Data transmission method, device and system, gateway, storage medium and program product

By using a gateway with high data processing capabilities to perform packet decapsulation and address translation in AI training, the problems of DPDK gateway congestion and packet loss under high traffic are solved, improving AI training efficiency and reducing costs.

CN120711073APending Publication Date: 2025-09-26BEIJING BAIDU NETCOM SCI & TECH CO LTD +1
View PDF 11 Cites 0 Cited by

Patent Information

Application Number
CN202510838426.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-09-26

Smart Images

  • Figure CN120711073A_ABST
    Figure CN120711073A_ABST
Patent Text Reader

Abstract

The invention provides a data transmission method, device and system, a gateway, a storage medium and a program product, and relates to the technical field of artificial intelligence, in particular to the technical field of cloud computing virtual networks. The method comprises the following steps: receiving a first encapsulation data packet from a cloud tenant server; in response to determining that the inner-layer destination address of the first encapsulated data packet is the address of the cloud public server, converting the outer-layer source address of the first encapsulated data packet into the address of a data packet shunting gateway and converting the outer-layer destination address into the address of a first gateway to obtain a second encapsulated data packet; wherein the data packet processing amount of the first gateway is higher than the data packet processing amount of the gateway based on the data plane development suite; transmitting the second encapsulation data packet to the first gateway based on the address of the first gateway; wherein the first gateway is used for transmitting a first decapsulated data packet obtained by performing data packet decapsulation and address conversion processing on the second encapsulated data packet to the cloud public server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of artificial intelligence technology, specifically to the field of cloud computing virtual network technology, and more particularly to a data transmission method, device, system, gateway, storage medium, and program product. Background Art

[0002] With the continued development of artificial intelligence (AI) technology, especially the large-scale evolution in deep learning, large-model pre-training, and multimodal learning, AI training tasks have placed stringent requirements on the underlying network bandwidth, throughput efficiency, and transmission quality. Specifically, a gateway based on the Data Plane Development Kit (DPDK) is required to forward data packets. However, due to the limited packet processing capacity of the DPDK-based gateway, when the total flow of data packets that need to be forwarded through the gateway is too large, congestion or packet loss is likely to occur, resulting in data loading delays, which in turn significantly prolongs the model convergence time and reduces the overall training efficiency. Summary of the Invention

[0003] The embodiments of the present disclosure provide a data transmission method, a data transmission device, a data transmission system, a gateway, a computer-readable storage medium, and a computer program product.

[0004] In a first aspect, an embodiment of the present disclosure proposes a data transmission method, which is applied to a packet diversion gateway, including: receiving a first encapsulated data packet from a cloud tenant server; in response to determining that the inner destination address of the first encapsulated data packet is the address of a cloud public server, converting the outer source address of the first encapsulated data packet into the address of the packet diversion gateway and converting the outer destination address into the address of the first gateway to obtain a second encapsulated data packet; wherein the data packet processing capacity of the first gateway is higher than the data packet processing capacity of the gateway based on the data plane development kit; based on the address of the first gateway, transmitting the second encapsulated data packet to the first gateway; wherein the first gateway is used to transmit a first decapsulated data packet obtained by performing data packet decapsulation and address conversion processing on the second encapsulated data packet to the cloud public server.

[0005] In a second aspect, an embodiment of the present disclosure proposes a data transmission device, which is applied to a packet diversion gateway, comprising: a first communication module, a packet reconstruction module, and a second communication module. The first communication module is configured to receive a first encapsulated data packet from a cloud tenant server; the packet reconstruction module is configured to, in response to determining that the inner destination address of the first encapsulated data packet is the address of a cloud public server, convert the outer source address of the first encapsulated data packet into the address of the packet diversion gateway and convert the outer destination address into the address of the first gateway, thereby obtaining a second encapsulated data packet; the packet processing capacity of the first gateway is higher than the packet processing capacity of the gateway based on the data plane development kit; the second communication module is configured to transmit the second encapsulated data packet to the first gateway based on the address of the first gateway; the first gateway is configured to transmit the first decapsulated data packet obtained by performing data packet decapsulation and address conversion processing on the second encapsulated data packet to the cloud public server.

[0006] In a third aspect, an embodiment of the present disclosure proposes a data transmission system, comprising: a data packet diversion gateway and a first gateway. The data packet diversion gateway is configured to: in response to determining that the inner destination address of a first encapsulated data packet received from a cloud tenant server is the address of a cloud public server, convert the outer source address of the first encapsulated data packet into the address of the data packet diversion gateway and convert the outer destination address into the address of the first gateway to obtain a second encapsulated data packet, and transmit the second encapsulated data packet to the first gateway based on the address of the first gateway; the data packet processing capacity of the first gateway is higher than the data packet processing capacity of the gateway based on the data plane development kit; the first gateway is configured to decapsulate the second encapsulated data packet and convert the inner source address of the second encapsulated data packet into the first destination address to obtain a first decapsulated data packet, and transmit the first decapsulated data packet to the public server based on the inner destination address of the second encapsulated data packet.

[0007] In a fourth aspect, an embodiment of the present disclosure provides a gateway, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can implement the data transmission method described in any of the above implementation methods when executing the instructions.

[0008] In a fifth aspect, an embodiment of the present disclosure provides a non-transitory computer-readable storage medium storing computer instructions, which are used to enable a computer to implement the data transmission method described in any of the above implementation methods when executed.

[0009] In a sixth aspect, an embodiment of the present disclosure provides a computer program product comprising a computer program, which, when executed by a processor, can implement the data transmission method described in any of the above implementations.

[0010] According to the data transmission scheme provided by the embodiment of the present disclosure, when it is determined that the inner destination address of the first encapsulated data packet received from the cloud tenant server side is the address of the cloud public server, it can be unloaded to the first gateway with higher data processing capabilities for processing by converting its outer source address to the address of the data packet diversion gateway and converting the outer destination address to the address of the first gateway, so that the first gateway can transmit the encapsulated data packet after address conversion, that is, the second encapsulated data packet, to the cloud public server after decapsulation and address conversion. In this way, by using a gateway with higher data processing capabilities to process data packet traffic, the data loading delay or packet loss rate caused by the limited data processing capability of the gateway can be reduced, thereby effectively alleviating network congestion and achieving the purpose of improving AI training efficiency. At the same time, it can also avoid the cost increase caused by the use of a large number of horizontal expansion processing methods.

[0011] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Other features, objects and advantages of the present disclosure will become more apparent from a reading of the detailed description of non-limiting embodiments made with reference to the following drawings:

[0013] Figure 1 A schematic diagram of a data transmission process based on a network architecture in related technologies;

[0014] Figure 2 is an exemplary system architecture in which the present disclosure may be applied;

[0015] Figure 3 A flowchart of a data transmission method provided in an embodiment of the present disclosure;

[0016] Figure 4 A structural block diagram of a data transmission device provided in an embodiment of the present disclosure;

[0017] Figure 5 A structural block diagram of a data transmission system provided in an embodiment of the present disclosure;

[0018] Figure 6 A schematic diagram of a data transmission solution implemented based on a network architecture in an application scenario provided by an embodiment of the present disclosure;

[0019] Figure 7 for Figure 6 The schematic diagram of the architecture of the high-performance public service gateway shown;

[0020] Figure 8 A schematic structural diagram of an electronic device suitable for executing a data transmission method provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0021] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be recognized by those skilled in the art that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description. It should be noted that the embodiments in the present disclosure and the features in the embodiments can be combined with each other unless there is a conflict.

