Point-to-multipoint access method for cross-region cloud service, and publishing method and system

By deploying user-side network cards and virtual switches in cloud servers, and using virtual Internet components to achieve cross-regional services, the problem that existing cloud services cannot be accessed across regions is solved, and access efficiency and quality is improved.

WO2025118847A1PCT designated stage expired Publication Date: 2025-06-12HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/126179
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-04
Filing Date
2024-10-21
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

Existing cloud services cannot achieve cross-region access, resulting in inefficient access of cloud services.

Method used

By deploying user-side network cards and virtual switches in cloud servers, virtual Internet components are used to achieve cross-regional service access operations. The specific steps include obtaining access requests for cross-region services, determining the user-side network card and the first virtual switch deployed in the cloud server, and sending the access request to the first virtual switch through the user-side network card, so that it can be transmitted through the second virtual switch, and realizing access to cross-region services.

Benefits of technology

It effectively realizes the access operation of cross-region services, improves the access efficiency and quality of cloud services, and improves users' cross-region access experience of cloud services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024126179_12062025_PF_FP_ABST
    Figure CN2024126179_12062025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present disclosure are a point-to-multipoint access method for a cross-region cloud service, and a publishing method and a system. The access method is applied to a user network component, wherein the user network component is in communication connection with at least one virtual Internet component. The method comprises: acquiring an access request for a cross-region service; on the basis of the access request, determining a user-side network interface card deployed in a cloud server and a first virtual switch that is in communication connection with the user-side network interface card, wherein the first virtual switch is located in a virtual Internet component, the virtual Internet component further comprises at least one second virtual switch in communication connection with the first virtual switch, and a region corresponding to the first virtual switch is different from a region corresponding to the second virtual switch; and sending the access request to the first virtual switch by means of the user-side network interface card, such that the first virtual switch transmits the access request by means of a target virtual switch among the at least one second virtual switch, so as to realize an access operation for the cross-region service.
Need to check novelty before this filing date? Find Prior Art

Description

Point-to-point cloud cross-region service access method, publishing method and system

[0001] This disclosure claims priority to a Chinese patent application filed with the Patent Office of China on December 4, 2023, with application number 202311650113.1 and application name “Point-to-point access method, publishing method and system for cross-regional cloud services,” the entire contents of which are incorporated by reference into this disclosure. Technical Field

[0002] The present disclosure relates to the field of network technology, and in particular to a method and a system for accessing and publishing point-to-point cross-regional cloud services. Background Art

[0003] With the rapid development of cloud technology, the application of cloud products is becoming increasingly widespread. Cloud platforms can publish cloud services for users to call. Currently, users often cannot access services across regions. Furthermore, established service connections are point-to-point, meaning users can access published cloud services in the same region or availability zone. Because cloud service access is restricted by region, cross-region access becomes complex and reduces access efficiency.

[0004] Summary of the Invention

[0005] The embodiments of the present disclosure provide a point-to-point cloud-based cross-region service access method, publishing method, and system, which can implement cross-region service access operations and ensure the access quality and efficiency of cloud services.

[0006] In a first aspect, an embodiment of the present disclosure provides a method for accessing cross-region services on a cloud in a point-to-point manner, which is applied to a user network component, wherein the user network component is communicatively connected to at least one virtual internetwork component. The method includes:

[0007] Obtain access requests for cross-region services;

[0008] Determining, based on the access request, a user-side network interface card (NIC) deployed in the cloud server and a first virtual switch communicatively connected to the user-side network interface card, wherein the first virtual switch is located in a virtual interconnection network component, the virtual interconnection network component further includes at least one second virtual switch communicatively connected to the first virtual switch, and the first virtual switch corresponds to a different zone than the second virtual switch.

[0009] The access request is sent to the first virtual switch through the user-side network card, so that the first virtual switch transmits the access request through the target virtual switch in at least one second virtual switch, thereby realizing the access operation of the cross-region service.

