Internet protocol (IP) address assignment method and address assignment system
Patent Information
- Application Number
- HK62026126398
- Authority / Receiving Office
- HK · HK
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-03-29
- Filing Date
- 2026-07-20
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2044-01-08
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
(12) International application published under the Patent Cooperation Treaty (19) International Bureau of the World Intellectual Property Organization (43) International Publication Date: 3 October 2024 (03.10.2024) WIPO I PCT (51) International Patent Classification: H04L 61 / 5007 (2022.0Ϊ) (21) International Application Number: PCT / CN2024 / 071278 (22) International Application Date: 9 January 2024 (09.01.2024) (25) Application Language: Chinese (26) Publication Language: Chinese (30) Priority: 202310323110.0 29 March 2023 (29.03.2023) CN (71) Applicant: Huawei Cloud Computing Technologies Co., Ltd. [CN / CN]; Huawei Cloud Data Center, Jiaoxinggong Road, Qianzhong Avenue, Gui'an New District, Guiyang City, Guizhou Province, China, 550025 (CN) 0 lllllllllllllllllllllllllllllllll^ (10) International Publication No. WO 2024 / 198619 Al (72) Inventors: Lin Lingqing (LIN, Lingqing); Huawei Cloud Data Center, Jiaoxinggong Road, Qianzhong Avenue, Gui'an New District, Guiyang City, Guizhou Province, China, 550025 (CN) 0 Song Deqiang (SONG, Deqiang); Huawei Cloud Data Center, Jiaoxinggong Road, Qianzhong Avenue, Gui'an New District, Guiyang City, Guizhou Province, China, 550025 (CN) 0 Yan Hongwei (VAN, Hongwei); Huawei Cloud Data Center, Jiaoxinggong Road, Qianzhong Avenue, Gui'an New District, Guiyang City, Guizhou Province, China, 550025 (CN) 0 (74) Agent: Beijing San Gao Yong Xin Intellectual Property Agency Co., Ltd.; 457, Section C, 4th Floor, Building 1, Third Street, Shangdi Information Industry Base, Haidian District, Beijing, 100085 (CN) 0 (81) Designated Country (unless otherwise specified, each of which requires available national protection): AE, AG, AL, AM, AO, AT, AU, AZ, BA, BB, BG, (54) Title: INTERNET PROTOCOL (IP) ADDRESS ASSIGNMENT METHOD AND ADDRESS ASSIGNMENT SYSTEM(54) Title of the invention: Network protocol IP address allocation method and address allocation system When aa client accesses RDSU, allocate 1P address BB Client " " CC Standalone DHCPD DD Network service EE Access RDP1 FF Create RDS1 GG Request to acquire an IP address HH IP address 1 II Associate RDS1 and the IP address 1 JJ Successful access KK Access network service by Loop LL Access the network service MM Access the network service by using the IP address 1 NN Response OO DHCPD: dynamic host configuration protocol Daemon PP RDSH: remote desktop session host QQ IP: Internet protocol RR RDP: remote desktop protocolI V 6 I 9 8 6 I / 蔚 o r O M (57) Abstract: The present application relates to the technical field of networks, and discloses an Internet protocol (IP) address assignment method and an address assignment system. The method provided by the present application is applied to the address assignment system. A cloud platform in the address assignment system can forward, to a target RDSH in the system, a first setup request sent by a first client; the target RDSH assigns, toA first session corresponding to the first client, a first IP address is obtained based on the IP address virtualization of the target RDSH; and the RDSH returns the first IP address to the cloud platform, and the cloud platform returns a first access response to the first client. On this basis, an IP virtualization function is achieved in public cloud service, an RDSH can assign IP addresses to clients based on a plurality of IP addresses obtained by virtualization, and therefore, when different clients access the same RDSH, network service can be obtained based on different IP addresses, thereby guaranteeing the security, privacy, and scalability of the network service. (57) Abstract: This application discloses a method and address allocation system for allocating network protocol IP addresses, belonging to the field of network technology. The method provided in this application is applied in an address allocation system, in which the cloud platform in the address allocation system can forward the first creation request sent by the first client to the target RDSH in the system; the target RDSH allocates a first IP address obtained based on the IP address virtualization of the target RDSH to the first session corresponding to the first client; the RDSH returns the first IP address to the cloud platform, and the cloud platform returns a first access response to the first client. Based on this, IP virtualization functionality has been implemented in public cloud services. RDSH can allocate multiple IP addresses to clients based on virtualization, thereby enabling different clients to obtain network access based on different IP addresses when accessing the same RDSH.Network services ensure the security, privacy, and scalability of network services. [See continued page] WO 2024 / 198619 Al IIIIIIIIIIIIIIIIIIIIIIIIIIIIIIIM BH, BN, BR, BW, BY BZ, CA, CH, CL, CN, CO, CR, CU, CY CZ, DE, DJ, DK, DM, DO, DZ, EC, EE, EG, ES, FI, GB, GD, GE, GH, GM, GT, HN, HR, HU, ID, IL, IN, IQ, IR, IS, IT, JM, JO, JP, KE, KG, KH, KN, KP, KR, KW, KZ, LA, LC, LK, LR, LS, LU, LY MA, MD, MG, MK, MN, MU, MW, MX, MY MZ, NA, NG, NI, NO, NZ, OM, PA, PE, PG, PH, PL, PT, QA, RO, RS, RU, RW, SA, SC, SD, SE, SG, SK, SL, ST, SY SY TH, TJ, TM, TN, TR, TT, TZ, UA, UG, US, UZ, VC, VN, WS, ZA, ZM, ZWO (84) Designated countries (unless otherwise specified, each of the available regional protections is required): ARIPO (BW, CV, GH, GM, KE, LR, LS, MW, MZ, NA, RW, SC, SD, SL, ST, SZ, TZ, UG, ZM, ZW), Eurasia (AM, AZ, BY, KG, KZ, RU, TJ, TM), Europe (AL, AT, BE, BG, CH, CY, CZ, DE, DK, EE, ES, FI, FR, GB, GR, HR, HU, IE, IS, IT, LT, LU, LV, MC, ME, MK, MT, NL, NO, PL, PT, RO, RS, SE, SI, SK, SM, TR), OAPI (BF, BJ, CF, CG, CI, CM, GA, GN, GQ, GW, KM, ML, MR, NE, SN, TD, TG). This international publication includes: the International Search Report (Article 21(3) of the Treaty WO 2024 / 198619 PCT / CN2024 / 071278 Network Protocol IP Address Allocation Method and Address Allocation System).This application claims priority to Chinese Patent Application No. 202310323110.0, filed on March 29, 2023, entitled "Network Protocol IP Address Allocation Method and Address Allocation System," the entire contents of which are incorporated herein by reference. Technical Field This application relates to the field of network technology, and particularly to an IP address allocation method and address allocation system. Background Art Remote Desktop Protocol (RDP) is a protocol that allows users to use terminal services provided by remote devices through local devices. Users access a remote desktop session host (RDSH) running on a remote device via RDP. The RDSH creates a remote desktop session (RDS) for the user, allowing the user to run applications, save files, and access other networks through the RDS. To distinguish different remote desktop sessions (RDS), related technologies use Dynamic Host Configuration Protocol (DHCP) to assign different Internet Protocol (IP) addresses to different RDSs. When a user connects to RDSH, RDSH creates a corresponding RDS and requests an IP address from the DHCP server (DHCP Daemon, DHCPD). This technology is also known as remote desktop IP virtualization. However, the above solution can only be applied to networks that support DHCP, such as LANs or parts of private clouds, and cannot be applied to public cloud network platforms. This is because, to ensure network service security, public cloud platforms use Virtual Private Clouds (VPCs) deployed within the public cloud to centrally manage resources such as IP addresses. This means that the server under the current DHCP architecture does not have the authority to request and maintain IP addresses, thus preventing remote desktop IP virtualization. Since remote desktop IP virtualization cannot be implemented in public clouds, the security, privacy, and scalability of various public cloud services cannot be guaranteed. Therefore, a method to implement remote desktop IP virtualization in a public cloud environment is urgently needed. This application provides an IP address allocation method, an address allocation system, a computing device cluster, and a storage medium, which can realize remote desktop IP virtualization in a public cloud mode, ensuring the security, privacy, and scalability of public cloud services. The technical solution is as follows:Firstly, this application provides an IP address allocation method. This method is applied to an address allocation system, which includes a cloud platform and a Remote Desktop Session Host (RDSH). The cloud platform provides public cloud services. The method includes: the cloud platform receiving a first creation request from a first client and forwarding the first creation request to a target RDSH. The first creation request requests the establishment of a first session with the target RDSH. In response to the first creation request, the target RDSH allocates a corresponding first IP address to the first session. The first IP address is obtained through IP address virtualization of the target RDSH. The target RDSH returns the first IP address to the cloud platform. The cloud platform returns a first access response to the first client, indicating that the first client has established a first session with the target RDSH based on the first IP address. The IP address allocation method provided in this application can be applied to public cloud services. By implementing remote desktop IP virtualization in public cloud services, when a client accesses the RDSH in the cloud platform, the RDSH can allocate an IP address to the client based on multiple virtualized IP addresses. This allows different clients to obtain network services through the same RDSH using different IP addresses, ensuring the security, privacy, and scalability of the network service. In one possible implementation, the method further includes: a cloud platform receiving a second creation request from a second client and forwarding the second creation request to a target RDSH, the second creation request being used to request the establishment of a second session with the target RDSH; in response to the second creation request, the target RDSH assigning a corresponding second IP address to the second session, the second IP address being obtained through IP address virtualization of the target RDSH; the target RDSH returning the second IP address to the cloud platform; and the cloud platform returning a second access response to the second client, the second access response indicating that the second client has established a second session with the target RDSH based on the second IP address. The IP address allocation method provided in this application allows different clients using the same RDSH to allocate different virtualized IP addresses to different sessions corresponding to different clients, enabling different clients to use different IP addresses to obtain network services. Therefore, when different clients obtain network services through the same RDSH, different IP addresses can be presented, thereby ensuring the security, privacy, and scalability of different clients obtaining network services within the same RDSH. In one possible implementation, the method further includes: the cloud platform providing a target function switch in a management interface, the target function switch being used to turn on and off the IP virtualization function for the target RDSH, the IP virtualization function including: enabling the RDSH to use multiple IP addresses obtained by virtualizing the IP address based on the RDSH.The above technical solution provides users with an on / off switch for the IP virtualization function on the front-end interface, allowing users to configure the IP virtualization function during the RDSH creation process according to business needs. In one possible implementation, the method further includes: In response to obtaining first specification information for the target RDSH from the cloud platform's management interface, during the creation of the target RDSH, the cloud platform obtains at least one IP address obtained from IP address virtualization of the target RDSH based on the first specification information, and sends the at least one virtualized IP address to the target RDSH. The first specification information indicates at least one of the following: the number of IP addresses used by the target RDSH, and the number of sessions supported by the target RDSH; In response to an IP update command, the cloud platform obtains at least one updated IP address obtained from IP address virtualization of the target RDSH based on second specification information carried by the IP update command, and sends the updated IP address to the target RDSH. The second specification information indicates at least one of the following: the number of IP addresses used by the updated target RDSH, and the number of sessions supported by the updated target RDSH. Based on this, the cloud platform can promptly release redundant IP addresses and promptly replenish usable IP addresses for the RDSH, thereby improving the real-time performance of IP resource management. In one possible implementation, the cloud platform obtains the updated IP address of the target RDSH based on the second specification information carried in the IP update instruction, including: comparing the first number currently available to the target RDSH with the second number indicated by the second specification information; if the second number is less than the first number, determining the IP address to be released this time, and obtaining at least one IP address obtained after virtualization based on the released IP address; if the second number is greater than the first number, determining the IP address of the newly applied virtualization, and obtaining at least one IP address obtained after virtualization based on the newly applied virtualization IP address. Through the above scheme, users can configure the number of sessions when creating an RDSH in the management interface provided by the cloud platform, effectively integrating IP virtualization functionality into actual business scenarios. In one possible implementation, the method further includes at least one of the following: in response to obtaining the second specification information for the target RDSH in the cloud platform's management interface, the cloud platform triggers an IP update instruction; in response to detecting that the usage of the target RDSH in the cloud platform meets the update conditions, the cloud platform triggers an IP update instruction. The above technical solution, using a single RDSH instance as the granularity, provides both active and passive update initiation methods for dynamically updating the IP address source of the RDSH. It can cover scenarios such as product changes on the business side and availability maintenance on the service side, greatly improving the flexibility of RDSH-based deployment and the availability of network services. In one possible implementation, the method further includes:In response to a first client's deregistration request for a first session, the target RDSH releases the first IP address allocated to the first session. In one possible implementation, the method further includes: in response to a network service request initiated by the first client through the first session, the target RDSH uses the first IP address to process the network service request. Based on this, this application can achieve session-level IP address isolation, effectively distinguishing network requests from different users and ensuring the privacy of network services used by different users. The cloud platform can maintain the IP address source allocated to each RDS, enabling each RDSH to allocate, reclaim, and reuse IP addresses; when programs in different sessions within the same RDSH are listening to the network interface card (NIC) of the RDSH host, allocating a unique virtualized IP address to each session can effectively avoid NIC listening conflicts caused by only one available IP address for the NIC. In summary, the technical solution of this application can effectively improve IP address allocation efficiency and greatly enhance the scalability of network services provided based on RDSH. 2 WO 2024 / 198619 PCT / CN2024 / 071278 In a second aspect, an address allocation system is provided, comprising a cloud platform and a Remote Desktop Session Host (RDSH). The cloud platform is used to provide public cloud services. The cloud platform is used to: receive a first creation request from a first client and forward the first creation request to a target RDSH. The first creation request is used to request the establishment of a first session with the target RDSH. The target RDSH is used to: respond to the first creation request and allocate a corresponding first IP address to the first session. The first IP address is obtained by virtualizing the IP address of the target RDSH. The target RDSH is used to: return the first IP address to the cloud platform. The cloud platform is used to: return a first access response to the first client, the first access response indicating that the first client has established a first session with the target RDSH based on the first IP address. In one possible implementation, the cloud platform is further configured to: receive a second creation request from a second client and forward the second creation request to the target RDSH, wherein the second creation request is used to request the establishment of a second session with the target RDSH; the target RDSH is further configured to: respond to the second creation request and allocate a corresponding second IP address for the second session, wherein the second IP address is obtained by IP address virtualization of the target RDSH; the target RDSH is further configured to: return the second IP address to the cloud platform; the cloud platform is further configured to: return a second access response to the second client, wherein the second access response indicates that the second client has established a second session with the target RDSH based on the second IP address. In one possible implementation, the cloud platform is further configured to: provide a target function switch in the management interface, wherein the target function switch is used to turn the IP virtualization function for the target RDSH on and off, wherein the IP virtualization function includes: enabling the RDSH to use multiple IP addresses obtained by IP address virtualization based on the RDSH.In one possible implementation, the cloud platform is further configured to, in response to obtaining first specification information for the target RDSH from the cloud platform's management interface, during the creation of the target RDSH, obtain the IP address of the target RDSH according to the first specification information, and send the IP address to the target RDSH. The first specification information indicates at least one of the following: the number of IP addresses of the target RDSH, and the number of sessions supported by the target RDSH. The cloud platform is further configured to, in response to an IP update command, obtain the updated IP address of the target RDSH according to second specification information carried in the IP update command, and send the updated IP address to the target RDSH. The second specification information indicates at least one of the following: the number of IP addresses of the updated target RDSH, and the number of sessions supported by the updated target RDSH. In one possible implementation, the cloud platform is configured to: compare the first number currently available to the target RDSH with the second number indicated by the second specification information; if the second number is less than the first number, determine the IP address to be released this time, and obtain the updated IP address based on the IP address released this time; if the second number is greater than the first number, determine the IP address of the newly applied virtualization, and obtain the updated IP address based on the IP address of the newly applied virtualization. In one possible implementation, the cloud platform is configured to perform at least one of the following: In response to obtaining second specification information for the target RDSH from the management interface of the cloud platform, the cloud platform triggers an IP update instruction; In response to detecting that the usage of the target RDSH in the cloud platform meets the update conditions, the cloud platform triggers an IP update instruction. In one possible implementation, the target RDSH is further configured to: In response to a first client's logout request for a first session, release the first IP address allocated to the first session. In one possible implementation, the target RDSH is further configured to: In response to a network service request initiated by the first client through the first session, use the first IP address to process the network service request. A third aspect provides a computing device cluster, including at least one computing device, each computing device including a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the computing device cluster to perform the IP address allocation method as provided in the first aspect. A fourth aspect provides a computer-readable storage medium including computer program instructions, which, when executed by the computing device cluster, cause the computing device cluster to perform the IP address allocation method as provided in the first aspect. Fifthly, a computer program product containing instructions is provided, which, when executed by a cluster of computing devices, causes the cluster of computing devices to perform the IP address allocation method provided in the first aspect. (3 WO 2024 / 198619 PCT / CN2024 / 071278 [Figure Description])Figure 1 is a schematic diagram of assigning IP addresses to remote desktop sessions based on the DHCP protocol in a related technology according to an embodiment of this application; Figure 2 is a schematic diagram of an implementation environment according to an embodiment of this application; Figure 3 is a schematic diagram of a management interface according to an embodiment of this application; Figure 4 is a schematic diagram of cloud platform initialization settings according to an embodiment of this application; Figure 5 is a schematic diagram of the principle of creating an RDSH according to an embodiment of this application; Figure 6 is a schematic diagram of the process of issuing IP addresses when creating an RDSH according to an embodiment of this application; Figure 7 is a schematic diagram of an IP address allocation method according to an embodiment of this application; Figure 8 is a schematic diagram of a client using network services according to an embodiment of this application; Figure 9 is a schematic diagram of a session cancellation process according to an embodiment of this application; Figure 10 is a schematic diagram of updating an IP address according to an embodiment of this application; Figure 11 is a schematic diagram of another management interface according to an embodiment of this application; Figure 12 is a schematic diagram of an IP address update process according to an embodiment of this application; Figure 13 is a schematic diagram of an address allocation system according to an embodiment of this application; Figure 14 is a schematic diagram of the hardware structure of a computing device according to an embodiment of this application; Figure 15 is a schematic diagram of a computing device cluster according to an embodiment of this application. To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings. Before introducing the technical solutions provided by the embodiments of this application, the terms involved in this application will be explained below. Internet Protocol Address (IP): An identifier assigned to a device when it accesses a network. Devices can communicate with each other through IP addresses. The IP address can determine which device is the sender and which is the receiver. Cloud platform is short for cloud computing platform, which can provide cloud services such as computing, networking, and storage based on massive hardware and software resources. Through the network "cloud," massive data computing and processing are performed remotely and then returned to the user, featuring large scale, distributed, virtualized, highly available, scalable, on-demand service, and security. Cloud platforms can achieve rapid deployment and release of configurable computing resources with relatively low management costs or low interaction complexity between users and service providers. OpenStack is a cloud platform with an Infrastructure as a Service (IAAS) architecture that provides a cloud operating system for managing a large pool of resources throughout a data center. Administrators can manage the entire cloud system through the cloud platform's console and provide users with available cloud resources via a web interface. Public cloud: A cloud infrastructure used by the general public or large industrial groups; that is, a type of cloud accessed through a public network.The public cloud platform refers to the ability of organizations with public clouds to deploy and use cloud services on demand by renting them out. Users can access the public cloud through public networks (such as the Internet) to use various network services it provides, including but not limited to computing, storage, and networking. Virtual Private Cloud (VPC): An isolated and private virtual network environment on a cloud platform. Users can freely configure IP address ranges, subnets, security groups, and other sub-services within the VPC. Elastic Cloud Server (ECS): A basic computing component consisting of CPU, memory, operating system, and cloud disks, characterized by its readily available availability and elastic scalability. Cloud Service: A service obtained on demand and easily scalable via a network. This service can be related to network technology, software, and the Internet, or other services. Network Interface Controller (NIC): A computer hardware device used to allow computers to communicate on a computer network; also known as a network access controller. Network Proxy: A special network service that allows one terminal to establish an indirect connection with another terminal through this service. Some network devices such as gateways and routers have network proxy functions. Proxy services are generally considered beneficial for protecting the privacy and security of network terminals and can, to some extent, prevent network attacks. Remote Desktop Protocol (RDP): A protocol that allows users to use terminal services provided by remote devices through their local devices. Remote Desktop Session Host (RDSH): The remote desktop session host can store applications and desktops shared with users based on remote desktop sessions (RDS). Remote Desktop Session (RDS): When a user logs into the remote desktop session host (RDSH), a remote desktop session can be started. Remote Desktop IP Virtualization: After enabling and configuring IP virtualization on