A cloud service access processing method, device, equipment and storage medium

CN122601764APending Publication Date: 2026-08-18BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510142365.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2026-08-18

AI Technical Summary

Technical Problem

[0003]显然,在租户的客户端访问云服务时,如果处理云服务访问请求的服务器所属的可用区与租户的客户端设备所在的可用区之间的距离较远,则会出现云服务访问时延较高的问题

Benefits of technology

[0027] The technical solution provided in this disclosure has the following advantages compared with the prior art:

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122601764A_ABST
    Figure CN122601764A_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to a cloud service access processing method and device, equipment and a storage medium. The method comprises: receiving, by a virtual switch, a cloud service access message for indicating access to a target cloud service having a target virtual network address, the target cloud service being deployed in a plurality of availability zones, and a target mapping relationship being maintained for the target cloud service, the target mapping relationship recording a physical network address of an availability zone in which the target cloud service is deployed, which is assigned to a source availability zone according to a geographical location proximity principle; determining, according to the target mapping relationship, a physical network address of an availability zone in which the target cloud service is deployed, which is assigned to an availability zone to which the virtual switch belongs, as a target physical network address; sending the cloud service access message to the availability zone corresponding to the target physical network address, and processing the cloud service access message by a server in which the target cloud service is deployed in the availability zone. It can be seen that the embodiments of the present disclosure can reduce the cloud service access delay and improve the access efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of virtual display technology, and in particular to a cloud service access processing method, apparatus, device, and storage medium. Background Technology

[0002] In large-scale cloud platforms, cloud services are typically provided to tenants in units of regions. Regions are divided based on geographical location and network latency, such as the Beijing region and the Shanghai region. A region typically includes multiple Availability Zones (AZs), each with its own independent power and network infrastructure. Because Availability Zones need to have disaster isolation capabilities, they are usually located far apart (around 100 kilometers), with latency between Availability Zones ranging from 2 to 3 milliseconds.

[0003] Obviously, when a tenant's client accesses cloud services, if the availability zone to which the server handling the cloud service access request belongs is far from the availability zone to which the tenant's client device is located, there will be a problem of high latency in cloud service access. Summary of the Invention

[0004] In order to solve the above-mentioned technical problems, or at least partially solve the above-mentioned technical problems, this disclosure provides a cloud service access processing method, apparatus, device and storage medium.

[0005] In a first aspect, embodiments of this disclosure provide a cloud service access processing method, the method comprising:

[0006] The cloud service access message is received through a virtual switch. The cloud service access message is used to indicate access to a target cloud service with a destination virtual network address. The target cloud service is deployed in multiple availability zones. Each availability zone in the multiple availability zones assigns a corresponding physical network address to the destination virtual network address of the target cloud service. A target mapping relationship is maintained for the target cloud service. The target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity.

[0007] Based on the target mapping relationship maintained for the target cloud service, the physical network address of the availability zone to which the virtual switch belongs, which is where the target cloud service is deployed, is determined as the destination physical network address;

[0008] The cloud service access message is sent to the availability zone corresponding to the destination physical network address, and the cloud service access message is processed by the server that deploys the target cloud service in the availability zone.

[0009] In one optional implementation, determining the physical network address of the availability zone where the target cloud service is deployed, allocated to the availability zone to which the virtual switch belongs, based on the target mapping relationship maintained for the target cloud service, as the destination physical network address, includes:

[0010] The virtual switch sends an address mapping request carrying the identifier of the source availability zone and the destination virtual network address to the target virtual private cloud gateway. The target virtual private cloud gateway determines the physical network address of the availability zone where the target cloud service is deployed, based on the identifier of the source availability zone, from the target mapping relationship maintained for the target cloud service, and uses it as the destination physical network address. The identifier of the source availability zone is used to identify the availability zone to which the virtual switch belongs.

[0011] In one optional implementation, the target mapping relationship maintained for the target cloud service also records the physical network addresses of availability zones where the target cloud service is deployed, allocated to the source availability zones where the target cloud service is not deployed, according to the principle of geographical proximity.

[0012] In one optional implementation, the method further includes:

[0013] If the target virtual private cloud gateway fails to determine the physical network address of the availability zone where the target cloud service is deployed from the target mapping relationship maintained for the target cloud service, then based on the availability zone topology information and the geographical proximity principle, it determines the nearest access availability zone for the source availability zone from among the multiple availability zones where the target cloud service is deployed, and determines the physical network address allocated by the nearest access availability zone for the target virtual network address of the target cloud service as the target physical network address; the availability zone topology information is used to characterize the geographical location relationship between the source availability zone and the multiple availability zones.

[0014] In an optional implementation, before receiving cloud service access messages via a virtual switch, the method further includes:

[0015] Receives a virtual network address allocated to the target cloud service via anycast address allocation, and a virtual tunnel endpoint network address allocated to each of the multiple availability zones where the target cloud service is deployed, wherein the virtual tunnel endpoint network address is the physical network address allocated by the corresponding availability zone for the target cloud service.

[0016] In one optional implementation, sending the cloud service access message to the availability zone corresponding to the destination physical network address, and processing the cloud service access message through a server deploying the target cloud service in the availability zone, includes:

[0017] The cloud service access message is sent to the load balancing node in the availability zone corresponding to the destination physical network address. The load balancing node then forwards the cloud service access message to the server in the availability zone that deploys the target cloud service, and the server processes the cloud service access message.

[0018] In one optional implementation, the method further includes:

[0019] In response to the existence of an abnormal availability zone among the plurality of availability zones where the target cloud service is deployed, the physical network address allocated by the abnormal availability zone to the target virtual network address of the target cloud service is removed from the target mapping relationship maintained for the target cloud service.

[0020] Secondly, this disclosure provides a cloud service access processing device, the device comprising:

[0021] The first receiving module is used to receive cloud service access messages through a virtual switch. The cloud service access messages are used to indicate access to a target cloud service with a destination virtual network address. The target cloud service is deployed in multiple availability zones. Each availability zone in the multiple availability zones assigns a corresponding physical network address to the destination virtual network address of the target cloud service. A target mapping relationship is maintained for the target cloud service. The target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity.

[0022] The first determining module is used to determine, based on the target mapping relationship maintained for the target cloud service, the physical network address of the availability zone to which the virtual switch belongs, which is where the target cloud service is deployed, as the destination physical network address;

[0023] The sending module is used to send the cloud service access message to the availability zone corresponding to the destination physical network address, and to process the cloud service access message through the server that deploys the target cloud service in the availability zone.