[0010] In a second aspect, an embodiment of the present disclosure provides a user network component, wherein the user network component is communicatively connected to at least one virtual internetwork component, and the user network component includes:

[0011] A first acquisition module is used to obtain access requests for cross-region services;

[0012] a first determining module configured to determine, based on the access request, a user-side network interface card (NIC) deployed in the cloud server and a first virtual switch communicatively connected to the user-side network interface card, wherein the first virtual switch is located in a virtual interconnection network component, the virtual interconnection network component further includes at least one second virtual switch communicatively connected to the first virtual switch, and the first virtual switch corresponds to a different zone than the second virtual switch;

[0013] The first processing module is configured to send the access request to the first virtual switch through the user-side network card, so that the first virtual switch transmits the access request through a target virtual switch in at least one second virtual switch, thereby implementing an access operation for a cross-region service.

[0014] In a third aspect, an embodiment of the present disclosure provides an electronic device comprising: a memory and a processor; wherein the memory is used to store one or more computer instructions, wherein when the one or more computer instructions are executed by the processor, the method for accessing point-to-point cross-regional cloud services shown in the first aspect above is implemented.

[0015] In a fourth aspect, an embodiment of the present disclosure provides a computer storage medium for storing a computer program, which enables a computer to implement the point-to-point cloud cross-region service access method shown in the first aspect when executed.

[0016] In a fifth aspect, an embodiment of the present disclosure provides a computer program product, comprising: a computer program, which, when executed by a processor of an electronic device, enables the processor to execute the steps in the point-to-point cloud cross-regional service access method shown in the first aspect above.

[0017] In a sixth aspect, embodiments of the present disclosure provide a point-to-point method for accessing cross-region services on a cloud, the method being applied to a virtual interconnection network component, the virtual interconnection network component including a first virtual switch and at least one second virtual switch communicatively connected to the first virtual switch, wherein the first virtual switch corresponds to a different region than the second virtual switch, the first virtual switch being used for communicatively connecting to a user network component, and the second virtual switch being used for communicatively connecting to a service provider network component; the method comprising:

[0018] The first virtual switch obtains the access request of the cross-region service through the user side network card in the user network component.

[0019] Determining a service access address corresponding to the access request;

[0020] The first virtual switch sends the access request to the service-side network card in the service provider network component based on the service access address and the second virtual switch to implement the access operation of the cross-region service.

[0021] In a seventh aspect, an embodiment of the present disclosure provides a virtual interconnection network component, comprising a first virtual switch and at least one second virtual switch communicatively connected to the first virtual switch, wherein the first virtual switch corresponds to a different zone than the second virtual switch, the first virtual switch is configured to communicate with a user network component, and the second virtual switch is configured to communicate with a service provider network component;

[0022] The first virtual switch is configured to obtain an access request for a cross-region service through a user-side network card in a user network component, determine a service access address corresponding to the access request, and send the access request to the second virtual switch based on the service access address;

[0023] The second virtual switch is used to send the access request to the service-side network card in the service provider's network component based on the service access address, so as to implement the access operation of the cross-region service.

[0024] In the eighth aspect, an embodiment of the present disclosure provides an electronic device, comprising: a memory and a processor; wherein the memory is used to store one or more computer instructions, wherein when the one or more computer instructions are executed by the processor, the method for accessing point-to-point cross-regional cloud services shown in the sixth aspect above is implemented.

[0025] In a ninth aspect, an embodiment of the present disclosure provides a computer storage medium for storing a computer program, which enables a computer to implement the point-to-point cloud cross-region service access method shown in the sixth aspect when executed.

[0026] In the tenth aspect, an embodiment of the present disclosure provides a computer program product, including: a computer program, which, when executed by a processor of an electronic device, enables the processor to execute the steps in the point-to-point cloud cross-regional service access method shown in the sixth aspect above.

[0027] In an eleventh aspect, an embodiment of the present disclosure provides a method for publishing a point-to-point cross-region cloud service, which is applied to a service provider network component, wherein the service provider network component is communicatively connected to at least one virtual internetwork component, and the method includes:

[0028] Obtain service publishing information of the cross-region service, wherein the service publishing information includes at least: a service identifier, a service port, identification information of a service provider network component, and a service detection strategy;

[0029] Determining, based on the service publishing information, a service-side network card deployed in the cloud server and a second virtual switch communicatively connected to the service-side network card, wherein the second virtual switch is located in a virtual interconnection network component, the virtual interconnection network component further includes a first virtual switch communicatively connected to the second virtual switch, and the first virtual switch corresponds to a different zone than the second virtual switch.