the remote desktop session host (RDSH), a unique IP address will be assigned and used in the remote desktop session. Dynamic Host Configuration Protocol (DHCP): A protocol that allows network administrators to centrally manage...This application relates to a communication protocol for automatically assigning IP network addresses. In an IP network, each device connected to the Internet needs to be assigned a unique IP address. Dynamic Host Configuration Protocol (DHCP) allows network administrators to monitor and assign IP addresses from a central node. When a computer moves to another location on the network, it automatically receives a new IP address. DHCP server (Daimon): Management software for network administrators that implements the DHCP communication protocol. DHCP client (Daimon): Client software for hosts that implements the DHCP communication protocol. The application scenarios of the technical solution in this application are described below. This application provides a method for providing IP addresses for remote desktop sessions, which can be applied in cloud platforms to assign different IP addresses to different remote desktop sessions running on a cloud platform. Related technologies use DHCP to dynamically assign IP addresses to different sessions on a remote desktop session host. Referring to Figure 1, which illustrates a related technology of assigning IP addresses to remote desktop sessions based on the DHCP protocol, when a client connects to an RDSH (e.g., RDSH2), a connection is established between the client and RDSH2 (indicated by RDP1). RDSH2 creates RDS1 and sends a DHCP request to its DHCP network (usually a local area network). The DHCPD in the LAN receives the DHCP request and assigns IP address 1 to RDS1. RDS1 then uses IP address 1 to enjoy network services. The process of assigning IP address 2 to another client's corresponding RDS2 is similar. This process relies on the DHCPD's ability to centrally manage IP addresses within the network. However, in a public cloud environment, DHCP cannot virtualize IP addresses for remote desktop sessions. The reasons are as follows: Firstly, DHCP cannot obtain management permissions for IP addresses within the cloud platform. To ensure the security of cloud services, the cloud platform's management plane, such as a Virtual Private Cloud (VPC) deployed in a public cloud, centrally manages resources like IP addresses. This results in the DHCP server in the current DHCP architecture lacking the authority to request and maintain IP addresses. On the other hand, DHCP is only suitable for IP management within a local network and is difficult to apply to cloud platforms. In a public cloud model, the massive underlying resources are abstracted and provided to users as cloud services. The actual hosts / virtual machines / containers used to implement these cloud services may be distributed across networks, for example, in different regions, which may include a data center network or multiple geographical locations.The current DHCP architecture, however, is only suitable for managing IP resources within a local area network (LAN) and cannot guarantee the real-time dynamic allocation and release of IP addresses in a large public cloud. For example, a DHCP request sent by a client is processed as soon as it is received by the nearest DHCPD (within the network), making it difficult to transmit across networks to the next, thus hindering dynamic IP allocation in the public cloud. In summary, current DHCP technology cannot be used to implement remote desktop IP virtualization in a public cloud. Therefore, this application provides an IP address allocation method applicable to cloud platforms providing public cloud services. This method enables remote desktop IP virtualization on the cloud platform, allowing different clients to access the RDSH (Remote Desktop Service) within the cloud platform. The RDSH assigns different virtualized IP addresses to different sessions corresponding to different clients, enabling different clients to use different IP addresses to access network services. Therefore, when clients access sessions in the RDSH to use various network services provided by the cloud platform, the security, privacy, and scalability of the network services are fully guaranteed. The technical solution of this application is further described below. This application provides a schematic diagram of an implementation environment, as shown in Figure 2. Figure 2 is a schematic diagram of an implementation environment provided by this application embodiment, which includes a client 210 and an address allocation system 220. The technology of providing remote sessions in a cloud host for the client in this application is also called a cloud desktop. RDSH running in a public cloud can also be called a remote desktop session host instance of a cloud desktop. Referring to Figure 2, the address allocation system 220 includes a cloud platform 221, which is used to provide IP virtualization functions in the public cloud. The VPC 222 running in the address allocation system 220 is used to maintain resources such as IP addresses within the cloud platform. A VPC is a logically isolated network space defined on a public cloud (5 WO 2024 / 198619 PCT / CN2024 / 071278). Resources on the public cloud, such as cloud hosts and load balancers, can be hosted within a VPC. Administrators can use VPCs to customize network segment divisions, IP addresses, and routing policies. In some embodiments, the address allocation system 220 includes an elastic cloud server 223, which is used to run at least one RDSH instance, referred to as RDSH1 to RDSH-n in Figure 2, where h is the number of RDSH instances and n is greater than or equal to 1. The elastic cloud server 223 is a basic computing component of the cloud platform, and the address allocation system 220 can provide the elastic cloud server 223 to users on demand. The client 210 is used to access the address allocation system 220, access the RDSH instances in the cloud platform, and use various remote access methods based on the RDS instances within the RDSH instances.The network services provided by the process include, for example, running applications, downloading files, or accessing the network (either within the cloud or outside the cloud). The administrator mentioned above refers to the user who manages the RDSH running in the cloud platform. In some embodiments, the administrator creates a target RDSH based on the public cloud through the management interface provided by the cloud platform and configures IP virtualization for the created target RDSH. The cloud platform 221, according to the administrator's configuration, requests one or more IP addresses from the VPC 222 and sends them to the target RDSH. When the target RDSH receives the first creation request from the first client, it creates a first session corresponding to the first client and allocates a first IP address to the first session from the multiple IP addresses it maintains. The multiple IP addresses obtained by the cloud platform from the VPC are obtained based on the IP address virtualization of the RDSH. When the client 210 accesses the session in the RDSH, it can use the virtualized IP address allocated by the RDSH for network communication. In some embodiments, referring to Figure 2, the RDSH in the address allocation system 220 is equipped with a standalone DHCPD, which is a management software for administrators that supports Dynamic Host Configuration Protocol (DHCP). Based on this, RDSH in cloud platform 220 can utilize DHCPD to dynamically manage multiple IP addresses within a single machine. Of course, the technical solution of this application can also be applied to other cloud platform models, such as hybrid clouds combining private and public clouds; this application does not limit this. In this embodiment, the address allocation system 220 can be implemented based on a computing device cluster, which includes at least one computing device. In some embodiments, the computing device cluster can be a server, a server cluster consisting of multiple physical servers, or a distributed file system, or a cloud server cluster providing basic cloud computing services such as cloud storage, cloud services, cloud databases, cloud computing, cloud functions, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDNs), big data, and artificial intelligence platforms; this application does not limit this. In this embodiment, client 210 runs on a computing device, which can be a terminal or a server. The terminal can be, for example, a desktop computer, a laptop, or a smartphone; the server can be, for example, a central server, an edge server, or a local server in a local data center; this application does not limit this. The same applies to the client where the administrator resides. In some embodiments, the administrator's terminal and the computing device accessing the RDS can be the same or different devices; this application does not limit this. In some embodiments, the IP address allocation method provided in this application can be implemented in the address allocation system 220 in the form of a computing instance.The computing instance can run in a public cloud as a virtual machine, container, or process, and be provided to users as a cloud service. The client 210 and the address allocation system 220 can communicate via a wired or wireless network. In some embodiments, the wireless or wired network uses standard communication technologies and / or protocols. The network includes, but is not limited to, data center networks, storage area networks (SANs), local area networks (LANs), metropolitan area networks (MANs), wide area networks (WANs), mobile, wired or wireless networks, private networks, or any combination of virtual private networks. In some implementations, technologies and / or formats including Hypertext Markup Language (HTML), Extensible Markup Language (XML), etc., are used to represent data exchanged over the network. In addition, conventional encryption technologies such as Secure Sockets Layer (SSL), Transport Layer Security (TLS), Virtual Private Network (VPN), and Internet Protocol Security (IPsec) can be used to encrypt all or part of the link. In other embodiments, customized and / or dedicated data communication technologies can be used to replace or supplement the above-mentioned data communication technologies. Next, based on the above application scenarios and implementation environments, the IP address allocation method provided by the embodiments of this application will be described in detail with reference to Figures 3-12 provided below. The following description takes the interaction between the client and the address allocation system as an example. Steps 301 to 307 below describe a brief process of allocating IP addresses for different Remote Desktop Sessions (RDS) used by different clients in a public cloud. 301. The cloud platform in the address allocation system responds to the RDSH creation command and creates the target RDSH. 6 WO 2024 / 198619 PCT / CN2024 / 071278 In some embodiments, the cloud platform provides a target function switch in the management interface. The target function switch is used to turn on and off the IP virtualization function for the target RDSH. The IP virtualization function includes: enabling the RDSH to use multiple virtualization functions obtained based on the IP address of the RDSH.Each IP address. In some embodiments, the cloud platform's management interface is also referred to as the public cloud's console. In some embodiments, the administrator creates and manages RDSHs in the cloud platform through the management interface provided by the cloud platform. The RDSH creation command can be triggered by the administrator. For example, the administrator logs into the management interface provided by the cloud platform through a terminal device and selects to create a target RDSH on the target server. Figure 3 is a schematic diagram of a management interface provided in this application. Referring to Figure 3, the administrator logs into the management interface provided by the public cloud platform and begins to create an RDSH (which can be one or a group). The management interface provides an input field to edit the name of the server group to be created, and supports the administrator to select the region where the target server group is located (which can be a data center divided by geographical region); the management interface provides a function to select an image, and the user can select the required image to create the RDSH; the management interface provides a target function switch. As shown in the figure, when the target function switch is on, the currently created RDSH can apply the IP virtualization function. Among them, the image provides the operating system, initial application data and pre-installed software used by the RDSH instance, etc. As shown in Figure 3, the administrator can directly select an image pre-installed with DHCPD. In some embodiments, the cloud platform supports pre-setting application rules for the IP virtualization function of RDSH, so that when creating an RDSH and enabling IP virtualization, the IP virtualization function of the target RDSH can be directly enabled according to the pre-set application rules, allowing administrators to create and manage RDSH in a simple and efficient manner in public cloud mode. The following description refers to Figure 4, which is a schematic diagram of cloud platform initialization settings, with its architecture referring to the description in Figure 2. In some embodiments, in the initial state, the cloud platform is ready, and the administrator has not yet set the application rules for the IP virtualization function of RDSH in the cloud platform. The administrator logs into the public cloud console (management interface) provided by the cloud platform and sets the application rules for enabling remote desktop IP virtualization. The cloud platform saves and records the application rules set by the administrator, which can be applied to newly created RDSH. In some embodiments, the above application rules indicate the object to which the IP virtualization function is applied, for example, a group of servers used to run RDSH, or a single server used to run RDSH. Accordingly, the application rules can instruct: all RDSH servers in a group to enable IP virtualization, or instruct a selected single RDSH server to enable IP virtualization. The above technical solution provides users with an on / off switch for the IP virtualization function on the front-end interface, allowing users to configure the IP virtualization function during the RDSH creation process according to their business needs. 302. Based on the target RDSH, the cloud platform applies to the VPC for at least one IP address obtained through IP address virtualization based on the target RDSH.In some embodiments, the first specification information indicates the specifications of the IP addresses involved in the target RDSH. Exemplarily, the first specification information includes at least one of the following: the number of IP addresses used by the target RDSH, for example, one or two; the number of sessions supported by the target RDSH, for example, two or three. In some embodiments, in response to obtaining the first specification information in the management interface, the cloud platform obtains at least one IP address virtualized based on the IP addresses of the RDSH. Exemplarily, the cloud platform obtains one or more virtualized IP addresses based on the number of IP addresses indicated by the first specification information; or, the cloud platform obtains one or more virtualized IP addresses supporting the number of sessions indicated by the first specification information. In some embodiments, the cloud platform can select a target physical host (such as a server) to run the created target RDSH according to a user-submitted request. Each physical host is equipped with a network interface card (NIC) for networking, and the IP address configured on the NIC when it is mounted to the physical host is also the IP address of the RDSH. In this example, the cloud platform requests the VPC to virtualize the corresponding number of IP addresses based on the RDSH's IP address and the quantity indicated by the first specification information. The virtualized IP addresses are then bound to the IP addresses corresponding to the RDSH. For example, multiple virtualized IP addresses are bound to the network interface card (NIC) corresponding to the RDSH, serving as equivalent IP addresses to the NIC's original fixed IP addresses, thus completing the networking process of the virtualized IP addresses on the public cloud management plane. In other embodiments, the relationship between the physical host, NIC, NIC IP address, and virtualized IP addresses is maintained by the VPC. Therefore, the multiple virtualized IP addresses can provide networking functionality equivalent to the NIC's original fixed IP addresses, providing data support from the public cloud management plane for the subsequent dynamic management of multiple IP addresses within the RDSH. In some embodiments, the cloud platform may request one or more virtualized IP addresses for the target RDSH. For example, the cloud platform determines this based on the first specification information submitted by the user, or it may request an equal number of IP addresses based on the product specifications (e.g., number of sessions) set by the administrator when creating the target RDSH. In some embodiments, the cloud platform's management interface provides an option to specify the region where the cloud server is located. That is, the administrator can select the region where the cloud server used to create the target RDSH is located. In this example, the administrator selects the server's region, submits the request to the cloud platform, triggering the cloud platform to request the IP address of the target RDSH from the VPC. The VPC then determines the IP address of the target RDSH based on the available cloud servers in the region selected by the administrator.The RDSH is assigned an IP address, and then a corresponding number of virtualized IP addresses are requested based on the administrator's needs for the number of sessions. Through this scheme, the cloud platform's management interface allows users to customize the number of sessions used when creating an RDSH, effectively integrating IP virtualization functionality into actual business scenarios. 303. The cloud platform sends at least one virtualized IP address to the created target RDSH. In some embodiments, the target RDSH runs a server-side DHCPD that supports Dynamic Host Configuration Protocol (DHCP). The cloud platform sends at least one virtualized IP address to the single-machine DHCPD running in the target RDSH. This DHCPD supports the DHCP protocol and can maintain (e.g., allocate and reclaim) the multiple virtualized IP addresses. Therefore, the multiple virtualized IP addresses issued by the cloud platform to the target RDSH are equivalent to the IP address source being maintained and managed by the DHCPD. Through the above technical solution, multiple individually assignable virtualized IP addresses are issued to the single-machine DHCPD running in the RDSH at the granularity of a single RDSH, thereby achieving flexible management of multiple IP addresses within a single RDSH. It should be noted that the above process is illustrated using the creation process of a single RDSH instance as an example. When an administrator creates multiple RDSH instances through a single configuration, the cloud platform can execute the RDSH creation and virtualization IP address distribution process for each RDSH instance, following a similar process to steps 301 to 303 above. To facilitate understanding of the processes described in steps 301 to 305 above, this application further provides Figures 5 and 6. Figure 5 is a schematic diagram illustrating the principle of RDSH creation provided by this application, and Figure 6 is a schematic diagram illustrating the process of distributing IP addresses during RDSH creation provided by this application. The technical solutions provided in steps 301 to 303 above will be further explained below in conjunction with Figures 5 and 6. Referring to Figure 5, in the scenario where an administrator creates one or more RDSH instances, the administrator logs into the management interface (public cloud console) provided by the cloud platform, selects the server group corresponding to the configured remote desktop IP virtualization rule, and purchases one or more RDSH instances (corresponding to one or more physical hosts). The cloud platform, based on the perspective of a single RDSH instance, requests one or more virtualized IP addresses from the VPC during the RDSH creation process, and then distributes these virtualized IP addresses to the single-machine DHCPD installed within the corresponding RDSH. Referring to Figure 6, the administrator submits an RDSH creation task to the cloud platform through the public cloud console provided by the cloud platform; the cloud platform returns a successful task submission response to the console and submits the RDSH creation task to the Elastic Cloud Server (ECS); after receiving the response from the ECS, the cloud platform requests virtualized IP addresses from the VPC to be allocated to the RDSH, and then distributes the obtained virtualized IP addresses to the RDSH; RDSHThe standalone DHCPD in the RDSH receives and stores these virtualized IP addresses as a source of IP addresses that can be used for allocation. The standalone DHCPD in the RDSH starts DHCP protocol listening and provides DHCP protocol support capabilities. Steps 301-303 above describe the creation process of the RDSH and the process of distributing multiple available virtualized IP addresses. The following describes the process of dynamically allocating IP addresses when a client accesses the RDSH. 304. The cloud platform receives the first creation request sent by the first client and forwards the first creation request to the target RDSH. The first creation request is used to request the establishment of a first session with the target RDSH. In some embodiments, the first creation request carries host information. The cloud platform can determine the target RDSH based on the host information and then forward the first creation request to the target RDSH. The host information may be the host name, host IP address, subnet address of the host, etc., and this application is not limited to this. In other embodiments, the cloud platform determines the target RDSH host that provides RDSH services to the first client according to the load balancing strategy. 305. In response to the first creation request, the target RDSH assigns a corresponding first IP address to the first session. The first IP address is obtained by the IP address virtualization of the target RDSH. Based on multiple virtual IP addresses corresponding to this IP address, the RDSH assigns virtual IP addresses to the running Remote Desktop Session (RDS). In some embodiments, the target RDSH runs a server-side DHCPD that supports the Dynamic Host Configuration Protocol (DHCP). The DHCPD supports the DHCP protocol and is capable of maintaining (e.g., allocating and reclaiming) the multiple virtualized IP addresses. In response to the first creation request, the target RDSH sends a DHCP request to the DHCPD; in response to the DHCP request, the DHCPD assigns a first IP address to the first session from the multiple virtualized IP addresses it maintains. In some embodiments, each session is assigned a unique session identifier within an RDSH. To facilitate understanding of steps 304 to 305 above, this application provides Figure 7 based on Figure 5. Figure 7 is a flowchart of an IP address allocation method provided by an embodiment of this application. Referring to Figures 7 and 5, after the client sends a first creation request, it accesses the RDSH via RDP. The RDSH marks this connection with RDP1, creates a corresponding first session RDS1, and associates the client's connection RDP1 with the first session RDS1. The RDSH issues a DHCP request to request an IP address for the first session from the running DHCPD. The standalone DHCPD within the RDSH receives the request, responds, and allocates a virtualized IP address 1. The RDSH obtains IP address 1 and associates RDS1 with IP address 1. Based on this, the first client can use IP address 1 as the IP address for subsequent access to network services based on the first session RDS1.306. The target RDSH returns the first IP address to the cloud platform. 8 WO 2024 / 198619 PCT / CN2024 / 071278 In some embodiments, based on the first IP address returned by the target RDSH, the cloud platform can determine at what time, which client, through which RDSH, and which session used the first IP address for network communication. Therefore, the cloud platform can effectively manage and trace the users of remote desktop sessions, thereby ensuring the security of remote desktop sessions in the public cloud. 307. The cloud platform returns a first access response to the first client, indicating that the first client has established a first session with the target RDSH based on the first IP address. In some embodiments, the cloud platform returns the IP address of the target RDSH (e.g., the fixed IP address configured on the network card of the physical host) to the first client, so that the first client can directly access the target RDSH based on the IP address. In other embodiments, the target RDSH can also return the first access response to the first client, so that the first client can directly interact with the accessed RDSH, reducing the forwarding and interaction overhead of the cloud platform. Similar to steps 304-307 above, for a second client using the target RDSH, the process of the address allocation system allocating an IP address includes: the cloud platform receiving a second creation request from the second client and forwarding the second creation request to the target RDSH, the second creation request being used to request the establishment of a second session with the target RDSH (refer to step 304); in response to the second creation request, the target RDSH allocating a corresponding second IP address for the second session, the second IP address being obtained by virtualizing the IP address of the target RDSH (refer to step 305); the target RDSH returning the second IP address to the cloud platform (refer to step 306); the cloud platform returning a second access response to the second client, the second access response indicating that the second client has established a second session with the target RDSH based on the second IP address (refer to step 307). In some other embodiments, in response to a network service request initiated by the first client through the first session, the target RDSH uses the first IP address to process the network service request. Exemplarily, this network service request includes accessing the network using proxy software, which will be described below with reference to Figure 8. Figure 8 is a schematic diagram of a client using network services provided in this application. Referring to Figure 8, in the secure Internet access scenario managed by the enterprise proxy server, the process of user A in the enterprise network accessing the external network by logging into the proxy server using proxy software through the remote desktop session in RDSH includes the following steps (1) to (5): (1) User A accesses RDSH via RDP through the client and is marked as RDP1. RDSH creates the corresponding RDS1. RDSH sends a DHCP request to apply for an IP address.