一种基于多网卡隔离的虚拟机弹性公网IP的通信方法

By building logical domains and dynamically mounting virtual network interface cards on the cloud platform, combined with a policy-based routing daemon, the issues of security isolation and scalability in virtual machine communication are resolved, achieving efficient routing configuration and business continuity.

CN122120025BActive Publication Date: 2026-07-17WUHAN CITMS TECH CO LTD +2

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
WUHAN CITMS TECH CO LTD
Filing Date
2026-04-27
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In existing technologies, the single-NIC solution for virtual machines results in the inability to physically isolate management traffic from business traffic, posing security risks and asymmetric routing vulnerabilities. The multi-NIC solution requires pre-configured scripts, has low efficiency in batch configuration, lacks session persistence mechanisms, and has limited scalability.

Method used

On the cloud management platform, a management plane logical domain and a business plane logical domain are built, multiple virtual network interface cards are dynamically mounted, and on-demand routing configuration and session persistence are achieved through a policy routing daemon. A destination IP-based routing forwarding mechanism is adopted to avoid source IP policy routing rule restrictions.

Benefits of technology

It achieves physical isolation between management and business planes, improves security and communication reliability, enhances operational efficiency, ensures business continuity and bandwidth utilization, and has high scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122120025B_ABST
    Figure CN122120025B_ABST
Patent Text Reader

Abstract

本发明涉及网络通信领域,公开了一种基于多网卡隔离的虚拟机弹性公网IP的通信方法,包括:在云管理平台构建管理平面逻辑域和业务平面逻辑域,为目标虚拟机动态挂载两张虚拟网卡分别接入两个逻辑域;在虚拟机内部部署策略路由守护进程,与云平台建立双向通信通道,虚拟机镜像不包含预置路由脚本;响应于弹性公网IP绑定请求,在网络节点建立一对一NAT映射,生成结构化参数下发至守护进程;守护进程在内核路由表中动态添加路由条目,并维护连接追踪表,强制已建立通信流沿用初始出口网卡,根据绑定或解绑事件动态调整超时或清理连接记录。本发明实现了管理流与业务流的物理隔离、会话保持及零依赖按需配置,提升了云平台安全性与运维效率。
Need to check novelty before this filing date? Find Prior Art