[0024] Thirdly, embodiments of this disclosure also provide an electronic device, the electronic device comprising: a processor; a memory for storing executable instructions of the processor; the processor being configured to read the executable instructions from the memory and execute the instructions to implement the cloud service access processing method provided in embodiments of this disclosure.

[0025] Fourthly, embodiments of this disclosure also provide a computer-readable storage medium storing a computer program for executing the cloud service access processing method provided in embodiments of this disclosure.

[0026] Fifthly, this disclosure provides a computer program product comprising a computer program / instruction that, when executed by a processor, implements the method described above.

[0027] The technical solution provided in this disclosure has the following advantages compared with the prior art:

[0028] In the cloud service access processing method provided in this embodiment, a cloud service access message is first received through a virtual switch. The cloud service access message is used to indicate access to a target cloud service with a destination virtual network address. The target cloud service is deployed in multiple availability zones, and a target mapping relationship is maintained for the target cloud service. The target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity. Then, based on the target mapping relationship maintained for the target cloud service, the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the availability zone to which the virtual switch belongs, is determined as the destination physical network address. Next, the cloud service access message is sent to the availability zone corresponding to the destination physical network address, and the cloud service access message is processed by the server in the availability zone where the target cloud service is deployed.

[0029] In this embodiment, a target mapping relationship is pre-maintained for the target cloud service, and the target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is allocated to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity. Therefore, after receiving a cloud service access message from any availability zone, the physical network address corresponding to the nearest availability zone can be determined as the destination physical network address of the cloud service access message based on the above target mapping relationship, so that the server in the nearest availability zone where the target cloud service is deployed can process the cloud service access message, thereby reducing cloud service access latency and improving access message processing efficiency. Attached Figure Description

[0030] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and the originals and elements are not necessarily drawn to scale.

[0031] Figure 1 A flowchart illustrating a cloud service access processing method provided in this embodiment of the disclosure;

[0032] Figure 2 A schematic diagram illustrating a cloud service deployed across availability zones, provided as an embodiment of this disclosure;

[0033] Figure 3 A schematic diagram illustrating another cloud service deployment across availability zones provided in this disclosure embodiment;

[0034] Figure 4 A schematic diagram illustrating another cloud service deployment across availability zones provided in this disclosure embodiment;

[0035] Figure 5 A flowchart illustrating a cloud service access process provided in this embodiment of the disclosure;

[0036] Figure 6 This is a schematic diagram of the structure of a cloud service access processing device provided in an embodiment of the present disclosure;

[0037] Figure 7 This is a schematic diagram of the structure of a cloud service access processing device provided in an embodiment of this disclosure. Detailed Implementation

[0038] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0039] It should be understood that the steps described in the method embodiments of this disclosure may be performed in different orders and / or in parallel. Furthermore, the method embodiments may include additional steps and / or omit the steps shown. The scope of this disclosure is not limited in this respect.

[0040] The term "comprising" and its variations as used herein are open-ended inclusions, meaning "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Definitions of other terms will be given in the description below.

[0041] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0042] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0043] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0044] Cloud services refer to a model that provides various computing resources and services via the internet. It allows users to access and use these resources on demand without having to maintain their own hardware and software infrastructure. Cloud services are typically provided by cloud service providers.

[0045] A Virtual Private Cloud (VPC) provides a secure and isolated network environment through logical network isolation. Users can define virtual networks within a VPC that are indistinguishable from traditional networks, while also providing advanced network services such as Elastic Networking Protocol (ELP) and security groups. From a service perspective, a VPC refers to a cloud computing service used to isolate a portion of public cloud resources for a specific user's private use. While a VPC is managed by the public cloud and runs on public resources, it ensures that resources are isolated between each user, and no single user's usage is affected by other users. For example, a Virtual Private Network includes multiple compute instances, such as virtual machines, with specified network relationships. As one possible implementation of a virtual machine, the virtual machine in this embodiment can be an Elastic Compute Service (ECS).

[0046] A virtual machine (VM) is a complete computer system with full hardware system functionality, simulated using virtualization technology and running in a completely isolated environment. A subset of the instructions in a VM can be processed on the host machine, while other instructions can be executed in an emulated manner. Users can purchase cloud services by renting VMs.

[0047] In large-scale cloud platforms, cloud services are typically provided to tenants in units of regions. Regions are divided based on geographical location and network latency, such as the Beijing region and the Shanghai region. A region typically includes multiple Availability Zones (AZs), each with its own independent power and network infrastructure. Because Availability Zones need to have disaster isolation capabilities, they are usually located far apart (around 100 kilometers), with latency between Availability Zones ranging from 2 to 3 milliseconds.

[0048] Obviously, when a tenant's client accesses cloud services, if the availability zone of the server handling the cloud service access request is far away from the availability zone of the tenant's client, the cloud service access latency will be high.

[0049] Therefore, in the cloud service access processing method provided in this embodiment, a cloud service access message is first received through a virtual switch. This cloud service access message is used to indicate access to a target cloud service with a destination virtual network address. The target cloud service is deployed in each of multiple availability zones, and a target mapping relationship is maintained for the target cloud service. This target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity. Then, based on the target mapping relationship maintained for the target cloud service, the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the availability zone to which the virtual switch belongs, is determined as the destination physical network address. Next, the cloud service access message is sent to the availability zone corresponding to the destination physical network address, and the cloud service access message is processed by the server in the availability zone where the target cloud service is deployed.

[0050] In this embodiment, a target mapping relationship is pre-maintained for the target cloud service, and the target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is allocated to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity. Therefore, after receiving a cloud service access message from any availability zone, the physical network address corresponding to the nearest availability zone can be determined as the destination physical network address of the cloud service access message based on the above target mapping relationship, so that the server in the nearest availability zone where the target cloud service is deployed can process the cloud service access message, thereby reducing cloud service access latency and improving access message processing efficiency.

[0051] Based on this, embodiments of this disclosure provide a cloud service access processing method, such as... Figure 1 The diagram shown is a flowchart illustrating a cloud service access processing method provided in this embodiment of the present disclosure. This method can be executed by a cloud service access processing device, which can be implemented using software and / or hardware, and is generally integrated into an electronic device. Figure 1 As shown, the method includes:

[0052] S101: Receive cloud service access messages through a virtual switch. The cloud service access messages are used to indicate access to a target cloud service with a destination virtual network address. The target cloud service is deployed in multiple availability zones, and each availability zone in the multiple availability zones assigns a corresponding physical network address to the destination virtual network address of the target cloud service. A target mapping relationship is maintained for the target cloud service. The target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity.