(2) The standalone DHCPD in RDSH receives the request, responds and assigns a virtualized IP address 1. RDSH obtains the IP address 1 and associates RDS1 with IP address 1. User A can use IP address 1 as the IP address for subsequent network communication through the client. (3) User A uses the proxy software running in RDSH through RDS1 to request to log in to the proxy server of the enterprise network. (4) The enterprise proxy server authenticates IP address 1 and the user credentials provided by user A. The enterprise proxy server records that IP address 1 has been authenticated and allows IP address 1 to access network resources through the proxy server. (5) User A uses the authenticated IP address 1 to access the proxy server to access network resources through the proxy server. User B goes through the same process from step (1) to step (5), and then uses the authenticated IP address 2 to access the proxy server to access network resources through the proxy server. In the above process, it is possible for user A and user B to use network services based on different IP addresses without affecting each other. Therefore, this application can at least achieve the following: a client uses a unique IP address within the RDSH for network access in a specified session of the specified RDSH; different clients use different IP addresses for network access within the same RDSH; and the same client uses different IP addresses in different sessions. Based on this, this application can achieve session-level IP address isolation, effectively distinguishing network requests from different users and ensuring the privacy of network services used by different users. In other embodiments, the RDSH responds to a session cancellation request for the RDS by releasing the virtual IP address allocated to the RDS. This application provides a schematic flowchart of session cancellation. Referring to Figure 9, the cancellation process includes: a first client requests to cancel the connection RDP1 with the RDSH. The RDSH receives the request and cancels the relevant resources of the first session RDS1 associated with RDP1. The RDSH issues a DHCP request to release IP address 1 associated with RDS1. A standalone DHCPD within the RDSH receives the request, reclaims IP address 1, and uses it for subsequent reassignment to other accessing RDPs. The RDSH releases the association between RDS1 and IP address 1, completing the session cancellation. The technical solution provided in this application enables the cloud platform to request an IP address from the public cloud management plane for each RDSH and maintain the IP address source (IP addresses obtained from multiple virtualizations) allocated to each RDSH. Within the public cloud RDSH, a customized single-machine DHCPD based on DHCP is implemented, thereby enabling each RDSH to allocate, reclaim, and reuse IP addresses. For programs in different sessions within the same RDSH listening to the network interface card port of the RDSH host, assigning a unique virtualized IP address to each session allows for...This effectively avoids the client-side listening conflict problem caused by only one available IP address for the network card. In summary, the technical solution of this application can effectively improve the efficiency of IP address allocation and greatly enhance the scalability of network services provided based on RDSH. Therefore, the IP address allocation method provided by this application can be applied to provide public cloud services and implement remote desktop IP virtualization for public cloud services. When a client accesses a session in RDSH to use various network services provided by the cloud platform, the security, privacy, and scalability of the network services can be fully guaranteed. The above embodiments describe how to distribute allocable virtualized IP addresses during the creation of RDSH so that RDSH can allocate different IP addresses to different sessions. In some other embodiments, based on the above embodiments, it is also supported to update the virtualized IP addresses already allocated to RDSH during the operation of RDSH. Figure 10 is a schematic diagram of updating an IP address provided by this application. The following description refers to Figure 10 and combines steps 1001 and 1002. 1001. In response to the IP update command, the cloud platform obtains at least one IP address obtained after the update based on the IP address virtualization of the target RDSH, according to the second specification information carried in the IP update command. The second specification information indicates at least one of the following: the number of IP addresses used by the target RDSH after the update, and the number of sessions supported by the target RDSH after the update. An example of the second specification information can be found in the description of the first specification information in step 302, and will not be repeated here. In some embodiments, the cloud platform determines the method of updating the IP addresses allocated to the virtualization of the target RDSH by comparing the first number currently available to the RDSH with the second number indicated by the second specification information. This number can be the number of sessions or the number of IP addresses. In some embodiments, if the second number is less than the first number, the cloud platform determines the IP addresses to be released this time, and obtains at least one IP address obtained after the update based on the released IP addresses. Based on this, the cloud platform can release redundant IP addresses in a timely manner. In other embodiments, if the second number is greater than the first number, the cloud platform determines the IP addresses of the newly applied virtualization, and obtains at least one IP address obtained after the update based on the newly applied virtualization IP addresses. Based on this, the cloud platform can replenish the available IP addresses in a timely manner. In summary, this improves the real-time performance of IP resource management. In some embodiments, the number of IP addresses obtained after the virtualization update is greater than or equal to the number of sessions corresponding to the updated target RDSH product specifications. Referring to Figure 10, the cloud platform can respond to the administrator's update request and, based on the above comparison process, determine whether to request new IP addresses from the VPC.Alternatively, it may request the VPC to release IP addresses; then, based on the newly acquired IP address or the released IP address, the updated IP address of the target RDSH is determined. In some embodiments, the cloud platform supports passively updating the IP address of the RDSH. In response to obtaining the second specification information for the target RDSH from the management interface of the cloud platform, the cloud platform triggers an IP update command. In some embodiments, the cloud platform obtains the second specification information for the target RDSH from the management interface. In some application scenarios, due to changes in product specifications (e.g., changes in the number of remote desktop sessions used), in order to improve the utilization efficiency of IP addresses and ensure that the number of IP addresses supports the business needs of the product, the administrator of the target RDSH will update the IP address used by the target RDSH. In this example, the administrator triggers the update process for the target RDSH in the management interface. Figure 11 is a schematic diagram of another management interface provided in this application. Referring to Figure 11, the administrator logs into the public cloud console (management interface) and operates to update the IP source of the target RDSH. As shown in Figure 11, the management interface displays multiple options for configuring the IP virtualization function of the current server group. The management interface displays information such as the name of the server group AAA used to run the target RDSH, the operating system or image information used by the server group, the specifications of the server group, the number of supported sessions, the capacity of the system hard disk, the creation time, and the server status. Referring to Figure 11, the server group used to run the target RDSH has enabled IP virtualization. See the management area of the target RDSH instance; the "More" option provides an option to update the virtual IP. In some embodiments, the cloud platform supports actively updating the virtualized IP addresses allocated to the RDSH. In response to detecting that the usage of the target RDSH in the cloud platform meets the update conditions, the cloud platform triggers an IP update command. These update conditions indicate the IP address usage; for example, if the number of virtualized IP addresses used on one or more RDSH hosts exceeds a first threshold, or if the number of remaining available virtualized IP addresses on one or more RDSH hosts is less than a second threshold, the cloud platform automatically triggers the allocation of additional virtualized IP addresses. Based on this, the cloud platform can dynamically maintain the number of virtualized IP addresses used by each host according to usage, thereby improving IP address utilization efficiency and maintaining service availability. The above describes the scenario of updating the IP address of a target RDSH. In some embodiments, the IP update command can target multiple RDSHs. The cloud platform can then, similarly, request or release virtualized IP addresses from the VPC at the granularity of a single RDSH, following the same approach described above. This technical solution provides both proactive and passive update initiation for dynamically updating IP addresses for RDSHs from the perspective of each RDSH.This approach can cover scenarios such as product changes on the business side and availability maintenance on the service side, greatly improving the flexibility of RDSH-based deployments and the availability of network services. 1002. The cloud platform sends at least one IP address obtained after updating virtualization to the target RDSH. In some embodiments, a server-side DHCPD supporting Dynamic Host Configuration Protocol runs in the target RDSH. In some embodiments, a single-machine DHCPD in the target RDSH receives and saves at least one IP address obtained after updating virtualization, restarts DHCP protocol listening, and uses at least one IP address obtained after updating virtualization as a source of IP addresses that can be used for allocation, continuing to provide DHCP protocol support capabilities. In other embodiments, a single-machine DHCPD in the target RDSH can update the maintained IP address source online based on the IP address obtained after updating virtualization without restarting. For example, if DHCPD detects that a new IP address has been added to the updated virtualized IP address pool, it adds the new IP address to the maintained IP address source. If DHCPD detects that the updated virtualized IP address pool does not contain the maintained IP address pool, it deletes that IP address pool from the maintained IP address source. In some embodiments, DHCPD detects the usage of this IP address pool. If it detects that this IP address pool is unused from the lease table, it deletes it directly. If it detects that this IP address pool is in use from the lease table, it deletes it after the IP address pool is reclaimed. Through the above technical solution, a DHCPD is customized for each RDSH in a public cloud based on the DHCP protocol. DHCPD can dynamically allocate, reclaim, or reuse IP addresses in a single RDSH, supporting dynamic updates to the IP address source. Based on this, the utilization efficiency of IP addresses can be fully guaranteed. When providing network services based on RDSH, the scalability of public cloud services can be improved through dynamically allocable virtualized IP addresses. To facilitate understanding of the above update process, this application provides a flowchart of an IP address update process. Referring to Figure 12, an exemplary IP address update process includes the following steps 1-4: 1. The administrator logs into the public cloud console (management interface), selects the RDSH whose IP address needs to be updated, and submits the IP address update task. 2. Based on the user-submitted instructions, the cloud platform determines the existing virtualized IP addresses of the target RDSH and compares the quantities (refer to step 1001) to determine whether to request additional or released redundant virtualized IP addresses from the VPC management interface. 3. The cloud platform distributes one or more updated virtualized IP addresses to the standalone DHCPD installed within the RDSH.4. A single-machine DHCPD receives and saves the updated virtualized IP address, restarts the DHCP protocol listening, and uses the updated virtualized IP address as a source of IP addresses for allocation, continuing to provide DHCP protocol support capabilities. The IP address allocation method provided in this application can be applied to public cloud services. For public cloud remote desktop IP virtualization, when different clients access the RDSH in the cloud platform, the RDSH allocates different virtualized IP addresses to different sessions corresponding to different clients, allowing different clients to use different IP addresses to obtain network services. Therefore, when clients access sessions in the RDSH to use various network services provided by the cloud platform, the security, privacy, and scalability of the network services can be fully guaranteed. Furthermore, the above technical solution provides RDSH with active and passive update initiation methods for the IP address update function, covering scenarios such as product changes on the business side and availability maintenance on the service side, effectively improving the utilization efficiency of IP addresses and ensuring that the number of IP addresses supports the business needs of the product. Figure 13 is a schematic diagram of an address allocation system provided in an embodiment of this application. Referring to Figure 13, the address allocation system includes a cloud platform and an RDSH. The cloud platform is used to provide public cloud services. The cloud platform 1301 is used to receive a first creation request from a first client and forward the first creation request to a target RDSH 1302. The first creation request is used to request the establishment of a first session with the target RDSH 1302. The target RDSH 1302 is used to respond to the first creation request and allocate a corresponding first IP address to the first session. The first IP address is obtained by virtualizing the IP address of the target RDSH 1302. The target RDSH 1302 is used to return the first IP address to the cloud platform 1301. The cloud platform 1301 is used to return a first access response to the first client. The first access response indicates that the first client has established a first session with the target RDSH 1302 based on the first IP address. In one possible implementation, the cloud platform 1301 is further configured to: receive a second creation request from a second client and forward the second creation request to a target RDSH 1302, wherein the second creation request is used to request the establishment of a second session with the target RDSH 1302; the target RDSH 1302 is further configured to: in response to the second creation request, allocate a corresponding second IP address for the second session, wherein the second IP address is obtained by virtualizing the IP address of the target RDSH 1302; the target RDSH 1302 is further configured to: return the second IP address to the cloud platform 1301; and the cloud platform 1301 is further configured to: return a second access response to the second client, wherein the second access response indicates that the second client has established a second session with the target RDSH 1302 based on the second IP address.In one possible implementation, the cloud platform 1301 is further configured to provide a target function switch in a management interface, the target function switch being used to turn on and off the IP virtualization function for the target RDSH 1302, the IP virtualization function including enabling the RDSH to use multiple IP addresses obtained by virtualizing the IP address based on the RDSH. 11 WO 2024 / 198619 PCT / CN2024 / 071278 In one possible implementation, the cloud platform 1301 is further configured to, in response to obtaining first specification information for the target RDSH 1302 from the management interface of the cloud platform 1301, during the creation of the target RDSH 1302, obtain at least one IP address obtained by IP address virtualization of the target RDSH 1302 according to the first specification information, and send the at least one virtualized IP address to the target RDSH 1302. The first specification information indicates at least one of the following: the number of IP addresses used by the target RDSH 1302, and the number of sessions supported by the target RDSH 1302; The cloud platform 1301 is further configured to, in response to an IP update instruction, obtain at least one IP address obtained by virtualization of the target RDSH 1302 after the update according to the second specification information carried by the IP update instruction, and send the at least one virtualized IP address obtained after the update to the target RDSH 1302. The second specification information indicates at least one of the following: the updated target RDSH The number of IP addresses used by RDSH 1302, and the number of sessions supported by the target RDSH 1302 after the update. In one possible implementation, cloud platform 1301 is used to: compare the first number currently available to the target RDSH 1302 with the second number indicated by the second specification information; if the second number is less than the first number, determine the IP addresses released this time, and based on the IP addresses released this time, obtain at least one IP address obtained by virtualization based on the IP address of the updated RDSH; if the second number is greater than the first number, determine the IP address of the newly applied virtualization this time, and based on the IP address of the newly applied virtualization, obtain at least one IP address obtained by the updated virtualization. In one possible implementation, cloud platform 1301 is used to perform at least one of the following: in response to obtaining the second specification information for the target RDSH 1302 in the management interface of cloud platform 1301, cloud platform 1301 triggers an IP update instruction; in response to detecting that the usage of the target RDSH 1302 in cloud platform 1301 meets the update conditions, cloud platform 1301 triggers an IP update instruction. In one possible implementation, target RDSH 1302 is further configured to: release the first IP address assigned to the first session in response to a first client's logout request for the first session. In one possible implementation, target RDSH 1302 is further configured to:In response to a network service request initiated by a first client through a first session, the network service request is processed using a first IP address. Here, cloud platform 1301 and target RDSH 1302 are equivalent to functional modules deployed in the address allocation system, both of which can be implemented in software or hardware. For example, the implementation of cloud platform 1301 will be described below. Similarly, the implementation of target RDSH 1302 can refer to the implementation of cloud platform 1301. Through the above technical solution, remote desktop IP virtualization is implemented in public cloud services. When a client accesses the RDSH in the cloud platform, the RDSH can allocate IP addresses to the client based on multiple virtualized IP addresses. This allows different clients to obtain network services through the same RDSH using different IP addresses, ensuring the security, privacy, and scalability of the network service. Furthermore, the above technical solution provides RDSH with both active and passive update initiation methods for the IP address update function, covering scenarios such as product changes on the business side and availability maintenance on the service side, effectively improving IP address utilization efficiency and ensuring that the number of IP addresses supports the business needs of the product. As an example of a software functional unit, the cloud platform 1301 may include code running on computing instances. These computing instances may include at least one of physical hosts (computing devices), virtual machines, and containers. Furthermore, the aforementioned computing instances may be one or more. For example, the cloud platform 1301 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run this code can be distributed in the same region or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run this code can be distributed in the same availability zone (AZ) or in different AZs, each AZ including one or more geographically proximate data centers. Typically, a region may include multiple AZs. Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same Virtual Private Cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, and between VPCs in different regions, requires a communication gateway within each VPC to achieve interconnection between VPCs. As an example of a hardware functional unit, the cloud platform 1301 may include at least one computing device, such as a server. Alternatively,The cloud platform 1301 can also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD can be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. The multiple computing devices included in the cloud platform 1301 can be distributed in the same region or in different regions. Similarly, the multiple computing devices included in the cloud platform 1301 can be distributed in the same Availability Zone (AZ) or in different AZs. Likewise, the multiple computing devices included in the cloud platform 1301 can be distributed in the same Virtual Private Cloud (VPC) or in multiple VPCs. These multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs. It should be noted that in other embodiments, the cloud platform 1301 and the target RDSH 1302 can be used to execute any step in the IP address allocation method. The steps implemented by the cloud platform 1301 and the target RDSH 1302 can be specified as needed. By implementing different steps in the IP address allocation method through the cloud platform 1301 and the target RDSH 1302, all functions of the address allocation system can be realized. That is, when implementing the corresponding steps, the address allocation system provided in the above embodiments is only illustrated by the division of the above functional modules. In actual applications, the above functions can be allocated by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. In addition, the address allocation system provided in the above embodiments and the IP address allocation method embodiments belong to the same concept. For details of its specific implementation process, please refer to the method embodiments, which will not be repeated here. The hardware structure of the computing device involved in the embodiments of this application will be described below. The embodiments of this application provide a computing device cluster, which includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device may also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.This application provides a computing device that can be configured as a computing device included in the aforementioned computing device cluster. Schematically, referring to FIG14, FIG14 is a schematic diagram of the component structure of a computing device provided in this application embodiment. As shown in FIG14, the computing device 1400 includes a memory 1401, a processor 1402, a communication interface 1403, and a bus 1404. The memory 1401, processor 1402, and communication interface 1403 are interconnected via the bus 1404. Memory 1401 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. Processor 1402 implements the methods in the above or below embodiments by reading the program code stored in memory 1401, or processor 1402 implements the IP address allocation methods in the above or below embodiments by internally stored program code. When the processor 1402 implements the IP address allocation method in the above or below embodiments by reading the program code stored in the memory 1401, the memory 1401 stores program code for implementing the IP address allocation method provided in the embodiments of this application. The processor 1402 may be a network processor (NP), a central processing unit (CPU), an application-specific integrated circuit (ASIC), or an integrated circuit for controlling the execution of the program in this application. The processor 1402 may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The number of processors 1402 may be one or more. The communication interface 1403 uses a transceiver module, such as a transceiver, to implement...The computing device 1400 communicates with other devices or communication networks. For example, it can receive requests sent by clients through the communication interface 1403. The memory 1401 and processor 1402 can be separate or integrated. The bus 1404 can include a path for transmitting information between various components of the computing device 1400 (e.g., memory 1401, processor 1402, communication interface 1403). The memories of one or more computing devices in the computing device cluster may store the same instructions for executing the IP address allocation method provided in this application. In some possible implementations, the memories of one or more computing devices in the computing device cluster may also each store partial instructions for executing the IP address allocation method provided in this application. In other words, a combination of one or more computing devices can jointly execute the instructions for executing the IP address allocation method provided in this application. In some possible implementations, one or more computing devices in the computing device cluster can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc. Figure 15 is a schematic diagram of a computing device cluster provided in an embodiment of this application. Referring to Figure 15, one or more computing devices 1400 in the computing device cluster are connected via a network. The description of the computing device 1400 is given above and will not be repeated here. It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in this application are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the IP address, user credentials, and other information involved in this application are obtained under fully authorized conditions. The terms "first," "second," etc., in this application are used to distinguish identical or similar items with essentially the same function. It should be understood that there is no logical or temporal dependency between "first," "second," and "nth," nor is there a limitation on the quantity or execution order. It should also be understood that although the following description uses the terms first, second, etc., to describe various elements, these elements should not be limited by the terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the various examples described, a first IP address may be referred to as a second IP address, and similarly, a second IP address may be referred to as a first IP address. Both the first IP address and the second IP address can be IP addresses, and in some cases, they can be separate and different IP addresses. The term "at least one" in this application means one or more, and the term "multiple" in this application means two or more.For example, multiple IP addresses refer to two or more IP addresses. The above description is merely a specific implementation of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims. In the above embodiments, all or part of the implementation can be achieved through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in the form of a program product, all or part of which includes one or more program instructions. When the program instructions are loaded and executed on a computing device, all or part of the flow or function according to the embodiments of this application is generated. Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware, or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk. The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application. 14 WO 2024 / 198619 PCT / CN2024 / 071278 Claim 1 A method for allocating network protocol IP addresses, characterized in that the method is applied to an address allocation system, the address allocation system including a cloud platform and a Remote Desktop Session Host (RDSH), the cloud platform being used to provide public cloud services, the method comprising: the cloud platform receiving a first creation request from a first client and forwarding the first creation request to a target RDSH, the first creation request being used to request the establishment of a first session with the target RDSH; in response to the first creation request, the target RDSH allocating a corresponding first IP address for the first session, the first IP address being obtained by virtualizing the IP address of the target RDSH; the target RDSH returning the first IP address to the cloud platform; the cloud platform returning a first access response to the first client, the first access response indicating that the first client has established the first session with the target RDSH based on the first IP address. 2. The method according to claim 1, characterized in that the method further comprises: the cloud platform receiving a second creation request from a second client and forwarding the second creation request to the target RDSH, the...The second creation request is used to request the establishment of a second session with the target RDSH; in response to the second creation request, the target RDSH allocates a corresponding second IP address for the second session, the second IP address being obtained by IP address virtualization of the target RDSH; the target RDSH returns the second IP address to the cloud platform; the cloud platform returns a second access response to the second client, the second access response indicating that the second client has established the second session with the target RDSH based on the second IP address. 3. The method according to claim 1 or 2, characterized in that the method further includes: the cloud platform provides a target function switch in the management interface, the target function switch being used to turn on and off the IP virtualization function for the target RDSH, the IP virtualization function including: enabling the RDSH to use multiple IP addresses obtained based on the IP address virtualization of the RDSH. 4. The method according to any one of claims 1-3, characterized in that the method further comprises: in response to obtaining first specification information for the target RDSH in the management interface of the cloud platform, the cloud platform, during the creation of the target RDSH, obtains at least one IP address obtained by IP address virtualization of the target RDSH according to the first specification information, and sends the at least one virtualized IP address to the target RDSH, wherein the first specification information indicates at least one of the following: the number of IP addresses used by the target RDSH, and the number of sessions supported by the target RDSH; in response to an IP update instruction, the cloud platform, according to second specification information carried by the IP update instruction, obtains at least one updated IP address obtained by virtualization of the target RDSH, and sends the at least one updated virtualized IP address to the target RDSH, wherein the second specification information indicates at least one of the following: the number of IP addresses used by the target RDSH after the update, and the number of sessions supported by the target RDSH after the update. 5. The method according to claim 4, characterized in that, the cloud platform obtains the updated IP address of the target RDSH according to the second specification information carried by the IP update instruction, including: comparing the first number currently available to the target RDSH with the second number indicated by the second specification information; if the second number is less than the first number, determining the IP address to be released this time, and obtaining at least one IP address obtained by the updated virtualization based on the IP address released this time; if the second number is greater than the first number, determining the IP address of the newly applied virtualization this time, and obtaining at least one IP address obtained by the updated virtualization based on the IP address of the newly applied virtualization. 67. The method according to any one of claims 4 or 5, characterized in that the method further comprises at least one of the following: In response to obtaining second specification information for the target RDSH in the management interface of the cloud platform, the cloud platform triggers the IP update instruction; In response to detecting that the usage of the target RDSH in the cloud platform meets the update conditions, the cloud platform triggers the IP update instruction. 8. The method according to any one of claims 1-6, characterized in that the method further comprises: In response to a logout request from the first client for the first session, the target RDSH releases the first IP address allocated to the first session. 9. The method according to any one of claims 1-7, characterized in that the method further comprises: In response to a network service request initiated by the first client through the first session, the target RDSH uses the first IP address to process the network service request. 9. An address allocation system, characterized in that the address allocation system includes a cloud platform and a Remote Desktop Session Host (RDSH), the cloud platform being used to provide public cloud services; the cloud platform being used to receive a first creation request from a first client and forward the first creation request to a target RDSH, the first creation request being used to request the establishment of a first session with the target RDSH; the target RDSH being used to, in response to the first creation request, allocate a corresponding first IP address to the first session, the first IP address being obtained by virtualizing the IP address of the target RDSH; the target RDSH being used to return the first IP address to the cloud platform; the cloud platform being used to, return a first access response to the first client, the first access response indicating that the first client has established the first session with the target RDSH based on the first IP address. 10. The system according to claim 9, wherein the cloud platform is further configured to: receive a second creation request from a second client and forward the second creation request to the target RDSH, the second creation request being used to request the establishment of a second session with the target RDSH; the target RDSH is further configured to: in response to the second creation request, allocate a corresponding second IP address to the second session, the second IP address being obtained by virtualizing the IP address of the target RDSH; the target RDSH is further configured to: return the second IP address to the cloud platform; the cloud platform is further configured to: return a second access response to the second client, the second access response indicating that the second client has established the second session with the target RDSH based on the second IP address. II. The system according to claim 9 or 10, wherein the cloud platform is further configured to: provide target functionality in the management interface.A switch, the target function switch being used to turn on and off the IP virtualization function for the target RDSH, the IP virtualization function including: enabling the RDSH to use multiple IP addresses obtained based on the IP address virtualization of the RDSH. 12. The system according to any one of claims 9-11, characterized in that, the cloud platform is further configured to, in response to obtaining first specification information for the target RDSH in the management interface of the cloud platform, during the creation of the target RDSH, obtain at least one IP address obtained by IP address virtualization of the target RDSH according to the first specification information, and send the at least one virtualized IP address to the target RDSH, wherein the first specification information indicates at least one of the following: the number of IP addresses used by the target RDSH, the number of sessions supported by the target RDSH; the cloud platform is further configured to, in response to an IP update instruction, obtain at least one updated IP address obtained by virtualization of the target RDSH according to second specification information carried by the IP update instruction, and send the updated virtualized at least one IP address to the target RDSH, wherein the second specification information indicates at least one of the following: the number of IP addresses used by the target RDSH after the update, the number of sessions supported by the target RDSH after the update. 13. The system according to claim 12, wherein the cloud platform obtains the updated IP address of the target RDSH according to the second specification information carried by the IP update instruction, comprising: comparing a first number of currently usable targets RDSH with a second number indicated by the second specification information; if the second number is less than the first number, determining the IP address to be released this time, and obtaining at least one IP address obtained by the updated virtualization based on the IP address to be released this time; if the second number is greater than the first number, determining the IP address of the newly applied virtualization this time, and obtaining at least one IP address obtained by the updated virtualization based on the IP address of the newly applied virtualization this time. 14. The system according to claim 12 or 13, wherein the cloud platform is further configured to perform at least one of the following: triggering the IP update instruction in response to obtaining the second specification information for the target RDSH in the management interface of the cloud platform; triggering the IP update instruction in response to detecting that the usage of the target RDSH in the cloud platform meets the update conditions. 15. The system according to any one of claims 9-14, wherein the target RDSH is further configured to: in response to a logout request from the first client for the first session, release the first IP address allocated to the first session. 16.17. A computing device cluster comprising at least one computing device, each computing device including a processor and a memory; the processor of the at least one computing device being configured to execute instructions stored in the memory of the at least one computing device to cause the computing device cluster to perform an IP address allocation method as described in any one of claims 1 to 8. 18. A computer-readable storage medium comprising computer program instructions, wherein when the computer program instructions are executed by the computing device cluster, the computing device cluster performs an IP address allocation method as described in any one of claims 1 to 8. 19. A computer program product comprising instructions, wherein when the instructions are executed by the computing device cluster, the computing device cluster performs an IP address allocation method as described in any one of claims 1 to 8. 17 WO 2024 / 198619 PCT / CN2024 / 071278 DHCP - Dynamic Host Configuration Protocol DH CPD - Dynamic Host Configuration Protocol Server RDSH - Remote Desktop Session Host RDS - Remote Desktop Session RDP - Remote Desktop Protocol Figure 1 Address Allocation System 220 Figure 2 WO 2024 / 198619 PCT / CN2024 / 071278 2 / 9 <Create Server Group Name Area Description Mirror Please enter name Applications in different areas are not interconnected on the intranet 9 Area A - 2010 Applications need to be managed by area, it is recommended to create applications in the same area 0 / 255 Public Mirror Private Mirror 0 Mirror with DHCPD software Mirror A (80GB Mirror is provided by a third party, if you use this service you need to comply with the terms of service 《XXX》 I................ I IP Virtualization Enable · 4................................................ Scaling Strategy (·Disable) II Enabling IP virtualization will assign different IP virtualization to each session I② < The number of virtual IPs pre-assigned by the server is consistent with the maximum number of sessions in the package. Target function switch (IP virtualization function is enabled). Figure 3 Network Service III. Figure 4 WO 2024 / 198619 PCT / CN2024 / 071278 3 / 9 Address allocation system issues IP address when creating RDSH. DHCPD - Dynamic Host Configuration Protocol server.RDSH-Remote Desktop Session Host IP-Internet Protocol VPC-Virtual Private Cloud ECS-Elastic Cloud Server Figure 6 WO 2024 / 198619 PCT / CN2024 / 071278 4 / 9 Assign IP address when client accesses RDSH DHCPD-Dynamic Host Configuration Protocol Server RDSH-Remote Desktop Session Host IP-Internet Protocol RDP-Remote Desktop Protocol Figure 7 WO 2024 / 198619 PCT / CN2024 / 071278 / 9 5 / T ■ Τ λ I 二 I J 困 A B D 依 公 国 Figure 8 WO 2024 / 198619 PCT / CN2024 / 071278 6 / 9 Recycle IP address when client logs out of RDSH RDSH-Remote Desktop Session Host IP-Internet Protocol RDP-Remote Desktop Protocol Figure 9 Address Allocation System Figure 10 WO 2024 / 198619 PCT / CN2024 / 071278 / 9 w 共 卡 圣 祭 唱d i 始 龚 0 般 也 。 我 带 。 想 航 -40 出 世 ^ S 3 醉 东 震 0 1 7 z s $ I 回 君 概 旱 c . o ^ E I X . I E J D U O &o. L U E O - n s d d e o O E d s d J O A V d s x m o s - s f k D b 鎏 累 唱< Q 懈 盘 距 ν 赵 建X 想 蛤 卷 黑 赵 黎 / 然 距S ( 3 / S d -M) 7 据 粼 壮 余* 略 c v w 思 静 出 蹙 皋Z ΐ $ 定 至 巴 想 生 款 晚 晨 联 解 / 她 家 * 笠 战4 . 8 6 6 . 8 二 0 E Z Z . I Bds± JOA98x ο -̂.0.0.0- 恕 抵p m c 8 石nd 。 寸 I>s,sdv di* 馈 褊 似 蜜 点 龈 牺 飞 黑 过 展 餐 黑 S 钞W 其 恻 厘 水 14 米 * Ν 良 秣Ξ 9 浮 Mldosv^ 秣a Figure 11 WO 2024 / 198619 PCT / CN2024 / 071278 8 / 9 Update IP address when RDSH is running DHCPD-Dynamic Host Configuration Protocol Server RDSH-Remote Desktop Session Host IP-Internet Protocol VPC-Virtual Private Cloud ECS-Elastic Cloud Server Figure 12 Address Allocation System Figure 13 WO 2024 / 198619 PCT / CN2024 / 071278 9 / 9 1402 1403 1401 Figure 14 Figure 15INTERNATIONAL SEARCH REPORT International application No. PCT / CN2024 / 071278 A. CLASSIFICATION OF SUBJECT MATTER H04L 61 / 5007(2022.01)1 According to International Patent Classification (IPC) or to both national classification and IPC B. FIELDS SEARCHED Minimum documentation searched (classification system followed by classification symbols) IPC: H04L Documentation searched other than minimum documentation to the extent that such documents are included in the fields searched Electronic data base consulted during the international search (name of data base and, where practicable, search terms used) CNTXT; ENTXT; ENTXTC; VEN; DWPI; CNKI; IEEE: virtual, remote, desktop, session, host, establish, create, connect, request, allocate, IP address, cloud C. DOCUMENTS CONSIDERED TO BE RELEVANT Category* Citation of document, with indication, where appropriate, of the relevant passages Relevant to claim No. A US 2022353335 A1 (MICROSOFT TECHNOLOGY LICENSING, L.L.C.) 03November 2022 (2022-11-03) description, paragraphs
[0026] -
[0134] , and figures 1-5 1-19 A CN 102820999 A (CHINA TELCOME CO., LTD.) 12 December 2012 (2012-12-12) entire document 1-19 A CN 103618752 A (GUANGDONG ZHONGKE REMOTE SENSING TECHNOLOGY CO., LTD.) 05 March 2014 (2014-03-05) entire document 1-19 A CN 113032805 A (CCB FINTECH CO., LTD.) 25 June 2021 (2021-06-25) entire document 1-19 A US 2020053162 Al (DELL PRODUCTS L.P.) 13 February 2020 (2020-02-13) entire document 1-19 | | Further documents are listed in the continuation of Box C. | / 1 See patent family annex. * Special categories of cited documents: “T" later document published after the international filing date or priority “A" document defining the general state of the art which is not considered date and not in conflict with the application but cited to understand the to be of paiticulai' relevance principle or theory underlying the invention "D” document cited by the applicant in the international application “χ” documentof particular relevance; the claimed invention cannot be “E” eailier application or patent but published on or after the international considered novel or cannot be considered to involve an inventive step filing date when the document is taken alone “L" document which may thi'ow doubts on priority claim(s) or which is “Y" document of paiticulai' relevance; the claimed invention cannot be cited to establish the publication date of another citation or other considered to involve an inventive step when the document is special reason (as specified) combined with one or more other such documents, such combination "O” document refen'ing to an oral disclosure, use, exhibition or other being obvious to a person skilled in the art means document member of the same patent family "P” document published prior to the international filing date but later than the priority date claimed Date of the actual completion of the international search 17 April 2024 Date of mailing of the international searchreport 23 April 2024 Name and mailing address of the ISA / CN China National Intellectual Property Administration (ISA / CN) China No. 6, Xitucheng Road, Jimenqiao, Haidian District, Beijing 100088 Authorized officer Telephone No. Form PCT / ISA / 210 (second sheet) (July 2022) INTERNATIONAL SEARCH REPORT Information on patent family members International application No. PCT / CN2024 / 071278 Patent document cited in search report Publication date (day / month / year) Patent family member(s) Publication date (day / month / year) US 2022353335 Al 03 November 2022 WO 2022231779 Al 03 November 2022 CN 102820999 A 12 December 2012 TW 201346623 A 16 November 2013 US 2013304880 A1 14 November 2013 CN 103618752 A 05 March 2014 None CN 113032805 A 25 June 2021 None US 2020053162 A1 13 February 2020 None Form PCT / ISA / 210 (patent family annex) (July 2022) PCT / CN2024 / 071278 International Search Report International Application No. A. Subject Classification H04L 61 / 5007 (2022.01) 1 According to the International Patent Classification (IPC) or both national classification and IPC classification B. Search Field Minimum Documents Searched (indicate classification system and classification number) IPC: H04L Search documents included in the search field other than the minimum documentsElectronic databases consulted during international searches (database names and search terms used, such as those used) CNTXrENT in rENTXTCVENQWPLCNKIUEEE:virtual, remote, desktop, session, host, establish, create, connect, request, allocate, IP address, cloud C. Related document types * Referenced documents, indicating relevant paragraphs where necessary Related claims A US 2022353335 A1 (MICROSOFT TECHNOLOGY LICENSING, LLC) November 3, 2022 (2022-11-03) Specification paragraphs
[0026] -
[0134] , Figures 1-5 1-19 A CN 102820999 A (Chunghwa Telecom Corporation Limited) December 12, 2012 (2012-12-12) Full text 1-19 A CN 103618752 A (Guangdong Zhongke Remote Sensing Technology Co., Ltd.) March 5, 2014 (2014-03-05) Full text 1-19 A CN 113032805 A (CCB Financial Technology Co., Ltd.) June 25, 2021 (2021-06-25) Full text 1-19 A US 2020053162 A1 (DELL PRODUCTS LP) February 13, 2020 (2020-02-13) Full text 1-19 □The remaining documents are listed on the continuation page in column C. *Specific types of cited documents: "A" Documents deemed not particularly relevant that describe the general state of the prior art. "D" Documents cited by the applicant in an international application. "E" Prior applications or patents published on or after the international application date. "L" Documents that may cast doubt on the priority claim, or documents cited to determine the publication date of another cited document, or documents cited for other specific reasons (as specifically stated). Documents involving disclosure, use, exhibition, or other forms of disclosure. "P" Documents published before the international application date but later than the claimed priority date (see appendices to the patent family). "T" Later documents published after the application date or priority date, not contradicting the application, but for understanding the inventive theory or principle. "X" Documents that are particularly different; considering only that document, the claimed invention is deemed not novel or lacking inventiveness. "Y" Documents that are particularly relevant, and when that document is not contiguous with one or more of these documents and such contiguousness is obviously inappropriate to those skilled in the art, the claimed invention is deemed not novel.International Search for Non-Inventive Patent Family Documents: Date of Completion: April 17, 2024; Name and Mailing Address of ISA / CN: China National Intellectual Property Administration, No. 6, Tucheng Road, Xijimenqiao, Haidian District, Beijing 100088, China; Mailing Date of International Search Report: April 23, 2024; Authorized Officer: Zhang Qian; Telephone: (+86) 010-53961574; PCT / ISA / 210 Form (Page 2) (July 2022); International Search Report Information on Patent Family: International Application Number: PCT / CN2024 / 071278; Publication Dates of Patent Documents Cited in the Search Report (Year / Month / Day); Publication Dates of Patent Family (Year / Month / Day): US 2022353335 A1 November 3, 2022; WO 2022231779 A1 November 3, 2022; CN 102820999 A December 12, 2012 TW 201346623 A November 16, 2013 US 2013304880 Al November 14, 2013 CN 103618752 A March 5, 2014 None CN 113032805 A June 25, 2021 None US 2020053162 Al February 13, 2020 None PCT / ISA / 210 Form (Appendix to Patent Family) (July 2022) (19) *EP004683300A1* (11) EP 4 683 300 A1 (12) EUROPEAN PATENT APPLICATION published in accordance with Art. 153(4) EPC (43) Date of publication: 21.01.2026 Bulletin 2026 / 04 (21) Application number: 24777415.1 (22) Date of filing: 09.01.2024 (51) International Patent Classification (IPC): H04L 61 / 5007 (2022.01) (52) Cooperative Patent Classification (CPC): H04L 61 / 5007; H04L 61 / 5014; H04L 67 / 08; H04L 67 / 141 (86) International application number: PCT / CN2024 / 071278 (87) Internationalpublication number: WO 2024 / 198619 (03.10.2024 Gazette 2024 / 40) (84) Designated Contracting States: AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR Designated Extension States: BA Designated Validation States: KH MA MD TN (30) Priority: 29.03.2023 CN 202310323110 (71) Applicant: Huawei Cloud Computing Technologies Co., Ltd. Guiyang, Guizhou 550025 (CN) (72) Inventors: • LIN, Lingqing Guiyang, Guizhou 550025 (CN) • SONG, Deqiang Guiyang, Guizhou 550025 (CN) • YAN, Hongwei Guiyang, Guizhou 550025 (CN) (74) Representative: Körber, Martin Hans et al Mitscherlich PartmbB Patent‑ und Rechtsanwälte Karlstraße 7 80333 München (DE) (54) INTERNET PROTOCOL (IP) ADDRESS ASSIGNMENT METHOD AND ADDRESS ASSIGNMENT SYSTEM (57) This application discloses an internet protocol IP address assignment method and an address assignment system, and belongs to the field of network technologies. The method provided in this application is appliedto the address assignment system. A cloud platform in the address assignment system can forward, to a target RDSH in the system, a first creation request sent by a first client; the target RDSH assigns, to a first session corresponding to the first client, a first IP address ob- tained through virtualization based on an IP address of the target RDSH; the RDSH returns the first IP address to the cloud platform; and the cloud platform returns a first access response to the first client. Based on this, an IP virtualization function is implemented in a public cloud service, and the RDSH can assign, to clients, a plurality of IP addresses obtained through virtualization, so that different clients obtain network services based on differ- ent IP addresses when accessing a same RDSH, thereby ensuring security, privacy, and scalability of the network services. EP 4 68 3 30 0 A 1 Processed by Luminess, 75001 PARIS (FR) 2 1 EP 4 683 300 A1 2 Description
[0001] This application claims priority toChinese Pa- tent Application No. 202310323110.0, filed with the Chi- na National Intellectual Property Administration on March 29, 2023 and entitled "INTERNET PROTOCOL IP AD- DRESS ASSIGNMENT METHOD AND ADDRESS AS- SIGNMENT SYSTEM", which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0002] This application relates to the field of network technologies, and in particular, to an IP address assign- ment method and an address assignment system. BACKGROUND
[0003] Remote desktop protocol (remote desktop pro- tocol, RDP) is a protocol that allows users to use, via a local device, terminal services provided by a remote device. The users accesses a remote desktop session host (remote desktop session host, RDSH) running on the remote device through the RDP, and the RDSH creates a remote desktop session (remote desktop ses- sion, RDS) for the users, so that the users can run applications, save files, access other networks, and the like on the RDSH through the RDS. Todistinguish between different remote desktop sessions (RDS), re- lated technologies adopt dynamic host configuration pro- tocol (dynamic host configuration protocol, DHCP) to assign different internet protocol (internet protocol, IP) addresses to different RDSs. When a user accesses the RDSH, the RDSH creates a corresponding RDS and applies for an IP address from a DHCP server (DHCP Daemon, DHCPD). This technology is also known as a remote desktop IP virtualization (remote desktop IP vir- tualization) function.
