Data packet processing system, method, device, medium and product

By separating the transmission strategy determination and packet forwarding steps into a computing subsystem and a forwarding component to be executed separately in the packet processing system, the problem of insufficient computing resources in traditional virtual switches is solved, and the effective transmission of high-concurrency packets and the ability to resist attacks are improved.

CN121728033APending Publication Date: 2026-03-24ALIBABA CLOUD COMPUTING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In existing technologies, limited computing resources during data packet transmission result in limited transmission performance. In particular, traditional virtual switches lack sufficient computing resources to effectively handle high-concurrency data packets.

Method used

The transmission strategy determination and packet forwarding steps in the packet processing system are separated into a computing subsystem and a forwarding component, which are executed separately. The computing subsystem uses its own computing resources to determine the transmission strategy, and the forwarding component uses the computing resources allocated by the physical host to forward packets.

Benefits of technology

By splitting and coordinating resources, the amount of computing resources available for each step is increased, improving data packet transmission performance, enabling the handling of high-concurrency data packets, and reducing the impact of distributed denial-of-service attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121728033A_ABST
    Figure CN121728033A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data packet processing system, method and device, a medium and a product. The system comprises a computing subsystem and a forwarding component deployed in a physical host. The computing subsystem can determine a transmission strategy of the received downlink data packet by using a first computing resource of the computing subsystem. And the forwarding component can utilize the second computing resource allocated by the physical host to transmit the downlink data packet according to the transmission strategy determined by the computing subsystem. Therefore, the system plays a role of a switch, and the transmission strategy determining step and the forwarding step in the data packet transmission process can be executed by different components in the system. Compared with a method for executing different steps in a data packet transmission process by using computing resources of the same component, the method has the advantages that the resource quantity of the computing resources which can be used when any step is executed can be increased by using the system, so that the transmission performance of the data packet is improved, and the data packet processing system can process high-concurrency data packets.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, and in particular to a data packet processing system, method, device, medium and product. BACKGROUND

[0002] The transmission process of a data packet is an important link in a computer network. The transmission process of a data packet can specifically include steps such as transmission strategy determination and forwarding. The transmission strategy can specifically include routing information, transmission speed, filtering rules, and the like.

[0003] Based on the above description, how to improve the transmission performance of a data packet has become a problem to be solved. SUMMARY

[0004] Therefore, the embodiments of the present application provide a data packet processing system, method, device, medium and product to improve the transmission performance of a data packet.

[0005] In a first aspect, the embodiments of the present application provide a data packet processing system, comprising: a computing subsystem and a forwarding component deployed in a physical host;

[0006] The computing subsystem is configured to receive a downlink data packet, and determine a transmission strategy of the downlink data packet by using a first computing resource of the computing subsystem.

[0007] The forwarding component is configured to receive the downlink data packet forwarded by the computing subsystem, and forward the downlink data packet according to the transmission strategy by using a second computing resource allocated by the physical host.

[0008] In a second aspect, the embodiments of the present application provide a data packet processing system, comprising: a computing subsystem and a physical host, wherein the physical host is deployed with a forwarding component and a virtual machine;

[0009] The computing subsystem is configured to receive a downlink data packet, and determine a transmission strategy of the downlink data packet by using a first computing resource of the computing subsystem.

[0010] The forwarding component is configured to receive the downlink data packet forwarded by the computing subsystem, and forward the downlink data packet to the virtual machine according to the transmission strategy by using a second computing resource allocated by the physical host.

[0011] The virtual machine is configured to process the downlink data packet by using a third computing resource allocated by the physical host.

[0012] In a third aspect, the embodiments of the present application provide a data packet processing method, comprising:

[0013] Receiving a downlink data packet;

[0014] determining a transmission strategy of the downlink data packet by using a first computing resource;

[0015] forwarding the downlink data packet according to the transmission strategy by using a second computing resource, the first computing resource and the second computing resource being provided by different devices.

[0016] In a fourth aspect, an electronic device is provided, which includes a processor and a memory. The memory is configured to store one or more computer instructions. When the one or more computer instructions are executed by the processor, the data packet processing method in the third aspect is implemented. The electronic device can further include a communication interface configured to communicate with other devices or communication networks.

[0017] In a fifth aspect, a non-transitory machine-readable storage medium is provided. The non-transitory machine-readable storage medium stores executable code. When the executable code is executed by a processor of an electronic device, the processor can implement at least the data packet processing method in the third aspect.

[0018] In a sixth aspect, a computer program product is provided. The computer program product includes a computer program or instructions. When the computer program or instructions are executed by a processor, the processor can implement the data packet processing method in the third aspect.

[0019] The data packet processing system provided by the embodiments of the present application can include a computing subsystem and a forwarding component deployed in a physical host. After receiving a downlink data packet, the computing subsystem can determine a transmission strategy of the downlink data packet by using a first computing resource of itself. The forwarding component can forward the downlink data packet according to the transmission strategy determined by the computing subsystem by using a second computing resource allocated by the physical host.

[0020] The system described above functions as a switch. The steps of determining a transmission strategy and forwarding a data packet in the process of data packet transmission can be performed by different components in the system, i.e., the computing subsystem determines a transmission strategy by using a computing resource of itself, and the forwarding component forwards a data packet by using a computing resource allocated by the physical host. Compared with a same component such as a traditional switch, the system described above can increase the amount of computing resources used when performing a step, thereby improving the transmission performance of a data packet and enabling the data packet processing system to process high-concurrency data packets. BRIEF DESCRIPTION OF DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings described below are only some embodiments of the present application, and the drawings can also be obtained by those skilled in the art without creative effort.

