High availability network connection method and electronic device using the same

eBPF modules and synchronization modules track and synchronize connection information across load balancers, ensuring high availability and effective network control.

JP7730187B2Active Publication Date: 2025-08-27NETLOX CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2023218912
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2023-05-24
Filing Date
2023-12-26
Publication Date
2025-08-27
Estimated Expiration
2043-12-26

AI Technical Summary

Technical Problem

Existing network systems lack efficient methods to synchronize packet connection information between load balancers and maintain connection status, hindering the creation of a highly available network infrastructure.

Method used

Utilizing eBPF modules to track and synchronize connection information, including source and destination IP addresses, port numbers, and protocol states, across load balancers, with synchronization modules monitoring and updating ConnTrack maps to ensure seamless communication.

Benefits of technology

Enables load balancers to synchronize packet connection information, monitor connection status, and maintain high availability, allowing cloud master nodes to control network connections effectively.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007730187000001
    Figure 0007730187000001
  • Figure 0007730187000002
    Figure 0007730187000002
  • Figure 0007730187000003
    Figure 0007730187000003
Patent Text Reader

Abstract

To provide a high-availability network connection method to be used to maintain the connection state by using an eBPF to synchronize packet connection information between load balancers and monitor each connection state, and to provide an electronic device using the same.SOLUTION: A traffic flow of a first load balancer comprises: an operation of receiving untracked new traffic from a client using a first eBPF module 411; an operation 713 of adding an entry corresponding to the new traffic to a Conn Track map in response to the operation of receiving the new traffic; an operation 715 of reporting the addition of the entry to a first synchronization module; and an operation 723 of monitoring a first connection corresponding to the new traffic using the first synchronization module.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Various embodiments of the present invention relate to a highly available network connection method and an electronic device using the same. [Background technology]

[0002] In the current hot topic of the fourth industry, various types of data can be hyper-connected through various devices. In this environment, the market for innovative convergence new products and service solutions that reflect user needs can expand, and for this, it may be necessary to build a network infrastructure that can process various types of data without loss. Summary of the Invention [Problem to be solved by the invention]

[0003] Using eBPF, packet connection information between load balancers can be synchronized, and each connection status can be monitored and maintained. In addition, the cloud master node can control the load balancers and packet connections between the cloud and external networks. This allows for the creation of a highly available network system. [Means for solving the problem]

[0004] According to various embodiments, in an electronic device method, a first eBPF module is configured to receive data from a client that is not tracked. have properties receiving new traffic; adding an entry corresponding to the new traffic to a ConnTrack map in response to receiving the new traffic in the first eBPF module; reporting the addition of the entry to a first synchronization module in the first eBPF module; and monitoring a first connection corresponding to the new traffic in the first synchronization module. and the act of adding the entry includes an act of updating the ConnTrack map with at least one of a source IP address (SIP), a destination IP address (DIP), a source port number (Sport), a destination port number (Dport), a protocol, or a state corresponding to the new traffic. It is possible.

[0005] According to various embodiments, a method of an external electronic device includes an operation of receiving first connectivity information from a first synchronization module of an electronic device in a cluster via a second synchronization module of the external electronic device; an operation of the second synchronization module requesting a second eBPF module of the external electronic device to update the first connectivity information to a Conntrack map of the external electronic device; and an operation of the second eBPF module updating the first connectivity information to the Conntrack map. The first connection information includes at least one of a source IP address (SIP), a destination IP address (DIP), a source port number (Sport), a destination port number (Dport), a protocol, or a state corresponding to new traffic that is not tracked by a client. It is possible.

[0006] According to various embodiments, in a cluster system including a client, an electronic device, an external electronic device, and a cloud server, the electronic device is not tracked by the client. have properties The electronic device may receive new traffic; add an entry corresponding to the new traffic by the electronic device; transmit connection information corresponding to the entry to an external electronic device by the electronic device; and store and synchronize the connection information with the external electronic device. and the act of adding the entry includes an act of updating at least one of a source IP address (SIP), a destination IP address (DIP), a source port number (Sport), a destination port number (Dport), a protocol, or a state corresponding to the new traffic in the ConnTrack map. It is possible. [Effects of the Invention]