[0004] However, the foregoing solution can be applied only to a network supporting DHCP, for example, a local area network or some networks on a private cloud, and cannot function on network platforms in a public cloud (Public Cloud) mode. This is because, a public cloud platform, to ensure security of network services, uni- formly manages resources such as IP addresses by using a virtual private cloud (virtual private cloud, VPC) deployed on a public cloud. As a result, aserver in a current DHCP architecture does not have permission to apply for and maintain IP addresses, making remote desktop IP virtualization unachievable. The inability to implement remote desktop IP virtualization on the public cloud means that security, privacy, and scalability of the services cannot be ensured when users use various public cloud services. Therefore, there is an urgent need for a method for implementing remote desktop IP virtua- lization in the public cloud mode is urgent. SUMMARY
[0005] This application provides an IP address assign- ment method, an address assignment system, a comput- ing device cluster, and a storage medium, to implement remote desktop IP virtualization in a public cloud mode, and ensure security, privacy, and scalability of a public cloud service. The technical solutions are as follows: According to a first aspect, an IP address assignment method is provided. The method is applied to an address assignment system, the address assignment systemincludes a cloud platform and a remote desktop session host RDSH, and the cloud platform is configured to provide a public cloud service. The method includes: The cloud platform receives a first creation request sent by a first client, and forwards the first creation request to a target RDSH, where the first creation request is used to request to establish a first session with the target RDSH; in response to the first creation request, the target RDSH assigns a corresponding first IP address to the first session, where the first IP address is ob- tained through virtualization of an IP address of the target RDSH; the target RDSH returns the first IP address to the cloud platform; and the cloud platform returns a first access response to the first client, where the first access response in- dicates that the first client has established the first session with the target RDSH based on the first IP address.
[0006] The IP address assignment method provided in this application can be appliedto a public cloud service, and implements remote desktop IP virtualization in the public cloud service, so that when a client accesses the RDSH on the cloud platform, the RDSH can assign an IP address to the client 7based on a plurality of IP addresses obtained through virtualization. In this way, different cli- ents can use different IP addresses to obtain network services through a same RDSH, thereby ensuring secur- ity, privacy, and scalability of the network services.
[0007] In a possible implementation, the method further includes: The cloud platform receives a second creation request sent by a second client, and forwards the second creation request to the target RDSH, where the second creation request is used to request to establish a second session with the target RDSH; in response to the second creation request, the target RDSH assigns a corresponding second IP address to the second session, where the second IP address is obtained through virtualization of an IP address of thetarget RDSH; the target RDSH returns the second IP address to the cloud platform; and the cloud platform returns a second access response 5 10 15 20 25 30 35 40 45 50 55 3 3 EP 4 683 300 A1 4 to the second client, where the second access re- sponse indicates that the second client has estab- lished the second session with the target RDSH based on the second IP address.
[0008] According to the IP address assignment meth- od provided in this application, for different clients using a same RDSH, the RDSH may assign, to different sessions corresponding to different clients, different IP addresses obtained through virtualization, so that different clients can use different IP addresses to obtain a network ser- vice. Therefore, when different clients obtain the network service using the same RDSH, different IP addresses may be presented, to ensure security, privacy, and scal- ability of obtaining the network service by different clients in the same RDSH.
[0009] In a possible implementation,the method further includes: The cloud platform provides a target function switch on a management interface, where the target function switch is used to enable and disable an IP virtualization function for the target RDSH, and the IP virtualization function includes: enabling the RDSH to use a plurality of IP addresses obtained through virtualization based on IP addresses of the RDSH.
[0010] According to the foregoing technical solution, the switch of the IP virtualization function is provided for a user on a front-end interface, so that the user can con- figure the IP virtualization function in a process of creating an RDSH based on a service requirement.
[0011] In a possible implementation, the method further includes: In response to obtaining first specification information for the target RDSH from the management interface of the cloud platform, in a process of creating the target RDSH, the cloud platform obtains, based on the first specification information, at least one IP addressobtained through virtualization of an IP address of the target RDSH, and sends, to the target RDSH, the at least one IP address obtained through virtualization, where the first specifica- tion information indicates at least one of the following: a quantity of IP addresses used by the target RDSH and a quantity of sessions supported by the target RDSH; and in response to an IP update instruction, the cloud platform obtains, based on second specification information car- ried in the IP update instruction, an updated version of at least one IP address obtained through virtualization based on an IP address of the target RDSH, and sends, to the target RDSH, the updated IP address, where the second specification information indicates at least one of the following: a quantity of updated IP addresses used by the target RDSH and a quantity of updated sessions supported by the target RDSH.
[0012] Based on this, the cloud platform can release a redundant IP address in a timely manner, and supple-ment an available IP address for the RDSH in a timely manner, thereby improving real-time performance of IP resource management.
[0013] In a possible implementation, that the cloud platform obtains, based on the second specification in- formation carried in the IP update instruction, the updated IP address of the target RDSH includes: comparing a first quantity currently available for the target RDSH with a second quantity indicated by the second specification information; and when the second quantity is less than the first quan- tity, determining an IP address released this time, and obtaining, based on the IP address released this time, the updated version of the at least one IP address obtained through virtualization; or when the second quantity is greater than the first quantity, determining a virtualized IP address that is newly applied for this time, and obtaining, based on the virtualized IP address that is newly applied for this time, the updated version of the at least one IPaddress obtained through virtualization.
[0014] According to the foregoing solution, on the man- agement interface provided by the cloud platform, the user may configure a quantity of sessions when creating the RDSH. This effectively integrates the IP virtualization function into an actual service scenario.
[0015] In a possible implementation, the method further includes at least one of the following: The cloud platform triggers the IP update instruction in response to obtaining the second specification informa- tion for the target RDSH from the management interface of the cloud platform; and the cloud platform triggers the IP update instruction in response to detecting that usage of the target RDSH on the cloud platform meets an update condition.
[0016] In the foregoing technical solution, an IP ad- dress source is dynamically updated for each RDSH, and an active update initiation manner and a passive update initiation manner are provided, so that scenarios such as a product change ona business side and availability maintenance on a service side can be covered, and RDSH-based deployment flexibility and network service availability are greatly improved.
[0017] In a possible implementation, the method further includes: In response to a deregistration request of the first client for the first session, the target RDSH releases the first IP address assigned to the first session.
[0018] In a possible implementation, the method further includes: In response to a network service request initiated by the first client through the first session, the target RDSH processes the network service request based on the first IP address.
[0019] Based on this, in this application, session-level IP address isolation can be implemented, network re- quests of different users can be effectively distinguished, and privacy of using network services by different users can be ensured. 5 10 15 20 25 30 35 40 45 50 55 4 5 EP 4 683 300 A1 6
[0020] The cloud platform can maintain an IP addresssource assigned to each RDS, so that each RDSH can assign, reclaim, and reuse IP addresses. When pro- grams in different sessions in a same RDSH listen to a network interface card port of the RDSH host, unique virtualized IP addresses are assigned to different ses- sions to effectively avoid port listening conflicts caused by only one available IP address of the network interface card. In conclusion, the technical solutions of this appli- cation can effectively improve IP address assignment efficiency, and greatly improve scalability of providing a network service based on the RDSH.
[0021] According to a second aspect, an address as- signment system is provided. The address assignment system includes a cloud platform and a remote desktop session host RDSH. The cloud platform is configured to provide a public cloud service. The cloud platform is configured to: receive a first creation request sent by a first client, and forward the first creation request to a target RDSH, where thefirst creation request is used to request to establish a first session with the target RDSH.
[0022] The target RDSH is configured to assign a corresponding first IP address to the first session in response to the first creation request, where the first IP address is obtained through virtualization of an IP ad- dress of the target RDSH.
[0023] The target RDSH is configured to return the first IP address to the cloud platform.
[0024] The cloud platform is configured to return a first access response to the first client, where the first access response indicates that the first client has established the first session with the target RDSH based on the first IP address.
[0025] In a possible implementation, the cloud platform is further configured to: receive a second creation re- quest sent by the second client, and forward the second creation request to the target RDSH, where the second creation request is used to request to establish the sec- ond session with the target RDSH.
[0026] Thetarget RDSH is further configured to assign a corresponding second IP address to the second ses- sion in response to the second creation request, where the second IP address is obtained through virtualization of an IP address of the target RDSH.
[0027] The target RDSH is further configured to return the second IP address to the cloud platform.
[0028] The cloud platform is further configured to re- turn a second access response to the second client, where the second access response indicates that the second client has established the second session with the target RDSH based on the second IP address.
[0029] In a possible implementation, the cloud platform is further configured to provide a target function switch on a management interface, where the target function switch is used to enable and disable an IP virtualization function for the target RDSH, and the IP virtualization function includes: enabling the RDSH to use a plurality of IP addresses obtained through virtualization based onIP addresses of the RDSH.
[0030] In a possible implementation, the cloud platform is further configured to: in response to obtaining first specification information for the target RDSH from the management interface of the cloud platform, in a process of creating the target RDSH, obtain an IP address of the target RDSH based on the first specification information, and send the IP address to the target RDSH, where the first specification information indicates at least one of the following: a quantity of IP addresses of the target RDSH and a quantity of sessions supported by the target RDSH.
[0031] The cloud platform is further configured to: in response to an IP update instruction, obtain, based on second specification information carried in the IP update instruction, an updated IP address of the target RDSH, and send, to the target RDSH, the updated IP address, where the second specification information indicates at least one of the following: a quantity of updated IP ad- dresses usedby the target RDSH, and a quantity of updated sessions supported by the target RDSH.
[0032] In a possible implementation, the cloud platform is configured to: compare a first quantity currently available for the target RDSH with a second quantity indicated by the second specification information; and when the second quantity is less than the first quan- tity, determine an IP address released this time, and obtain the updated IP address based on the IP ad- dress released this time; or when the second quantity is greater than the first quantity, determine a virtualized IP address that is newly applied for this time, and obtain the updated IP address based on the virtualized IP address that is newly applied for this time.
[0033] In a possible implementation, the cloud platform is configured to perform at least one of the following:
[0034] The cloud platform triggers the IP update in- struction in response to obtaining the second specifica- tion information for the target RDSH from themanage- ment interface of the cloud platform; and the cloud platform triggers the IP update instruction in response to detecting that usage of the target RDSH on the cloud platform meets an update condition.
[0035] In a possible implementation, the target RDSH is further configured to: in response to a deregistration request of the first client for the first session, release the first IP address assigned to the first session.
[0036] In a possible implementation, the target RDSH is further configured to: in response to a network service request initiated by the first client through the first session, process the network service request based on the first IP address.
[0037] According to a third aspect, a computing device cluster is provided, including at least one computing 5 10 15 20 25 30 35 40 45 50 55 5 7 EP 4 683 300 A1 8 device. Each computing device includes a processor and a memory. A processor of the at least one computing device is configured to execute instructions stored in amemory of the at least one computing device, to cause the computing device cluster to perform the IP address assignment method provided in the first aspect.
[0038] According to a fourth aspect, a computer-read- able storage medium is provided, including computer program instructions. When the computer program in- structions are executed by a computing device cluster, the computing device cluster performs the IP address assignment method provided in the first aspect.
[0039] According to a fifth aspect, a computer program product including instructions is provided. When the in- structions included in the computer program product are run by a computing device cluster, the computing device cluster is caused to perform the IP address assignment method provided in the first aspect. BRIEF DESCRIPTION OF DRAWINGS
[0040] FIG. 1 is a diagram of assigning an IP address to a remote desktop session based on a DHCP protocol in a related technology according to an embodiment of this application; FIG.2 is a diagram of an implementation environ- ment according to an embodiment of this application; FIG. 3 is a diagram of a management interface according to an embodiment of this application; FIG. 4 is a diagram of initialization setting of a cloud platform according to an embodiment of this applica- tion; FIG. 5 is a diagram of a principle of creating an RDSH according to an embodiment of this application; FIG. 6 is a schematic flowchart of delivering an IP address when an RDSH is created according to an embodiment of this application; FIG. 7 is a diagram of an IP address assignment method according to an embodiment of this applica- tion; FIG. 8 is a diagram of using a network service by a client according to an embodiment of this applica- tion; FIG. 9 is a schematic flowchart of session deregis- tration according to an embodiment of this applica- tion; FIG. 10 is a diagram of updating an IP address according to an embodiment of this application; FIG. 11 is a diagram of anothermanagement inter- face according to an embodiment of this application; FIG. 12 is a schematic flowchart of updating an IP address according to an embodiment of this applica- tion; FIG. 13 is a diagram of an address assignment system according to an embodiment of this applica- tion; FIG. 14 is a diagram of a hardware structure of a computing device according to an embodiment of this application; and FIG. 15 is a diagram of a computing device cluster according to an embodiment of this application. DESCRIPTION OF EMBODIMENTS
[0041] To make the objectives, technical solutions, and advantages of this application clearer, the following further describes implementations of this application in detail with reference to accompanying drawings.
[0042] Before the technical solutions provided in em- bodiments of this application are described, the following first describes terms in this application.
[0043] An internet protocol (internet protocol, IP) ad- dress is an identifier assigned to a deviceupon access of the device to a network. Devices can communicate with each other through IP addresses. IP addresses may be used to identify which device is a sender and which device is a receiver.
[0044] A cloud platform, short for a cloud computing platform, can provide cloud services such as computing, networks, and storage based on massive hardware and software resources. The cloud platform remotely pro- cesses and analyzes massive data by using a network "cloud" and returns the data to users, and features scal- ability, distributed nature, virtualization, high availability, scalability, on-demand services, and security. The cloud platform can quickly provision and release configurable computing resources at low management costs or with low complexity of interaction between the users and a service provider. OpenStack is a cloud platform with an infrastructure as a service (infrastructure as a Service, IAAS) architecture, and provides a cloud operating sys- tem for managing a largequantity of resource pools in an entire data center. Administrators may manage an entire cloud system through a consoleof the cloud platform, and provide available cloud resources for the users through web interfaces.
[0045] A public cloud (Public Cloud) is a cloud infra- structure used by the general public or large industries collectively, that is, a cloud platform accessed through a public network. Organizations with public clouds can provide users with an ability to deploy and use cloud services on demand through leasing. The users can access the public clouds through public networks (such as the Internet) to use various network services provided by the public clouds, including but not limited to comput- ing, storage, and networks.
[0046] A virtual private cloud (virtual private cloud, VPC) is an isolated and private virtual network environ- ment on a cloud platform. Users can freely configure subservices such as IP address segments, subnets, and security groups on the virtualprivate cloud.
[0047] An elastic cloud server (elastic cloud server, ECS) is a basic computing component including a CPU, a memory, an operating system, and an EVS disk, 5 10 15 20 25 30 35 40 45 50 55 6 9 EP 4 683 300 A1 10 and can be obtained at any time and expanded elasti- cally.
[0048] A cloud service (Cloud Service) is a service that is obtained through a network in an on-demand and easy- to-expand manner. The service may be a service related to a network technology, software, and the internet, or may be another service.
[0049] A network interface card (network interface card, NIC), also known as a network interface controller, is a type of computer hardware that allows computers to communicate on a computer network.
[0050] A network proxy (proxy) is a special network service that allows a terminal to indirectly connect to another terminal through the service. Some network devices such as gateways and routers have a network proxy function. It is generally considered that a proxyservice helps ensure privacy or security of a network terminal, and can prevent network attacks to some ex- tent.
[0051] A remote desktop protocol (remote desktop protocol, RDP) is a protocol that allows a user to use, via a local device, a terminal service provided by a remote device.
[0052] A remote desktop session host (remote desktop session host, RDSH) can store an application and a desktop that are based on a remote desktop session (remote desktop session, RDS) and that are shared with a user.
[0053] A remote desktop session (RDS) is started when a user logs in to a remote desktop session host (RDSH).
[0054] Remote desktop IP virtualization (remote desk- top IP virtualization): After IP virtualization is configured and enabled on a remote desktop session host (RDSH), a unique IP address is assigned to and used in a remote desktop session.
[0055] A dynamic host configuration protocol (dynamic host configuration protocol, DHCP) is a communication protocol that enables a networkadministrator to centrally manage and automatically assign IP network addresses. In an IP network, each device connected to the internet (Internet) needs to be assigned a unique IP address. The dynamic host configuration protocol enables the network administrator to monitor and assign IP addresses from a central node. When a computer is moved to another location in the network, the computer can automatically receive a new IP address.
[0056] A dynamic host configuration protocol server (DHCP Daemon) is a type of management software that is oriented to a network administrator and that imple- ments a dynamic host configuration protocol (DHCP).
[0057] A dynamic host configuration protocol client (DHCP Client Daemon) is a type of client software that is oriented to a host and that implements a dynamic host configuration protocol (DHCP).
[0058] The following describes an application scenario of the technical solutions of this application.
[0059] This application provides a method forproviding an IP address for a remote desktop session. The method can be applied to a cloud platform, and assign different IP addresses to different remote desktop sessions running on a remote desktop session host on the cloud platform.
[0060] In a related technology, a DHCP is used to dynamically assign IP addresses to different sessions in a remote desktop session host. FIG. 1 is a diagram of assigning IP addresses to remote desktop sessions based on the DHCP protocol in the related technology. When a client accesses an RDSH, for example, an RDSH 2, the client establishes a connection (indicated by an RDP 1) to the RDSH 2, and the RDSH 2 creates an RDS 1 and sends a DHCP request to a DHCP network (usually a local area network) in which the RDSH 2 is located. After receiving the DHCP request, a DHCPD in the local area network assigns an IP address 1 to the RDS 1, and the client uses the IP address 1 to enjoy a network service. A process of assigning an IP address 2 to an RDS 2corresponding to another client is similar. The foregoing process is based on that the DHCPD can centrally man- age IP addresses in the network.
[0061] However, in a public cloud mode, the DHCP cannot be used to implement IP virtualization for remote desktop sessions. Reasons are as follows: In one aspect, the DHCPD cannot obtain permission to manage IP addresses on the cloud platform. To ensure security of cloud services, a management plane of the cloud platform, for example, a virtual private cloud (virtual private cloud, VPC) deployed on a public cloud, centrally manages resources such as IP addresses of the cloud platform. As a result, the DHCP server in a current DHCP architecture does not have permission to apply for and maintain IP addresses.
[0062] In another aspect, the DHCP is applicable only to IP management in a local network, and is difficult to be applied to the cloud platform. In the public cloud mode, massive resources at the bottom layer are abstracted and provided forusers in a form of cloud services. Hos- ts / virtual machines / containers actually used to imple- ment cloud services may be distributed across networks, for example, distributed in different regions. Different regions may further include one data center network or a plurality of data center networks that are geographically close to each other. However, the current DHCP archi- tecture is only applicable to management of IP resources in the local area network, and cannot ensure real-time dynamic assignment and release of IP addresses on a huge public cloud. For example, after a DHCP request sent by a client is received by a nearest DHCPD (inside a network), the DHCP request is processed, and it is diffi- cult to transmit the DHCP request to a next network across networks. Consequently, it is difficult to dynami- cally assign IP addresses on the public cloud.
[0063] In conclusion, the current DHCP technology cannot be used to implement remote desktop IP virtua- lization on the public cloud.
[0064] In view of this, this application provides an IP address assignment method. The method can be applied 5 10 15 20 25 30 35 40 45 50 55 7 11 EP 4 683 300 A1 12 to a cloud platform that provides a public cloud service, and can implement remote desktop IP virtualization for the cloud platform, so that when different clients access an RDSH on the cloud platform, the RDSH assigns different IP addresses obtained through virtualization to different sessions corresponding to different clients, so that different clients can obtain network services based on different IP addresses. Therefore, when a client accesses a session in the RDSH to use various network services provided by the cloud platform, security, privacy, and scalability of the network services can be fully en- sured.
[0065] The following further describes the technical solutions of this application.
[0066] An embodiment of this application provides a diagram of an implementation environment. FIG. 2 is a diagram of animplementation environment according to an embodiment of this application. The implementation environment includes a client 210 and an address as- signment system 220.
[0067] In this application, a technology that provides a remote session in a cloud host for a client is also referred to as a cloud desktop, and an RDSH running on a public cloud may also be referred to as a remote desktop ses- sion host instance of the cloud desktop. Refer to FIG. 2. The address assignment system 220 includes a cloud platform 221. The cloud platform 221 is configured to provide an IP virtualization function on the public cloud.
[0068] A VPC 222 running in the address assignment system 220 is configured to maintain resources such as IP addresses on the cloud platform. A VPC is a logically isolated network space defined on the public cloud. All resources on the public cloud, such as cloud hosts and load balancers, can be hosted on the VPC. An adminis- trator may use the VPC to customize network segments,IP addresses, and routing policies.
[0069] In some embodiments, the address assignment system 220 includes an elastic cloud server 223. The elastic cloud server 223 is configured to run at least one RDSH instance. Refer to an RDSH 1 to an RDSH-n in FIG. 2, where n is a quantity of RDSHs, and n is greater than or equal to 1. The elastic cloud server 223 is a basic computing component of the cloud platform, and the address assignment system 220 can provide the elastic cloud server 223 for a user as required.