[0030] The service publishing information is sent to the second virtual switch through the service-side network card, so that the second virtual switch sends the service publishing information to the configuration unit for service publishing operation, wherein the configuration unit is communicatively connected with virtual switches corresponding to multiple different areas.

[0031] In a twelfth aspect, an embodiment of the present disclosure provides a service provider network component, wherein the service provider network component is communicatively connected to at least one virtual internetwork component, and the service provider network component includes:

[0032] A second acquisition module is used to obtain service publishing information of the cross-region service, wherein the service publishing information includes at least: a service identifier, a service port, identification information of a service provider network component, and a service detection strategy;

[0033] a second determining module, configured to determine, based on the service publishing information, a service-side network card deployed in the cloud server and a second virtual switch communicatively connected to the service-side network card, wherein the second virtual switch is located in a virtual interconnection network component, the virtual interconnection network component further comprising a first virtual switch communicatively connected to the second virtual switch, and the first virtual switch corresponds to a different region than the second virtual switch;

[0034] The second processing module is used to send the service publishing information to the second virtual switch through the service-side network card, so that the second virtual switch sends the service publishing information to the configuration unit for service publishing operation, wherein the configuration unit is communicatively connected with virtual switches corresponding to multiple different areas.

[0035] In the thirteenth aspect, an embodiment of the present disclosure provides an electronic device, comprising: a memory and a processor; wherein the memory is used to store one or more computer instructions, wherein when the one or more computer instructions are executed by the processor, the method for publishing point-to-point cross-regional cloud services shown in the above-mentioned eleventh aspect is implemented.

[0036] In a fourteenth aspect, an embodiment of the present disclosure provides a computer storage medium for storing a computer program, which enables a computer to implement the method for publishing point-to-point cross-regional cloud services shown in the eleventh aspect when executed.

[0037] In the fifteenth aspect, an embodiment of the present disclosure provides a computer program product, including: a computer program, which, when executed by a processor of an electronic device, enables the processor to execute the steps in the method for publishing point-to-face cross-regional cloud services shown in the eleventh aspect above.

[0038] The presently disclosed embodiments provide a point-to-point cloud-based cross-regional service access method, publishing method, and system, which obtain an access request for a cross-regional service; and then determine, based on the access request, a user-side network card deployed in a cloud server and a first virtual switch communicatively connected to the user-side network card, and send the access request to the first virtual switch through the user-side network card, so that the first virtual switch transmits the access request through a target virtual switch in at least one second virtual switch. Since the first virtual switch is communicatively connected to at least one second virtual switch, and the region corresponding to the first virtual switch is different from the region corresponding to the second virtual switch, the cross-regional service access operation is effectively realized, that is, users can quickly and flexibly access services in different regions according to application requirements, which not only ensures the quality and efficiency of cloud service access, but also improves the user's good experience of cross-regional access to cloud services, which is conducive to market promotion and application. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0040] FIG1 is a schematic diagram showing the principle of a method for accessing cross-region services on a cloud in a point-to-point manner according to an embodiment of the present disclosure;

[0041] FIG2 is a flow chart of a method for accessing a point-to-point cross-region cloud service provided by an embodiment of the present disclosure;

[0042] FIG3 is a flow chart of another method for accessing cross-region services on a point-to-point basis in a cloud according to an embodiment of the present disclosure;

[0043] FIG4 is a flow chart of another method for accessing a point-to-point cross-region cloud service provided by an embodiment of the present disclosure;

[0044] FIG5 is a flow chart of another method for accessing a point-to-point cross-region cloud service provided by an embodiment of the present disclosure;

[0045] FIG6 is a flow chart of another method for accessing a point-to-point cross-region cloud service provided by an embodiment of the present disclosure;

[0046] FIG7 is a schematic diagram showing the principle of a method for accessing a point-to-point cross-region cloud service provided by an embodiment of the present disclosure;

[0047] FIG8 is a schematic diagram of the structure of a user network component provided by an embodiment of the present disclosure;

[0048] FIG9 is a schematic structural diagram of an electronic device corresponding to the user network component provided in the embodiment shown in FIG8 ;

[0049] FIG10 is a schematic diagram of the structure of a virtual internetwork component provided by an embodiment of the present disclosure;

[0050] FIG11 is a schematic diagram of the structure of an electronic device corresponding to the virtual internetwork component provided in the embodiment shown in FIG10 ;

[0051] FIG12 is a schematic diagram of the structure of a service provider network component provided by an embodiment of the present disclosure;

[0052] FIG13 is a schematic structural diagram of an electronic device corresponding to the service provider network component provided in the embodiment shown in FIG12 ;

[0053] FIG14 is a schematic structural diagram of a point-to-point cloud cross-region service access system provided by an embodiment of the present disclosure. DETAILED DESCRIPTION

[0054] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure more clear, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present disclosure without making any creative efforts shall fall within the scope of protection of the present disclosure.