[0007] According to various embodiments of the present invention, the load balancer can synchronize packet connection information between each load balancer using eBPF, monitor each connection status, and maintain the connection status. Also, the master node of the cloud can control the load balancer and control packet connection between the cloud and an external network. This allows for the construction of a highly available network system. [Brief explanation of the drawings]

[0008] [Figure 1] 1 is a block diagram of an electronic device in a network environment according to various embodiments of the present invention. [Figure 2] 1 is a diagram of a highly available network system according to various embodiments of the present invention. [Figure 3] 1 is a diagram illustrating a load balancer according to various embodiments of the present invention; [Figure 4] 10 is a diagram illustrating a method for tracking new connections of a load balancer according to various embodiments of the present invention. [Figure 5] 10 is a diagram illustrating a method for a load balancer to synchronize with another load balancer according to various embodiments of the present invention. [Figure 6] 4 is a diagram illustrating a traffic flow of a first load balancer according to various embodiments of the present invention; [Figure 7] 10 is a diagram illustrating a traffic flow of a second load balancer according to various embodiments of the present invention. [Figure 8] 1 illustrates a high availability network connection of a network system according to various embodiments of the present invention. [Figure 9] 1 is a diagram showing a conventional network system. [Figure 10] 1 is a diagram illustrating a network system using eBPF according to various embodiments of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0009] 1 is a block diagram of an electronic device 101 in a network environment 100 according to various embodiments. Referring to FIG. 1 , in the network environment 100, the electronic device 101 can communicate with an electronic device 102 via a first network 198 (e.g., a short-range wireless communication network) or with an electronic device 104 or a server 108 via a second network 199 (e.g., a long-range wireless communication network). According to one embodiment, the electronic device 101 can communicate with the electronic device 104 via the server 108. According to one embodiment, the electronic device 101 can include a processor 120, a memory 130, an input device 150, an audio output device 155, a display device 160, an audio module 170, a sensor module 176, an interface 177, a haptic module 179, a camera module 180, a power management module 188, a battery 189, a communication module 190, a subscriber identity module 196, or an antenna module 197. In some embodiments, electronic device 101 may omit at least one of these components (e.g., display device 160 or camera module 180) or may include one or more additional components. In some embodiments, some of these components may be implemented as a single integrated circuit. For example, sensor module 176 (e.g., a fingerprint sensor, iris sensor, or illuminance sensor) may be implemented as embedded in display device 160 (e.g., a display).

[0010] The processor 120 may, for example, execute software (e.g., program 140) to control at least one other component (e.g., a hardware or software component) of the electronic device 101 coupled to the processor 120, and may perform various data processing or computations. According to one embodiment, as at least part of the data processing or computation, the processor 120 may load instructions or data received from another component (e.g., the sensor module 176 or the communication module 190) into the volatile memory 132, process the instructions or data stored in the volatile memory 132, and store the resulting data in the non-volatile memory 134. According to one embodiment, the processor 120 may include a main processor 121 (e.g., a central processing unit or application processor) and an auxiliary processor 123 (e.g., a graphics processing unit, an image signal processor, a sensor hub processor, or a communication processor) that may operate independently or together with the main processor 121. Additionally or alternatively, the auxiliary processor 123 may be configured to use less power than the main processor 121 or to be specialized for a designated function. The auxiliary processor 123 may be embodied separately from the main processor 121 or as part of it.

[0011] The auxiliary processor 123 may control at least a portion of the functions or states associated with at least one component (e.g., the display device 160, the sensor module 176, or the communication module 190) of the electronic device 101, either in place of the main processor 121 while the main processor 121 is in an inactive (e.g., sleep) state, or together with the main processor 121 while the main processor 121 is in an active (e.g., application execution) state. According to one embodiment, the auxiliary processor 123 (e.g., an image signal processor or a communication processor) may be embodied as part of another component (e.g., the camera module 180 or the communication module 190) to which it is functionally related.

[0012] The memory 130 may store various data used by at least one component (e.g., the processor 120 or the sensor module 176) of the electronic device 101. The data may include, for example, input data or output data for software (e.g., the program 140) and associated instructions. The memory 130 may include a volatile memory 132 or a non-volatile memory 134.