[0022] Figure 1 A structural schematic diagram of a data packet processing system provided by an embodiment of the present application is shown in FIG. 1.

[0023] Figure 2 A structural schematic diagram of another data packet processing system provided by an embodiment of the present application is shown in FIG. 2.

[0024] Figure 3 A structural schematic diagram of another data packet processing system provided by an embodiment of the present application is shown in FIG. 3.

[0025] Figure 4 A structural schematic diagram of another data packet processing system provided by an embodiment of the present application is shown in FIG. 4.

[0026] Figure 5 A flow chart of a data packet processing method provided by an embodiment of the present application is shown in FIG. 5.

[0027] Figure 6 A flow chart of another data packet processing method provided by an embodiment of the present application is shown in FIG. 6.

[0028] Figure 7 A structural schematic diagram of a data packet processing device provided by an embodiment of the present application is shown in FIG. 7.

[0029] Figure 8 A structural schematic diagram of an electronic device provided by an embodiment of the present application is shown in FIG. 8. DETAILED DESCRIPTION

[0030] In order to make the objects, technical solutions and advantages of the embodiments of the present application clearer, the following will combine the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative effort are within the protection scope of the present application.

[0031] The terms used in the embodiments of the present application are only for the purpose of describing the specific embodiments, and are not intended to limit the present application. The singular forms "a", "said" and "the" used in the embodiments of the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. "Plural" generally includes at least two, but does not exclude the case of including at least one.

[0032] It should be understood that the term "and / or" as used herein merely describes an associated relationship among associated objects, and indicates that there can be three relationships, for example, A and / or B, which can represent three cases of A existing alone, A and B existing simultaneously, and B existing alone. In addition, the character " / " herein generally represents an "or" relationship between the front and rear associated objects.

[0033] Depending on the context, the word "if" as used herein can be interpreted as meaning "when" or "upon" or "in response to determining" or "in response to identifying." Similarly, depending on the context, the phrase "if it is determined" or "if (a stated condition or event) is identified" can be interpreted as meaning "when it is determined" or "in response to determining" or "when (a stated condition or event) is identified" or "in response to identifying (a stated condition or event)."

[0034] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation portal for user to choose authorization or refusal.

[0035] It should also be noted that the terms "comprise", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the goods or systems comprising a series of elements not only include those elements, but also include other elements not explicitly listed, or include elements inherent to such goods or systems. Without more limitations, the element defined by the sentence "comprises a" does not exclude the existence of another identical element in the goods or system comprising the element.

[0036] Before the embodiments provided by the present application are described in detail, the use scenarios of the embodiments provided by the present application can also be introduced in combination with the content in the background art.

[0037] In order to improve the utilization rate, flexibility and management efficiency of computing resources, a plurality of virtual machines can be deployed on a physical host by using virtualization technology, and the data packet transmission mentioned in the background art can occur between different virtual machines or between a virtual machine and a physical device. That is, the virtual machine or the physical device can act as both a producer and a consumer of data packets. Moreover, the producer and the consumer of data packet transmission can also be located in the same or different networks.

[0038] When the consumer and / or producer of data packets is a virtual machine, the data packets can be transmitted using a virtual switch (Vswitch). Specifically, the virtual switch can utilize the computing resources allocated to it by the physical host to sequentially execute steps such as determining transmission policies and forwarding, thereby completing the transmission of data packets. The virtual switch can be deployed on the same physical host as the consumer of the data packets and / or the consumer virtual machine.

[0039] However, it's easy to understand that besides the virtual switch, at least one virtual machine can be deployed on the physical host. The physical host also needs to allocate its computing resources to the virtual machine, which limits the computing resources allocated to the virtual switch. This limited computing resources ultimately restrict the data packet transmission performance of the virtual switch. Optionally, the transmission performance of the virtual switch can be measured by Packets Per Second (PPS) and / or the number of virtual machines establishing connections to the same virtual switch per second, i.e., Creations Per Second (CPS). It's easy to understand that higher PPS and CPS indicate better transmission performance.

[0040] In order to improve the transmission performance of data packets, the systems and / or methods provided in the following embodiments of the present invention can be used.

[0041] Based on the above description, some embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Where there is no conflict between the embodiments, the following embodiments and features can be combined with each other. Furthermore, the timing of the steps in the following method embodiments is merely an example and not a strict limitation.

[0042] The following can be a brief description of the present invention. Figure 1 and Figure 2 The overall working principle of the system provided in the illustrated embodiment is summarized as follows:

[0043] The system provided in the embodiments of the present invention described below may include a computing subsystem and a forwarding component. Since at least one of the data consumer and data producer in the data packet transmission process mentioned in the following embodiments is a virtual machine, the data packet processing system functions as a traditional virtual switch. This system can separate the transmission policy determination and forwarding capabilities of a traditional virtual switch, allowing the transmission policy determination and forwarding steps in the data packet transmission process to be executed by different components within the system. This capability-based separation enables the use of more computing resources when executing any step, thereby improving data packet transmission performance. The data packet processing system can also handle high-concurrency data packets.

[0044] The data packet processing system and method provided in the various embodiments of the present invention will be described in detail below.