[0055] The terms used in the embodiments of the present disclosure are for the purpose of describing specific embodiments only and are not intended to limit the present disclosure. The singular forms "a," "the," and "the" used in the embodiments of the present disclosure and the appended claims are also intended to include plural forms, unless the context clearly indicates otherwise. "A plurality" generally includes at least two, but does not exclude the inclusion of at least one.

[0056] It should be understood that the term "and / or" as used herein is merely a description of the relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the associated objects are in an "or" relationship.

[0057] As used herein, the words "if" and "if" may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to the determination" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)," depending on the context.

[0058] It should also be noted that the terms "include," "comprises," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a product or system comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such product or system. In the absence of further limitations, an element defined by the phrase "comprises a..." does not exclude the presence of other identical elements in the product or system comprising the element.

[0059] In addition, the step sequence in the following method embodiments is only an example and not a strict limitation.

[0060] Definition of terms:

[0061] Cross-region connectivity: also known as cross-region interconnection, refers to the network connection between applications in virtual private clouds (VPCs) distributed in two different regions.

[0062] Service subscription: Service users access services by subscribing.

[0063] In order to facilitate understanding of the implementation process of each step in the method of this embodiment, the implementation principle of the technical solution in this embodiment is briefly described below:

[0064] In order to solve the problem of low efficiency of cross-regional access to cloud services existing in the related art, this embodiment provides a point-to-point cloud cross-regional service access method, publishing method and system, wherein the execution subject of the point-to-cloud cloud cross-regional service access method is an access system. As shown in Figure 1, the access system may include a user network component, a virtual internet network component and a service provider network component, wherein the user network component is used to implement the deployment operation of the user network, the virtual internet network component is used to implement the deployment operation of the virtual internet network, and the service provider network component is used to implement the deployment operation of the service provider network. In addition, the region to which the user network component belongs is different from the region to which the service provider network component belongs. For example, the region to which the user network component belongs may be region 1, and the region to which the service provider network component belongs may be region 2, which is different from region 1. The user network component can be communicatively connected with the client so that the user can use the deployed user network through the client. The user network can be a user shared network or a user private network. The virtual network component is communicatively connected with the user network component and the service provider network component to implement cross-regional network data transmission operations. The service provider network component is communicatively connected with the server so that the server can implement corresponding operations based on the transmitted network data, such as cross-regional service access operations, etc.

[0065] Furthermore, for a client that is communicatively connected to a user network component, the client is used for the user to execute an application to generate or obtain a service access request. The client can be any computing device with a certain data transmission capability. In specific implementations, the client can be a mobile phone, a personal computer (PC), a tablet computer, a configuration application, and the like. Furthermore, the basic structure of the client can include: at least one processor. The number of processors depends on the configuration and type of the client. The client can also include memory, which can be volatile, such as random access memory (RAM), non-volatile, such as read-only memory (ROM), flash memory, or both. The memory typically stores an operating system (OS), one or more application programs, and may also store program data. In addition to the processing unit and memory, the client also includes some basic configurations, such as a network card chip, an I / O bus, a display component, and some peripheral devices. Optionally, some peripheral devices may include, for example, a keyboard, a mouse, a stylus, a printer, and the like. Other peripheral devices are well known in the art and are not described in detail here.

[0066] A server refers to a device that provides service access within a network virtual environment, typically a device that utilizes the network for information planning and service access. Physically, a server can be any device capable of providing computing services, responding to service access requests, and performing service access operations based on those requests. Examples include cluster servers, conventional servers, cloud servers, cloud hosts, and virtual centers. The server's components primarily include a processor, hard drive, memory, and system bus, similar to a typical computer architecture.