[0013] The programs 140 may be stored as software in the memory 130 and may include, for example, an operating system 142 , middleware 144 or applications 146 .

[0014] The input device 150 can receive instructions or data from outside (e.g., a user) the electronic device 101 for use by components (e.g., the processor 120) of the electronic device 101. The input device 150 can include, for example, a microphone, a mouse, or a keyboard.

[0015] The audio output device 155 can output an audio signal to the outside of the electronic device 101. The audio output device 155 can include, for example, a speaker or a receiver. The speaker can be used for general purposes such as multimedia playback or recording and playback, and the receiver can be used to receive incoming calls. According to an embodiment, the receiver can be embodied separately from the speaker or as part of the speaker.

[0016] The display device 160 may visually provide information to an external device (e.g., a user) of the electronic device 101. The display device 160 may include, for example, a display, a holographic device, or a projector, and control circuitry for controlling the device. According to one embodiment, the display device 160 may include touch circuitry configured to sense a touch or a sensor circuit (e.g., a pressure sensor) configured to measure the strength of a force generated by the touch.

[0017] The audio module 170 can convert sound into an electrical signal or vice versa. According to one embodiment, the audio module 170 can acquire sound via the input device 150 or output sound via the audio output device 155 or an external electronic device (e.g., electronic device 102) (e.g., a speaker or headphones) directly or wirelessly connected to the electronic device 101.

[0018] The sensor module 176 may sense an operating state (e.g., power or temperature) of the electronic device 101 or an external environmental state (e.g., user state) and generate an electrical signal or data value corresponding to the sensed state. According to one embodiment, the sensor module 176 may include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0019] The interface 177 may support one or more specified protocols that can be used to directly or wirelessly connect the electronic device 101 to an external electronic device (e.g., the electronic device 102). According to one embodiment, the interface 177 may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0020] The connection terminal 178 may include a connector through which the electronic device 101 may be physically connected to an external electronic device (e.g., the electronic device 102). According to one embodiment, the connection terminal 178 may include, for example, an HDMI (registered trademark) connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0021] Haptic module 179 can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through touch or kinesthetic sensation. According to one embodiment, haptic module 179 can include, for example, a motor, a piezoelectric element, or an electrical stimulator.

[0022] Camera module 180 can capture still and video images. According to one embodiment, camera module 180 can include one or more lenses, an image sensor, an image signal processor, or a flash.

[0023] The power management module 188 may manage the power supplied to the electronic device 101. According to one embodiment, the power management module 188 may be embodied as at least a part of a power management integrated circuit (PMIC), for example.

[0024] Battery 189 can provide power to at least one component of electronic device 101. According to one embodiment, battery 189 can include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0025] Communications module 190 can facilitate establishing a direct (e.g., wired) or wireless communication channel between electronic device 101 and an external electronic device (e.g., electronic device 102, electronic device 104, or server 108) and conducting communication via the established communication channel. Communications module 190 can include one or more communications processors that operate independently of processor 120 (e.g., an application processor) and facilitate direct (e.g., wired) or wireless communication. According to one embodiment, communications module 190 can include wireless communication module 192 (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or wired communication module 194 (e.g., a local area network (LAN) communication module, or a power line communication module). The corresponding communication module among these communication modules can communicate with an external electronic device via a first network 198 (e.g., a short-range communication network such as Bluetooth, Wi-Fi Direct, or IrDA (infrared data association)) or a second network 199 (e.g., a long-range communication network such as a cellular network, the Internet, or a computer network (e.g., LAN or WAN)). These various communication modules can be integrated into a single component (e.g., a single chip) or embodied as multiple separate components (e.g., a separate chip). The wireless communication module 192 can identify and authenticate the electronic device 101 within a communication network, such as the first network 198 or the second network 199, using subscriber information (e.g., an International Mobile Subscriber Identity (IMSI)) stored in the subscriber identification module 196.

[0026] The antenna module 197 can transmit or receive signals or power to or from the outside (e.g., an external electronic device). According to one embodiment, the antenna module 197 can include one or more antennas, from which at least one antenna suitable for a communication method used in a communication network such as the first network 198 or the second network 199 can be selected, for example, by the communication module 190. The signals or power can be transmitted or received between the communication module 190 and the external electronic device via the selected at least one antenna.