[0045] Figure 1 This is a schematic diagram of the structure of a data packet processing system provided in an embodiment of the present invention. Figure 1 As shown, the system may include a computing subsystem and a forwarding component deployed in a physical host.

[0046] Optionally, the computing subsystem can be a separate device independent of the physical device where the forwarding component resides, or it can be a computing cluster independent of the physical device. The computing cluster can consist of multiple devices. The device serving as the computing subsystem can be a physical host or a virtual machine deployed on a physical host. Optionally, the number of devices serving as the computing subsystem can be flexibly adjusted. Optionally, the computing subsystem and the physical host with the forwarding component deployed can reside in the same Virtual Private Cloud (VPC).

[0047] The computing subsystem provides computing resources, as does the physical host. Since the physical host can deploy at least one virtual machine alongside the forwarding component, it can allocate its computing resources to both the virtual machine and the forwarding component. For clarity, the computing resources of the computing subsystem itself are referred to as the first computing resource, the computing resources allocated from the physical host to the forwarding component are referred to as the second computing resource, and the computing resources allocated from the physical host to the virtual machine are referred to as the third computing resource. Considering the limited computing resources of the physical host and the need to maintain a certain virtual machine density, the amount of the second computing resource is typically less than that of the third computing resource. Here, virtual machine density refers to the number of virtual machines deployed on the physical host.

[0048] In addition, the computing subsystem and the forwarding component can communicate over a network. Forwarding components and virtual machines on the same physical host can communicate via input / output (I / O) using the computing resources allocated to the forwarding component.

[0049] The working process of each part of the system can be described below:

[0050] The computing subsystem receives data packets, which may include uplink or downlink data packets. The computing subsystem then uses its primary computing resources to determine a transmission strategy for the received data packets. Optionally, the transmission strategy may include at least one of routing information, transmission speed, and data packet filtering.

[0051] Optionally, packet filtering can be implemented using the settings recorded in Access Control Lists (ACLs); it can be implemented using Deep Packet Inspection (DPI) technology; or it can be implemented using traffic inspection. Optionally, traffic inspection can be performed using an Intrusion Detection System (IDS) and / or an Intrusion Prevention System (IPS), that is, identifying potential attack behaviors and blocking traffic when an attack behavior is identified. The computing subsystem can also pre-configure its own Quality of Service (QoS) rate limiting function, which can limit, reduce, or increase the forwarding speed of the forwarding components for packets.

[0052] Optionally, the data packets mentioned in the various embodiments of the present invention can be data packets generated by any computationally intensive task that requires CPU or memory, that is, the above-mentioned transmission strategies are applicable to computationally intensive tasks.

[0053] The forwarding component is used to forward data packets. Specifically, the forwarding component can use its allocated second computing resources to receive uplink data packets and forward them to the computing subsystem via the network; or it can use the second computing resources to forward downlink data packets to the virtual machine according to the transmission strategy determined by the computing subsystem, so that the virtual machine can use the third computing resources allocated by the physical host to process the downlink data packets.

[0054] The following can be further described from a process perspective: the system's processing of uplink or downlink data packets.

[0055] For a downlink data packet, the computing subsystem can receive the downlink data packet via the network and determine the transmission strategy for the downlink data packet using its own first computing resources. The downlink data packet and its transmission strategy can then be further sent to the forwarding component. Finally, the forwarding component can utilize its allocated second computing resources and forward the downlink data packet according to the transmission strategy.

[0056] For uplink data packets, the forwarding component can use its allocated second computing resources to receive the uplink data packets, and then forward them to the computing subsystem via the network between the forwarding component and the computing subsystem. The computing subsystem can use its first computing resources to determine the transmission strategy for the uplink data packet, and then use the first computing resources to transmit the uplink data packet according to this transmission strategy.

[0057] The transmission of uplink or downlink data packets can occur between different virtual machines, or between a virtual machine and a physical device, and the two devices involved in the data packet transmission can be located in the same or different networks. In other words, data packets can be transmitted between different devices located in the same or different networks. Specifically, the devices involved in the data packet transmission can be virtual machines and physical hosts, or virtual machines deployed on different physical hosts.

[0058] In this embodiment, the computing subsystem and forwarding component in the system are used to determine the transmission strategy and forward data packets, respectively. Working together, they function as a virtual switch. Furthermore, since the transmission strategy determination and forwarding steps during data packet transmission can be delegated to different components in the system, compared to using the computing resources of the same component (i.e., a traditional virtual switch) to execute different steps in the data packet transmission process, the above system can increase the amount of computing resources available for executing any step, thereby improving data packet transmission performance and enabling the data packet processing system to handle high-concurrency data packets.

[0059] The above effect can also be explained from another perspective:

[0060] When a physical host allocates its secondary computing resources to a traditional virtual switch, the traditional virtual switch can use these secondary computing resources to determine transmission strategies and to forward data packets. Obviously, the size of the secondary computing resources will limit the data packet transmission performance.

[0061] Using the aforementioned system, the first computing resource is used to determine the data packet transmission strategy, while the second computing resource is used to forward the data packets. Furthermore, when the computing subsystem and the physical host have the same amount of resources, it's easy to understand that the second computing resource is obviously less than the first. Therefore, using this system increases the amount of computing resources available for both determining the transmission strategy and forwarding data packets, thereby improving data packet transmission performance and enabling the data packet processing system to handle high-concurrency data packets.