[0070] The client 210 is configured to: access the ad- dress assignment system 220, access an RDSH on the cloud platform, and use various remote network services based on an RDS in the RDSH, for example, run an application program, download a file, or access a network (which may be accessing an intra-cloud network or ac- cessing an external network).
[0071] The foregoing administrator is a user who man- ages the RDSH running on the cloud platform. In some embodiments, theadministrator creates a target RDSH based on the public cloud through a management inter- face provided by the cloud platform in which the admin- istrator is located, and configures an IP virtualization function for the created target RDSH. The cloud platform 221 applies for one or more IP addresses from the VPC 222 based on a configuration of the administrator, and sends the one or more IP addresses to the target RDSH. When receiving a first creation request of a first client, the target RDSH creates a first session corresponding to the first client, and assigns a first IP address to the first session from a plurality of maintained IP addresses. The plurality of IP addresses obtained by the cloud plat- form from the VPC are obtained through virtualization based on IP addresses of the RDSH. When accessing a session in the RDSH, the client 210 may perform network communication based on a virtualized IP address as- signed by the RDSH to the session.
[0072] In some embodiments, refer toFIG. 2. A stan- dalone DHCPD is installed on the RDSH in the address assignment system 220. The DHCPD is a type of man- agement software that is oriented to the administrator and that supports a dynamic host configuration protocol (DHCP). Based on this, the RDSH on the cloud platform 221 can dynamically manage a plurality of IP addresses in a single machine by using the DHCPD.
[0073] Certainly, the technical solutions of this applica- tion may also be applied to a cloud platform in another mode, for example, a hybrid cloud deployed in combina- tion with a private cloud and a public cloud. This is not limited in this application.
[0074] In this embodiment of this application, the ad- dress assignment system 220 may be implemented based on a computing device cluster, and the computing device cluster includes at least one computing device. In some embodiments, the computing device cluster may be a server cluster or a distributed file system including a server and a plurality of physicalservers, or a cloud server cluster that provides basic cloud computing ser- vices such as cloud storage, cloud services, cloud data- bases, cloud computing, cloud functions, network ser- vices, cloud communication, middleware services, do- main name services, security services, content delivery networks (content delivery network, CDN), big data, and artificial intelligence platforms. This is not limited in this application.
[0075] In this embodiment of this application, the client 210 runs on a computing device. The computing device is a terminal or a server. The terminal is, for example, a desktop computer, a notebook computer, or a smart- phone. The server is, for example, a central server, an edge server, or a local server in a local data center. This is not limited in this application. The same applies to a client in which the foregoing administrator is located. In some embodiments, a terminal in which the administrator is located and a computing device that accesses an RDS may bea same device or different devices. This is not limited in this application.
[0076] In some embodiments, the IP address assign- ment method provided in this application can be imple- mented in the address assignment system 220 in a form of a computing instance. The computing instance can run 5 10 15 20 25 30 35 40 45 50 55 8 13 EP 4 683 300 A1 14 on a public cloud in a form of a virtual machine, a contain- er, or a process, and is provided for a user as a cloud service.
[0077] The client 210 and the address assignment system 220 may be communicatively connected through a wired network or a wireless network. In some embodi- ments, the wireless network or the wired network uses a standard communication technology and / or protocol. The network includes but is not limited to any combination of a data center network (data center network), a storage area network (storage area network, SAN), a local area network (local area network, LAN), a metropolitan area network (metropolitan area network,MAN), a wide area network (wide area network, WAN), a mobile, wired, or wireless network, a private network, or a virtual private network. In some implementations, technologies and / or formats including a hypertext markup language (hyper- text markup language, HTML), an extensible markup language (extensible markup language, XML), and the like are used to represent data exchanged through the network. In addition, all or some links can be encrypted by using conventional encryption technologies such as se- cure sockets layer (secure sockets layer, SSL), transport layer security (transport layer security, TLS), virtual pri- vate network (virtual private network, VPN), and network protocol security (internet protocol security, IPsec). In some other embodiments, customized and / or dedicated data communication technologies can alternatively be used to replace or supplement the foregoing data com- munication technology.
[0078] The following describes, based on the foregoing application scenarioand the foregoing implementation environment, the IP address assignment method pro- vided in embodiments in detail with reference to FIG. 3 to FIG. 12 provided below. The following uses interaction between a client and an address assignment system as an example for description.
[0079] Step 301 to step 307 below describe a brief procedure of assigning IP addresses to different remote desktop sessions RDSs used by different clients on a public cloud.
[0080] 301: A cloud platform in the address assign- ment system creates a target RDSH in response to an RDSH creation instruction.
[0081] In some embodiments, the cloud platform pro- vides a target function switch on a management inter- face, where the target function switch is used to enable and disable an IP virtualization function for the target RDSH, and the IP virtualization function includes: en- abling the RDSH to use a plurality of IP addresses obtained through virtualization based on IP addresses of the RDSH. In some embodiments,the management interface of the cloud platform is also referred to as a console of the public cloud.
[0082] In some embodiments, an administrator cre- ates and manages an RDSH on the cloud platform through the management interface provided by the cloud platform. The RDSH creation instruction may be trig- gered by the administrator. For example, the adminis- trator logs in, via a terminal device, to the management interface provided by the cloud platform, and chooses to create the target RDSH on a target server. FIG. 3 is a diagram of a management interface according to this application. Refer to FIG. 3. The administrator logs in to the management interface provided by a public cloud platform, and starts to create an RDSH (which may be one RDSH or a group of RDSHs). The management interface provides an input option for editing a name of a server group to be created, and supports the adminis- trator in selecting a region in which the target server group is located (which may be a datacenter divided by geographical region). The management interface pro- vides a function of selecting an image, and a user may select a required image to create an RDSH. The manage- ment interface provides the target function switch. As shown in the figure, if the target function switch is on, an IP virtualization function can be applied to the created RDSH. The image provides an operating system, initi- alized application data, pre-installed software, and the like used by an RDSH instance. As shown in FIG. 3, the administrator may directly select an image pre-installed with a DHCPD.
[0083] In some embodiments, the cloud platform sup- ports presetting an application rule of the IP virtualization function of the RDSH, so that when the RDSH is created and the IP virtualization function is enabled, the IP vir- tualization function of the target RDSH may be enabled directly according to the preset application rule. In this way, the administrator can simply and efficiently create and manageRDSHs in a public cloud mode. The follow- ing provides descriptions with reference to FIG. 4. FIG. 4 is a diagram of initialization setting of a cloud platform. For an architecture of the cloud platform, refer to descrip- tions in FIG. 2.
[0084] In some embodiments, in an initial state, the cloud platform is ready, and the administrator has not set an application rule of an IP virtualization function of the RDSH on the cloud platform. The administrator logs in to a public cloud console (management interface) provided by the cloud platform, and sets the application rule for enabling remote desktop IP virtualization. The cloud platform stores and records the application rule set by the administrator, where the application rule can be ap- plied to a newly created RDSH.
[0085] In some embodiments, the application rule in- dicates an object to which the IP virtualization function is applied, for example, a group of servers configured to run the RDSH, or a standalone server configured to runthe RDSH. Correspondingly, the application rule may indi- cate to enable the IP virtualization function for all RDSH servers in a group, or indicate to enable the IP virtualiza- tion function for a selected standalone RDSH server.
[0086] According to the foregoing technical solution, the switch of the IP virtualization function is provided for a user on a front-end interface, so that the user can con- figure the IP virtualization function in a process of creating 5 10 15 20 25 30 35 40 45 50 55 9 15 EP 4 683 300 A1 16 an RDSH based on a service requirement.
[0087] 302: The cloud platform applies, based on the target RDSH, to a VPC for at least one IP address obtained through virtualization based on an IP address of the target RDSH.
[0088] In some embodiments, first specification infor- mation indicates a specification of an IP address related to the target RDSH. For example, the first specification information includes at least one of the following: a quan- tity of IP addresses used bythe target RDSH, for exam- ple, 1 or 2; and a quantity of sessions supported by the target RDSH, for example, 2 or 3.
[0089] In some embodiments, in response to obtaining the first specification information from the management interface, the cloud platform obtains the at least one IP address obtained through virtualization based on the IP address of the RDSH. For example, the cloud platform obtains, based on the quantity that is of IP addresses and that is indicated by the first specification information, one or more IP addresses obtained through virtualization; or the cloud platform obtains, based on the quantity that is of sessions and that is indicated by the first specification information, one or more IP addresses that are obtained through virtualization and that support the quantity of sessions.
[0090] In some embodiments, the cloud platform can select, based on a request submitted by a user, a target physical host (for example, a server) to run the created target RDSH. A networkinterface card used for network- ing is installed on each physical host. An IP address configured for the network interface card when the net- work interface card is installed to the physical host is an IP address of the RDSH. In this example, the cloud platform requests, based on the IP address of the RDSH and the quantity indicated by the first specification information, the VPC to obtain, through virtualization based on the IP address of the RDSH, an IP address corresponding to the quantity. The IP address obtained through virtualization is bound to the IP address corresponding to the RDSH. For example, a plurality of IP addresses obtained through virtualization are bound to a network interface card cor- responding to the RDSH, and are used as IP addresses equivalent to an original fixed IP address of the network interface card, so that a networking process of a virtual IP address is completed on a management plane of the public cloud. In some other embodiments, a relationshipbetween a physical host, a network interface card, an IP address of the network interface card, and an IP address obtained through virtualization is maintained by the VPC.
[0091] Therefore, the plurality of IP addresses ob- tained through virtualization can implement a networking function equivalent to the original fixed IP address of the network interface card, and provide data support of the management plane of the public cloud for subsequent dynamic management of the plurality of IP addresses in the RDSH.
[0092] In some embodiments, the cloud platform may apply for one or more virtualized IP addresses for the target RDSH. For example, the cloud platform deter- mines, based on the first specification information sub- mitted by the user, to apply for an equal quantity of IP addresses, or the cloud platform applies for an equal quantity of IP addresses based on a product specification (for example, a quantity of sessions) set by the adminis- trator when the administrator creates thetarget RDSH.
[0093] In some embodiments, the management inter- face of the cloud platform provides an option for specify- ing a region in which a cloud server is located. In other words, the administrator may select the region in which the cloud server used to create the target RDSH is located. In this example, the administrator selects the region in which the server is located, and submits the region to the cloud platform, to trigger the cloud platform to apply to the VPC for the IP address of the target RDSH. The VPC determines the IP address of the RDSH based on an available cloud server in the region selected by the administrator, and further applies for a corresponding quantity of virtualized IP addresses based on a require- ment of the administrator for a quantity of sessions.
[0094] According to the foregoing solution, the man- agement interface provided by the cloud platform allows the user to customize a quantity of sessions to be used when the RDSH is created. Thiseffectively integrates the IP virtualization function into an actual service scenario.
[0095] 303: The cloud platform sends, to the created target RDSH, the at least one IP address obtained through virtualization.
[0096] In some embodiments, a server DHCPD that supports a dynamic host configuration protocol runs in the target RDSH, and the cloud platform sends, to the standalone DHCPD running in the target RDSH, the at least one IP address obtained through virtualization. The DHCPD supports the DHCP protocol, and can maintain (for example, assign and reclaim) the plurality of IP addresses obtained through virtualization. Therefore, the plurality of virtualized IP addresses delivered by the cloud platform to the target RDSH are equivalent to an IP address source maintained and managed by the DHCPD.
[0097] According to the foregoing technical solution, at a granularity of a standalone RDSH, a plurality of assign- able virtualized IP addresses are delivered to a standa- lone DHCPD runningin the RDSH, to implement flexible management of a plurality of IP addresses in the stan- dalone RDSH.
[0098] It should be noted that the foregoing process is described by using a process of creating a standalone RDSH as an example. When the administrator creates a plurality of RDSHs through one configuration, the cloud platform can execute an RDSH creation process and a virtualized IP address delivery process by using the same process as step 301 to step 303 above at a granularity of each RDSH.
[0099] To facilitate understanding of the procedure described in step 301 to step 305 above, this application further provides FIG. 5 and FIG. 6. FIG. 5 is a diagram of a 5 10 15 20 25 30 35 40 45 50 55 10 17 EP 4 683 300 A1 18 principle of creating an RDSH according to this applica- tion. FIG. 6 is a schematic flowchart of delivering an IP address when an RDSH is created according to this application. The following further describes the technical solutions provided in step 301 to step 303above with reference to FIG. 5 and FIG. 6.
[0100] Refer to FIG. 5. In a scenario in which the administrator creates one or more RDSHs, the adminis- trator logs in to the management interface (a public cloud console) provided by the cloud platform, selects a server group corresponding to a set rule for enabling remote desktop IP virtualization, and purchases one or more RDSHs (corresponding to one or more physical hosts). In a process of creating the RDSH, the cloud platform applies, at a granularity of a standalone RDSH, to the VPC for one or more IP addresses obtained through virtualization, and delivers the IP addresses obtained through virtualization to standalone DHCPDs installed in corresponding RDSHs.
[0101] Refer to FIG. 6. The administrator submits an RDSH creation task to the cloud platform through a public cloud console provided by the cloud platform. The cloud platform returns a task submission success response to the console, and submits the RDSH creation task to an elasticcloud server (ECS). After receiving a response returned by the ECS, the cloud platform applies to the VPC for virtualized IP addresses assigned to an RDSH, and delivers the received virtualized IP addresses to the RDSH. A standalone DHCPD in the RDSH receives and stores these virtualized IP addresses as an IP address source that can be used for assignment. The standalone DHCPD in the RDSH starts DHCP protocol listening, and provides a DHCP protocol support capability.
[0102] The foregoing step 301 to step 303 describe a process of creating an RDSH and a process of delivering a plurality of available virtualized IP addresses. The following describes a process of dynamically assigning an IP address when a client accesses an RDSH.
[0103] 304: The cloud platform receives the first crea- tion request sent by the first client, and forwards the first creation request to the target RDSH, where the first creation request is used to request to establish a first session with the target RDSH.
[0104] In some embodiments, the first creation request carries host information, and the cloud platform can determine the target RDSH based on the host informa- tion, to forward the first creation request to the target RDSH. The host information may be a host name, a host IP address, a subnet address of the host, or the like. This application is not limited thereto.
[0105] In some other embodiments, the cloud platform determines, for the first client according to a load balan- cing policy, a target RDSH host that provides an RDSH service.
[0106] 305: In response to the first creation request, the target RDSH assigns a corresponding first IP address to the first session, where the first IP address is obtained through virtualization of an IP address of the target RDSH, and the RDSH assigns a virtual IP address to a running remote desktop session RDS based on a plur- ality of virtual IP addresses corresponding to the IP address.
[0107] In some embodiments, a server DHCPD that supports thedynamic host configuration protocol runs in the target RDSH. The DHCPD supports the DHCP pro- tocol, and can maintain (for example, assign and reclaim) the plurality of IP addresses obtained through virtualiza- tion. The target RDSH sends a DHCP request to the DHCPD in response to the first creation request. The DHCPD assigns, in response to the DHCP request, the first IP address to the first session from the plurality of maintained virtualized IP addresses. In some embodi- ments, a unique session identifier is assigned to each session in one RDSH.
[0108] To facilitate understanding of step 304 and step 305, this application provides FIG. 7 based on FIG. 5. FIG. 7 is a flowchart of an IP address assignment method according to an embodiment of this application. Refer to FIG. 7 and FIG. 5. After sending the first creation request, the client accesses an RDSH through an RDP, and the RDSH marks a connection by using an RDP 1, creates a corresponding first session RDS 1, and associates theconnection RDP 1 of the client with the first session RDS 1. The RDSH sends a DHCP request to apply for an IP address from a running DHCPD for the first session. The standalone DHCPD in the RDSH receives the request, responds to the request, and assigns a virtualized IP address 1. The RDSH obtains the IP address 1, and associates the RDS 1 with the IP address 1. Based on this, the first client may use the IP address 1 as an IP address used for subsequent access to a network service based on the first session RDS 1.
[0109] 306: The target RDSH returns the first IP ad- dress to the cloud platform.
[0110] In some embodiments, the cloud platform may determine, based on the first IP address returned by the target RDSH, at what time, which client, through which session in which RDSH, uses the first IP address to perform network communication. Therefore, the cloud platform can effectively manage and trace a user of a remote desktop session. This ensures security of remote desktop sessions onthe public cloud.
[0111] 307: The cloud platform returns a first access response to the first client, where the first access re- sponse indicates that the first client has established the first session with the target RDSH based on the first IP address.
[0112] In some embodiments, the cloud platform re- turns an IP address (for example, a fixed IP address configured for a network interface card of a physical host) of the target RDSH to the first client, so that the first client can directly access the target RDSH based on the IP address. In some other embodiments, the target RDSH may alternatively return the first access response to the first client, so that the first client directly interacts with the accessed RDSH, thereby reducing forwarding and inter- 5 10 15 20 25 30 35 40 45 50 55 11 19 EP 4 683 300 A1 20 action overheads of the cloud platform.
[0113] Similar to the foregoing steps 304 to 307, a process in which the address assignment system as- signs an IP address to a secondclient that uses the target RDSH includes: The cloud platform receives a second creation request sent by the second client, and forwards the second creation request to the target RDSH, where the second creation request is used to request to estab- lish a second session with the target RDSH (referring to step 304); in response to the second creation request, the target RDSH assigns a corresponding second IP address to the second session, where the second IP address is obtained through virtualization of an IP address of the target RDSH (referring to step 305); the target RDSH returns the second IP address to the cloud platform (referring to step 306); and the cloud platform returns a second access response to the second client, where the second access response indicates that the second client has established the second session with the target RDSH based on the second IP address (referring to step 307).
[0114] In some other embodiments, in response to a network service request initiatedby the first client through the first session, the target RDSH processes the network service request based on the first IP address. For ex- ample, the network service request includes accessing a network by using proxy software. The following provides descriptions with reference to FIG. 8. FIG. 8 is a diagram of using a network service by a client according to this application.
[0115] Refer to FIG. 8. In a secure network access scenario controlled by an enterprise proxy server, a process in which a user A of an enterprise network uses proxy software to log in to the proxy server through a remote desktop session in an RDSH, to access an ex- ternal network includes the following step (1) to step (5): (1) The user A accesses, via a client, the RDSH through an RDP, where the RDP is marked as an RDP 1, the RDSH creates a corresponding RDS 1, and the RDSH sends a DHCP request to apply for an IP address. (2) A standalone DHCPD in the RDSH receives the request, responds to the request, andassigns a virtualized IP address 1. The RDSH obtains the IP address 1, and associates the RDS 1 with the IP address 1. The user A can use the IP address 1 as an IP address for subsequent network communication via the client. (3) The user A uses the proxy software running in the RDSH through the RDS 1, to request to log in to the proxy server of the enterprise network. (4) The enterprise proxy server authenticates the IP address 1 and a user credential provided by the user A, and the enterprise proxy server records that authentication on the IP address 1 succeeds, and allows the user A to use the IP address 1 to access a network resource via the proxy server. (5) The user A uses the authenticated IP address 1 to access the proxy server, to access the network re- source via the proxy server.
[0116] After a similar process of step (1) to step (5), a user B uses an authenticated IP address 2 to access the proxy server, to access the network resource via the proxy server.
[0117] In theforegoing process, the user A and the user B can use network services based on different IP ad- dresses without affecting each other.
[0118] Therefore, in this application, at least the follow- ing can be implemented: A client performs network ac- cess in a specified session of a specified RDSH based on a unique IP address in the RDSH; different clients per- form network access in a same RDSH based on different IP addresses; and a same client uses different IP ad- dresses in different sessions. Based on this, in this ap- plication, session-level IP address isolation can be im- plemented, network requests of different users can be effectively distinguished, and privacy of using network services by different users can be ensured.
[0119] In some other embodiments, the RDSH re- leases a virtual IP address assigned to an RDS in re- sponse to a session deregistration request for the RDS. This application provides a schematic flowchart of ses- sion deregistration. Refer to FIG. 9. Aderegistration process includes: The first client requests to deregister the connection RDP 1 between the first client and the RDSH. The RDSH receives the request, and deregisters a related resource of the first session RDS 1 associated with the RDP 1. The RDSH sends a DHCP request to release the IP address 1 associated with the RDS 1. The standalone DHCPD in the RDSH receives the request, and reclaims the IP address 1 for subsequent assign- ment to other connected RDPs. The RDSH disassociates the RDS 1 from the IP address 1 to complete session deregistration.