[0027] At least some of the components are connected to each other via a peripheral communication method (e.g., a bus, a general purpose input and output (GPIO), a serial peripheral interface (SPI), or a mobile industry processor interface (MIPI)) and can exchange signals (e.g., commands or data) between them.

[0028] According to one embodiment, commands or data may be transmitted or received between the electronic device 101 and the external electronic device 104 via a server 108 connected to the second network 199. The electronic devices 102 and 104 may be the same or different types of devices as the electronic device 101. According to one embodiment, all or part of the operations performed by the electronic device 101 may be performed by one or more external devices, such as the external electronic devices 102, 104, or 108. For example, if the electronic device 101 must perform a certain function or service automatically or in response to a request from a user or another device, the electronic device 101 may request one or more external electronic devices to perform at least part of the function or service, instead of or in addition to performing the function or service itself. The one or more external electronic devices that receive the request may perform at least part of the requested function or service, or an additional function or service related to the request, and transmit the results of the execution to the electronic device 101. The electronic device 101 may process the results directly or additionally and provide them as at least part of a response to the request. For this purpose, for example, cloud computing, distributed computing, or client-server computing techniques can be utilized.

[0029] 2 is a block diagram 200 of a program 140 according to various embodiments. According to one embodiment, the program 140 may include an operating system 142 for controlling one or more resources of the electronic device 101, middleware 144, or an application 146 executable on the operating system 142. The operating system 142 may include, for example, Android™, iOS™, Windows™, Symbian™, Tizen™, or Bada™. At least some of the programs 140 may be preloaded onto the electronic device 101 at the time of manufacture, or may be downloaded or updated from an external electronic device (e.g., electronic device 102 or 104, or server 108) during a user's environment.

[0030] The operating system 142 may control (e.g., allocate or reclaim) system resources (e.g., processes, memory, or power) of the electronic device 101. The operating system 142 may additionally or alternatively include one or more driver programs for driving other hardware devices of the electronic device 101, such as the input device 150, the audio output device 155, the display device 160, the audio module 170, the sensor module 176, the interface 177, the haptic module 179, the camera module 180, the power management module 188, the battery 189, the communication module 190, the subscriber identity module 196, or the antenna module 197.

[0031] The middleware 144 may provide various functions to the application 146 so that the application 146 can use functions or information provided by one or more resources of the electronic device 101. The middleware 144 may include, for example, an application manager 201, a window manager 203, a multimedia manager 205, a resource manager 207, a power manager 209, a database manager 211, a package manager 213, a connectivity manager 215, a notification manager 217, a location manager 219, a graphics manager 221, a security manager 223, a call manager 225, or a voice recognition manager 227. The application manager 201 may, for example, manage the life cycle of the application 146. The window manager 203 may, for example, manage GUI resources used on the screen. The multimedia manager 205 may, for example, determine the format required for playback of a media file and encode or decode the media file using a codec that matches the format. The resource manager 207 may, for example, manage the source code or memory space of the application 146. The power manager 209 may manage, for example, the capacity, temperature, or power supply of a battery, and may use the information to determine or provide power information required for operation of the electronic device 101. According to one embodiment, the power manager 209 may interface with a basic input / output system (BIOS).

[0032] The database manager 211 may, for example, create, search, or modify a database used by the application 146. The package manager 213 may, for example, manage the installation or update of an application distributed in the form of a package file. The connectivity manager 215 may, for example, manage wireless or wired connections between the electronic device 101 and an external electronic device. The notification manager 217 may, for example, provide a function for notifying a user of an event (e.g., a call, a message, or an alarm). The location manager 219 may, for example, manage location information of the electronic device 101. The graphics manager 221 may, for example, manage graphic effects or associated user interfaces provided to a user. The security manager 223 may, for example, provide system security or user authentication. The telephony manager 225 may, for example, manage the voice call or video call functions of the electronic device 101. For example, the voice recognition manager 227 may transmit user voice data to the server 108 and receive commands corresponding to functions to be performed by the electronic device 101 based on the voice data or text data converted based on the voice data. According to one embodiment, the middleware 144 may dynamically delete some existing components or add new components. According to one embodiment, at least a portion of the middleware 144 may be included as part of the operating system 142 or may be implemented as software separate from the operating system 142.