[0067] In the above embodiment, a network connection is established between the client and the user network component, and between the server and the service provider network component. The network connection can be a wireless or wired network connection. If a communication connection is established between the client and the user network component, and between the server and the service provider network component, the network standard of the mobile network can be any one of 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), 4G+ (LTE+), WiMax, 5G, 6G, etc.

[0068] In an embodiment of the present disclosure, a client is used by a user to generate or obtain an access request for a cross-regional service. Specifically, the client can display an interactive interface, and the user can perform operations on the interactive interface to generate or obtain an access request for a cross-regional service. After obtaining the access request for the cross-regional service, in order to implement the service access operation, the access request for the cross-regional service can be sent to the user network component.

[0069] The user network component is used to obtain access requests for cross-region services, and then determine the user-side network card deployed in the cloud server and the first virtual switch communicatively connected to the user-side network card based on the access request, wherein the first virtual switch is located in the virtual internet component. It should be noted that the virtual internet component includes not only the first virtual switch, but also at least one second virtual switch communicatively connected to the first virtual switch, and the region corresponding to the first virtual switch is different from the region corresponding to the second virtual switch.

[0070] After determining the user-side network card deployed in the cloud server and the first virtual switch in communication with the user-side network card, the user-side network card can be used to send an access request to the first virtual switch, so that the first virtual switch in the virtual internetwork component obtains the access request.

[0071] The service provider network component includes a first virtual switch and at least one second virtual switch. After the first virtual switch obtains an access request for a cross-region service through a user-side network card in the user network component, it can determine a service access address corresponding to the access request, and based on the service access address, determine a second target virtual switch in at least one second virtual switch; then the second target virtual switch can send the access request to the service-side network card in the service provider network component based on the service access address to implement the access operation of the cross-region service.

[0072] The service provider network component is used to obtain access requests for cross-regional service access operations through the user-side network card, and then send the access requests to the corresponding server through the user-side network card. Since the server belongs to a different region than the client, cross-regional service access operations are achieved.

[0073] The technical solution provided in this embodiment implements cross-regional service access operations through the first virtual switch and the second virtual switch in the interconnected network component. Specifically, the first virtual switch can obtain the access request for the cross-regional service through the user-side network card in the user network component, determine the service access address corresponding to the access request, and send the access request to the second target virtual switch based on the service access address. The second target virtual switch can send the access request to the service provider network component through the service-side network card in the service provider network component based on the service access address, thereby implementing cross-regional service access operations. This not only effectively guarantees the applicability of cloud services, ensures the access quality and efficiency of cross-regional cloud services, but also improves the user's good experience in accessing cross-regional services, which is conducive to market promotion and application.

[0074] Some embodiments of the present disclosure are described in detail below with reference to the accompanying drawings. The following embodiments and features thereof may be combined with one another unless they conflict with each other. Furthermore, the sequence of steps in the following method embodiments is provided for illustrative purposes only and is not intended to be a strict limitation.

[0075] FIG2 is a flow chart of a method for accessing a point-to-point cross-regional cloud service provided by an embodiment of the present disclosure. Referring to FIG2 , this embodiment provides a method for accessing a point-to-point cross-regional cloud service. The execution subject of the access method may be a user network component, that is, the access method may be applied to the user network component. The user network component is communicatively connected to at least one virtual internet component. The user network component is used to implement the deployment operation of the user network. The user network may be a user shared network or a user private network. Similarly, the virtual internet component is used to implement the deployment operation of the virtual internet network. The virtual internet network may also be a virtual shared internet network or a virtual private internet network. Those skilled in the art may flexibly configure the user network component and the virtual internet component according to specific application scenarios. Specifically, the method may include:

[0076] Step S201: Obtain an access request for a cross-region service.

[0077] Step S202: Based on the access request, determine a user-side network card deployed in the cloud server and a first virtual switch communicatively connected to the user-side network card, wherein the first virtual switch is located in a virtual internetwork component, and the virtual internetwork component further includes at least one second virtual switch communicatively connected to the first virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch.

[0078] Step S203: Sending the access request to the first virtual switch through the user-side network card, so that the first virtual switch transmits the access request through the target virtual switch in at least one second virtual switch, thereby implementing the access operation of the cross-region service.

[0079] The following is a detailed description of the specific implementation process and results of each of the above steps:

[0080] Step S201: Obtain an access request for a cross-region service.