[0022] It should be pointed out that in the technical solutions disclosed herein, the collection, acquisition, storage, processing, transmission, provision, disclosure and application of user personal information (such as account information, etc.) are all carried out with the user's knowledge and explicit authorization, comply with the relevant laws and regulations, and do not violate public order and good morals.

[0023] With the continuous development of AI technology, especially the large-scale evolution in deep learning, large model pre-training and multimodal learning, in typical data parallel training scenarios, there are thousands of graphics processing unit (GPU) nodes that need to synchronously and concurrently read different shards of the same data set. This will result in massive data packets being loaded between GPUs and parallel file storage services (PFS) (such as Figure 1 If network congestion or packet loss occurs at this time, data loading latency will increase exponentially, causing GPU computing resources to idle for extended periods of time (for example, if a single node latency increases by 1ms, the cumulative GPU idle time in a Qianka cluster may reach several hours). This will significantly prolong model convergence time and reduce overall training efficiency. Therefore, resolving network congestion or packet loss caused by high-frequency traffic between GPUs and PFS is crucial.

[0024] Currently, PFS deployed in the cloud public service area can provide services to cloud platform tenants in the following two modes:

[0025] Mode 1: Deploy parallel file storage services directly on the cloud platform tenant server (such as Figure 1 Within the GPU server (shown in the figure), tenants access the parallel file storage service through a virtual network. Model 2: Centrally deploy the parallel file storage service in the cloud public service area. Subsequently, tenants are provided access to the parallel file storage service through a shared Remote Direct Memory Access (RDMA) network, an independent storage network, or a virtual network.

[0026] Compared with independently deploying parallel file storage services in each tenant server of the cloud platform for their own use, the solution of centrally deploying parallel file storage services in the cloud public service area and enabling shared use by all tenants through a virtual network has more significant advantages. The parallel file storage service centrally deployed in the cloud public service area can achieve unified cluster management, which can effectively avoid the problems caused by building a separate parallel file storage service cluster for each tenant, such as separate deployment leading to severe resource fragmentation, difficulty in efficiently utilizing a large number of scattered resources, increased management complexity, and a heavy burden on operation and maintenance work. In addition, accessing the parallel file storage service through a virtual network can also avoid interference with AI training due to shared use of RDMA networks, as well as the high cost of building an independent storage network.

[0027] In the related art, in order to enable cloud platform tenant servers to access the parallel file storage service deployed in the cloud public service area through a virtual private network, a virtual router can be used for transfer. The network architecture in the related art is as follows: Figure 1 As shown in the figure, for cloud platform tenants' GPU servers, there are usually two networks: the High-Performance Network (HPN) and the Virtual Private Cloud (VPC). The HPN network can provide low-latency, high-bandwidth network services to meet the efficient requirements of AI model training and inference through a customized high-performance protocol stack, communication library protocol, and congestion control algorithm. The VPC network can implement scenarios such as cloud platform tenant servers accessing the same VPC, accessing across VPCs, and accessing public services through a series of products developed based on the Data Plane Development Kit (DPDK). Among them, cloud platform tenant servers accessing parallel file storage services is one of the typical application scenarios for accessing public services.

[0028] like Figure 1As shown in the network architecture of the related art, the virtual router implemented based on DPDK in the virtual router cluster serves as the gateway for the cloud platform tenant server. The traffic from the cloud platform tenant server to the parallel file storage service will be transferred by the virtual router. The specific data packet transmission process may include:

[0029] (1) After a data packet is sent from a cloud platform tenant GPU server, it is encapsulated in a Virtual Extensible Local Area Network (VXLAN) in the virtual switch and then sent to the virtual router. The data packet is forwarded between the virtual switch and the virtual router via the overlay network. High-speed data transmission is achieved between multiple GPU servers using RDMA / RDMA over Converged Ethernet (RoCE) technology.

[0030] (2) Since the Internet Protocol (IP) address of the cloud platform tenant GPU server may conflict with the IP address of the server in the cloud public service area, it is necessary to give the cloud platform tenant GPU server an identity that can be accessed by the cloud public service area through a virtual router, that is, to convert the source address of the data packet into an address that does not conflict with the IP address of the cloud platform tenant GPU server and can be accessed.

[0031] (3) After the virtual router routes the data packet, performs security access control based on the access control list (ACL), performs address translation, and reconstructs the data packet, the data packet is then sent to the underlying physical network (underlay network) of the cloud public service area. Data packet reconstruction refers to the fact that the data packet received from the cloud platform tenant GPU server is in VXLAN message format, and the parallel file storage service in the cloud public area cannot process data packets in VXLAN message format. Therefore, the data packet needs to be converted into a non-VXLAN message format.

[0032] (4) The data packet is forwarded via the Underlay network and sent to the parallel file storage service for processing.

[0033] (5) The same applies to the transmission of return data packets from the parallel file storage service to the cloud platform tenant GPU server.

[0034] Because the virtual routers (or gateways) in related technologies are implemented based on DPDK, the packet processing capabilities of a single virtual router are relatively limited. During the AI ​​training process, its processing power is far from meeting business needs. Currently, it can only be met through large-scale horizontal expansion, but this will cause costs to rise sharply. At the same time, when faced with a single large flow (i.e., elephant flow), the processing power of the virtual router is limited. When such a large flow occurs, the core computing unit (Worker CPU) resources responsible for processing packet forwarding in the virtual router will be fully occupied, which will lead to problems such as increased data loading delay or packet loss after the data packet passes through the virtual router.

[0035] Therefore, how to effectively alleviate network congestion, reduce loading delays and packet loss rates in data packet transmission, and thus improve AI training efficiency, has become a technical problem that needs to be solved urgently.

[0036] Figure 2 An exemplary system architecture 200 is shown to which embodiments of the data transmission scheme of the present disclosure may be applied.

[0037] like Figure 2 As shown, system architecture 200 may include server 201 and server 202. Gateway 203 is used to provide data packet forwarding or transmission services between server 201 and server 202. In the embodiment of the present disclosure, server 201 may be a GPU server of a cloud platform tenant, and server 202 may be a PFS server in a cloud public service area for providing large-scale data storage and efficient data access.

[0038] Tenants or users can use server 201 to interact with server 202 via gateway 203 to receive or send data packets, etc. Server 201 and server 202 can be installed with various applications for transmitting data packets between them, such as data transmission applications, instant messaging applications, etc.

[0039] Servers 201 and 202 can be either hardware or software. When hardware, they can be implemented as a distributed server cluster consisting of multiple servers or as a single server. When software, they can be implemented as multiple software programs or software modules or as a single software program or software module, without further limitation. Gateway 203 can be either hardware or software.

[0040] The gateway 203 can provide data transmission services through various built-in applications. The gateway 203 can achieve the following effects when running data transmission applications: when it is determined that the inner destination address of the first encapsulated data packet received from the cloud tenant server side is the address of the cloud public server, it can be unloaded to the first gateway with higher data processing capabilities for processing by converting its outer source address to the address of the data packet diversion gateway and converting the outer destination address to the address of the first gateway, so that the first gateway can transmit the encapsulated data packet after address conversion, that is, the second encapsulated data packet, to the cloud public server after decapsulation and address conversion. In this way, by using a gateway with higher data processing capabilities to process data packet traffic, the data loading delay or packet loss rate caused by the limited data processing capacity of the gateway can be reduced, thereby effectively alleviating network congestion and achieving the purpose of improving AI training efficiency. At the same time, it can also avoid the cost increase caused by the use of a large number of horizontal expansion processing methods.