[0033] The applications 146 may include, for example, a home 251, a dialer 253, an SMS / MMS 255, an instant message (IM) 257, a browser 259, a camera 261, an alarm 263, a contact 265, a voice recognition 267, an email 269, a calendar 271, a media player 273, an album 275, a watch 277, a health 279 (e.g., measuring activity or blood glucose), or an environmental information 281 (e.g., air pressure, humidity, or temperature information) application. According to one embodiment, the applications 146 may further include an information exchange application (not shown) that can support information exchange between the electronic device 101 and an external electronic device. The information exchange application may include, for example, a notification relay application for transmitting specified information (e.g., calls, messages, or alarms) to the external electronic device, or a device management application for managing the external electronic device. The notification relay application can, for example, transmit notification information corresponding to an event (e.g., received mail) that occurs in another application (e.g., email application 269) of electronic device 101 to an external electronic device, or receive notification information from an external electronic device and provide it to a user of electronic device 101. The device management application can, for example, control the power (e.g., turn on or turn off) or functions (e.g., brightness, resolution, or focus of display device 160 or camera module 180) of an external electronic device or some of its components (e.g., display device 160 or camera module 180) that communicate with electronic device 101. The device management application can additionally or alternatively support the installation, removal, or updating of applications running on the external electronic device.

[0034] Electronic devices according to various embodiments disclosed herein may take various forms. The electronic devices may include, for example, a portable communication device (e.g., a smartphone), a computing device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a consumer electronic device. The electronic devices according to embodiments of the present document are not limited to the aforementioned devices.

[0035] The various embodiments and terms used herein are not intended to limit the technical features described herein to specific embodiments, but should be understood to include various modifications, equivalents, or alternatives of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item can include one or more of the item, unless the relevant context clearly dictates otherwise. In this document, phrases such as “A or B,” “at least one of A and B,” “at least one of A or B,” “A, B, or C,” “at least one of A, B, and C,” and “at least one of A, B, or C” each include all possible combinations of the items listed in the phrase. Terms such as “first,” “second,” “primarily,” or “secondarily” are used merely to distinguish a corresponding element from other corresponding elements and do not limit the corresponding element in other aspects (e.g., importance or order). When a (e.g., first) component is referred to as being "coupled" or "connected" to another (e.g., second) component, with or without the terms "functionally" or "communicatively," it means that the component can be coupled to the other component directly (e.g., by wire), wirelessly, or through a third component.

[0036] The term "module" as used herein may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integrated component or the smallest unit or portion of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0037] Various embodiments of this document may be embodied as software (e.g., program 140) including one or more commands stored in a storage medium (e.g., internal memory 136 or external memory 138) that can be read by a machine (e.g., electronic device 101). For example, a processor (e.g., processor 120) of the machine (e.g., electronic device 101) can retrieve and execute at least one instruction from the one or more commands stored in the storage medium. This allows the machine to be operated to perform at least one function according to the retrieved at least one command. The one or more commands may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, "non-transitory" simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves). This term does not distinguish between data being stored semi-permanently and data being stored temporarily on the storage medium.

[0038] According to one embodiment, methods according to various embodiments disclosed herein may be provided in a computer program product. The computer program product may be traded as a commodity between a seller and a buyer. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., a compact disc read-only memory (CD-ROM)) or may be distributed online (e.g., downloaded or uploaded) via an application store (e.g., Play Store™) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily generated on a machine-readable storage medium, such as the memory of a manufacturer's server, an application store server, or an intermediary server.

[0039] According to various embodiments, each of the components described above (e.g., modules or programs) may include one or more entities. According to various embodiments, one or more of the components or operations may be omitted, or one or more other components or operations may be added. Alternatively or additionally, multiple components (e.g., modules or programs) may be integrated into a single component. In such cases, the integrated component may perform one or more functions of each of the multiple components in a manner that is the same as or similar to that performed by the corresponding component of the multiple components prior to the integration. According to various embodiments, operations performed by a module, program, or other component may be performed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be performed in a different order, omitted, or one or more other operations may be added.

[0040] FIG. 2 is a diagram of a highly available network system according to various embodiments of the present invention.