[0062] The technical effects achieved by the system provided in this embodiment of the invention can also be understood in conjunction with the following:

[0063] Because traditional virtual switches have limited computing resources, when a virtual machine on a physical host is attacked by a Distributed Denial-of-Service (DDoS) attack, most of the traditional virtual switch's computing resources are used to combat the DDoS attack, thus affecting the normal data packet sending and receiving of different virtual machines on the physical host. However, using the system provided in the embodiments of this invention, more computing resources are available to combat the attack, thereby reducing the impact of DDoS attacks on the virtual switch and improving the virtual machine's resistance to attacks.

[0064] Figure 2 This is a schematic diagram of another data packet processing system provided in an embodiment of the present invention. Figure 1 As can be seen from the description in the illustrated embodiment, a virtual machine is involved in the data packet transmission process; therefore, Figure 1 The forwarding component in the system shown can specifically be represented as a virtual switch. It should be noted that the virtual switch provided in the embodiments of this invention is a functionally decomposed virtual switch, and not the traditional virtual switch mentioned in the above embodiments. That is, the virtual switch provided in the embodiments of this invention is used for forwarding data packets, not for determining transmission strategies.

[0065] Optionally, traditional virtual switches can be configured with Elastic Network Interfaces (ENIs). The transmission policy determination and forwarding capabilities of the traditional virtual switch can then be implemented using these ENIs. Furthermore, each traditional virtual switch can be configured with one or more ENIs.

[0066] Furthermore, the virtual switches provided in the embodiments of this invention, after functional decomposition, can also be configured with elastic network interface cards (NICs), and each virtual switch can also be configured with one or more elastic NICs. The forwarding function of the virtual switch can then be specifically implemented by these elastic NICs. That is, compared to the elastic NICs in traditional virtual switches, the elastic NICs mentioned in the embodiments of this invention can perform packet forwarding without determining transmission strategies. Moreover, the elastic NICs mentioned in the embodiments of this invention can be a virtual network interface that provides network interfaces and network addresses (i.e., IP addresses) for virtual machines in a VPC.

[0067] The following details the system's processing of uplink and downlink data packets:

[0068] Assuming downlink data packets are transmitted between different virtual machines (VMs) located on the same network, where these different VMs can include the target VM and other VMs deployed on different physical hosts within the same network, the transmission process can be described as follows: other VMs can generate downlink data packets; the computing subsystem can receive these packets via the network and determine a transmission strategy for the downlink data packets using its own primary computing resources. The downlink data packets and their transmission strategies can then be further transmitted to the elastic network interface card (NIC) via the network. Finally, the elastic NIC can utilize its allocated secondary computing resources and transmit the downlink data packets to the target VM according to the transmission strategy.

[0069] Assume that downlink data packets are transmitted between a target virtual machine and a physical host located in different networks, where the physical host is located on the target network and the target virtual machine is located on another network. The transmission process of the downlink data packets can be described as follows: The physical host can generate downlink data packets; the computing subsystem can receive these downlink data packets using the network and determine the transmission strategy for the downlink data packets using first computing resources. Then, the computing subsystem can also use the first computing resources to send the downlink data packets and their transmission strategy to the elastic network interface card (NIC). Finally, the elastic NIC can use its allocated second computing resources to transmit the downlink data packets to the target virtual machine according to the transmission strategy.

[0070] Optionally, both the target virtual machine and other virtual machines may also have their own virtual network interface cards (NICs). Furthermore, for the target virtual machine and virtual switch deployed on the same physical host, the target virtual NIC deployed on the target virtual machine and the elastic NIC in the virtual switch have a binding relationship. Therefore, the transmission of downlink data packets between the virtual switch and the virtual machine is actually the transmission of data packets between the bound virtual NICs and elastic NICs. Each virtual NIC and elastic NIC deployed on the same physical host has a one-to-one binding relationship.

[0071] Assuming uplink data packets are transmitted between a target virtual machine and other virtual machines located on the same network, the transmission process can be described as follows: The elastic network interface card (NIC) in the virtual switch can utilize its secondary computing resources to receive the uplink data packets generated by the target virtual machine and send them to the computing subsystem via the network. The computing subsystem can utilize its primary computing resources to determine the transmission strategy for the uplink data packet and forward it to other virtual machines according to this strategy.

[0072] Assume that uplink data packets are transmitted between a target virtual machine and a physical host located in different networks. The transmission process of the uplink data packets can be described as follows: The elastic network interface card in the virtual switch can utilize its secondary computing resources to receive the uplink data packets generated by the target virtual machine and send them to the computing subsystem via the network. The computing subsystem can utilize its primary computing resources to determine the transmission strategy of the uplink data packets and forward them to the physical host in the target network according to this strategy.

[0073] Similar to downlink data packets, the transmission of the aforementioned uplink data packets between the virtual switch and the virtual machine is actually the transmission of data packets between virtual network interface cards (NICs) and elastic NICs that have a binding relationship.

[0074] In this embodiment, data packet transmission is specifically achieved using the elastic network interface cards (NICs) configured in the functionally split virtual switch and the virtual NICs configured in the virtual machine. Because traditional virtual switches undergo functional splitting, using the above system can increase the amount of computing resources available for determining transmission strategies and for forwarding data packets, thereby improving data packet transmission performance and enabling the data packet processing system to handle high-concurrency data packets.