[0041] It should be understood that Figure 2 The number of servers 201, servers 202 and gateways 203 in FIG. 2 is merely illustrative. Any number of servers 201, servers 202 and gateways 203 may be provided as required.

[0042] Please refer to Figure 3 , Figure 3 This is a flowchart of a data transmission method provided in an embodiment of the present disclosure. The data transmission method is performed by a data packet offloading gateway, wherein the data packet offloading gateway can be specifically implemented as a high-performance virtual router. The process 300 includes the following steps:

[0043] Step 301: Receive a first encapsulated data packet from a cloud tenant server.

[0044] This step is intended to be performed by the above-mentioned execution subject of the data transmission method (for example Figure 2 The gateway 203 shown receives a first encapsulated data packet from a cloud tenant server. The cloud tenant server may be a GPU server deployed on a virtual private cloud (VPC) network. The cloud tenant server may access the VPC network via a virtual switch and implement encapsulation of the data packet to be sent through the virtual switch. Specifically, the VXLAN protocol may be used to encapsulate the data packet to be sent. That is, the first encapsulated data packet may be in a VXLAN format to achieve network isolation and ensure security during data packet transmission. In some optional implementations of the embodiments of the present disclosure, a communication connection may be established between the virtual switch and the data packet diversion gateway via an overlay network.

[0045] Step 302: In response to determining that the inner destination address of the first encapsulated data packet is the address of the cloud public server, the outer source address of the first encapsulated data packet is converted to the address of the packet offloading gateway, and the outer destination address is converted to the address of the first gateway, thereby obtaining a second encapsulated data packet. The packet processing capacity of the first gateway is higher than that of a gateway based on the Data Plane Development Kit (DPDK).

[0046] In an embodiment of the present disclosure, the first encapsulated data packet is at least provided with: an inner source address, i.e., the address of the cloud tenant server; an inner destination address, i.e., the address of the cloud public server to be accessed; an outer source address converted to the address of the above-mentioned virtual switch, and an outer destination address, i.e., the address of the data packet diversion gateway. Wherein, the cloud public server can be implemented as a PFS server deployed in the public area of ​​the cloud network. When the above-mentioned execution entity receives the first encapsulated data packet, it reads its inner destination address, and when the read inner destination address is the address of the cloud public server, it can be unloaded to the first gateway for processing, and in order to ensure the stability and reliability of forwarding the first encapsulated data packet to the first gateway, it is necessary to perform address translation, i.e., Network Address Translation (NAT), convert its outer source address into the address of the data packet diversion gateway and convert the outer destination address into the address of the first gateway to obtain a second encapsulated data packet.

[0047] In the embodiments of the present disclosure, the first gateway has data processing capabilities far exceeding those of DPDK-based gateways in related technologies. Specifically, this can be demonstrated by the first gateway processing a higher packet throughput than the DPDK-based gateway. The data processing capabilities of each gateway can be characterized by bandwidth capacity. For example, the first gateway can have a bandwidth capacity of up to Tbps, while the DPDK-based gateway only has a bandwidth capacity of Gbps.

[0048] In an embodiment of the present disclosure, the first gateway may implement a data processing capability far exceeding that of a DPDK-based gateway in related technologies based on a preset type of chip, and the specific capability may be determined according to actual needs.

[0049] Step 303: Based on the address of the first gateway, the second encapsulated data packet is transmitted to the first gateway, wherein the first gateway is configured to transmit a first decapsulated data packet obtained by decapsulating and translating the address of the second encapsulated data packet to the cloud public server.

[0050] In an embodiment of the present disclosure, after completing the conversion of the outer destination address of the first encapsulated data packet, the encapsulated data packet obtained after address conversion, i.e., the second encapsulated data packet, can be transmitted to the first gateway based on the converted outer destination address, i.e., the address of the first gateway. Furthermore, the first gateway can perform data packet decapsulation and address conversion on the received second encapsulated data packet to obtain a first decapsulated data packet that can be recognized and received by the cloud public server, thereby completing the data transmission or forwarding from the cloud tenant server to the cloud public server.

[0051] In an embodiment of the present disclosure, the first gateway decapsulating the second encapsulated data packet may include removing its outer address and reconstructing the data into a non-VXLAN formatted data packet that can be processed by the cloud public server. The first gateway translating the address of the second encapsulated data packet may include translating its inner source address, i.e., the address of the cloud tenant server, to assign the data packet a first destination address that can be recognized by the cloud public server and avoid address conflicts with the cloud tenant server. The first destination address can be used to uniquely identify the cloud tenant server currently accessing the cloud public server.

[0052] The data transmission method provided by the embodiment of the present disclosure, when it is determined that the inner destination address of the first encapsulated data packet received from the cloud tenant server side is the address of the cloud public server, can be unloaded to a first gateway with higher data processing capabilities for processing by converting its outer source address to the address of the data packet diversion gateway and converting the outer destination address to the address of the first gateway, so that the first gateway can transmit the encapsulated data packet after the address conversion, that is, the second encapsulated data packet, to the cloud public server after decapsulation and address conversion. In this way, by using a gateway with higher data processing capabilities to process data packet traffic, the data loading delay or packet loss rate caused by the limited data processing capability of the gateway can be reduced, thereby effectively alleviating network congestion and achieving the purpose of improving AI training efficiency. At the same time, it can also avoid the cost increase caused by the use of a large number of horizontal expansion processing methods.

[0053] In some optional embodiments of the present disclosure, the data transmission method may further include the following:

[0054] Receive a third encapsulated data packet from the first gateway; wherein the third encapsulated data packet is obtained by the first gateway performing address conversion and encapsulation processing on the first data packet to be encapsulated, the first data packet to be encapsulated is fed back to the first gateway by the public server in response to the received first decapsulated data packet, the inner destination address of the third encapsulated data packet is the address of the cloud tenant server and the outer destination address is the address of the data packet diversion gateway; based on the inner destination address of the third encapsulated data packet, transmit the third encapsulated packet to the cloud tenant server.

[0055] In this embodiment, after forwarding the data packet from the cloud tenant server to the cloud public server, the data packet fed back by the cloud public server in response to the received data packet can be further forwarded to the cloud tenant server to achieve effective access of the cloud tenant server to the cloud public server. Specifically, the return routing path of the data packet fed back by the cloud public server to the cloud tenant server is still forwarded through the first gateway, that is, the cloud public server feeds back the first to-be-encapsulated data packet fed back in response to the first decapsulated data packet received from the first gateway to the first gateway, and the first gateway performs address conversion and encapsulation processing on the received first to-be-encapsulated data packet to obtain a third encapsulated data packet, wherein the inner destination address of the third encapsulated data packet points to the cloud tenant server, and then the corresponding data packet can be smoothly routed to the cloud tenant server based on its inner destination address, thereby completing the data packet transmission or forwarding from the cloud public server to the cloud tenant server.

[0056] In the embodiment of the present disclosure, the above-mentioned first data packet to be encapsulated is provided with at least: an inner source address, namely the address of the cloud public server; an inner destination address, namely the address corresponding to the cloud tenant server after the address conversion by the first gateway (ie the above-mentioned first target address).