[0041] According to various embodiments, the highly available network system 300 may include a first load balancer 310 , a second load balancer 320 , a master node 330 , and a worker node 340 .

[0042] According to various embodiments, a load balancer may refer to a device that distributes loads applied to a cloud server, loads applied to the end of a network, or all loads applied to a cloud server and the end of a network. For example, a load balancer may synchronize packet connection information between each load balancer and monitor the status of each connection to ensure high availability. For example, a load balancer may be located between a client and a cloud server and manage traffic to prevent load concentration on a single server, allowing each server to perform optimally. For example, a load balancer may be used in a distributed processing system that provides network services using multiple servers. For example, a load balancer may activate keep-alive to reuse created connections. Because disconnecting previously created connections consumes resources, this cost can be reduced and communication can be made faster.

[0043] According to various embodiments, a cloud controller manager (CCM) 330 may control the connection status between the cloud server and the load balancer as a master node. For example, the cloud controller manager 330 may correspond to the Loxi-ccm solution. For example, the cloud controller manager 330 may act as the brain of a cluster consisting of multiple servers and perform tasks such as container scheduling, service management, and API request processing.

[0044] According to various embodiments, the node component 340 may manage container runtime and monitor status on a worker node to execute workloads reserved for the node. The node component 340 may route network traffic between pods on different nodes and between pods and the Internet on a worker node. The node component 340 may start or stop containers and handle communication between containers on a worker node.

[0045] According to various embodiments, a pod corresponds to a basic unit of work in a cluster and can specify a single container or a group of containers to be scheduled.

[0046] According to various embodiments, a service can route traffic to a corresponding pod in a cluster via an IP address or DNS name.

[0047] FIG. 3 is a diagram illustrating a load balancer according to various embodiments of the present invention.

[0048] According to various embodiments, the first load balancer 310 may include a first eBPF module 411 in the kernel plane 410 and a first synchronization module 421 in the user plane 420. For example, the eBPF module may refer to an extended Berkeley Packet Filter module, which may refer to a technology for applying user-defined code on the kernel. The eBPF module may execute user-created code on the kernel plane based on predefined hooks, kprobes, uprobes, tracepoints, etc. within the kernel code.

[0049] According to various embodiments, the second load balancer 320 may include a second eBPF module 413 in the kernel plane 410 and a second synchronization module 423 in the user plane 420 .

[0050] According to various embodiments, the eBPF module can locate 'kprobe / htab_map_update_elem' and 'kprobe / htab_map_delete_elem' to search for eBPF map updates. For example, the eBPF module can add an entry to the ConnTrack map (connection information / packet path) when new untracked traffic arrives. For example, the eBPF module can report the added entry to a user plane synchronization module.

[0051] According to various embodiments, the synchronization module can check entries via map updates in the user plane 420 and filter entries in the CT map. For example, the synchronization module can search for new untracked connections if new untracked traffic is tracked (established) in the eBPF data path. For example, the synchronization module can update all members of the cluster once the connection is tracked.

[0052] FIG. 4 is a diagram 500 illustrating a method for tracking new connections to a load balancer according to various embodiments of the present invention.

[0053] According to various embodiments, the first synchronization module 421 of the user plane 420 may periodically check whether a newly reported untracked connection has been established. For example, the first synchronization module 421 may synchronize a long lived connection that has been maintained for at least 10 seconds. Specifically, the first synchronization module 421 may synchronize only a long lived connection that has been maintained for at least 10 seconds.

[0054] FIG. 5 is a diagram 600 illustrating how a load balancer synchronizes with other load balancers according to various embodiments of the present invention.

[0055] According to various embodiments, the first synchronization module 421 of the first load balancer 310 can check a new established connection from the first eBPF module 411.

[0056] According to various embodiments, the first load balancer 310 may synchronize a newly established connection with other members of the cluster to which the first load balancer belongs. For example, the first load balancer 310 may synchronize a newly established connection with the second load balancer 320. For example, each event occurring in the cluster may be updated in the CT map of the eBPF module. That is, traffic generated by the first load balancer 310 may be updated in the CT map of the second eBPF module 413 of the second load balancer 320.

[0057] FIG. 6 is a diagram 700 illustrating a traffic flow of a first load balancer according to various embodiments of the present invention.