[0075] Furthermore, the contents not described in detail in this embodiment and the technical effects that can be achieved can be found in the relevant descriptions in the above embodiments, and will not be repeated here.

[0076] Figure 3 This is a schematic diagram illustrating another data packet processing structure provided in an embodiment of the present invention. Figure 1 On the basis of, such as Figure 3 As shown, the system may also include a virtual machine for processing data packets. The virtual machine and the forwarding component are deployed on the same physical host.

[0077] Optionally, the computing subsystem can be a separate device independent of the physical device where the forwarding component resides, or it can be a computing cluster independent of the physical device. The computing cluster can consist of multiple devices. The devices serving as computing subsystems can be physical hosts or virtual machines deployed on physical hosts. Optionally, the number of devices serving as computing subsystems can be flexibly adjusted.

[0078] The system's processing of downlink data packets can be described as follows: The computing subsystem receives the downlink data packet via the network and determines its transmission strategy using its primary computing resources. The downlink data packet and its transmission strategy can then be further sent to the forwarding component. Finally, the forwarding component utilizes its allocated secondary computing resources and forwards the downlink data packet according to the transmission strategy.

[0079] The system's processing of uplink data packets can be described as follows: The forwarding component can use its allocated second computing resources to receive uplink data packets, and then, with the help of the network between the forwarding component and the computing subsystem, forward the uplink data packets to the computing subsystem. The computing subsystem can use its first computing resources to determine the transmission strategy for the uplink data packet, and then use the first computing resources to transmit the uplink data packet according to this transmission strategy.

[0080] according to Figure 1 As described in the illustrated embodiments, the transmission of uplink or downlink data packets can occur between different virtual machines or between a virtual machine and a physical device. Optionally, uplink data packets are typically generated by a virtual machine, and the computing subsystem can transmit the uplink data packet from one virtual machine to another or from one virtual machine to a physical host according to a transmission strategy. Downlink data packets are typically generated by a physical host or a virtual machine, and the forwarding component can transmit the downlink data packet from a physical host to a virtual machine or from one virtual machine to another according to a transmission strategy.

[0081] When an uplink or downlink data packet is forwarded to a virtual machine, the virtual machine can utilize the third-party computing resources allocated by the physical host to process the packet. The virtual machine processing the packet and the forwarding component are deployed on the same physical host. When an uplink or downlink data packet is forwarded to the physical host, the physical host can process the packet.

[0082] In this embodiment, the computing subsystem and forwarding component in the system are used to determine the transmission strategy and forward data packets, respectively. Working together, they function as a virtual switch. Furthermore, since the transmission strategy determination and forwarding steps during data packet transmission can be delegated to different components in the system, compared to using the computing resources of the same component (i.e., a traditional virtual switch) to execute different steps in the data packet transmission process, the above system can increase the amount of computing resources available for executing any step, thereby improving data packet transmission performance and enabling the data packet processing system to handle high-concurrency data packets.

[0083] Furthermore, the contents not described in detail in this embodiment and the technical effects that can be achieved can be found in the relevant descriptions in the above embodiments, and will not be repeated here.

[0084] Figure 4 This is a schematic diagram illustrating another data packet processing structure provided in an embodiment of the present invention. Figure 3 On the basis of, such as Figure 4 As shown, the forwarding component in the system behaves as a virtual switch, and is connected to... Figure 2Similar to the illustrated embodiments, this embodiment of the invention provides a virtual switch with functional decomposition, rather than the traditional virtual switch mentioned in the above embodiments. Optionally, the virtual switch may also be configured with an elastic network interface card (NIC). The forwarding function of the virtual switch can be specifically performed by this elastic NIC.

[0085] The following details the system's processing of uplink and downlink data packets:

[0086] Assuming downlink data packets are transmitted between different virtual machines (VMs) located on the same network, where these different VMs can include the target VM and other VMs deployed on different physical hosts within the same network, the transmission process can be described as follows: Other VMs can generate downlink data packets. The computing subsystem can receive these downlink data packets via the network and determine the transmission strategy for the downlink data packets using its own first computing resources. The downlink data packets and their transmission strategy can then be further transmitted to the elastic network interface card (NIC) via the network. Finally, the elastic NIC can utilize its allocated second computing resources and transmit the downlink data packets to the target VM according to the transmission strategy, so that the target VM can process the downlink data packets using its allocated third computing resources.

[0087] Assume that downlink data packets are transmitted between a target virtual machine and a physical host located in different networks, where the physical host is located on the target network and the target virtual machine is located on another network. The transmission process of the downlink data packets can be described as follows: The physical host can generate downlink data packets; the computing subsystem can receive these downlink data packets using the network and determine the transmission strategy for the downlink data packets using first computing resources. Then, the computing subsystem can also use the first computing resources to send the downlink data packets and their transmission strategy to the elastic network interface card (NIC). Finally, the elastic NIC can use its allocated second computing resources and, according to the transmission strategy, transmit the downlink data packets to the target virtual machine, so that the target virtual machine can process the downlink data packets using its allocated third computing resources.

[0088] Optionally, if the target virtual machine or other virtual machines are also configured with virtual network cards, then the transmission of the downlink data packets between the virtual switch and the virtual machine is actually the transmission of downlink data packets between virtual network cards and elastic network cards with a binding relationship.