[0081] When a user has access requirements for cross-regional services on the cloud, the user network component can obtain an access request for the cross-regional service. The access request includes at least identification information of the service to be accessed, access address information of the service to be accessed, etc. In some instances, the access request for the cross-regional service is obtained through human-computer interaction operations. At this time, obtaining the access request for the cross-regional service may include: displaying a human-computer interaction interface, obtaining an execution operation entered by the user in the human-computer interaction interface, and generating and obtaining an access request for the cross-regional service based on the execution operation.

[0082] In other instances, access requests for cross-regional services are obtained through preset devices. In this case, obtaining access requests for cross-regional services may include: determining a preset device (which may be a client or a third-party device) that is communicatively connected to a user network component, wherein the preset device stores access requests for cross-regional services; and actively or passively obtaining access requests for cross-regional services through the preset device, thereby effectively ensuring the accuracy and reliability of obtaining access requests for cross-regional services.

[0083] Step S202: Based on the access request, determine a user-side network card deployed in the cloud server and a first virtual switch communicatively connected to the user-side network card, wherein the first virtual switch is located in a virtual internetwork component, and the virtual internetwork component further includes at least one second virtual switch communicatively connected to the first virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch.

[0084] In order to accurately implement point-to-point access operations to cross-regional services on the cloud, after obtaining the access request for the cross-regional service, in order to transmit the access request from the user network component located in area 1 to the service provider network component in area 2, the user-side network card deployed in the cloud server can be determined, that is, the user network component includes a cloud server, and the cloud server is configured with a user-side network card that is communicatively connected to the client and at least one virtual Internet network component, wherein the virtual Internet network component includes a first virtual switch that is communicatively connected to the user-side network card and at least one second virtual switch that is communicatively connected to the first virtual switch. The above-mentioned second virtual switch can communicate with the service provider network component, and the access request can be transmitted through the first virtual switch and the second virtual switch.

[0085] For the first and second virtual switches, to accurately implement cross-region service access operations, the region corresponding to the first virtual switch can be the same as the region corresponding to the access request, while the region corresponding to the second virtual switch is different from the region corresponding to the first virtual switch. In this way, the cross-region service access request can be transmitted across regions via the first and second virtual switches. Since a user network component can be communicatively connected to at least one virtual interconnect network component, and different virtual interconnect network components can correspond to different regions and address segments, after receiving a cross-region service access request, the access request can be analyzed and processed to determine the user-side network interface card deployed in the cloud server and the first virtual switch communicatively connected to the service-side network interface card. In some instances, determining the first virtual switch communicatively connected to the user-side network interface card based on the access request can include: obtaining a service access address corresponding to the access request; determining all virtual switches communicatively connected to the user-side network interface card; and determining the first virtual switch among all virtual switches based on the access address, thereby effectively ensuring the accurate and reliable determination of the first virtual switch.

[0086] Step S203: Sending the access request to the first virtual switch through the user-side network card, so that the first virtual switch transmits the access request through the target virtual switch in at least one second virtual switch, thereby implementing the access operation of the cross-region service.

[0087] After determining a user-side network card located in a cloud server and a first virtual switch communicatively connected to the user-side network card, an access request can be sent to the first virtual switch via the user-side network card. In some instances, the access request can include IP address information, in which case the user-side network card can directly send the access request to the first virtual switch. In other instances, the access request can include domain name information. In this case, sending the access request to the first virtual switch via the user-side network card can include: obtaining domain name information corresponding to the access request and a domain name information table for analyzing and processing the access request via a configuration unit, wherein the configuration unit is communicatively connected to a user network component; determining a service access address corresponding to the access request based on the configuration unit, the domain name information table, and the domain name information; and sending the access request to the first virtual switch based on the service access address.

[0088] The user network component is communicatively connected to a configuration unit, which may store a domain name information table for performing domain name resolution operations on access requests. The domain name information table may include a mapping relationship between domain name information and a service access address. When the access request is a domain name access request, in order to accurately send the access request to the first virtual switch, after obtaining the access request, the access request may be sent to the configuration unit. After obtaining the access request, the configuration unit may perform a domain name resolution operation on the access request to obtain domain name information corresponding to the access request. Based on the domain name information table and the domain name information, the service access address corresponding to the access request may be obtained. The service access address may be an IPv4 address or an IPv6 address. This effectively ensures the accuracy and reliability of determining the service access address.