[0058] According to various embodiments, the first eBPF module 411 may attach "kprobe / htab_map_update_elem" and "kprobe / htab_map_delete_elem" to search for eBPF map updates at operation 711. According to various embodiments, the first synchronization module 421 may perform a health check on clusters between load balancers at operation 721.

[0059] According to various embodiments, in operation 713, the first eBPF module 411 can update the connectivity information in the CT map upon arrival of a new packet. For example, the connectivity information can be: Source IP address ( SIP :Source IP address, hereinafter referred to as "SIP") , Destination IP address ( DIP : Destination IP address, hereinafter referred to as "DIP") , Source port number ( Sport :Source port number (hereinafter referred to as "Sport") , Destination port number ( Dport :Destination port number, hereinafter referred to as "Dport") The status may include information such as the name, protocol, and status. For example, the status may include "untracked" and "tracked." For example, "untracked" may mean that a connection has not yet been established, and "tracked" may mean that a connection has been successfully established, i.e., a network session is connected.

[0060] According to various embodiments, in operation 715, the first eBPF module 411 may report new connection information that is currently not being tracked to the first synchronization module 421. According to various embodiments, in operation 723, the first synchronization module 421 may transmit new connection information that is currently not being tracked and periodically monitor the corresponding connection information from the first eBPF module 411. For example, the first synchronization module 421 may be configured to periodically check only conntrack entries that have been connected for a certain period of time or more by setting a time condition. For example, the first synchronization module 421 may check only long-lived connections, but may treat short-lived connections such as rests as noise and may be configured to periodically check only connections that last at least 10 seconds.

[0061] According to various embodiments, in operation 717, the first eBPF module 411 may update the status of the new connection information based on monitoring by the first synchronization module 421. For example, the first eBPF module 411 may update the status of the new connection information from untracked to tracked.

[0062] According to various embodiments, the first synchronization module 421 may transmit ConnTrack (CT) map information to load balancers in the cluster in operation 725. For example, ConnTrack may refer to a Linux module that manages network connection status.

[0063] FIG. 7 is a diagram 800 illustrating a traffic flow of a secondary load balancer according to various embodiments of the present invention.

[0064] According to various embodiments, the second eBPF module 413 can attach "kprobe / htab_map_update_elem" and "kprobe / htab_map_delete_elem" to search for eBPF map updates at operation 811. According to various embodiments, the second synchronization module 423 can perform a health check on clusters between load balancers at operation 821.

[0065] According to various embodiments, in operation 823, the second synchronization module 423 can receive newly tracked connectivity information via the first synchronization module 421 of the first load balancer 310 in the cluster.

[0066] According to various embodiments, at operation 825, the second synchronization module 423 can request the second eBPF module 413 to update the CT map.

[0067] According to various embodiments, in operation 813, the second eBPF module 413 can add Conntrack of the same route in response to a request from the second synchronization module 423. That is, through a series of operations, synchronized sessions that perform the same function within the cluster can be created.

[0068] FIG. 8 is a diagram 900 illustrating high availability network connections in a network system according to various embodiments of the present invention.

[0069] According to various embodiments, if the first load balancer 310 in the cluster is down for maintenance, the second load balancer 320 in the cluster can be used to process traffic without delay or loss.

[0070] FIG. 9 is a diagram showing a conventional network system.

[0071] FIG. 10 illustrates a network system using eBPF according to various embodiments of the present invention.

[0072] According to various embodiments, instead of synchronization using a conventional legacy network, traffic can be synchronized through an eBPF module on the kernel plane to implement a connection without delay or loss.

[0073] According to various embodiments, a method of an electronic device may include an operation of receiving new untracked traffic from a client in a first eBPF module; an operation of adding an entry corresponding to the new traffic to a ConnTrack map in response to the operation of receiving the new traffic in the first eBPF module; an operation of reporting the addition of the entry to a first synchronization module in the first eBPF module; and an operation of monitoring a first connection corresponding to the new traffic in the first synchronization module.

[0074] The electronic device may include an operation of transmitting information corresponding to the first connection to a second synchronization module of an external electronic device via the first synchronization module.

[0075] Adding the entry may include updating at least one of SIP, DIP, Sport, Dport, Protocol, or State corresponding to the new traffic to the ConnTrack map.