[0057] In the above embodiment of the present disclosure, the first gateway encapsulates the first data packet to be encapsulated, which may include reconstructing the non-VXLAN formatted data packet to be encapsulated into a VXLAN formatted data packet that can be processed by the cloud tenant server, and the address conversion may include restoring the inner destination address of the first data packet to be encapsulated (i.e., the above-mentioned first target address) to the (real) address of the cloud tenant server, and setting its outer source address to the address of the first gateway, and the outer destination address to the address of the data packet diversion gateway, so as to ensure that correct routing to the cloud tenant server can be achieved.

[0058] In some optional embodiments of the present disclosure, the data transmission method may further include the following:

[0059] In response to determining that the first encapsulated data packet is a data packet based on a preset version of the Internet Protocol, the outer source address of the first encapsulated data packet is converted into the address of the data packet diversion gateway and the outer destination address is converted into the address of the second gateway to obtain a fourth encapsulated data packet; wherein the data packet processing volume of the first gateway is higher than the data packet processing volume of the second gateway; based on the address of the second gateway, the fourth encapsulated data packet is transmitted to the second gateway; wherein the second gateway is used to transmit a second decapsulated data packet obtained after data packet decapsulation and address conversion processing on the fourth encapsulated data packet to the cloud public server.

[0060] In this embodiment, in order to control the flow of data packets diverted to the first gateway for processing, ensure its performance in data packet processing, and avoid network congestion or packet loss, a specific type of data packet, namely a data packet based on a preset version of the Internet Protocol, can be diverted to a second gateway different from the first gateway for processing, wherein the data packet processing capacity of the first gateway is higher than that of the second gateway. Exemplarily, the second gateway may include a DPDK-based gateway, and the preset version of the Internet Protocol includes but is not limited to Internet Protocol Version 6 (IPV6); further, the data packet diverted to the first gateway for processing may be a data packet based on another version of the Internet Protocol (such as IPV4) that is different from the data packet based on the preset version of the Internet Protocol. Specifically, when it is determined that the type of the first encapsulated data packet received from the cloud tenant server side is a data packet based on the preset version of the Internet Protocol, the fourth encapsulated data packet obtained after address conversion can be diverted to the second gateway for processing by converting its outer source address to the address of the data packet diversion gateway and converting the outer destination address to the address of the second gateway, so that the second gateway can transmit the fourth encapsulated data packet to the cloud public server after decapsulation and address conversion. This can further alleviate network congestion.

[0061] In an embodiment of the present disclosure, similarly, the decapsulation processing of the fourth encapsulated data packet by the second gateway may include removing its outer address and reconstructing its data into a data packet in a non-VXLAN format that can be processed by the cloud public server, and performing address conversion may include converting its inner source address, i.e., the address of the cloud tenant server, to give the data packet a second target address that can be recognized by the cloud public server and avoid address conflicts with the cloud tenant server. The second target address can be used to uniquely identify the cloud tenant server currently accessing the public server. In some optional implementations of the embodiments of the present disclosure, the first target address may be the same as or different from the above-mentioned first target address.

[0062] In some optional implementations of the embodiments of the present disclosure, the priority of the routing path corresponding to the first gateway is higher than the priority of the routing path corresponding to the second gateway.

[0063] In this embodiment, the routing path corresponding to the first gateway may include a routing path for data packets passing through the cloud tenant server, the data packet diversion gateway, the routing path from the first gateway to the cloud public server, and a corresponding routing path for data packets returning from the cloud public server to the cloud tenant server; and the routing path corresponding to the second gateway may include a routing path for data packets passing through the cloud tenant server, the data packet diversion gateway, the routing path from the second gateway to the cloud public server, and a corresponding routing path for data packets returning from the cloud public server to the cloud tenant server. Specifically, by setting the priority of data packet transmission or forwarding on the routing path where the first gateway is located to be higher than the priority of data packet transmission or forwarding on the routing path where the second gateway is located, it can be effectively ensured that data packet traffic is preferentially offloaded to the first gateway with higher data processing capabilities for processing, so as to reduce data loading delay or packet loss rate caused by the limited data processing capabilities of the gateway, thereby effectively alleviating network congestion.

[0064] Further references Figure 4 As an implementation of the methods shown in the above figures, the present disclosure provides an embodiment of a data transmission device. Figure 3 Corresponding to the method embodiment shown, the device can be specifically applied to a data packet splitting gateway.

[0065] like Figure 4 As shown, the data transmission device 400 of the embodiment of the present disclosure may include: a first communication module 401, a data packet reconstruction module 402, and a second communication module 403. The first communication module 401 is configured to receive a first encapsulated data packet from a cloud tenant server; the data packet reconstruction module 402 is configured to, in response to determining that the inner destination address of the first encapsulated data packet is the address of the cloud public server, convert the outer source address of the first encapsulated data packet into the address of the data packet offloading gateway and convert the outer destination address into the address of the first gateway, thereby obtaining a second encapsulated data packet; the data packet processing capacity of the first gateway is higher than the data packet processing capacity of the gateway based on the data plane development kit; the second communication module 403 is configured to transmit the second encapsulated data packet to the first gateway based on the address of the first gateway; the first gateway is configured to transmit the first decapsulated data packet obtained by performing data packet decapsulation and address conversion processing on the second encapsulated data packet to the cloud public server.

[0066] In the embodiment of the present disclosure, the specific processing of the first communication module 401, the data packet reconstruction module 402 and the second communication module 403 and the technical effects thereof can be referred to in the respective Figure 3The relevant descriptions of steps 301-303 in the corresponding embodiment are not repeated here.

[0067] In some optional implementations of the embodiments of the present disclosure, the above-mentioned second communication module 403 can also be configured to receive a third encapsulated data packet from the first gateway; wherein, the third encapsulated data packet is obtained by the first gateway performing address conversion and encapsulation processing on the first data packet to be encapsulated, the first data packet to be encapsulated is fed back to the first gateway by the public server in response to the received first decapsulated data packet, the inner destination address of the third encapsulated data packet is the address of the cloud tenant server and the outer destination address is the address of the data packet diversion gateway; and the above-mentioned first communication module 401 can also be configured to transmit the third encapsulated packet to the cloud tenant server based on the inner destination address of the third encapsulated data packet.

[0068] In some optional implementations of the embodiments of the present disclosure, the data transmission device 400 may further include a third communication module (not shown in the figure). The packet reconstruction module 402 may further be configured to, in response to determining that the first encapsulated packet is a packet based on a preset version of the Internet Protocol, convert the outer source address of the first encapsulated packet into the address of the packet diversion gateway and convert the outer destination address into the address of the second gateway, thereby obtaining a fourth encapsulated packet; wherein the packet processing capacity of the first gateway is higher than the packet processing capacity of the second gateway; and the third communication module may be configured to transmit the fourth encapsulated packet to the second gateway based on the address of the second gateway; wherein the second gateway is configured to transmit the second decapsulated packet obtained after performing packet decapsulation and address conversion on the fourth encapsulated packet to the cloud public server.

[0069] In some optional implementations of the embodiments of the present disclosure, the priority of the routing path corresponding to the first gateway is higher than the priority of the routing path corresponding to the second gateway.