[0089] Assuming uplink data packets are transmitted between a target virtual machine and other virtual machines located on the same network, the transmission process can be described as follows: The elastic network interface card (NIC) in the virtual switch can utilize its secondary computing resources to receive the uplink data packets generated by the target virtual machine and send them to the computing subsystem via the network. The computing subsystem can utilize its primary computing resources to determine the transmission strategy for the uplink data packet and forward it to other virtual machines according to this strategy, so that the other virtual machines can process the uplink data packet using their allocated computing resources.

[0090] Assume that uplink data packets are transmitted between a target virtual machine and a physical host located in different networks. The transmission process of the uplink data packets can be described as follows: The elastic network interface card in the virtual switch can utilize secondary computing resources to receive the uplink data packets generated by the target virtual machine and send them to the computing subsystem via the network. The computing subsystem can utilize its own primary computing resources to determine the transmission strategy of the uplink data packets and forward the uplink data packets to the physical host in the target network according to this transmission strategy, so that the physical host can process the uplink data packets.

[0091] Similarly, the transmission of uplink data packets between the virtual switch and the virtual machine is actually the transmission of data packets between virtual network interface cards (NICs) and elastic NICs that have a binding relationship.

[0092] In this embodiment, data packet transmission is specifically achieved using the elastic network interface cards (NICs) configured in the functionally split virtual switch and the virtual NICs configured in the virtual machine. Using the above system increases the amount of computing resources available for determining transmission strategies and for forwarding data packets, thereby improving data packet transmission performance and enabling the data packet processing system to handle high-concurrency data packets. Furthermore, any content not described in detail in this embodiment and the technical effects achieved can be found in the relevant descriptions in the above embodiments, and will not be repeated here.

[0093] The above embodiments have described the uplink and downlink transmission process of data packets from a system perspective. The uplink and downlink transmission process of data packets can also be described from a methodological perspective below.

[0094] Figure 5 This is a flowchart illustrating a data packet processing method provided in an embodiment of the present invention. The method provided in this embodiment is a downlink data packet processing procedure, and this method can be executed by the aforementioned data packet processing system. Figure 5 As shown, the method may include the following steps:

[0095] S101, Receive downlink data packets.

[0096] S102, using the first computing resource, determine the transmission strategy for downlink data packets.

[0097] S103, using the second computing resource, forward downlink data packets according to the transmission strategy. The first computing resource and the second computing resource are provided by different devices.

[0098] The system can receive downlink data packets and determine the transmission strategy for those packets using the first computing resource. The system can also use the second computing resource to forward the downlink data packets according to the transmission strategy. For details regarding the transmission strategy, please refer to [link to relevant documentation]. Figure 1 The relevant descriptions in the illustrated embodiments will not be repeated here.

[0099] The first and second computing resources can be provided by different devices in the system. As described in the above system embodiment, the second computing resource can be provided by a physical host with a forwarding component, and the first computing resource can be provided by a computing subsystem. Optionally, the forwarding component can be a virtual switch. Optionally, the computing subsystem can be another device independent of the physical device where the forwarding component resides, or it can be a computing cluster independent of the physical device. The computing cluster can consist of multiple devices. The device serving as the computing subsystem can be a physical host or a virtual machine deployed on a physical host.

[0100] And according to Figure 2 As described in the illustrated embodiment, the downlink data packet can be generated by a virtual machine or a physical host. Assuming the downlink data packet is generated by another virtual machine and transmitted to the target virtual machine, the computing subsystem can receive the downlink data packet generated by that other virtual machine via the network, determine the transmission strategy of the downlink data packet using the first computing resource, and finally, the forwarding component uses the second computing resource to forward the downlink data packet to the target virtual machine according to the transmission strategy. The other virtual machine and the target virtual machine can be deployed on different physical hosts within the same network.

[0101] Assuming the downlink data packet is generated by a physical host in the target network and transmitted to the target virtual machine, the computing subsystem can receive the downlink data packet generated by the physical host via the network, determine the transmission strategy for the downlink data packet, and finally, the forwarding component uses secondary computing resources to forward the downlink data packet to the target virtual machine according to the transmission strategy. Note that the network in which the target virtual machine is located is different from the target network.

[0102] Optionally, the forwarding component can be represented as a virtual switch, which is configured with elastic network interface cards (NICs). The virtual machine is configured with a virtual NIC. Specifically, the transmission of downlink data packets between the forwarding component and the virtual machine is the transmission of downlink data packets between the elastic NIC and the virtual NIC.

[0103] In addition, for any content not described in detail in this embodiment, please refer to the relevant descriptions in the above embodiments, which will not be repeated here.

[0104] Figure 6 This is a flowchart illustrating another data packet processing method provided in an embodiment of the present invention. The method provided in this embodiment is for processing uplink data packets, and this method can still be executed by a data packet processing system. Figure 6 As shown, the method may include the following steps:

[0105] S201, using the second computing resource, receives uplink data packets.

[0106] S202, using the first computing resource, determine the transmission strategy for uplink data packets.

[0107] S203, forward the uplink data packet according to the uplink data packet transmission strategy.

[0108] The system can use the second computing resource to receive uplink data packets, and then use the first computing resource to determine the transmission strategy for those uplink data packets. Finally, the system can also use the first computing resource to forward the uplink data packets according to the transmission strategy.