[0120] According to the technical solutions provided in this application, the cloud platform can apply to the management plane of the public cloud for an IP address for each RDSH, and maintain an IP address source (a plurality of IP addresses obtained through virtualization) assigned to each RDSH; in the RDSH of the public cloud, the standalone DHCPD is customized based on the DHCP, so that each RDSH can assign, reclaim, andreuse IP addresses; and in a same RDSH, when pro- grams in different sessions listen to a network interface card port of an RDSH host, unique virtualized IP ad- dresses are assigned to different sessions, to effectively avoid port listening conflicts caused by only one available IP address of the network interface card. In conclusion, the technical solutions of this application can effectively improve IP address assignment efficiency, and greatly improve scalability of providing a network service based on the RDSH.
[0121] Therefore, the IP address assignment method provided in this application can be applied to providing a public cloud service, and implementing remote desktop 5 10 15 20 25 30 35 40 45 50 55 12 21 EP 4 683 300 A1 22 IP virtualization for the public cloud service, so that when a client accesses a session in an RDSH to use various network services provided by a cloud platform, security, privacy, and scalability of the network services can be fully ensured.
[0122] Theforegoing embodiment describes a princi- ple of how to deliver assignable virtualized IP addresses in a process of creating an RDSH, so that the RDSH can assign different IP addresses to different sessions. In some other embodiments, based on the foregoing em- bodiment, a virtualized IP address that has been as- signed to an RDSH can be updated in a running process of the RDSH. FIG. 10 is a diagram of updating an IP address according to this application. The following pro- vides descriptions with reference to FIG. 10, step 1001, and step 1002.
[0123] 1001: In response to an IP update instruction, a cloud platform obtains, based on second specification information carried in the IP update instruction, an up- dated version of at least one IP address obtained through virtualization based on an IP address of the target RDSH.
[0124] The second specification information indicates at least one of the following: a quantity of updated IP addresses used by the target RDSH and a quantity ofupdated sessions supported by the target RDSH. For an example of the second specification information, refer to descriptions of the first specification information in step 302. Details are not described herein again.
[0125] In some embodiments, the cloud platform com- pares a first quantity currently available for the RDSH with a second quantity indicated by the second specification information, to determine a manner of updating a virtua- lized IP address assigned to the target RDSH. The quan- tity may be a quantity of sessions or a quantity of IP addresses.
[0126] In some embodiments, when the second quan- tity is less than the second quantity, it indicates that the cloud platform determines an IP address released this time, and obtains, based on the IP address released this time, the updated version of the at least one IP address obtained through virtualization. Based on this, the cloud platform can release redundant IP addresses in a timely manner. In some other embodiments, whenthe second quantity is greater than the first quantity, a virtualized IP address that is newly applied for this time is determined, and the updated version of at least one IP address obtained through virtualization is obtained based on the virtualized IP address that is newly applied for this time. Based on this, the cloud platform can supplement available IP addresses in a timely manner. In conclusion, real-time performance of IP resource management can be improved.
[0127] In some embodiments, a quantity of updated IP addresses obtained through virtualization is greater than or equal to an updated quantity of sessions correspond- ing to a product specification of the target RDSH.
[0128] Refer to FIG. 10. In response to an update request of the administrator, the cloud platform can de- termine, based on the foregoing comparison process, to apply to the VPC for a new IP address or request the VPC to release an IP address, and further determine an up- dated IP address of the target RDSHbased on the newly applied IP address or the released IP address.
[0129] In some embodiments, the cloud platform sup- ports passive update of an IP address of an RDSH. The cloud platform triggers the IP update instruction in re- sponse to obtaining the second specification information for the target RDSH from the management interface of the cloud platform.
[0130] In some embodiments, the cloud platform ob- tains the second specification information for the target RDSH from the management interface. In some applica- tion scenarios, because a product specification changes (for example, a quantity of used remote desktop sessions changes), to improve IP address utilization efficiency and ensure that a quantity of IP addresses supports a service requirement of a product, the administrator of the target RDSH updates an IP address used by the target RDSH. In this example, the administrator triggers the update process for the target RDSH on the management inter- face.
[0131] FIG. 11 is adiagram of another management interface according to this application. Refer to FIG. 11, an administrator logs in to a public cloud console (a management interface), and updates an IP source of a target RDSH. As shown in FIG. 11, the management interface displays a plurality of options for configuring an IP virtualization function of a current server group. The management interface displays information such as a name of a server group AAA configured to run the target RDSH, an operating system or image information used by the server group, specifications of the server group, a quantity of supported sessions, a capacity of a system hard disk, creation time, and a server status. Refer to FIG. 11. The IP virtualization function has been enabled for the server group configured to run the target RDSH. Refer to a management area of a target RDSH instance. An option to update a virtual IP is provided in a "More" option.
[0132] In some other embodiments, the cloud platform supports activelyupdating a virtualized IP address as- signed to an RDSH. The cloud platform triggers the IP update instruction in response to detecting that usage of the target RDSH on the cloud platform meets an update condition. The update condition indicates IP address usage. For example, a quantity of used virtualized IP addresses on one or more RDSH hosts exceeds a first threshold, or a quantity of remaining available virtualized IP addresses on one or more RDSHs is less than a second threshold. In this case, the cloud platform auto- matically triggers additional assignment of virtualized IP addresses. Based on this, the cloud platform can dyna- mically maintain, based on usage, a quantity of virtua- lized IP addresses used by each host. This improves IP address utilization and maintains service availability.
[0133] The foregoing is a case in which the IP address of the target RDSH is updated. In some embodiments, 5 10 15 20 25 30 35 40 45 50 55 13 23 EP 4 683 300 A1 24 the IP update instructionmay be used for a plurality of RDSHs. In this case, the cloud platform can apply to the VPC for or release a virtualized IP address at a granu- larity of a standalone RDSH in the foregoing similar manner.
[0134] In the foregoing technical solution, an IP ad- dress source is dynamically updated for each RDSH, and an active update initiation manner and a passive update initiation manner are provided, so that scenarios such as a product change on a business side and availability maintenance on a service side can be covered, and RDSH-based deployment flexibility and network service availability are greatly improved.
[0135] 1002: The cloud platform sends, to the target RDSH, the updated version of the at least one IP address obtained through virtualization.
[0136] In some embodiments, a server DHCPD that supports the dynamic host configuration protocol runs in the target RDSH.
[0137] In some embodiments, the standalone DHCPD in the target RDSH receives and stores the updated version of theat least one IP address obtained through virtualization, restarts DHCP protocol listening, and uses the updated version of the at least one IP address ob- tained through virtualization as an IP address source that can be used for assignment, to continue to provide a DHCP protocol support capability.
[0138] In some other embodiments, the standalone DHCPD in the target RDSH can update, based on the updated version of the IP address obtained through virtualization, a maintained IP address source online without restarting. For example, if detecting that a new IP address is added to updated versions of IP addresses obtained through virtualization, the DHCPD adds the newly added IP address to the maintained IP address source; or if detecting that updated versions of IP ad- dresses obtained through virtualization do not include some maintained IP addresses, the DHCPD deletes the some IP addresses from the maintained IP address source. In some embodiments, the DHCPD detects usage of some IPaddresses, and if the DHCPD detects, from a lease table, that the some IP addresses are not used, the DHCPD directly deletes the some IP ad- dresses; or if the DHCPD detects, from the lease table, that the some IP addresses are in use, the DHCPD deletes the IP addresses after reclaiming the IP ad- dresses.
[0139] According to the foregoing technical solution, a DHCPD deployed in a standalone manner is customized for each RDSH on a public cloud based on a DHCP protocol, and the DHCPD can dynamically assign, re- claim, or reuse an IP address in a standalone RDSH, and supports dynamic update of an IP address source. In this way, IP address utilization can be fully ensured, and when network services are provided based on the RDSH, virtualized IP addresses can be dynamically assigned, to improve scalability of public cloud services.
[0140] To facilitate understanding of the foregoing up- date process, this application provides a schematic flow- chart of updating an IP address. Refer to FIG.12. An example of an IP address update process includes the following step 1 to step 4: 1. An administrator logs in to a public cloud console (management interface), selects an RDSH whose IP address needs to be updated, and submits an IP address update task. 2. A cloud platform determines, based on an instruc- tion submitted by a user, an existing IP address that is of a target RDSH and that is obtained through virtualization, and compares quantities (referring to step 1001), to determine to apply to a VPC manage- ment plane for adding or releasing a redundant IP address obtained through virtualization. 3. The cloud platform delivers, to a standalone DHCPD installed on the RDSH, updated versions of one or more IP addresses obtained through vir- tualization. 4. The standalone DHCPD receives and stores the updated versions of the IP addresses obtained through virtualization, restarts DHCP protocol listen- ing, and uses the updated versions of the IP ad- dresses obtained throughvirtualization as an IP address source that can be used for assignment, to continue to provide a DHCP protocol support capability.
[0141] The IP address assignment method provided in this application can be applied to a public cloud service, and can implement remote desktop IP virtualization for a public cloud, so that when different clients access an RDSH on a cloud platform, the RDSH assigns different IP addresses obtained through virtualization to different sessions corresponding to different clients, so that dif- ferent clients can obtain network services based on different IP addresses. Therefore, when a client ac- cesses a session in the RDSH to use various network services provided by the cloud platform, security, privacy, and scalability of the network services can be fully en- sured.
[0142] Further, in the foregoing technical solution, for a function of updating an IP address, an active update initiation manner and a passive update initiation manner are provided for the RDSH,so that scenarios such as a product change on a business side and availability main- tenance on a service side can be covered, IP address utilization efficiency is effectively improved, and it is en- sured that a quantity of IP addresses meets a service requirement of a product.
[0143] FIG. 13 is a diagram of an address assignment system according to an embodiment of this application. Refer to FIG. 13, the address assignment system in- cludes a cloud platform and an RDSH. The cloud platform is configured to provide a public cloud service.
[0144] The cloud platform 1301 is configured to: re- ceive a first creation request sent by a first client, and 5 10 15 20 25 30 35 40 45 50 55 14 25 EP 4 683 300 A1 26 forward the first creation request to the target RDSH 1302, where the first creation request is used to request to establish a first session with the target RDSH 1302.
[0145] The target RDSH 1302 is configured to assign a corresponding first IP address to the first session in responseto the first creation request, where the first IP address is obtained through virtualization of an IP ad- dress of the target RDSH 1302.
[0146] The target RDSH 1302 is configured to return the first IP address to the cloud platform 1301.
[0147] The cloud platform 1301 is configured to return a first access response to the first client, where the first access response indicates that the first client has estab- lished the first session with the target RDSH 1302 based on the first IP address.
[0148] In a possible implementation, the cloud platform 1301 is further configured to: receive a second creation request sent by a second client, and forward the second creation request to the target RDSH 1302, where the second creation request is used to request to establish a second session with the target RDSH 1302.
[0149] The target RDSH 1302 is further configured to assign a corresponding second IP address to the second session in response to the second creation request, where the second IPaddress is obtained through virtua- lization of an IP address of the target RDSH 1302.
[0150] The target RDSH 1302 is further configured to return the second IP address to the cloud platform 1301.
[0151] The cloud platform 1301 is further configured to return a second access response to the second client, where the second access response indicates that the second client has established the second session with the target RDSH 1302 based on the second IP address.
[0152] In a possible implementation, the cloud platform 1301 is further configured to provide a target function switch on a management interface, where the target function switch is used to enable and disable an IP virtualization function for the target RDSH 1302, and the IP virtualization function includes: enabling the RDSH to use a plurality of IP addresses obtained through vir- tualization based on IP addresses of the RDSH.
[0153] In a possible implementation, the cloud platform 1301 is further configured to: in response toobtaining first specification information for the target RDSH 1302 from the management interface of the cloud platform 1301, in a process of creating the target RDSH 1302, obtain, based on the first specification information, at least one IP address obtained through virtualization of an IP address of the target RDSH 1302, and send, to the target RDSH 1302, the at least one IP address obtained through virtualization, where the first specification information indicates at least one of the following: a quantity of IP addresses used by the target RDSH 1302 and a quantity of sessions supported by the target RDSH 1302.
[0154] The cloud platform 1301 is further configured to: in response to an IP update instruction, obtain, based on second specification information carried in the IP update instruction, an updated version of at least one IP address obtained through virtualization based on the target RDSH 1302, and send, to the target RDSH 1302, the updated version of the at least one IPaddress obtained through virtualization, where the second specification information indicates at least one of the following: a quantity of updated IP addresses used by the target RDSH 1302 and a quantity of updated sessions supported by the target RDSH 1302.
[0155] In a possible implementation, the cloud platform 1301 is configured to: compare a first quantity currently available for the target RDSH 1302 with a second quantity indicated by the second specification information; and when the second quantity is less than the first quan- tity, determine an IP address released this time, and obtain, based on the IP address released this time, the updated version of the at least one IP address obtained through virtualization based on an IP ad- dress of the RDSH; or when the second quantity is greater than the first quantity, determine a virtualized IP address that is newly applied for this time, and obtain, based on the virtualized IP address that is newly applied for this time, the updatedversion of at least one IP address obtained through virtualization.
[0156] In a possible implementation, the cloud platform 1301 is configured to perform at least one of the following: The cloud platform 1301 triggers the IP update instruction in response to obtaining the second specification infor- mation for the target RDSH 1302 from the management interface of the cloud platform 1301; and the cloud platform 1301 triggers the IP update instruction in response to detecting that usage of the target RDSH 1302 on the cloud platform 1301 meets an update con- dition.
[0157] In a possible implementation, the target RDSH 1302 is further configured to: in response to a deregistration request of the first client for the first session, release the first IP address assigned to the first session.
[0158] In a possible implementation, the target RDSH 1302 is further configured to: in response to a network service request initiated by the first client through the first session, process the networkservice request based on the first IP address.
[0159] The cloud platform 1301 and the target RDSH 1302 are equivalent to functional modules deployed in the address assignment system, and both may be im- plemented by using software or hardware. For example, the following uses the cloud platform 1301 as an example to describe an implementation of the cloud platform 1301. Similarly, for an implementation of the target RDSH 1302, refer to the implementation of the cloud platform 1301.
[0160] According to the foregoing technical solution, remote desktop IP virtualization is implemented in a public cloud service, so that when a client accesses an 5 10 15 20 25 30 35 40 45 50 55 15 27 EP 4 683 300 A1 28 RDSH on a cloud platform, the RDSH can assign an IP address to the client based on a plurality of IP addresses obtained through virtualization. In this way, different cli- ents can use different IP addresses to obtain network services through a same RDSH, thereby ensuring secur- ity, privacy,and scalability of the network services.
[0161] Further, in the foregoing technical solution, for a function of updating an IP address, an active update initiation manner and a passive update initiation manner are provided for the RDSH, so that scenarios such as a product change on a business side and availability main- tenance on a service side can be covered, IP address utilization efficiency is effectively improved, and it is en- sured that a quantity of IP addresses meets a service requirement of a product.
[0162] The functional module is used as an example of a software functional unit, and the cloud platform 1301 may include code running on a computing instance. The computing instance may include at least one of a physical host (a computing device), a virtual machine, and a container. Further, there may be one or more computing instances. For example, the cloud platform 1301 may include code running on a plurality of hosts / virtual ma- chines / containers. It should be noted thatthe plurality of hosts / virtual machines / containers used to run the code may be distributed in a same region (region) or different regions. Further, the plurality of hosts / virtual machines / - containers used to run the code may be distributed in a same availability zone (availability zone, AZ) or different AZs. Each AZ includes one data center or a plurality of data centers that are geographically close to each other. Generally, one region may include a plurality of AZs.
[0163] Similarly, the plurality of hosts / virtual machi- nes / containers used to run the code may be distributed on a same virtual private cloud (virtual private cloud, VPC) or a plurality of VPCs. Generally, one VPC is set in one region, and a communication gateway needs to be set in each VPC for cross-region communication be- tween two VPCs in a same region and between VPCs in different regions. The VPCs are interconnected through the communication gateway.
[0164] The module is used as an example of a hard- warefunctional unit, and the cloud platform 1301 may include at least one computing device, for example, a server. Alternatively, the cloud platform 1301 may be a device implemented by using an application-specific in- tegrated circuit (application-specific integrated circuit, ASIC), a programmable logic device (programmable lo- gic device, PLD), or the like. The PLD may be a complex programmable logic device (complex programmable lo- gic device, CPLD), a field-programmable gate array (field-programmable gate array, FPGA), a generic array logic (generic array logic, GAL), or any combination thereof.
[0165] A plurality of computing devices included in the cloud platform 1301 may be distributed in a same region or different regions. The plurality of computing devices included in the cloud platform 1301 may be distributed in a same AZ or different AZs. Similarly, the plurality of computing devices included in the cloud platform 1301 may be distributed in a same VPC or a plurality of VPCs. Theplurality of computing devices may be any combina- tion of computing devices such as a server, an ASIC, a PLD, a CPLD, an FPGA, or GAL.
[0166] It should be noted that, in another embodiment, the cloud platform 1301 and the target RDSH 1302 may be configured to perform any step in the IP address assignment method, steps that the cloud platform 1301 and the target RDSH 1302 are responsible for imple- menting may be specified based on a requirement, and the cloud platform 1301 and the target RDSH 1302 separately implement different steps in the IP address assignment method, to implement all functions of the address assignment system. That is, when the address assignment system provided in the foregoing embodi- ment implements corresponding steps, division of the foregoing functional modules is merely used as an ex- ample for description. In actual application, the foregoing functions may be allocated to different functional mod- ules for implementation based on a requirement, that is, aninternal structure of an apparatus is divided into dif- ferent functional modules, to complete all or some of the functions described above. In addition, the address as- signment system provided in the foregoing embodiment and the IP address assignment method embodiment belong to a same idea. For a specific implementation process of the address assignment system, refer to the method embodiment. Details are not described herein again.
[0167] The following describes a hardware structure of a computing device in embodiments of this application.
[0168] An embodiment of this application provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device may be a server, for example, a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device may alterna- tively be a terminal device, for example, a desktop com- puter, a notebook computer, or a smartphone.
[0169] An embodimentof this application provides a computing device that can be configured as a computing device included in the foregoing computing device clus- ter. For example, FIG. 14 is a diagram of a hardware structure of a computing device according to an embodi- ment of this application. As shown in FIG. 14, a comput- ing device 1400 includes a memory 1401, a processor 1402, a communication interface 1403, and a bus 1404. The memory 1401, the processor 1402, and the commu- nication interface 1403 are communicatively connected to each other through the bus 1404.
[0170] The memory 1401 may be a read-only memory (read-only memory, ROM) or another type of static sto- rage device that can store static information and instruc- tions, a random access memory (random access mem- ory, RAM) or another type of dynamic storage device that can store information and instructions, an electrically 5 10 15 20 25 30 35 40 45 50 55 16 29 EP 4 683 300 A1 30 erasable programmable read-only memory (electrically erasableprogrammable read-only memory, EEPROM), a compact disc read-only memory (compact disc read- only memory, CD-ROM) or another optical disk storage, an optical disc storage (including a compact disc, a laser disc, an optical disc, a digital versatile disc, a Blu-ray disc, and the like), a magnetic disk storage medium or another magnetic storage device, or any other medium that can carry or store expected program code in a form of an instruction or a data structure and that can be accessed by a computer. This is not limited thereto. The processor 1402 implements the method in the foregoing or the following embodiments by reading program code stored in the memory 1401, or the processor 1402 implements the IP address assignment method in the foregoing or the following embodiments by using internally stored pro- gram code. When the processor 1402 implements the IP address assignment method in the foregoing or the fol- lowing embodiments by reading the program code stored in the memory 1401,the memory 1401 stores program code used to implement the IP address assignment method provided in embodiments of this application.
[0171] The processor 1402 may be a network proces- sor (network processor, NP), a central processing unit (central processing unit, CPU), an application-specific integrated circuit (application-specific integrated circuit, ASIC), or an integrated circuit configured to control pro- gram execution of the solutions of this application. The processor 1402 may be a single-core (single-CPU) pro- cessor, or may be a multi-core (multi-CPU) processor. There may be one or more processors 1402. The com- munication interface 1403 uses a transceiver module such as a transceiver, to implement communication be- tween the computing device 1400 and another device or a communication network. For example, a request sent by a client may be obtained through the communication interface 1403.
[0172] The memory 1401 and the processor 1402 may be disposed separately, or may beintegrated together.
[0173] The bus 1404 may include a path for transmit- ting information between components (for example, the memory 1401, the processor 1402, and the communica- tion interface 1403) of the computing device 1400.
[0174] Memories in one or more computing devices in the computing device cluster may store the same instruc- tions used to perform the IP address assignment method provided in this application. In some possible implemen- tations, the memories in the one or more computing devices in the computing device cluster may alternatively store some instructions used to perform the IP address assignment method provided in this application. In other words, a combination of one or more computing devices may jointly execute instructions used to perform the IP address assignment method provided in this application.