[0070] This embodiment exists as an apparatus embodiment corresponding to the above-mentioned method embodiment. When it is determined that the inner destination address of the first encapsulated data packet received from the cloud tenant server side is the address of the cloud public server, it can be unloaded to a first gateway with higher data processing capabilities for processing by converting its outer source address to the address of the data packet diversion gateway and converting the outer destination address to the address of the first gateway, so that the first gateway can transmit the encapsulated data packet after address conversion, i.e., the second encapsulated data packet, to the cloud public server after decapsulation and address conversion. In this way, by using a gateway with higher data processing capabilities to process data packet traffic, the data loading delay or packet loss rate caused by the limited data processing capability of the gateway can be reduced, thereby effectively alleviating network congestion and achieving the purpose of improving AI training efficiency. At the same time, it can also avoid the cost increase caused by the use of a large number of horizontal expansion processing methods.

[0071] Further references Figure 5 As a system implementation related to the methods shown in the above figures, the present disclosure also provides an embodiment of a data transmission system. The content related to the data packet splitting gateway in the embodiment of the system is similar to Figure 3 The method embodiment shown corresponds to the embodiment shown.

[0072] like Figure 5 As shown, the data transmission system 500 of the embodiment of the present disclosure may include: a packet offload gateway 501 and a first gateway 502. The packet offload gateway 501 is configured to, in response to determining that the inner destination address of a first encapsulated packet received from a cloud tenant server is the address of a cloud public server, convert the outer source address of the first encapsulated packet into the address of the packet offload gateway 501 and the outer destination address into the address of the first gateway 502, thereby obtaining a second encapsulated packet, and transmit the second encapsulated packet to the first gateway 502 based on the address of the first gateway 502; the packet processing capacity of the first gateway 502 is higher than the packet processing capacity of a gateway based on a data plane development kit; and the first gateway 502 is configured to decapsulate the second encapsulated packet, convert the inner source address of the second encapsulated packet into the first destination address, thereby obtaining a first decapsulated packet, and transmit the first decapsulated packet to the public server based on the inner destination address of the second encapsulated packet.

[0073] In this embodiment, when the packet diversion gateway 501 in the packet transmission system determines that the inner destination address of the first encapsulated data packet received from the cloud tenant server side is the address of the cloud public server, it can convert its outer source address into the address of the packet diversion gateway and convert the outer destination address into the address of the first gateway 502 in the packet transmission system, and unload it to the first gateway 502 with higher data processing capabilities for processing, so that the first gateway 502 can transmit the encapsulated data packet after address conversion, that is, the second encapsulated data packet, to the cloud public server after decapsulation and address conversion. In this way, by using a gateway with higher data processing capabilities to process data packet traffic, the data loading delay or packet loss rate caused by the limited data processing capacity of the gateway can be reduced, thereby effectively alleviating network congestion and achieving the purpose of improving AI training efficiency. At the same time, it can also avoid the cost increase caused by the use of a large number of horizontal expansion processing methods.

[0074] In an embodiment of the present disclosure, the cloud tenant server can be a GPU server deployed on a virtual private cloud (VPC) network, and the cloud tenant server can access the VPC network through a virtual switch and implement encapsulation processing of the data packets to be sent through the virtual switch. Specifically, the VXLAN protocol can be used to encapsulate the data packets to be sent, that is, the first encapsulated data packets can be in the VXLAN format to achieve network isolation and ensure security during data packet transmission. In some optional implementations of the embodiments of the present disclosure, a communication connection can be established between the virtual switch and the data packet diversion gateway 501 via an overlay network.

[0075] In the embodiment of the present disclosure, the first encapsulated data packet is provided with at least: an inner source address, i.e., the address of the cloud tenant server; an inner destination address, i.e., the address of the cloud public server to be accessed; and an outer destination address, i.e., the address of the data packet diversion gateway 501. The cloud public server can be implemented as a PFS server deployed in a public area of ​​a cloud network. Upon receiving the first encapsulated data packet, the data packet diversion gateway 501 reads its inner destination address, and when the read inner destination address is the address of the cloud public server, it can be unloaded to the first gateway 502 for processing. In order to ensure the stability and reliability of forwarding the first encapsulated data packet to the first gateway 502, it is necessary to perform address translation, i.e., network address translation NAT, to convert its outer source address to the address of the data packet diversion gateway 501 and the outer destination address to the address of the first gateway 502, so as to obtain a second encapsulated data packet.

[0076] In the embodiments of the present disclosure, the first gateway 502 has data processing capabilities far exceeding those of DPDK-based gateways in related technologies. Specifically, this can be demonstrated by the fact that the first gateway 502 processes more packets than the DPDK-based gateway. The data processing capabilities of each gateway can be characterized by bandwidth capacity. For example, the first gateway 502 can have a bandwidth capacity of up to Tbps, while the DPDK-based gateway only has a bandwidth capacity of Gbps.

[0077] In an embodiment of the present disclosure, the first gateway 502 can implement a data processing capability far exceeding that of a DPDK-based gateway in related technologies based on a preset type of chip, and the specific capability can be determined according to actual needs.

[0078] In the embodiment of the present disclosure, after completing the conversion of the inner source address and outer destination address of the first encapsulated data packet, the data packet offloading gateway 501 can transmit the encapsulated data packet obtained after address conversion, i.e., the second encapsulated data packet, to the first gateway 502 based on the converted outer destination address, i.e., the address of the first gateway 502. Furthermore, the first gateway 502 performs data decapsulation processing on the second encapsulated data packet, which may include removing its outer address and reconstructing its data into a non-VXLAN format data packet that can be processed by the cloud public server, and performing address conversion, which may include converting its inner source address, i.e., the address of the cloud tenant server, to give the data packet a first destination address that can be recognized by the cloud public server and avoid address conflicts with the cloud tenant server. The first destination address can be used to uniquely identify the cloud tenant server currently accessing the public server.

[0079] In some optional implementations of the embodiments of the present disclosure, the above-mentioned first gateway 502 can also be configured to: receive the first data packet to be encapsulated from the cloud public server in response to the feedback of the first decapsulated data packet; convert the first target address of the first data packet to be encapsulated into the address of the cloud tenant server, and encapsulate the first data packet to be encapsulated after the address conversion to obtain a third encapsulated data packet; wherein the inner destination address of the third encapsulated data packet is the address of the cloud tenant server and the outer destination address is the address of the data packet diversion gateway 501.

[0080] In the embodiment of the present disclosure, the above-mentioned first data packet to be encapsulated is provided with at least: an inner source address, namely the address of the cloud public server; an inner destination address, namely the address corresponding to the cloud tenant server after the address conversion by the first gateway 502 (ie the above-mentioned first target address).

[0081] In an embodiment of the present disclosure, upon receiving a first data packet to be encapsulated fed back by the cloud public server in response to a first decapsulated data packet received from the first gateway 502, the first gateway 502 performs address translation and encapsulation processing on the first data packet to be encapsulated. Specifically, performing address translation on the first data packet to be encapsulated includes restoring its first destination address to the (real) address of the cloud tenant server, and setting its outer source address to the address of the first gateway 502 and the outer destination address to the address of the data packet diversion gateway 501, so as to ensure that correct routing to the cloud tenant server can be achieved; and performing encapsulation processing on the first data packet to be encapsulated includes reconstructing the non-VXLAN formatted data packet to be encapsulated into a VXLAN formatted data packet that can be processed by the cloud tenant server.