[0109] And according to Figure 2 As described in the illustrated embodiment, the uplink data packet can be generated by a virtual machine. Assuming the uplink data packet is generated by another virtual machine and transmitted to the target virtual machine, the forwarding component can utilize the second computing resources to receive the uplink data packet generated by the target virtual machine and send it to the computing subsystem via the network. The computing subsystem can utilize the first computing resources to determine the transmission strategy of the uplink data packet and ultimately forward it to the other virtual machine. The other virtual machines and the target virtual machine can be deployed on different physical hosts within the same network.

[0110] The uplink data packet can also be transmitted from the target virtual host to a physical host located in the target network. In this case, the forwarding component can receive the uplink data packet using the second computing resource and then send it to the computing subsystem via the network. The computing subsystem can use the first computing resource to determine the transmission strategy for the uplink data packet and ultimately forward it to the physical host. Note that the network where the target virtual machine is located is different from the target network.

[0111] In addition, for any content not described in detail in this embodiment, please refer to the relevant descriptions in the above embodiments, which will not be repeated here.

[0112] The data tampering detection apparatus of one or more embodiments of the present invention will be described in detail below. Those skilled in the art will understand that the apparatus can be configured using commercially available hardware components through the steps taught in this solution.

[0113] Figure 7 This is a schematic diagram of the structure of a data packet processing device provided in an embodiment of the present invention, as shown below. Figure 7 As shown, the device includes:

[0114] The receiving module 11 is used to receive downlink data packets.

[0115] The strategy determination module 12 is used to determine the transmission strategy of the downlink data packet using the first computing resources.

[0116] The sending module 13 is used to forward the downlink data packets according to the transmission strategy using the second computing resources, wherein the first computing resources and the second computing resources are provided by different devices.

[0117] Optionally, the receiving module 11 is used to receive uplink data packets using the second computing resource.

[0118] The strategy determination module 12 is used to determine the transmission strategy of the uplink data packet using the first computing resources.

[0119] The sending module 13 is used to forward the uplink data packet according to the transmission strategy of the uplink data packet.

[0120] The first computing resource is provided by a computing cluster, which consists of at least one first physical host; the second computing resource is provided by a virtual switch deployed in a second physical host.

[0121] Figure 7 The device shown can perform Figure 5 or Figure 6 For the methods shown in the embodiments, the parts not described in detail in this embodiment can be referred to the following: Figure 5 or Figure 6 The relevant descriptions of the illustrated embodiments are provided below. For the execution process and technical effects of this technical solution, please refer to [link / reference]. Figure 5 or Figure 6 The descriptions in the illustrated embodiments will not be repeated here.

[0122] In one possible design, the data packet processing methods provided in the above embodiments can be applied to an electronic device, such as... Figure 8 As shown, the electronic device may include a processor 21 and a memory 22. The memory 22 is used to store data that supports the electronic device in performing the above-described actions. Figure 5 or Figure 6 The program of the data packet processing method provided in the illustrated embodiment is configured to execute the program stored in the memory 22.

[0123] The program includes one or more computer instructions, wherein when the one or more computer instructions are executed by the processor 21, they can perform the following steps:

[0124] Receive downlink data packets;

[0125] Using the first computing resource, determine the transmission strategy for the downlink data packet;

[0126] The downlink data packets are forwarded using the second computing resource in accordance with the transmission strategy, wherein the first computing resource and the second computing resource are provided by different devices.

[0127] Optionally, the processor 21 is further configured to perform the aforementioned Figure 5 or Figure 6 All or part of the steps in the illustrated embodiments.

[0128] The structure of the electronic device may also include a communication interface 23 for the electronic device to communicate with other devices or communication networks.

[0129] Furthermore, embodiments of the present invention provide a non-transitory machine-readable storage medium for storing computing unit instructions used in the aforementioned electronic device, which includes instructions for executing the above-mentioned... Figure 5 or Figure 6 The procedure involved in the packet processing is shown.

[0130] In addition, embodiments of the present invention provide a computer program product. This computer program product includes a computer program or instructions. When the computer program or instructions are executed by a processor, the processor is able to perform the above-described functions. Figure 5 or Figure 6 The steps or functions of the data packet processing method shown.

[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A data packet processing system, characterized in that, include: Computing subsystems and forwarding components deployed in physical hosts; The computing subsystem is used to receive downlink data packets; The transmission strategy for the downlink data packet is determined using the first computing resources of the computing subsystem; The forwarding component is used to receive the downlink data packets forwarded by the computing subsystem; and to forward the downlink data packets according to the transmission strategy using the second computing resources allocated by the physical host.

2. The system according to claim 1, characterized in that, The forwarding component is a virtual switch, and the virtual switch is configured with a flexible network interface card (NIC). The computing subsystem is used to receive the downlink data packets originating from the target network or other virtual machines; The elastic network interface card is used to receive the downlink data packets forwarded by the computing subsystem; using the second computing resources, the downlink data packets are forwarded to the target virtual machine according to the transmission strategy of the downlink data packets, wherein the other virtual machines and the target virtual machine are deployed on different physical hosts in the same network, the virtual switch and the target virtual machine are deployed on the same physical host, and the target network is different from the network where the target virtual machine is located.

3. The system according to claim 2, characterized in that, The elastic network interface card (NIC) is used to send the downlink data packets to the target virtual network interface card configured in the target virtual machine. The target virtual network interface card and the elastic NIC have a binding relationship.