[0089] After determining the service access address, an access request can be sent to the first virtual switch based on the service access address, effectively ensuring that the first virtual switch can stably obtain the access request. After the first virtual switch obtains the access request, it can transmit the access request through a target virtual switch among at least one virtual switch communicatively connected to the first virtual switch. In other words, the first virtual switch can transmit the access request to the service provider network component through the target virtual switch, thereby enabling cross-region service access operations.

[0090] The present embodiment provides a point-to-point method for accessing cross-regional services on the cloud, which obtains an access request for the cross-regional service; then, based on the access request, determines the user-side network card deployed in the cloud server and the first virtual switch communicatively connected to the user-side network card, and sends the access request to the first virtual switch through the user-side network card, so that the first virtual switch transmits the access request through the target virtual switch in at least one second virtual switch. Since the first virtual switch is communicatively connected to at least one second virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch, the access operation of the cross-regional service is effectively realized, that is, the user can quickly and flexibly access the services in different areas according to the application requirements, which not only ensures the quality and efficiency of the cloud service access, but also improves the user's good experience of cross-regional access to the cloud service, which is conducive to market promotion and application.

[0091] FIG3 is a flow chart of another method for accessing a cross-region service on a cloud in a point-to-point manner provided by an embodiment of the present disclosure. Based on the above embodiment, with reference to FIG3 , before obtaining an access request for a cross-region service, a user-side network card may be deployed in the user network component. In this case, the method in this embodiment may further include:

[0092] Step S301: Acquire network card configuration information corresponding to a virtual internetwork component, where the network card configuration information at least includes: a network identifier and first virtual switch information.

[0093] Step S302: deploying a user-side network card in the user network component based on the network card configuration information, wherein the user-side network card is communicatively connected to the first virtual switch in the virtual internetwork component.

[0094] Before obtaining an access request for a cross-regional service, in order to implement the cross-regional service access operation based on the user-side network card, the user-side network card configuration operation can be performed first. Since the user-side network card is communicatively connected to the first virtual switch in the virtual interconnection network component, it is necessary to perform the configuration operation of the user-side network card based on the virtual interconnection network component, that is, to obtain the network card configuration information corresponding to the virtual interconnection network component, and the network card configuration information at least includes a network identifier and the first virtual switch information; in some instances, the network card configuration information can be obtained through human-computer interaction or transmission through a preset device (virtual interconnection network component). When the network card configuration information is stored in the preset device, the network card configuration information corresponding to the virtual interconnection network component can be actively or passively obtained through the virtual interconnection network component, thereby effectively ensuring the accuracy and reliability of the acquisition of the network card configuration information.

[0095] Since the user-side network card needs to communicate and connect with the first virtual switch in the virtual internet network component, and the user-side network card needs to be deployed in the user network component, the network card configuration information at least includes: a network identifier corresponding to the virtual internet network component and information about the first virtual switch. After obtaining the network card configuration information, the user-side network card is deployed in the user network component based on the network card configuration information, thereby effectively completing the configuration operation of the user-side network card.

[0096] In other instances, the network card configuration information may include not only the network identifier and the first virtual switch information, but also the first security component information, wherein the first security component information corresponds to the first security component. At this time, when the user-side network card is deployed in the user network component based on the network card configuration information, the deployed user-side network card can be communicated with the first virtual switch through the first security component corresponding to the first security component information, thereby also realizing the configuration operation of the user-side network card.

[0097] In this embodiment, network card configuration information corresponding to the virtual interconnection network component is obtained, and then a user-side network card is deployed in the user network component based on the network card configuration information, thereby effectively ensuring the stability and reliability of the configuration of the user-side network card. Then, the transmission operation of the access request of the cross-region service can be performed based on the configured user-side network card, thereby improving the quality and efficiency of the access operation of the cross-region service.