[0082] In some optional implementations of the disclosed embodiments, the architecture of the first gateway 502 includes a data plane, which includes a switching chip layer for decapsulating and performing address translation on the second encapsulated data packet, and encapsulating and performing address translation on the first to-be-encapsulated data packet. In this embodiment, to ensure that the first gateway 502 can smoothly decapsulate, encapsulate, and perform address translation on the corresponding data packets, a switching chip layer can be provided on its data plane to ensure the packet processing capability of the first gateway 502.

[0083] In some optional implementations of the embodiments of the present disclosure, the architecture of the above-mentioned first gateway 502 also includes a control plane, and the data plane also includes a business logic layer and a kernel layer; and the business logic layer is used to receive a preset configuration from the control plane through a remote procedure call interface, and transmit the preset configuration to the switching chip layer; the kernel layer is used to establish a BGP neighbor relationship with the upstream switch through the Border Gateway Protocol (BGP), and publish the address of the first gateway based on the BGP neighbor relationship; the switching chip layer is used to decapsulate and perform address translation processing on the second encapsulated data packet based on the preset configuration, and to encapsulate and perform address translation processing on the first data packet to be encapsulated.

[0084] In this embodiment, the network architecture of the first gateway 502 may include a control plane in addition to the data plane, and in addition to the switching chip layer, the data plane may also include a business logic layer and a kernel layer, and the business logic layer may be used to implement effective interaction between the data plane and the control plane, and the address of the first gateway may be published through the kernel layer so that the first gateway can be correctly identified. In some optional implementations of the embodiments of the present disclosure, the above-mentioned remote procedure call (RPC) interface may include but is not limited to a gRPC interface, and the above-mentioned preset configuration includes routing rule settings, address translation rule configuration, security access control rule settings, etc. The above-mentioned uplink switch may be set between the first gateway 502 and the data packet diversion gateway 501 to implement data packet flow.

[0085] In some optional implementations of the embodiments of the present disclosure, the packet splitting gateway 501 may also be configured to transmit the third encapsulated packet to the cloud tenant server. For details, please refer to the above Figure 3 The contents of the corresponding parts in the corresponding embodiments will not be repeated here.

[0086] In some optional implementations of the embodiments of the present disclosure, the data transmission system 500 may further include a second gateway (not shown in the figure). The packet diversion gateway 501 is further configured to: in response to determining that the first encapsulated packet is a packet based on a preset version of the Internet Protocol, convert the outer source address of the first encapsulated packet into the address of the packet diversion gateway and convert the outer destination address into the address of the second gateway to obtain a fourth encapsulated packet, and transmit the fourth encapsulated packet to the second gateway based on the address of the second gateway; wherein the packet processing capacity of the first gateway 502 is higher than the data processing capacity of the second gateway; the second gateway is configured to: decapsulate the fourth encapsulated packet and convert the inner source address of the fourth encapsulated packet into the second destination address to obtain a second decapsulated packet, and transmit the second decapsulated packet to the cloud public server based on the inner destination address of the fourth encapsulated packet.

[0087] In this embodiment, in order to control the data packet flow diverted to the first gateway 502 for processing, ensure its data packet processing performance, and avoid network congestion or packet loss, the above-mentioned data packet diversion gateway 501 can divert specific types of data packets, namely data based on a preset version of the Internet Protocol, to a second gateway different from the first gateway 502 in the data packet transmission system for processing, wherein the data packet processing volume of the first gateway 502 is higher than the data packet processing volume of the second gateway. Exemplarily, the second gateway may include a DPDK-based gateway, and the preset version of the Internet Protocol includes but is not limited to IPV6; further, the data packets diverted to the first gateway for processing may be data packets based on other versions of the Internet Protocol (such as IPV4) that are different from the data packets based on the preset version of the Internet Protocol. Specifically, when the packet offloading gateway 501 determines that the type of the first encapsulated packet received from the cloud tenant server is a packet based on the preset version of the Internet Protocol, it can offload the fourth encapsulated packet obtained after address conversion to the second gateway for processing by converting the outer source address of the packet offloading gateway to the address of the packet offloading gateway and converting the outer destination address to the address of the second gateway. The second gateway then decapsulates and performs address conversion on the fourth encapsulated packet and transmits it to the cloud public server. In this way, network congestion can be further alleviated.

[0088] In some optional implementations of the embodiments of the present disclosure, the above-mentioned second gateway is further configured to: receive a second data packet to be encapsulated from the public server in response to feedback from the public server on receiving the second decapsulated data packet; convert the second destination address of the second data packet to be encapsulated into the address of the cloud tenant server, and encapsulate the second data packet to be encapsulated after the address conversion to obtain a fifth encapsulated data packet; transmit the fifth encapsulated data packet to the cloud tenant server; wherein the inner destination address of the fifth encapsulated data packet is the address of the cloud tenant server.

[0089] In this embodiment, the second gateway performs address conversion and encapsulation processing on the second data packet to be encapsulated when receiving the second data packet to be encapsulated fed back by the cloud public server in response to the second decapsulated data packet received from the second gateway. Specifically, performing address conversion on the second data packet to be encapsulated includes restoring its second target address to the (real) address of the cloud tenant server to ensure that correct routing to the cloud tenant server can be achieved; and performing encapsulation processing on the second data packet to be encapsulated includes reconstructing the non-VXLAN formatted data packet to be encapsulated into a VXLAN formatted data packet that can be processed by the cloud tenant server, and then the processed fifth encapsulated data packet can be directly fed back to the cloud tenant server without being forwarded through the data packet diversion gateway 501. In this way, the transmission efficiency of the data packet can be improved.

[0090] In some optional implementations of the embodiments of the present disclosure, the priority of the routing path corresponding to the first gateway 502 is higher than the priority of the routing path corresponding to the second gateway.

[0091] In this embodiment, the routing path corresponding to the first gateway may include a routing path for data packets passing through the cloud tenant server, the data packet diversion gateway, the routing path from the first gateway to the cloud public server, and a corresponding routing path for data packets returning from the cloud public server to the cloud tenant server, and the routing path corresponding to the second gateway may include a routing path for data packets passing through the cloud tenant server, the data packet diversion gateway, the routing path from the second gateway to the cloud public server, and a corresponding routing path for data packets returning from the cloud public server to the cloud tenant server. Specifically, by setting the priority of data packet transmission or forwarding on the routing path where the first gateway is located to be higher than the priority of data packet transmission or forwarding on the routing path where the second gateway is located, it can be effectively ensured that data packet traffic is preferentially offloaded to the first gateway with higher data processing capabilities for processing, so as to reduce data loading delay or packet loss rate caused by the limited data processing capabilities of the gateway, thereby effectively alleviating network congestion.

[0092] In some optional implementations of the embodiments of the present disclosure, a communication connection can be established between the above-mentioned first gateway or second gateway and the cloud public server through an underlay network; and the transmission or forwarding of data packets can be achieved between the first gateway or second gateway and the data packet diversion gateway through an uplink switch.

[0093] To deepen understanding, this disclosure also provides a specific implementation plan in combination with a specific application scenario. Based on a comprehensive multi-dimensional perspective, the preferred solution is to deploy parallel file storage services in the cloud public service area and use a virtual network to achieve service sharing. Specifically, it focuses on: deploying parallel file storage services in the cloud public service area, and using a virtual network to enable tenants to share the storage service under the architecture system, and strives to explore and overcome key technical difficulties such as how to effectively alleviate network congestion and significantly reduce the packet loss rate in the data transmission link.