[0175] In some possible implementations, the one or more computing devices in the computing device cluster may be connected through a network. The network may bea wide area network, a local area network, or the like. FIG. 15 is a diagram of a computing device cluster according to an embodiment of this application. Refer to FIG. 15. One or more computing devices 1400 in the computing device cluster are connected through a net- work. For descriptions of the computing device 1400, refer to the foregoing descriptions. Details are not de- scribed herein again.
[0176] It should be noted that information (including but not limited to user equipment information, personal in- formation of a user, and the like), data (including but not limited to data used for analysis, stored data, displayed data, and the like), and signals in this application are all authorized by a user or fully authorized by all parties, and collection, use, and processing of related data need to conform to related laws, regulations, and standards of related countries and regions. For example, information such as an IP address and a user credential in this application is obtainedunder full authorization.
[0177] In this application, terms such as "first" and "second" are used to distinguish between same items or similar items that have basically same functions. It should be understood that there is no logical or time sequence dependency between "first", "second", and "nth", and a quantity and an execution sequence are not limited either. It should also be understood that although the following descriptions use terms such as "first" and "second" to describe various elements, these elements should not be limited by the terms. These terms are merely used to distinguish one element from another. For example, without departing from the scope of the various examples, a first IP address may be referred to as a second IP address, and similarly, a second IP address may be referred to as a first IP address. Both the first IP address and the second IP address may be IP ad- dresses, and in some cases, may be separate and dif- ferent IP addresses.
[0178] In thisapplication, the term "at least one" means one or more, and the term "a plurality of" means two or more. For example, a plurality of IP addresses means two or more IP addresses.
[0179] The foregoing descriptions are merely specific implementations of this application, but are not intended to limit the protection scope of this application. Any equivalent modification or replacement readily figured out by persons skilled in the art within the technical scope disclosed in this application shall fall within the protection scope of this application. Therefore, the protection scope of this application shall be subject to the protection scope of the claims.
[0180] All or some of the foregoing embodiments may be implemented by using software, hardware, firmware, or any combination thereof. When software is used to implement embodiments, embodiments may be imple- mented completely or partially in a form of a program product. The program product includes one or more program instructions. Whenthe program instructions are loaded and executed on a computing device, the procedures or functions according to embodiments of 5 10 15 20 25 30 35 40 45 50 55 17 31 EP 4 683 300 A1 32 this application are all or partially generated.
[0181] Persons of ordinary skill in the art may under- stand that all or some of the steps of embodiments may be implemented by hardware or a program instructing related hardware. The program may be stored in a com- puter-readable storage medium. The storage medium may include a read-only memory, a magnetic disk, or an optical disc.
[0182] In conclusion, the foregoing embodiments are merely intended for describing the technical solutions of this application, but not for limiting this application. Although this application is described in detail with re- ference to the foregoing embodiments, persons of ordin- ary skill in the art should understand that they may still make modifications to the technical solutions described in the foregoing embodiments ormake equivalent repla- cements to some technical features thereof, without de- parting from the scope of the technical solutions of em- bodiments of this application. Claims 1. An internet protocol IP address assignment method, wherein the method is applied to an address assign- ment system, the address assignment system com- prises a cloud platform and a remote desktop ses- sion host RDSH, and the cloud platform is configured to provide a public cloud service; and the method comprises: receiving, by the cloud platform, a first creation request sent by a first client, and forwarding the first creation request to a target RDSH, wherein the first creation request is used to request to establish a first session with the target RDSH; assigning, by the target RDSH, a corresponding first IP address to the first session in response to the first creation request, wherein the first IP address is obtained through virtualization of an IP address of the target RDSH; returning, by the target RDSH,the first IP ad- dress to the cloud platform; and returning, by the cloud platform, a first access response to the first client, wherein the first access response indicates that the first client has established the first session with the target RDSH based on the first IP address. 2. The method according to claim 1, wherein the meth- od further comprises: receiving, by the cloud platform, a second crea- tion request sent by a second client, and for- warding the second creation request to the tar- get RDSH, wherein the second creation request is used to request to establish a second session with the target RDSH; assigning, by the target RDSH, a corresponding second IP address to the second session in response to the second creation request, wherein the second IP address is obtained through virtualization of an IP address of the target RDSH; returning, by the target RDSH, the second IP address to the cloud platform; and returning, by the cloud platform, a second ac- cess response to thesecond client, wherein the second access response indicates that the sec- ond client has established the second session with the target RDSH based on the second IP address. 3. The method according to claim 1 or 2, wherein the method further comprises: providing, by the cloud platform, a target function switch on a management interface, wherein the tar- get function switch is used to enable and disable an IP virtualization function for the target RDSH, and the IP virtualization function comprises: enabling the RDSH to use a plurality of IP addresses obtained through virtualization based on IP addresses of the RDSH. 4. The method according to any one of claims 1 to 3, wherein the method further comprises: in response to obtaining first specification infor- mation for the target RDSH from the manage- ment interface of the cloud platform, in a process of creating the target RDSH, obtaining, by the cloud platform based on the first specification information, at least one IP address obtainedthrough virtualization of an IP address of the target RDSH, and sending, to the target RDSH, the at least one IP address obtained through virtualization, wherein the first specification in- formation indicates at least one of the following: a quantity of IP addresses used by the target RDSH or a quantity of sessions supported by the target RDSH; and in response to an IP update instruction, obtain- ing, by the cloud platform based on second specification information carried in the IP update instruction, an updated version of at least one IP address obtained through virtualization based on the target RDSH, and sending, to the target RDSH, the updated version of the at least one IP address obtained through virtualization, where- in the second specification information indicates at least one of the following: a quantity of up- dated IP addresses used by the target RDSH and a quantity of updated sessions supported by the target RDSH. 5. The method according to claim 4, wherein obtaining, 510 15 20 25 30 35 40 45 50 55 18 33 EP 4 683 300 A1 34 by the cloud platform based on the second specifica- tion information carried in the IP update instruction, the updated version of the IP address of the target RDSH comprises: comparing a first quantity currently available for the target RDSH with a second quantity indi- cated by the second specification information; and when the second quantity is less than the first quantity, determining an IP address released this time, and obtaining, based on the IP address released this time, the updated version of the at least one IP address obtained through virtuali- zation; or when the second quantity is greater than the first quantity, determining a virtualized IP address that is newly applied for this time, and obtaining, based on the virtualized IP address that is newly applied for this time, the updated version of the at least one IP address obtained through virtua- lization. 6. The method according to claim 4 or 5, wherein the methodfurther comprises at least one of the follow- ing: triggering, by the cloud platform, the IP update instruction in response to obtaining the second specification information for the target RDSH from the management interface of the cloud platform; and triggering, by the cloud platform, the IP update instruction in response to detecting that usage of the target RDSH on the cloud platform meets an update condition. 7. The method according to any one of claims 1 to 6, wherein the method further comprises: in response to a deregistration request of the first client for the first session, releasing, by the target RDSH, the first IP address assigned to the first session. 8. The method according to any one of claims 1 to 7, wherein the method further comprises: in response to a network service request initiated by the first client through the first session, processing, by the target RDSH, the network service request based on the first IP address. 9. An address assignment system, wherein thead- dress assignment system comprises a cloud plat- form and a remote desktop session host RDSH, and the cloud platform is configured to provide a public cloud service; the cloud platform is configured to: receive a first creation request sent by a first client, and for- ward the first creation request to a target RDSH, wherein the first creation request is used to request to establish a first session with the target RDSH; the target RDSH is configured to assign a cor- responding first IP address to the first session in response to the first creation request, wherein the first IP address is obtained through virtuali- zation of an IP address of the target RDSH; the target RDSH is configured to return the first IP address to the cloud platform; and the cloud platform is configured to return a first access response to the first client, wherein the first access response indicates that the first client has established the first session with the target RDSH based on the first IP address. 10.The system according to claim 9, wherein the cloud platform is further configured to: receive a second creation request sent by a second client, and forward the second creation request to the target RDSH, wherein the second creation request is used to re- quest to establish a second session with the target RDSH; the target RDSH is further configured to assign a corresponding second IP address to the second session in response to the second creation re- quest, wherein the second IP address is ob- tained through virtualization of an IP address of the target RDSH; the target RDSH is further configured to return the second IP address to the cloud platform; and the cloud platform is further configured to return a second access response to the second client, wherein the second access response indicates that the second client has established the sec- ond session with the target RDSH based on the second IP address. 11. The system according to claim 9 or 10, wherein the cloud platform isfurther configured to provide a target function switch on a management interface, wherein the target function switch is used to enable and disable an IP virtualization function for the target RDSH, and the IP virtualization function comprises: enabling the RDSH to use a plurality of IP addresses obtained through virtualization based on IP ad- dresses of the RDSH. 12. The system according to any one of claims 9 to 11, wherein the cloud platform is further configured to: in response to obtaining first specification information for the target RDSH from the management interface of the cloud platform, in a process of creating the target RDSH, obtain, based on the first specification information, at least one IP address obtained 5 10 15 20 25 30 35 40 45 50 55 19 35 EP 4 683 300 A1 36 through virtualization of an IP address of the target RDSH, and send, to the target RDSH, the at least one IP address obtained through virtualization, wherein the first specification information indicates atleast one of the following: a quantity of IP ad- dresses used by the target RDSH and a quantity of sessions supported by the target RDSH; and the cloud platform is further configured to: in re- sponse to an IP update instruction, obtain, based on second specification information carried in the IP update instruction, an updated version of at least one IP address obtained through virtualization based on the target RDSH, and send, to the target RDSH, the updated version of the at least one IP address ob- tained through virtualization, wherein the second specification information indicates at least one of the following: a quantity of updated IP addresses used by the target RDSH and a quantity of updated sessions supported by the target RDSH. 13. The system according to claim 12, wherein that the cloud platform obtains, based on the second speci- fication information carried in the IP update instruc- tion, the updated version of the IP address of the target RDSH comprises: comparing a firstquantity currently available for the target RDSH with a second quantity indi- cated by the second specification information; and when the second quantity is less than the first quantity, determining an IP address released this time, and obtaining, based on the IP address released this time, the updated version of the at least one IP address obtained through virtuali- zation; or when the second quantity is greater than the first quantity, determining a virtualized IP address that is newly applied for this time, and obtaining, based on the virtualized IP address that is newly applied for this time, the updated version of the at least one IP address obtained through virtua- lization. 14. The system according to claim 12 or 13, wherein the cloud platform is further configured to perform at least one of the following: triggering the IP update instruction in response to obtaining the second specification informa- tion for the target RDSH from the management interface of the cloud platform;and triggering the IP update instruction in response to detecting that usage of the target RDSH on the cloud platform meets an update condition. 15. The system according to any one of claims 9 to 14, wherein the target RDSH is further configured to: in response to a deregistration request of the first client for the first session, release, for the target RDSH, the first IP address assigned to the first session. 16. The system according to any one of claims 9 to 15, wherein the target RDSH is further configured to: in response to a network service request initiated by the first client through the first session, process, for the target RDSH, the network service request based on the first IP address. 17. A computing device cluster, comprising at least one computing device, wherein each computing device comprises a processor and a memory; and a processor of the at least one computing device is configured to execute instructions stored in a mem- ory of the at least one computing device, tocause the computing device cluster to perform the IP address assignment method according to any one of claims 1 to 8. 18. A computer-readable storage medium, comprising computer program instructions, wherein when the computer program instructions are executed by a computing device cluster, the computing device cluster performs the IP address assignment method according to any one of claims 1 to 8. 19. A computer program product comprising instruc- tions, wherein when the instructions are run by a computing device cluster, the computing device cluster is caused to perform the IP address assign- ment method according to any one of claims 1 to 8. 5 10 15 20 25 30 35 40 45 50 55 20 EP 4 683 300 A1 21 EP 4 683 300 A1 22 EP 4 683 300 A1 23 EP 4 683 300 A1 24 EP 4 683 300 A1 25 EP 4 683 300 A1 26 EP 4 683 300 A1 27 EP 4 683 300 A1 28 EP 4 683 300 A1 29 EP 4 683 300 A1 30 EP 4 683 300 A1 31 EP 4 683 300 A1 32 EP 4 683 300 A1 33 EP 4 683 300 A1 34 EP 4 683 300 A1 5 10 15 20 25 30 35 40 45 50 5535 EP 4 683 300 A1 5 10 15 20 25 30 35 40 45 50 55 36 EP 4 683 300 A1 REFERENCES CITED IN THE DESCRIPTION This list of references cited by the applicant is for the reader’s convenience only. It does not form part of the European patent document. Even though great care has been taken in compiling the references, errors or omissions cannot be excluded and the EPO disclaims all liability in this regard. Patent documents cited in the description • CN 202310323110
[0001]
Claims
1. An internet protocol IP address assignment method, wherein the method is applied to an address assignment system, the address assignment system comprises a cloud platform and a remote desktop session host RDSH, and the cloud platform is configured to provide a public cloud service; and the method comprises: receiving, by the cloud platform, a first creation request sent by a first client, and forwarding the first creation request to a target RDSH, wherein the first creation request is used to request to establish a first session with the target RDSH; assigning, by the target RDSH, a corresponding first IP address to the first session in response to the first creation request, wherein the first IP address is obtained through virtualization of an IP address of the target RDSH; returning, by the target RDSH, the first IP address to the cloud platform; and returning, by the cloud platform, a first access response to the first client, wherein the first access response indicates that the first client has established the first session with the target RDSH based on the first IP address.
2. The method according to claim 1, wherein the method further comprises: receiving, by the cloud platform, a second creation request sent by a second client, and forwarding the second creation request to the target RDSH, wherein the second creation request is used to request to establish a second session with the target RDSH; assigning, by the target RDSH, a corresponding second IP address to the second session in response to the second creation request, wherein the second IP address is obtained through virtualization of an IP address of the target RDSH; returning, by the target RDSH, the second IP address to the cloud platform; and returning, by the cloud platform, a second access response to the second client, wherein the second access response indicates that the second client has established the second session with the target RDSH based on the second IP address.
3. The method according to claim 1 or 2, wherein the method further comprises: providing, by the cloud platform, a target function switch on a management interface, wherein the target function switch is used to enable and disable an IP virtualization function for the target RDSH, and the IP virtualization function comprises: enabling the RDSH to use a plurality of IP addresses obtained through virtualization based on IP addresses of the RDSH.
4. The method according to any one of claims 1 to 3, wherein the method further comprises: in response to obtaining first specification information for the target RDSH from the management interface of the cloud platform, in a process of creating the target RDSH, obtaining, by the cloud platform based on the first specification information, at least one IP address obtained through virtualization of an IP address of the target RDSH, and sending, to the target RDSH, the at least one IP address obtained through virtualization, wherein the first specification information indicates at least one of the following: a quantity of IP addresses used by the target RDSH or a quantity of sessions supported by the target RDSH; and in response to an IP update instruction, obtaining, by the cloud platform based on second specification information carried in the IP update instruction, an updated version of at least one IP address obtained through virtualization based on the target RDSH, and sending, to the target RDSH, the updated version of the at least one IP address obtained through virtualization, wherein the second specification information indicates at least one of the following: a quantity of updated IP addresses used by the target RDSH and a quantity of updated sessions supported by the target RDSH.
5. The method according to claim 4, wherein obtaining, by the cloud platform based on the second specification information carried in the IP update instruction, the updated version of the IP address of the target RDSH comprises: comparing a first quantity currently available for the target RDSH with a second quantity indicated by the second specification information; and when the second quantity is less than the first quantity, determining an IP address released this time, and obtaining, based on the IP address released this time, the updated version of the at least one IP address obtained through virtualization; or when the second quantity is greater than the first quantity, determining a virtualized IP address that is newly applied for this time, and obtaining, based on the virtualized IP address that is newly applied for this time, the updated version of the at least one IP address obtained through virtualization.
6. The method according to claim 4 or 5, wherein the method further comprises at least one of the following: triggering, by the cloud platform, the IP update instruction in response to obtaining the second specification information for the target RDSH from the management interface of the cloud platform; and triggering, by the cloud platform, the IP update instruction in response to detecting that usage of the target RDSH on the cloud platform meets an update condition.
7. The method according to any one of claims 1 to 6, wherein the method further comprises: in response to a deregistration request of the first client for the first session, releasing, by the target RDSH, the first IP address assigned to the first session.
8. The method according to any one of claims 1 to 7, wherein the method further comprises: in response to a network service request initiated by the first client through the first session, processing, by the target RDSH, the network service request based on the first IP address.
9. An address assignment system, wherein the address assignment system comprises a cloud platform and a remote desktop session host RDSH, and the cloud platform is configured to provide a public cloud service; the cloud platform is configured to: receive a first creation request sent by a first client, and forward the first creation request to a target RDSH, wherein the first creation request is used to request to establish a first session with the target RDSH; the target RDSH is configured to assign a corresponding first IP address to the first session in response to the first creation request, wherein the first IP address is obtained through virtualization of an IP address of the target RDSH; the target RDSH is configured to return the first IP address to the cloud platform; and the cloud platform is configured to return a first access response to the first client, wherein the first access response indicates that the first client has established the first session with the target RDSH based on the first IP address.
10. The system according to claim 9, wherein the cloud platform is further configured to: receive a second creation request sent by a second client, and forward the second creation request to the target RDSH, wherein the second creation request is used to request to establish a second session with the target RDSH; the target RDSH is further configured to assign a corresponding second IP address to the second session in response to the second creation request, wherein the second IP address is obtained through virtualization of an IP address of the target RDSH; the target RDSH is further configured to return the second IP address to the cloud platform; and the cloud platform is further configured to return a second access response to the second client, wherein the second access response indicates that the second client has established the second session with the target RDSH based on the second IP address.
11. The system according to claim 9 or 10, wherein the cloud platform is further configured to provide a target function switch on a management interface, wherein the target function switch is used to enable and disable an IP virtualization function for the target RDSH, and the IP virtualization function comprises: enabling the RDSH to use a plurality of IP addresses obtained through virtualization based on IP addresses of the RDSH.
12. The system according to any one of claims 9 to 11, wherein the cloud platform is further configured to: in response to obtaining first specification information for the target RDSH from the management interface of the cloud platform, in a process of creating the target RDSH, obtain, based on the first specification information, at least one IP address obtained through virtualization of an IP address of the target RDSH, and send, to the target RDSH, the at least one IP address obtained through virtualization, wherein the first specification information indicates at least one of the following: a quantity of IP addresses used by the target RDSH and a quantity of sessions supported by the target RDSH; and the cloud platform is further configured to: in response to an IP update instruction, obtain, based on second specification information carried in the IP update instruction, an updated version of at least one IP address obtained through virtualization based on the target RDSH, and send, to the target RDSH, the updated version of the at least one IP address obtained through virtualization, wherein the second specification information indicates at least one of the following: a quantity of updated IP addresses used by the target RDSH and a quantity of updated sessions supported by the target RDSH.
13. The system according to claim 12, wherein that the cloud platform obtains, based on the second specification information carried in the IP update instruction, the updated version of the IP address of the target RDSH comprises: comparing a first quantity currently available for the target RDSH with a second quantity indicated by the second specification information; and when the second quantity is less than the first quantity, determining an IP address released this time, and obtaining, based on the IP address released this time, the updated version of the at least one IP address obtained through virtualization; or when the second quantity is greater than the first quantity, determining a virtualized IP address that is newly applied for this time, and obtaining, based on the virtualized IP address that is newly applied for this time, the updated version of the at least one IP address obtained through virtualization.
14. The system according to claim 12 or 13, wherein the cloud platform is further configured to perform at least one of the following: triggering the IP update instruction in response to obtaining the second specification information for the target RDSH from the management interface of the cloud platform; and triggering the IP update instruction in response to detecting that usage of the target RDSH on the cloud platform meets an update condition.
15. The system according to any one of claims 9 to 14, wherein the target RDSH is further configured to: in response to a deregistration request of the first client for the first session, release, for the target RDSH, the first IP address assigned to the first session.
16. The system according to any one of claims 9 to 15, wherein the target RDSH is further configured to: in response to a network service request initiated by the first client through the first session, process, for the target RDSH, the network service request based on the first IP address.
17. A computing device cluster, comprising at least one computing device, wherein each computing device comprises a processor and a memory; and a processor of the at least one computing device is configured to execute instructions stored in a memory of the at least one computing device, to cause the computing device cluster to perform the IP address assignment method according to any one of claims 1 to 8.
18. A computer-readable storage medium, comprising computer program instructions, wherein when the computer program instructions are executed by a computing device cluster, the computing device cluster performs the IP address assignment method according to any one of claims 1 to 8.
19. A computer program product comprising instructions, wherein when the instructions are run by a computing device cluster, the computing device cluster is caused to perform the IP address assignment method according to any one of claims 1 to 8.