[0053] In this embodiment of the disclosure, the cloud service may include database services, Platform as a Service (PaaS), Software as a Service (SaaS), machine learning services, etc., and the target cloud service can be any cloud service. The cloud service runs on a virtualization layer created on a physical machine using virtualization technology. Virtualization technology is a technology that abstracts physical resources into virtual resources, allowing the creation of virtual machines on physical machines and forming a virtualization layer by running these virtual machines. This virtualization layer manages the allocation of physical resources and the operation of virtual machines, enabling cloud services to be deployed and run on virtual machines.

[0054] The target cloud service is deployed in each of multiple availability zones. Each availability zone may include one or more physical machines that serve as virtual machine runtime environments. These physical machines can be configured and managed to support different cloud services. For example... Figure 2 The diagram shown is a schematic of a target cloud service deployed across availability zones according to an embodiment of this disclosure. The target cloud service is deployed in availability zones 1, 2 and 3. A virtual switch 1 is also deployed on the physical machine in availability zone 1, a virtual switch 2 is also deployed on the physical machine in availability zone 2 and a virtual switch 3 is also deployed on the physical machine in availability zone 3.

[0055] The target cloud service is provided by a cloud service provider, which is primarily responsible for the cloud service and the management of the cloud service infrastructure. The cloud service provider relies on hardware resources provided by resource providers to deploy and maintain the cloud service platform. Resource providers are organizations or enterprises that provide the underlying hardware resources, which may include servers, storage devices, network equipment, etc. Cloud service consumers are individuals, organizations, or enterprises that use the resources and services provided by the cloud service; they are also known as tenants. Cloud service consumers use cloud services to support business processes, develop applications, or store large amounts of data, etc.

[0056] The cloud service access processing method provided in this disclosure can be applied to any physical machine in any availability zone, where a virtual switch (BVS) is deployed and used to receive cloud service access messages.

[0057] In this embodiment of the disclosure, the cloud service access message is used to indicate a target cloud service with a destination virtual network address.

[0058] In practical applications, when creating a target cloud service, a corresponding destination virtual network address is usually assigned to that target cloud service. After receiving a cloud service access message carrying the destination virtual network address, the virtual switch can forward the cloud service access message to the server of the target cloud service, so that the server can process the cloud service access message, such as querying the database or performing computing tasks.

[0059] The destination virtual network address refers to the virtual network address pre-assigned to the target cloud service. The client device corresponding to the cloud service consumer can access the server in the target cloud service through the destination virtual network address.

[0060] In this embodiment of the disclosure, the target cloud service is deployed in each of the multiple availability zones, and each of the multiple availability zones assigns a corresponding physical network address to the target cloud service for its destination virtual network address.

[0061] like Figure 2 As shown, the target cloud service's destination virtual network address is service IP1. The target cloud service is deployed in Availability Zone 1, Availability Zone 2, and Availability Zone 3. The physical network address assigned to the destination virtual network address service IP1 in Availability Zone 1 can be represented by vtep IP1, the physical network address assigned to the destination virtual network address service IP1 in Availability Zone 2 can be represented by vtep IP2, and the physical network address assigned to the destination virtual network address service IP1 in Availability Zone 3 can be represented by vtep IP3. It can be understood that the target virtual network address service IP1 corresponds to multiple physical network addresses, namely vtep IP1, vtep IP2, and vtep IP3.

[0062] In this embodiment of the disclosure, each of the multiple availability zones maintains a target mapping relationship for the target cloud server. The target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity.

[0063] In this embodiment of the disclosure, the source availability zone for requesting access to the target cloud service refers to the availability zone to which the virtual switch receiving the cloud service access message belongs, such as... Figure 2 As shown, when receiving cloud service access packets through virtual switch 2, the corresponding source availability zone is availability zone AZ2 to which virtual switch 2 belongs; when receiving cloud service access packets through virtual switch 3, the corresponding source availability zone is availability zone AZ3 to which virtual switch 3 belongs.

[0064] The physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone, can be used to identify which of the multiple availability zones where the target cloud service is deployed will process the cloud service access message requesting access to the target cloud service.

[0065] like Figure 2 As shown, the target cloud service is deployed in Availability Zone 1, Availability Zone 2, and Availability Zone 3. Based on the principle of geographical proximity, the physical network address of the Availability Zone where the target cloud service is deployed is assigned to the source Availability Zone AZ1 as vtep IP1, to the source Availability Zone 2 as vtep IP2, and to the source Availability Zone 3 as vtep IP3. Therefore, the target mapping relationship maintained for the target cloud service is: AZ1-vtep IP, AZ2-vtep IP2, AZ3-vtep IP3.

[0066] In this embodiment of the disclosure, when a target cloud service is deployed within the availability zone to which the virtual switch belongs, the cloud service access packets received by the virtual switch are processed by the server of the target cloud service within the availability zone to which the virtual switch belongs. It is understood that cloud service access packets originating from the availability zone to which the virtual switch belongs can typically be processed by the server within that availability zone. For example... Figure 2 As shown, when the availability zone to which the virtual switch 1 belongs is AZ1, based on the above target mapping relationship, vtep IP1 can be determined as the physical network address of the availability zone to which the virtual switch belongs, which is the availability zone where the target cloud service is deployed.

[0067] In one optional implementation, the target mapping relationship maintained for the target cloud service also records the physical network addresses of availability zones where the target cloud service is deployed, allocated to the source availability zones where the target cloud service is not deployed, according to the principle of geographical proximity.

[0068] In this embodiment of the disclosure, when no target cloud service is deployed in the availability zone to which the virtual switch belongs, the cloud service access message received by the virtual switch is processed by a server in an availability zone to which the target cloud service is deployed that is geographically close to the availability zone to which the virtual switch belongs.

[0069] like Figure 3The diagram shown is a schematic of another cloud service deployed across availability zones according to an embodiment of this disclosure. The target cloud service is deployed in availability zones 1 and 2, but not in availability zone 3. Virtual switch 1 is also deployed on the physical machine in availability zone 1, virtual switch 2 is also deployed on the physical machine in availability zone 2, and virtual switch 3 is also deployed on the physical machine in availability zone 3.