[0094] See Based on Figure 6 The data transmission scheme implemented by the network architecture shown mainly includes the following processes:

[0095] (1) A cloud tenant server (such as the GPU shown in the figure) accesses the parallel file storage service deployed in the cloud public service area (corresponding to the cloud public server in the above embodiment). The traffic (or data packet) will first be encapsulated as a VXLAN message on the virtual switch, and then the encapsulated data packet will be passed to a high-performance virtual router (corresponding to the data packet diversion gateway in the above embodiment, which may specifically include a virtual router based on a preset type of chip) for processing.

[0096] (2) After receiving the message, the high-performance virtual router confirms that the destination of the data packet is the public service area based on the route. Therefore, it modifies the outer message information of the data packet and forwards it to the high-performance public service gateway (specifically, it may include a gateway based on a preset type of chip. The preset type of chip has excellent data packet processing capabilities and P4 programming capabilities. For example, its data packet processing capability is as high as 6.4Tbps, which far exceeds the performance of the virtual router solution implemented based on DPDK) for processing.

[0097] (3) After receiving the message, the high-performance public service gateway (corresponding to the first gateway in the above embodiment, specifically) performs address translation on it (assigning a public service area identity to the cloud tenant server), then reconstructs the data packet into a non-VXLAN message and sends it to the parallel file storage service.

[0098] (4) After the parallel file storage service completes the processing, it returns a packet (corresponding to the first data packet to be encapsulated in the above embodiment). Since the cloud tenant server is only given an identity identifier accessible to the public service area on the high-performance public service gateway (corresponding to the first target address in the above embodiment) and has a higher priority, the data packet will be sent to the high-performance public service gateway for processing first.

[0099] (5) After the high-performance public service gateway performs address translation and restores the real IP address of the cloud tenant server, it reconstructs the data packet into a VXLAN message and sends the VXLAN formatted data packet to the high-performance virtual router for processing.

[0100] (6) After being processed by security access control and routing modules, the high-performance virtual router sends the data packet to the cloud tenant server.

[0101] In this model, traffic from cloud tenant servers accessing the parallel file storage service is offloaded to the high-performance public service gateway for forwarding. This completely resolves the performance and cost issues associated with using a DPDK-based virtual router, while maintaining a consistent data forwarding path.

[0102] In this embodiment, if the type of data packet sent by the cloud tenant server is a data packet based on the IPV6 protocol, it is also possible to choose not to offload it to the high-performance public service gateway. The specific process may include:

[0103] (1) Traffic from cloud tenant servers accessing the parallel file storage service deployed in the cloud public server area will first be encapsulated as a VXLAN packet on the virtual switch, and then the encapsulated data packet will be passed to the high-performance virtual router for processing.

[0104] (2) After receiving the message, the high-performance virtual router confirms that the data packet is destined for the public service area based on the route. Therefore, it modifies the outer message information of the data packet and forwards it to the virtual router 1 implemented based on DPDK (corresponding to the second gateway in the above embodiment) for processing.

[0105] (3) After routing, security access control, address translation, and data packet reconstruction, virtual router 1 forwards the data packet to the parallel file storage service.

[0106] (4) For the return packets of the parallel file storage service, the data packets will be sent to virtual router 1 for processing first (because the cloud tenant server is only given an identity accessible to the public service area on virtual router 1 (corresponding to the second target address in the above embodiment)).

[0107] (5) After address translation, security access control, and routing, virtual router 1 finally sends the data packet returned from the cloud public service area to the cloud tenant server. The forwarding paths of the data packets are inconsistent.

[0108] In this embodiment, if Figure 7 As shown, the overall architecture of the above-mentioned high-performance public service gateway can be divided into two levels, including the control plane and the data plane.

[0109] Among them, the border gateway controller (bagw-controller) in the control plane monitors the relevant business conditions, calls the gRPC interface according to the actual situation, and sends down configurations to the data plane, which may include routing rule configuration, address translation rule configuration, etc.

[0110] The data plane can be divided into three layers: business logic layer, kernel layer and switching chip layer. Among them, the business logic layer mainly includes: border gateway agent (bagw-agent) and client (client component). Bagw-agent is responsible for receiving gRPC calls from the control plane, and then calls the gRPC interface of the hardware running server (BfRuntime Sever) according to the processing logic to configure and distribute the chip. The server is used to send programmable instructions to the chip to make the configuration effective. The fixed-function server (Fixed-Func Server) is used to provide access to fixed functions of the chip, such as packet forwarding function, traffic monitoring function, etc. The client provides a simple command line for operation and maintenance use, communicates with bagw-agent through gRPC, and sends network requests or receives network responses. The kernel layer mainly includes related kernel modules, including the hardware kernel network (bf-knet) module, the hardware kernel packet processing (bf-kpkt) module, and the hardware kernel driver (bf-kdrv). Among them, the bf-knet module is used to create the corresponding (Virtual Network Interface Card, VNIC) port to communicate with the kernel and establish a BGP neighbor relationship with the upstream switch, etc., to enable the introduction of data packets into the high-performance public service gateway for processing, which can be specifically introduced through the physical interface. The switching chip layer is the core of data processing. The chips it contains are interconnected with other hardware through the high-speed Serial Computer Expansion Internet Protocol (PCIE) bus. The data packets passing through are processed according to business logic, including: routing, access control, address translation, etc., ultimately realizing the needs of cloud tenant servers to access the parallel file storage services in the public service area.

[0111] According to an embodiment of the present disclosure, the present disclosure also provides a gateway, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the data transmission method described in any of the above embodiments can be implemented when the at least one processor executes them.

[0112] According to an embodiment of the present disclosure, the present disclosure further provides a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to implement the data transmission method described in any of the above embodiments when executed.

[0113] According to an embodiment of the present disclosure, the present disclosure further provides a computer program product including a computer program, which can implement the data transmission method described in any of the above embodiments when executed by a processor.

[0114] Figure 8A schematic block diagram of an example electronic device 800 that can be used to implement an embodiment of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein. In some optional implementations of the embodiments of the present disclosure, the electronic device 800 can be specifically implemented as a gateway.

[0115] like Figure 8 As shown, the electronic device 800 includes a processing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 can also be stored. The processing unit 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0116] Multiple components in the electronic device 800 are connected to the I / O interface 805, including an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a magnetic disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the electronic device 800 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0117] The processing unit 801 can be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the processing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processing units that run machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The processing unit 801 performs the various methods and processes described above, such as the data transmission method. For example, in some embodiments, the data transmission method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as a storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the processing unit 801, one or more steps of the update processing method described above can be performed. Alternatively, in other embodiments, the processing unit 801 can be configured to perform the data transmission method by any other appropriate means (e.g., by means of firmware).

[0118] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0119] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0120] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0121] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0122] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0123] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact via a communication network. This client-server relationship is established by computer programs running on the respective computers, establishing a client-server relationship. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain. A cloud server, also known as a cloud computing server or cloud host, is a host product within the cloud computing service ecosystem. It addresses the management difficulties and poor scalability of traditional physical hosts and virtual private server (VPS) services.