4. The system according to claim 1, characterized in that, The forwarding component is used to receive uplink data packets using the second computing resource and forward the uplink data packets to the computing subsystem. The computing subsystem is used to determine the transmission strategy of the uplink data packet using the first computing resources; The uplink data packet is transmitted according to the uplink data packet transmission strategy.

5. The system according to claim 4, characterized in that, The forwarding component is a virtual switch, and the virtual switch is configured with a flexible network interface card (NIC). The elastic network interface card is used to receive uplink data packets from the target virtual machine using the second computing resource; Send the uplink data packet to the computing subsystem; The computing subsystem is used to forward the uplink data packet to other virtual machines or a target network according to the transmission strategy of the uplink data packet, wherein the other virtual machines and the target virtual machine are deployed on different physical hosts in the same network, the virtual switch and the target virtual machine are deployed on the same physical host, and the target network is different from the network where the target virtual machine is located.

6. The system according to claim 5, characterized in that, The elastic network interface card (NIC) is used to receive the uplink data packets sent by the target virtual network interface card (NIC) using the second computing resource. The target virtual network interface card is deployed in the target virtual machine, and the target virtual network interface card and the elastic network interface card have a binding relationship.

7. The system according to any one of claims 1 to 6, characterized in that, The computing subsystem includes a computing cluster consisting of at least one physical host.

8. A data packet processing system, characterized in that, include: The computing subsystem and the physical host, wherein the physical host is deployed with forwarding components and virtual machines; The computing subsystem is used to receive downlink data packets; The transmission strategy for the downlink data packet is determined using the first computing resources of the computing subsystem; The forwarding component is used to receive the downlink data packets forwarded by the computing subsystem; and to forward the downlink data packets to the virtual machine according to the transmission strategy using the second computing resources allocated by the physical host. The virtual machine is used to process the downlink data packets using the third computing resources allocated by the physical host.

9. The system according to claim 8, characterized in that, The forwarding component is a virtual switch, which is configured with an elastic network interface card. There is at least one physical host in the system, and the target virtual machine and other virtual machines are deployed on different physical hosts in the same network on the at least one physical host. The virtual machine is configured with a virtual network interface card (NIC), and the virtual NIC and the elastic NIC deployed on the same physical host have a binding relationship. The computing subsystem is configured to receive downlink data packets from a target network or the other virtual machine, wherein the target network is different from the network in which the target virtual machine is located; The elastic network interface card is used to receive the downlink data packets sent by the computing subsystem; Using the second computing resource, the downlink data packet is forwarded to the target virtual network interface card in the target virtual machine according to the downlink data packet transmission strategy. The target virtual network interface card is bound to the elastic network interface card. The target virtual machine is used to process the downlink data packets using the third computing resource.

10. The system according to claim 8, characterized in that, The forwarding component is used to receive uplink data packets using the second computing resource and forward the uplink data packets to the computing subsystem. The computing subsystem is used to determine the transmission strategy of the uplink data packet using the first computing resources; The uplink data packet is transmitted according to the uplink data packet transmission strategy.

11. The system according to claim 10, characterized in that, The forwarding component is a virtual switch, which is configured with an elastic network interface card. There is at least one physical host in the system, and the target virtual machine and other virtual machines are deployed on different physical hosts in the same network on the at least one physical host. The virtual machine is configured with a virtual network interface card (NIC), and the virtual NIC and the elastic NIC deployed on the same physical host have a binding relationship. The elastic network interface card is used to receive the uplink data packets using the second computing resource; The uplink data packet is sent to the computing subsystem, and the uplink data packet originates from the target virtual network interface card in the target virtual machine that is bound to the elastic network interface card. The computing subsystem is used to forward the uplink data packet to the other virtual machine or the target network according to the transmission strategy of the uplink data packet, wherein the target network is different from the network where the target virtual machine is located; The other virtual machines are configured to process the uplink data packet using the third computing resources if they receive the uplink data packet sent by the computing subsystem.

12. The system according to any one of claims 8 to 11, characterized in that, The computing subsystem includes a computing cluster consisting of at least one physical host.

13. A data packet processing method, characterized in that, include: Receive downlink data packets; Using the first computing resource, determine the transmission strategy for the downlink data packet; The downlink data packets are forwarded using the second computing resource in accordance with the transmission strategy, wherein the first computing resource and the second computing resource are provided by different devices.

14. The method according to claim 13, characterized in that, The method further includes: Using the second computing resource, receive uplink data packets; Using the first computing resource, determine the transmission strategy for the uplink data packet; The uplink data packets are forwarded according to the uplink data packet transmission strategy.

15. The method according to claim 13 or 14, characterized in that, The first computing resource is provided by a computing cluster, which consists of at least one first physical host; the second computing resource is provided by a virtual switch deployed in a second physical host.

16. An electronic device, characterized in that, include: A memory and a processor; wherein the memory stores executable code, and when the executable code is executed by the processor, the processor performs the data packet processing method as described in any one of claims 13 to 15.

17. A non-transitory machine-readable storage medium, characterized in that, The non-transitory machine-readable storage medium stores executable code that, when executed by a processor of an electronic device, causes the processor to perform the packet processing method as described in any one of claims 13 to 15.

18. A computer program product, characterized in that, The computer program product includes a computer program or instructions that enable the computer program or instructions to perform the steps of the data packet processing method according to any one of claims 13 to 15.