[0070] like Figure 3 As shown, continuing with the example where the physical network address assigned to the destination virtual network address service IP1 in Availability Zone 1 can be represented by vtep IP1, and the physical network address assigned to the destination virtual network address service IP1 in Availability Zone 2 can be represented by vtep IP2, the target virtual network address service IP1 corresponds to vtep IP1 and vtep IP2. Following the principle of geographical proximity, the physical network address vtepIP2 of Availability Zone AZ2, where the target cloud service is deployed, can be determined as the physical network address assigned to the source Availability Zone AZ3, which does not have the target cloud service deployed. It is understandable that cloud service access packets received by the virtual switch under Availability Zone AZ3 will be processed by the server of the target cloud service deployed in Availability Zone ZA2, which is geographically closer to Availability Zone AZ3.

[0071] In this embodiment of the disclosure, after receiving a cloud service access message through a virtual switch, the physical network address of the availability zone to which the virtual switch belongs, which is where the target cloud service is deployed, can be determined according to the target mapping relationship maintained for the target cloud service. This physical network address is then used as the destination physical network address, and the cloud service access message is forwarded and processed based on the destination physical network address.

[0072] In one optional implementation, before receiving cloud service access messages through a virtual switch, the system may also receive a virtual network address allocated to the target cloud service via anycast address allocation, and a virtual tunnel endpoint network address allocated to each of the multiple availability zones where the target cloud service is deployed. The virtual tunnel endpoint network address is the physical network address allocated by the corresponding availability zone for the target cloud service.

[0073] When allocating a virtual network address to a target cloud service using anycast address allocation, the availability zone to which the virtual network address will be accessed will be specified. Typically, the availability zone to which the virtual switch is accessed will be consistent with the availability zone to which the virtual switch belongs (i.e., the availability zone where the tenant's client devices are located).

[0074] In practical applications, when a target cloud service is not deployed in a certain availability zone, a correspondence can be established between the identifiers of availability zones that do not have the target cloud service and the identifiers of availability zones that have the target cloud service. This allows multiple availability zone identifiers to correspond to the same physical network address, thereby enabling availability zones that do not have the target cloud service to connect to the nearest availability zone that has the target cloud service.

[0075] In addition, in scenarios where the target cloud service is not deployed in a certain availability zone, the availability zone topology information can be used to enable the availability zone without the target cloud service to connect to the nearest availability zone that has the target cloud service deployed.

[0076] S102: Based on the target mapping relationship maintained for the target cloud service, determine the physical network address of the availability zone to which the virtual switch belongs, which is where the target cloud service is deployed, as the destination physical network address.

[0077] In this embodiment of the disclosure, after receiving a cloud service access message indicating access to a target cloud service through a virtual switch, the physical network address of the availability zone to which the target cloud service is deployed can be determined as the destination physical network address based on the target mapping relationship maintained for the target cloud service.

[0078] Since virtual switches are deployed on physical machines within availability zones, after receiving cloud service access packets via the virtual switch, the physical machine hosting the virtual switch can be identified as the availability zone to which the virtual switch belongs. For example... Figure 2 As shown, after receiving a cloud service access message, virtual switch 1 can determine the availability zone 1 where virtual switch 1 is located as the availability zone to which the virtual switch belongs, and determine the physical network address of the availability zone to which the target cloud service is deployed, which is allocated to the availability zone to which the virtual switch belongs, as the destination physical network address, according to the target mapping relationship maintained for the target cloud service.

[0079] In this embodiment of the disclosure, when accessing a target cloud service through a destination virtual network address, the physical network address corresponding to the physical network address of the availability zone where the target cloud service is deployed is found from among multiple physical network addresses allocated to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity. This physical network address is the one geographically closest to the availability zone to which the virtual switch belongs. The cloud service access message is then sent to the availability zone corresponding to the destination physical network address based on the destination physical network address. This allows the server of the target cloud service deployed in that availability zone to process the cloud service access message, thereby reducing cloud service access latency and improving access efficiency.

[0080] In practical applications, there may be abnormal availability zones among the multiple availability zones where the target cloud service is located. Servers in abnormal availability zones cannot operate normally. Therefore, if the availability zone corresponding to the target physical network address happens to be an abnormal availability zone, and the server in the abnormal availability zone is used to process cloud service access packets, cloud service access will fail.

[0081] In this embodiment of the disclosure, in response to the existence of an abnormal availability zone among the multiple availability zones where the target cloud service is deployed, the physical network address allocated by the abnormal availability zone to the target virtual network address of the target cloud service can be deleted from the target mapping relationship maintained for the target cloud service, so as to improve the success rate of cloud service access.

[0082] For example, suppose the mapping relationship between availability zone identifiers and physical network addresses allocated to the target cloud service is as follows: AZ1 corresponds to VTEP IP, AZ2 corresponds to VTEP IP2, and AZ3 corresponds to VTEP IP3. When there is an anomaly in availability zone 1 corresponding to AZ1, the availability zone identifier of the anomaly availability zone can be deleted from the above mapping relationship to obtain the updated mapping relationship: AZ2 corresponds to VTEP IP2, and AZ3 corresponds to VTEP IP3.

[0083] S103: Send the cloud service access message to the availability zone corresponding to the destination physical network address, and process the cloud service access message through the server that deploys the target cloud service in the availability zone.

[0084] In practical applications, a server is a high-performance computer used to run applications and store data, providing various services to users. Servers can include physical servers and virtual servers. Cloud service providers can use a large number of servers to build their data centers and provide users with various cloud services. Understandably, servers are the foundation of cloud services.

[0085] In this embodiment of the disclosure, after determining the physical network address corresponding to the availability zone identifier of the availability zone to which the virtual switch belongs as the destination physical network address based on the mapping relationship maintained for the target cloud service, the cloud service access message is sent to the availability zone corresponding to the destination physical network address so that the server deploying the target cloud service in the availability zone can process the cloud service access message.

[0086] In this embodiment of the disclosure, the physical network address allocated to the availability zone to which the virtual switch belongs can be used to characterize the address of the server in the availability zone where the target cloud service is deployed, or the address of the load balancing node in the availability zone where the target cloud service is deployed. When the destination physical network address is used to characterize the address of the load balancing node in the availability zone, the cloud service access message is first sent to the load balancing node based on the destination physical network address, and then the cloud service access message is forwarded to the server in the availability zone where the target cloud service is deployed based on the load balancing algorithm or load balancing strategy, so that the server can process the cloud service access message.

