the request message, and to match the identification information of the virtual extended local area network in the flow table with the identification information of the virtual extended local area network in the request message, and if a match is successful, write the first source IP address, the virtual IP address of the gateway device, and the preset identifier into a session tracking table; The virtual switch is further configured to match the preconfigured identifier in the flow table with the preset identifier in the response message, and to match the identification information of the virtual extended local area network in the flow table with the identification information of the virtual extended local area network in the response message, and in the event of a successful match, determine the virtual IP address of the gateway device through the session tracking table, and send the response message to the gateway device based on the virtual IP address of the gateway device.

7. The method according to claim 1, characterized in that After receiving the response message, the method further includes: setting the preset identifier to a target character different from the preset identifier.

8. A data forwarding device, characterized in that: include: A receiving module, configured to receive a request message sent by a client through a listener based on a user datagram protocol, wherein the request message includes at least: a first source IP address and a first destination IP address, wherein the first destination IP address is a virtual IP address of a gateway device; A forwarding module is used to convert the first destination IP address into the IP address of the server, and insert a preset identifier into the preset field of the request message to obtain a processed request message, and forward the processed request message to the server through a virtual switch, wherein the virtual switch is used to receive a flow table, and the flow table includes at least: a pre-configured identifier; the virtual switch is also used to match the pre-configured identifier in the flow table with the preset identifier in the request message, and if the match is successful, write the first source IP address, the virtual IP address of the gateway device and the preset identifier into the virtual switch. The virtual switch is further configured to receive a response message sent by the server in response to the request message, wherein the response message includes: a second source IP address, a second destination IP address, and the preset identifier, and the second source IP address is the IP address of the server; the virtual switch is further configured to match the pre-configured identifier in the flow table with the preset identifier in the response message, and if a match is successful, determine the virtual IP address of the gateway device through the session tracking table, and send the response message to the gateway device based on the virtual IP address of the gateway device; A receiving module is used to receive the response message, convert the second source IP address into the virtual IP address of the gateway device, obtain a processed response message, and forward the processed response message to the client.

9. A non-volatile storage medium, characterized in that: The non-volatile storage medium includes a stored program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the data forwarding method according to any one of claims 1 to 7.

10. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is used to run a program stored in the memory, wherein the program executes the data forwarding method according to any one of claims 1 to 7 when running.

11. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the data forwarding method according to any one of claims 1 to 7 is implemented.