[0124] According to the technical solution of the embodiment of the present disclosure, when it is determined that the inner destination address of the first encapsulated data packet received from the cloud tenant server side is the address of the cloud public server, it can be unloaded to the first gateway with higher data processing capabilities for processing by converting its outer source address into the address of the data packet diversion gateway and converting the outer destination address into the address of the first gateway, so that the first gateway can transmit the encapsulated data packet after address conversion, that is, the second encapsulated data packet, to the cloud public server after decapsulation and address conversion. In this way, by using a gateway with higher data processing capabilities to process data packet traffic, the data loading delay or packet loss rate caused by the limited data processing capability of the gateway can be reduced, thereby effectively alleviating network congestion and achieving the purpose of improving AI training efficiency. At the same time, it can also avoid the cost increase caused by the use of a large number of horizontal expansion processing methods.

[0125] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not a limitation herein.

[0126] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1. A data transmission method, applied to a data packet distribution gateway, comprising: receiving a first encapsulated data packet from a cloud tenant server; In response to determining that the inner destination address of the first encapsulated data packet is the address of the cloud public server, converting the outer source address of the first encapsulated data packet to the address of the data packet offloading gateway and converting the outer destination address to the address of the first gateway, thereby obtaining a second encapsulated data packet; wherein the data packet processing capacity of the first gateway is higher than the data packet processing capacity of the gateway based on the data plane development kit; Based on the address of the first gateway, the second encapsulated data packet is transmitted to the first gateway; wherein the first gateway is used to transmit the first decapsulated data packet obtained by decapsulating and address converting the second encapsulated data packet to the cloud public server.

2. The method according to claim 1, further comprising: receiving a third encapsulated data packet from the first gateway; wherein the third encapsulated data packet is obtained by the first gateway performing address translation and encapsulation processing on the first data packet to be encapsulated, the first data packet to be encapsulated is fed back to the first gateway by the public server in response to receiving the first decapsulated data packet, the inner destination address of the third encapsulated data packet is the address of the cloud tenant server, and the outer destination address is the address of the data packet diversion gateway; Based on the inner destination address of the third encapsulated data packet, the third encapsulated packet is transmitted to the cloud tenant server.

3. The method according to claim 1, further comprising: In response to determining that the first encapsulated data packet is a data packet based on a preset version of the Internet Protocol, translating the outer source address of the first encapsulated data packet into the address of the data packet offloading gateway and translating the outer destination address of the first encapsulated data packet into the address of a second gateway, thereby obtaining a fourth encapsulated data packet; wherein the data packet processing capacity of the first gateway is higher than the data packet processing capacity of the second gateway; Based on the address of the second gateway, the fourth encapsulated data packet is transmitted to the second gateway; wherein the second gateway is used to transmit the second decapsulated data packet obtained after decapsulating and address converting the fourth encapsulated data packet to the cloud public server.

4. The method according to claim 3, wherein: The priority of the routing path corresponding to the first gateway is higher than the priority of the routing path corresponding to the second gateway.

5. A data transmission device, applied to a data packet distribution gateway, comprising: A first communication module is configured to receive a first encapsulated data packet from a cloud tenant server; a data packet reconstruction module configured to, in response to determining that the inner destination address of the first encapsulated data packet is the address of the cloud public server, convert the outer source address of the first encapsulated data packet into the address of the data packet offloading gateway and convert the outer destination address into the address of the first gateway, thereby obtaining a second encapsulated data packet; the data packet processing capacity of the first gateway is higher than the data packet processing capacity of the gateway based on the data plane development kit; The second communication module is configured to transmit the second encapsulated data packet to the first gateway based on the address of the first gateway; wherein the first gateway is used to transmit the first decapsulated data packet obtained by decapsulating and address converting the second encapsulated data packet to the cloud public server.

6. A data transmission system comprising a data packet splitting gateway and a first gateway; wherein: The packet offloading gateway is configured to, in response to determining that the inner destination address of a first encapsulated packet received from the cloud tenant server is the address of the cloud public server, translate the outer source address of the first encapsulated packet into the address of the packet offloading gateway and translate the outer destination address into the address of the first gateway to obtain a second encapsulated packet, and transmit the second encapsulated packet to the first gateway based on the address of the first gateway; The packet processing capacity of the first gateway is higher than the packet processing capacity of the gateway based on the data plane development kit; The first gateway is configured to decapsulate the second encapsulated data packet and convert the inner source address of the second encapsulated data packet into a first destination address to obtain a first decapsulated data packet, and transmit the first decapsulated data packet to the public server based on the inner destination address of the second encapsulated data packet.

7. The system according to claim 6, wherein: The first gateway is further configured to: receiving a first data packet to be encapsulated fed back by the cloud public server in response to receiving the first decapsulated data packet; Convert the first target address of the first data packet to be encapsulated into the address of the cloud tenant server, and encapsulate the first data packet to be encapsulated after the address conversion to obtain a third encapsulated data packet; wherein the inner destination address of the third encapsulated data packet is the address of the cloud tenant server and the outer destination address is the address of the data packet diversion gateway.

8. The system according to claim 7, wherein: The architecture of the first gateway includes a data plane, and the data plane includes a switching chip layer for decapsulating and address converting the second encapsulated data packet, and encapsulating and address converting the first to-be-encapsulated data packet.

9. The system according to claim 8, wherein: The architecture of the first gateway further comprises a control plane, and the data plane further comprises a business logic layer and a kernel layer; and The business logic layer is used to receive the preset configuration from the control plane through the remote procedure call interface, and transmit the preset configuration to the switching chip layer; The kernel layer is used to establish a BGP neighbor relationship with the upstream switch through the Border Gateway Protocol BGP, and publish the address of the first gateway based on the BGP neighbor relationship; The switching chip layer is used to decapsulate and perform address conversion processing on the second encapsulated data packet, and to encapsulate and perform address conversion processing on the first to-be-encapsulated data packet based on the preset configuration.

10. The system according to claim 6, further comprising a second gateway, wherein The data packet offloading gateway is further configured to: in response to determining that the first encapsulated data packet is a data packet based on a preset version of the Internet Protocol, translate the outer source address of the first encapsulated data packet into the address of the data packet offloading gateway and translate the outer destination address into the address of a second gateway to obtain a fourth encapsulated data packet, and transmit the fourth encapsulated data packet to the second gateway based on the address of the second gateway; wherein the data packet processing capacity of the first gateway is higher than the data processing capacity of the second gateway; The second gateway is configured to: decapsulate the fourth encapsulated data packet and convert the inner source address of the fourth encapsulated data packet into a second destination address to obtain a second decapsulated data packet, and transmit the second decapsulated data packet to the cloud public server based on the inner destination address of the fourth encapsulated data packet.

11. The system according to claim 10, wherein: The second gateway is further configured to: receiving a second data packet to be encapsulated fed back by the public server in response to receiving the second decapsulated data packet; Convert the second destination address of the second data packet to be encapsulated into the address of the cloud tenant server, and encapsulate the second data packet to be encapsulated after the address conversion to obtain a fifth encapsulated data packet; The fifth encapsulated data packet is transmitted to the cloud tenant server; wherein the inner destination address of the fifth encapsulated data packet is the address of the cloud tenant server.

12. A gateway, comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the data transmission method according to any one of claims 1 to 4.

13. A non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to execute the data transmission method according to any one of claims 1 to 4.

14. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the steps of the data transmission method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • Data packet sending method, device and hybrid cloud network system

    CN107948086A

  • Virtualized network networking system and data packet sending method

    CN108768817A

  • Method, device and system for transmitting data

    CN110708393A

  • Cross-cluster network communication system and method

    CN114640556A

  • Network virtualization implementation method, system, device and program product

    CN115189987A