[0087] Since the availability zone corresponding to the destination physical network address is geographically close to the availability zone to which the virtual switch belongs, the cloud service access latency can be reduced by sending the cloud service access message to the availability zone corresponding to the destination physical network address and using the server in the availability zone to which the nearest virtual switch belongs to process the cloud service access message.

[0088] In the cloud service access processing method provided in this embodiment, a cloud service access message is first received through a virtual switch. This cloud service access message indicates access to a target cloud service with a destination virtual network address. The target cloud service is deployed in each of multiple availability zones, and a target mapping relationship is maintained for the target cloud service. This target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity. Then, based on the target mapping relationship maintained for the target cloud service, the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the availability zone to which the virtual switch belongs, is determined as the destination physical network address. Next, the cloud service access message is sent to the availability zone corresponding to the destination physical network address, and the cloud service access message is processed by the server in the availability zone where the target cloud service is deployed.

[0089] In this embodiment, a target mapping relationship is pre-maintained for the target cloud service, and the target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is allocated to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity. Therefore, after receiving a cloud service access message from any availability zone, the physical network address corresponding to the nearest availability zone can be determined as the destination physical network address of the cloud service access message based on the above target mapping relationship, so that the server in the nearest availability zone where the target cloud service is deployed can process the cloud service access message, thereby reducing cloud service access latency and improving access message processing efficiency.

[0090] In practical applications, Virtual Private Cloud (VPC) provides an isolated and private virtual network environment for cloud services. Through VPC, cloud services can be deployed in a subnet isolated from the public network, thereby improving the security of cloud services.

[0091] The Target Virtual Private Cloud Gateway (RCM) is a component within a Virtual Private Cloud responsible for mapping virtual network addresses (overlay IPs) and physical network addresses (underlay IPs). Physical network addresses are IP addresses used at the physical network layer, forming the network infrastructure and handling actual data packet transmission. Virtual network addresses are IP addresses used in the logical network layer built on top of the physical network. Therefore, upon receiving a cloud service access message, it is necessary to locate the destination physical network address corresponding to the destination virtual network address indicated by the message before forwarding it.

[0092] In one optional implementation, a cloud service access message is first received through a virtual switch. Then, an address mapping request carrying the identifier of the source availability zone and the destination virtual network address is sent to the target virtual private cloud gateway RCM through the virtual switch. The target virtual private cloud gateway RCM determines the physical network address of the availability zone where the target cloud service is deployed from the target mapping relationship maintained for the target cloud service based on the identifier of the source availability zone, and uses it as the destination physical network address.

[0093] The identifier of the source availability zone can be used to identify the availability zone to which the virtual switch belongs. For example, assuming that the tenant's client device is located in availability zone 3, when the tenant accesses the target cloud service through the client device, it will send a cloud service access message to the virtual switch in availability zone 3. Therefore, when the virtual switch receives the cloud service access message, it can determine the identifier corresponding to its own availability zone 3 as the identifier of the source availability zone, and encapsulate the identifier of the source availability zone together with the destination virtual network address in the address mapping request to send it to the target virtual private cloud gateway.

[0094] In this embodiment of the disclosure, by sending an address mapping request carrying the identifier of the source availability zone and the destination virtual network address to the target virtual private cloud gateway, the target virtual private cloud gateway can determine the physical network address on which the target cloud service is deployed, which is assigned to the identifier of the source availability zone, from the target mapping relationship maintained for the target cloud service, and use it as the destination physical network address.

[0095] Among them, the target mapping relationship maintained for the target cloud service records the physical network address of the availability zone where the target cloud service is deployed, assigned according to the principle of geographical proximity to the source availability zone requesting access to the target cloud service. For example... Figure 3As shown, assuming the address mapping request carries the source availability zone identifier "AZ3" and the destination virtual network address "serviceIP1", then according to the destination mapping relationship, the physical network address "vtepIP2" corresponding to the source availability zone identifier "AZ3" can be determined as the destination physical network address, so that cloud service access packets can be forwarded based on this destination physical network address in the future.

[0096] As can be seen, the embodiments of this disclosure can determine the physical network address of the availability zone where the target cloud service is deployed, based on the identifier of the source availability zone, from the target mapping relationship maintained for the target cloud service. Since the geographical location between the availability zone corresponding to the target physical network address and the availability zone to which the virtual switch belongs is relatively close, it can save cloud service access time and improve access efficiency.

[0097] In one optional implementation, if the target virtual private cloud gateway fails to determine the physical network address of the availability zone where the target cloud service is deployed from the target mapping relationship maintained for the source availability zone, then based on the availability zone topology information and the principle of proximity in geographical location, the nearest access availability zone is determined for the source availability zone from multiple availability zones where the target cloud service is deployed, and the physical network address allocated by the nearest access availability zone for the target virtual network address of the target cloud service is determined as the target physical network address.

[0098] Among them, availability zone topology information is used to characterize the geographical location relationship between the source availability zone and multiple availability zones. Through availability zone topology information, the availability zone that is geographically close to the source availability zone can be determined from multiple availability zones that have deployed the target cloud service.

[0099] In this embodiment of the disclosure, if the physical network address of the availability zone that is allocated to the source availability zone and which is deploying the target cloud service cannot be determined from the target mapping relationship maintained for the target cloud service, it indicates that the target cloud service does not have an availability zone allocated to the source availability zone, or that the availability zone that is allocated to the source availability zone and which is deploying the target cloud service may be abnormal and has been deleted from the target mapping relationship. In this case, based on the availability zone topology information and the principle of proximity in geographical location, the nearest access availability zone can be re-determined from the multiple availability zones to which the target cloud service belongs, and the physical network address allocated by the nearest access availability zone for the target virtual network address of the target cloud service can be used as the target physical network address.

[0100] Specifically, if the target virtual private cloud gateway cannot determine the physical network address of the availability zone that has deployed the target cloud service from the target mapping relationship maintained for the source availability zone, it first determines the availability zone that meets the geographical proximity principle with the availability zone to which the virtual switch belongs, and determines the availability zone that meets the proximity principle as the nearest access availability zone, and determines the physical network address corresponding to the nearest access availability zone as the destination physical network address; if no availability zone that meets the geographical proximity principle is found, then based on the availability zone topology information, it determines the availability zone that is geographically closer to the availability zone to which the virtual switch belongs from multiple availability zones, and determines the availability zone that is geographically closer as the nearest access availability zone, and determines the physical network address corresponding to the nearest access availability zone as the destination physical network address.