[0076] The monitoring operation may include monitoring the first connection corresponding to the new traffic if the entry is maintained for a predetermined time or more.

[0077] The electronic device may include an operation of receiving, via the first synchronization module, information corresponding to a second connection of traffic different from the new traffic from the second synchronization module of the external electronic device.

[0078] The first synchronization module may be located in a user plane, and the first eBPF module may be located in a kernel plane.

[0079] The predetermined time may be at least 10 seconds or more.

[0080] According to various embodiments, the method of the external electronic device may include an operation of receiving first connectivity information from a first synchronization module of an electronic device in a cluster via a second synchronization module of the external electronic device; an operation of the second synchronization module requesting a second eBPF module of the external electronic device to update the first connectivity information to a Conntrack map of the external electronic device; and an operation of the second eBPF module updating the first connectivity information to the Conntrack map.

[0081] According to various embodiments, in a cluster system including a client, an electronic device, an external electronic device, and a cloud server, the method may include an operation in which the electronic device receives new untracked traffic from a client; an operation in which the electronic device adds an entry corresponding to the new traffic; an operation in which the electronic device transfers connection information corresponding to the entry to the external electronic device; and an operation in which the external electronic device stores the connection information and synchronizes it with the electronic device.

[0082] The cloud server may include an operation of processing the connection information via the external electronic device when the electronic device is not operational.

Claims

1. 1. A method of an electronic device, comprising: receiving, at the first eBPF module, new traffic from the client having a non-tracked nature; an operation of adding an entry corresponding to the new traffic to a ConnTrack map in response to the operation of receiving the new traffic, in the first eBPF module; an operation of reporting, in the first eBPF module, the addition of the entry to a first synchronization module; The first synchronization module includes an operation of monitoring a first connection corresponding to the new traffic; The method of the electronic device, wherein the operation of adding the entry includes an operation of updating at least one of the source IP address (SIP), destination IP address (DIP), source port number (Sport), destination port number (Dport), protocol, or status corresponding to the new traffic to the ConnTrack map.

2. The method of claim 1 , further comprising the step of transmitting information corresponding to the first connection to a second synchronization module of an external electronic device via the first synchronization module.

3. The monitoring operation includes:

2. The method of claim 1, further comprising the act of monitoring the first connection for new traffic if the entry has been maintained for a predetermined period of time.

4. 3. The method of claim 2, further comprising receiving information corresponding to a second connection of traffic different from the new traffic from the second synchronization module of the external electronic device via the first synchronization module.

5. The method of claim 4 , wherein the first synchronization module is located in a user plane and the first eBPF module is located in a kernel plane.

6. 4. The method of claim 3, wherein the predetermined time is at least 10 seconds.

7. In a method of an external electronic device, receiving first connection information from a first synchronization module of an electronic device in the cluster via a second synchronization module of the external electronic device; an operation in which the second synchronization module requests a second eBPF module of the external electronic device to update the first connection information to a connection map of the external electronic device; The second eBPF module updates the first connection information to the connection map; A method for an electronic device, wherein the first connection information includes at least one of a source IP address (SIP), a destination IP address (DIP), a source port number (Sport), a destination port number (Dport), a protocol, or a status corresponding to new traffic that is not tracked by the client.

8. In a cluster system including a client, an electronic device, an external electronic device, and a cloud server, the electronic device receiving new traffic from the client that has a non-tracking nature; the electronic device adding an entry corresponding to the new traffic; The electronic device transmits the connection information corresponding to the entry to an external electronic device; The external electronic device stores the connection information and synchronizes it with the electronic device; The operation of adding the entry includes an operation of updating at least one of the source IP address (SIP), destination IP address (DIP), source port number (Sport), destination port number (Dport), protocol, or status corresponding to the new traffic to the ConnTrack map, in a cluster system.

9. The cluster system of claim 8 , wherein the cloud server processes the connection information via the external electronic device when the electronic device is not operational.

Citation Information

Patent Citations

  • Load balancing ipsec tunnel processing with extended berkeley packet filer (EBPF)

    US20190173841A1

  • Method for controlling of accelerating edge platform network and electronic device using the same

    US20220027208A1