[0101] In one optional implementation, a correspondence can be established between the identifier of the source availability zone that has not deployed the target cloud service and the identifier of the availability zone that has deployed the target cloud service, based on the principle of geographical proximity. That is, multiple availability zone identifiers can correspond to the same physical network address, thereby enabling availability zones that have not deployed the target cloud service to access availability zones that have deployed the target cloud service nearby.

[0102] For example, in Figure 3 In the scenario shown, the above mapping relationship can include: AZ1 corresponds to the physical network address vtep IP1, and AZ2 and AZ3 both correspond to the physical network address vtep IP2. Assuming the availability zone identifier of the availability zone to which the virtual switch belongs is AZ3, then the destination physical network address is vtep IP2.

[0103] In practical applications, since the physical network addresses corresponding to Availability Zone Identifier 2 and Availability Zone Identifier 3 are both vtepIP2, and the target cloud service is not deployed in Availability Zone 3, after sending an address mapping request carrying the target Availability Zone 3 and the destination virtual network address to the Virtual Private Cloud Gateway through the Virtual Switch 3, the destination physical network address obtained by the Virtual Private Cloud Gateway based on the target Availability Zone 3 can be vtepIP2. At this time, the cloud service access message is sent to Availability Zone 2 where the target cloud service is deployed, and the server in Availability Zone 2 that deploys the target cloud service processes the cloud service access message.

[0104] In some cloud platforms that require high availability and scalability, load balancers (LB), also known as load balancing nodes, are often used to distribute traffic and manage servers that deploy cloud services. Because load balancing nodes have traffic scheduling capabilities, they can reduce the management costs of servers.

[0105] like Figure 4The diagram illustrates another cloud service deployment across availability zones provided in this embodiment. The load balancing cluster includes load balancing node 1, load balancing node 2, and load balancing node 3. Load balancing node 1 is deployed in availability zone 1, load balancing node 2 in availability zone 2, and load balancing node 3 in availability zone 3. Because the load balancing nodes are deployed across availability zones, when any availability zone fails, the load balancer can automatically reroute traffic to other normally operating availability zones for processing, thus achieving high availability of the cloud service. Furthermore, the load balancer can evenly distribute traffic across multiple availability zones, avoiding excessive load on a single availability zone and ensuring efficient resource utilization.

[0106] In practical applications, the physical network address allocated to the target virtual network address of the target cloud service can also be used to allocate physical network addresses separately to load balancing nodes in multiple availability zones where the target cloud service is deployed. Specifically, the target cloud service is deployed in multiple availability zones, and each availability zone includes one or more load balancing nodes. A load balancing node is also called a load balancer. Both the load balancer (LB) and the target virtual private cloud gateway (RCM) are components of a virtual private cloud (VCP). The load balancing nodes in multiple availability zones belong to a load balancing cluster (LB cluster), such as... Figure 4 As shown, the load balancing cluster is deployed across multiple availability zones, meaning the load balancing cluster is deployed across availability zones.

[0107] In this embodiment of the disclosure, based on the target mapping relationship maintained for the target cloud service, the physical network address of the availability zone to which the virtual switch belongs, which is used to deploy the target cloud service, is determined as the destination physical network address. The cloud service access message can also be sent to the load balancing node in the availability zone corresponding to the destination physical network address based on the destination physical network address. The load balancing node then forwards the cloud service access message to the server that deploys the target cloud service, and the server that deploys the target cloud service processes the cloud service access message.

[0108] For example, after receiving a cloud service access message carrying the destination virtual network address through virtual switch 1, the physical network address (vtep IP1) of the availability zone to which the virtual switch 1 belongs, which is the availability zone 1 to which the target cloud service is deployed, is first determined from the target mapping relationship maintained for the target cloud service. This physical network address is then sent to the availability zone corresponding to the destination physical network address, i.e., load balancer 1 within availability zone 1. Next, load balancer 1 forwards the cloud service access message to the server in availability zone 1 that deploys the target cloud service, and the server processes the cloud service access message.

[0109] likeFigure 5 The diagram shown is a flowchart of a cloud service access process provided in an embodiment of this disclosure. Figure 4 As shown, a Virtual Private Cloud (VPC) includes components such as a VPC controller, a target Virtual Private Cloud Gateway (RCM), and a Virtual Switch (BVS). Among these, Figure 4 The flowchart shown mainly includes two stages. The first stage includes steps ①, ②, and ③, which are mainly used to create the target cloud service. The second stage includes steps ④, ⑤, ⑥, ⑦, ⑧, and ⑨, which are mainly used to process the received cloud service access messages.

[0110] Step 1: In a Virtual Private Cloud (VPC), utilize Load Balancer (LB) to manage and receive virtual network addresses (service IPs) allocated to the target cloud service via anycast address allocation. Specifically, create an LB instance and use anycast virtual network addresses (service IPs) provided by the VPC within the LB instance. Anycast, also known as selectcast, overcast, or any-cast, is a network communication technology in VPC that allocates virtual network addresses to the source availability zone, providing high availability and proximity functionality.

[0111] In practical applications, when allocating virtual network addresses via anycast, the nearest availability zone to which the virtual network address will be accessed will be specified. Usually, the nearest availability zone is consistent with the availability zone to which the virtual switch belongs (i.e., the availability zone where the tenant server is deployed). The range of availability zones that the tenant can access is the range of availability zones deployed by the LB cluster.

[0112] Step 2: The load balancer (LB) receives the virtual network address (service IP) allocated to the target cloud service via anycast address allocation, and the virtual tunnel endpoint network address (vtep IP) allocated to each of the multiple availability zones where the target cloud service is deployed. The vtep IP is then sent to the VPC controller along with the virtual network interface (ENI). Here, the vtep IP refers to the physical network address with virtual network functionality.

[0113] Step 3: The VPC controller manages the virtual network addresses in the VPC. After receiving the VTEP IP assigned to each of the multiple availability zones for deploying the target cloud service, it establishes a mapping relationship between the virtual network address service IP and the virtual tunnel endpoint network address VTEP IP. It then sends the target mapping relationship maintained for the target cloud service to the target virtual private cloud gateway RCM. This allows the RCM to determine the physical network address of the availability zone where the target cloud service is deployed, based on the identifier of the source availability zone, from the target mapping relationship maintained for the target cloud service. This physical network address is then used as the destination physical network address.

[0114] Step 4: When the virtual switch receives a cloud service access message, it sends an address mapping request carrying the identifier of the source availability zone and the destination virtual network address to the target virtual private cloud gateway RCM.

[0115] Step 5: The target virtual private cloud gateway RCM determines the physical network address of the availability zone where the target cloud service is deployed, based on the identifier of the source availability zone and the target mapping relationship maintained for the target cloud service. This physical network address is then used as the destination physical network address.

[0116] If the destination physical network address corresponding to the identifier of the source availability zone cannot be determined from the target mapping relationship maintained for the target cloud service, then based on the availability zone topology information and the principle of proximity in geographical location, the nearest access availability zone is determined from the multiple availability zones where the target cloud service is deployed, and the physical network address allocated by the nearest access availability zone for the target virtual network address of the target cloud service is used as the destination physical network address.

[0117] Step 6: The target virtual private cloud gateway RCM sends the target physical network address to the virtual switch.

[0118] Step 7: After receiving the destination physical network address, the virtual switch finds the nearest load balancer (LB) node in the availability zone based on the destination physical network address, and sends the cloud service access message to the load balancer (LB) node in the availability zone corresponding to the destination physical network address.

[0119] Step 8: After receiving the cloud service access message, the load balancer (LB) node determines the server for deploying the target cloud service based on the load balancing algorithm.

[0120] Step 9: Forward the cloud service access message to the server where the target cloud service is deployed, so that the server can process the cloud service access message.

[0121] In this embodiment of the disclosure, a target mapping relationship is maintained for the target cloud service, and the target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is allocated to the source availability zone of the requesting access to the target cloud service according to the principle of geographical proximity. Therefore, after receiving a cloud service access message from any availability zone, the physical network address corresponding to the nearest availability zone can be determined as the destination physical network address of the cloud service access message based on the above mapping relationship, so that the server in the nearest availability zone where the target cloud service is deployed can process the cloud service access message, thereby reducing the cloud service access latency and improving the access message processing efficiency.

[0122] To implement the above embodiments, this disclosure also proposes a cloud service access processing device. Figure 6 This is a schematic diagram of a cloud service access processing device provided in an embodiment of this disclosure. The device can be implemented by software and / or hardware, and is generally integrated into an electronic device. Figure 6 As shown, the device includes:

[0123] The first receiving module 601 is used to receive cloud service access messages through a virtual switch. The cloud service access messages are used to indicate access to a target cloud service with a destination virtual network address. The target cloud service is deployed in multiple availability zones. Each availability zone in the multiple availability zones assigns a corresponding physical network address to the destination virtual network address of the target cloud service. A target mapping relationship is maintained for the target cloud service. The target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity.

[0124] The first determining module 602 is used to determine, based on the target mapping relationship maintained for the target cloud service, the physical network address of the availability zone to which the virtual switch belongs, which is where the target cloud service is deployed, as the destination physical network address.

[0125] The sending module 603 is used to send the cloud service access message to the availability zone corresponding to the destination physical network address, and to process the cloud service access message through the server that deploys the target cloud service in the availability zone.

[0126] In one optional implementation, the first determining module includes:

[0127] The first sending submodule is used to send an address mapping request carrying the identifier of the source availability zone and the destination virtual network address to the target virtual private cloud gateway through the virtual switch. The target virtual private cloud gateway determines the physical network address of the availability zone where the target cloud service is deployed, which is allocated to the source availability zone, based on the identifier of the source availability zone from the target mapping relationship maintained for the target cloud service, and uses it as the destination physical network address. The identifier of the source availability zone is used to identify the availability zone to which the virtual switch belongs.

[0128] In one optional implementation, the target mapping relationship maintained for the target cloud service also records the physical network addresses of availability zones where the target cloud service is deployed, allocated to the source availability zones where the target cloud service is not deployed, according to the principle of geographical proximity.

[0129] In one optional embodiment, the apparatus further includes:

[0130] The second determining module is configured to, if the target virtual private cloud gateway fails to determine the physical network address of the availability zone where the target cloud service is deployed from the target mapping relationship maintained for the target cloud service, determine the nearest access availability zone for the source availability zone based on availability zone topology information and the geographical proximity principle, and determine the physical network address allocated by the nearest access availability zone for the target cloud service's destination virtual network address as the destination physical network address; the availability zone topology information is used to characterize the geographical location relationship between the source availability zone and the multiple availability zones.

[0131] In one optional embodiment, the apparatus further includes:

[0132] The second receiving module is used to receive a virtual network address allocated to the target cloud service through anycast address allocation, and a virtual tunnel endpoint network address allocated to each of the multiple availability zones where the target cloud service is deployed. The virtual tunnel endpoint network address is the physical network address allocated by the corresponding availability zone for the target cloud service.

[0133] In one optional implementation, the sending module includes:

[0134] The second sending submodule is used to send the cloud service access message to the load balancing node in the availability zone corresponding to the destination physical network address, and then forward the cloud service access message to the server in the availability zone that deploys the target cloud service through the load balancing node, and the server processes the cloud service access message.

[0135] In one optional embodiment, the apparatus further includes:

[0136] The deletion module is configured to, in response to the existence of an abnormal availability zone among the plurality of availability zones where the target cloud service is deployed, delete the physical network address allocated by the abnormal availability zone to the target virtual network address of the target cloud service from the target mapping relationship maintained for the target cloud service.

[0137] In the cloud service access processing apparatus provided in this embodiment, a cloud service access message is first received through a virtual switch. The cloud service access message is used to indicate access to a target cloud service with a destination virtual network address. The target cloud service is deployed in each of multiple availability zones, and a target mapping relationship is maintained for the target cloud service. The target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity. Then, based on the target mapping relationship maintained for the target cloud service, the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the availability zone to which the virtual switch belongs, is determined as the destination physical network address. Next, the cloud service access message is sent to the availability zone corresponding to the destination physical network address, and the cloud service access message is processed by the server in the availability zone where the target cloud service is deployed.

[0138] In this embodiment, a target mapping relationship is pre-maintained for the target cloud service, and the target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is allocated to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity. Therefore, after receiving a cloud service access message from any availability zone, the physical network address corresponding to the nearest availability zone can be determined as the destination physical network address of the cloud service access message based on the above target mapping relationship, so that the server in the nearest availability zone where the target cloud service is deployed can process the cloud service access message, thereby reducing cloud service access latency and improving access message processing efficiency.

[0139] The cloud service access processing device provided in this disclosure can execute the cloud service access processing method provided in any embodiment of this disclosure, and has the corresponding functional modules and beneficial effects of executing the method.

[0140] In addition to the methods and apparatus described above, this disclosure also provides a computer-readable storage medium storing instructions that, when executed on a terminal device, cause the terminal device to implement the cloud service access processing method described in this disclosure.

[0141] This disclosure also provides a computer program product, which includes a computer program / instruction. When the computer program / instruction is executed by a processor, it implements the cloud service access processing method described in this disclosure.

[0142] In addition, this disclosure also provides a cloud service access processing device, see [link to relevant documentation]. Figure 7 As shown, it may include:

[0143] The cloud service access processing device includes a processor 701, a memory 702, an input device 703, and an output device 704. The number of processors 701 in the device can be one or more. Figure 7 Taking a processor as an example. In some embodiments of this disclosure, the processor 701, memory 702, input device 703, and output device 704 can be connected via a bus or other means, wherein, Figure 7 Taking the example of a connection between China and Israel via a bus.

[0144] The memory 702 can be used to store software programs and modules. The processor 701 executes various functional applications and data processing of the cloud service access processing device by running the software programs and modules stored in the memory 702. The memory 702 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function, etc. In addition, the memory 702 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. The input device 703 can be used to receive input digital or character information, and to generate signal inputs related to user settings and function control of the cloud service access processing device.

[0145] Specifically in this embodiment, the processor 701 will load the executable files corresponding to the processes of one or more applications into the memory 702 according to the following instructions, and the processor 701 will run the applications stored in the memory 702, thereby realizing the various functions of the cloud service access processing device mentioned above.

[0146] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0147] The above description is merely a specific embodiment of this disclosure, enabling those skilled in the art to understand or implement it. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments described herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A cloud service access processing method, characterized in that, The method includes: The cloud service access message is received through a virtual switch. The cloud service access message is used to indicate access to a target cloud service with a destination virtual network address. The target cloud service is deployed in multiple availability zones. Each availability zone in the multiple availability zones assigns a corresponding physical network address to the destination virtual network address of the target cloud service. A target mapping relationship is maintained for the target cloud service. The target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity. Based on the target mapping relationship maintained for the target cloud service, the physical network address of the availability zone to which the virtual switch belongs, which is where the target cloud service is deployed, is determined as the destination physical network address; The cloud service access message is sent to the availability zone corresponding to the destination physical network address, and the cloud service access message is processed by the server that deploys the target cloud service in the availability zone.

2. The method according to claim 1, characterized in that, The step of determining the physical network address of the availability zone where the target cloud service is deployed, allocated to the availability zone to which the virtual switch belongs, based on the target mapping relationship maintained for the target cloud service, as the destination physical network address includes: The virtual switch sends an address mapping request carrying the identifier of the source availability zone and the destination virtual network address to the target virtual private cloud gateway. The target virtual private cloud gateway determines the physical network address of the availability zone where the target cloud service is deployed, based on the identifier of the source availability zone, from the target mapping relationship maintained for the target cloud service, and uses it as the destination physical network address. The identifier of the source availability zone is used to identify the availability zone to which the virtual switch belongs.

3. The method according to claim 2, characterized in that, The target mapping relationship maintained for the target cloud service also records the physical network addresses of availability zones where the target cloud service is deployed, allocated to the source availability zones where the target cloud service is not deployed, according to the principle of geographical proximity.

4. The method according to claim 2, characterized in that, The method further includes: If the target virtual private cloud gateway fails to determine the physical network address of the availability zone where the target cloud service is deployed from the target mapping relationship maintained for the target cloud service, then based on the availability zone topology information and the geographical proximity principle, it determines the nearest access availability zone for the source availability zone from among the multiple availability zones where the target cloud service is deployed, and determines the physical network address allocated by the nearest access availability zone for the target virtual network address of the target cloud service as the target physical network address; the availability zone topology information is used to characterize the geographical location relationship between the source availability zone and the multiple availability zones.

5. The method according to claim 1, characterized in that, Before receiving cloud service access messages through the virtual switch, the process also includes: Receives a virtual network address allocated to the target cloud service via anycast address allocation, and a virtual tunnel endpoint network address allocated to each of the multiple availability zones where the target cloud service is deployed, wherein the virtual tunnel endpoint network address is the physical network address allocated by the corresponding availability zone for the target cloud service.

6. The method according to claim 1, characterized in that, The step of sending the cloud service access message to the availability zone corresponding to the destination physical network address, and processing the cloud service access message through the server deploying the target cloud service in the availability zone, includes: The cloud service access message is sent to the load balancing node in the availability zone corresponding to the destination physical network address. The load balancing node then forwards the cloud service access message to the server in the availability zone that deploys the target cloud service, and the server processes the cloud service access message.

7. The method according to claim 1, characterized in that, The method further includes: In response to the existence of an abnormal availability zone among the plurality of availability zones where the target cloud service is deployed, the physical network address allocated by the abnormal availability zone to the target virtual network address of the target cloud service is removed from the target mapping relationship maintained for the target cloud service.

8. A cloud service access processing device, characterized in that, The device includes: The first receiving module is used to receive cloud service access messages through a virtual switch. The cloud service access messages are used to indicate access to a target cloud service with a destination virtual network address. The target cloud service is deployed in multiple availability zones. Each availability zone in the multiple availability zones assigns a corresponding physical network address to the destination virtual network address of the target cloud service. A target mapping relationship is maintained for the target cloud service. The target mapping relationship records the physical network address of the availability zone where the target cloud service is deployed, which is assigned to the source availability zone requesting access to the target cloud service according to the principle of geographical proximity. The first determining module is used to determine, based on the target mapping relationship maintained for the target cloud service, the physical network address of the availability zone to which the virtual switch belongs, which is where the target cloud service is deployed, as the destination physical network address; The sending module is used to send the cloud service access message to the availability zone corresponding to the destination physical network address, and to process the cloud service access message through the server that deploys the target cloud service in the availability zone.

9. An electronic device, characterized in that, The electronic device includes: processor; Memory used to store the processor's executable instructions; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the cloud service access processing method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which is used to execute the cloud service access processing method according to any one of claims 1-7.

11. A computer program product, characterized in that, The computer program product includes a computer program / instruction that, when executed by a processor, implements the method as described in any one of claims 1-7.