[0098] FIG4 is a flow chart of another method for accessing cross-region services on a point-to-point cloud provided by an embodiment of the present disclosure. Referring to FIG4 , this embodiment provides a method for accessing cross-region services on a point-to-point cloud. The execution subject of the access method may be a virtual interconnection network component, that is, the access method may be applied to the virtual interconnection network component. The virtual interconnection network component is communicatively connected to a user network component and a service provider network component. The user network component is used to implement the deployment operation of the user network, which may be a user's shared network or a user's private network. Similarly, the virtual interconnection network component is used to implement the deployment operation of the virtual interconnection network, which may be a virtual interconnection shared network or a virtual interconnection private network. The service provider network component is used to implement the deployment operation of the service provider network, which may be a service provider's shared network or a service provider's private network. Those skilled in the art may flexibly configure the user network component, the virtual interconnection network component, and the service provider network component according to specific application scenarios. Specifically, the virtual interconnection network component includes a first virtual switch and at least one second virtual switch communicatively connected to the first virtual switch. The region corresponding to the first virtual switch is different from the region corresponding to the second virtual switch. The first virtual switch is used to communicate with the user network component, and the second virtual switch is used to communicate with the service provider network component.

[0099] Based on the aforementioned virtual internetwork components, the method in this embodiment may include:

[0100] Step S401: The first virtual switch obtains an access request for a cross-region service through a user-side network card in a user network component.

[0101] Among them, when a user has a need to access a cross-regional service, an access request for the cross-regional service can be generated and obtained through the user network component. Specifically, the access request for the cross-regional service can be sent to the Internet network component through the user-side network card in the user network component, so that the first virtual switch in the Internet network component can obtain the access request for the cross-regional service through the user-side network card, wherein the service access request includes at least the service identification information of the service to be accessed.

[0102] In some other instances, the virtual internetwork component may further include: a first security component communicatively connected to the user network component and the first virtual switch; before the first virtual switch obtains an access request for a cross-region service through the user-side network card in the user network component, this embodiment may perform a legitimacy identification operation on the access request. At this time, the method in this embodiment may further include: identifying whether the access request is a legal request through the first security component; when the access request is a legal request, allowing the first virtual switch to obtain an access request for a cross-region service through the user-side network card in the user network component; when the access request is an illegal request, prohibiting the first virtual switch from obtaining an access request for a cross-region service through the user-side network card in the user network component.

[0103] Specifically, before the first virtual switch obtains an access request for a cross-region service through the user-side network card in the user network component, the first security component may first obtain the access request through the user-side network card and analyze and identify the access request to determine whether the access request is a legitimate request. In some instances, identifying whether the access request is a legitimate request may include: obtaining a preset request identifier corresponding to the access request; when the preset request identifier is in a preset whitelist, determining that the access request is a legitimate request; when the preset request identifier is not in the preset whitelist, determining that the access request is an illegal request. In other instances, the access request can be identified as a legitimate request not only by the preset request identifier, but also by analyzing and processing the access request through a preset algorithm or a pre-trained machine learning model. As long as it can accurately identify whether the access request is a legitimate request, it will not be further described here.

[0104] When it is determined that the access request is a legal request, the first virtual switch is allowed to obtain the access request for the cross-regional service through the user-side network card in the user network component, and then the legal access operation of the cross-regional service can be performed based on the access request; when it is determined that the access request is an illegal request, the first virtual switch is prohibited from obtaining the access request for the cross-regional service through the user-side network card in the user network component, that is, the illegal access operation of the cross-regional service is prohibited, which effectively ensures the security and reliability of the access operation to the cross-regional service.

[0105] Step S402: Determine the service access address corresponding to the access request.

[0106] After the first virtual switch receives an access request for a cross-region service, it may analyze and process the access request to implement cross-region service access operations and determine a service access address corresponding to the access request. The service access address may be domain name access information or an IP address. In some instances, determining the service access address corresponding to the access request may include: obtaining domain name information corresponding to the access request and a domain name information table used to analyze and process the access request. Specifically, the domain name information corresponding to the access request and the domain name information table may be obtained via a configuration unit, wherein the configuration unit is in communication with a user network component. The service access address corresponding to the access request may then be determined based on the configuration unit, the domain name information table, and the domain name information, thereby effectively ensuring accurate and reliable determination of the service access address.

[0107] Step S403: Based on the service access address, determine a second target virtual switch in at least one second virtual switch.

[0108] Since the first virtual switch can be communicatively connected to at least one second virtual switch, and different second virtual switches correspond to different areas and address segments, after obtaining the service access address, the second target virtual switch can be determined in the at least one second virtual switch based on the service access address. Specifically, determining the second target virtual switch in the at least one second virtual switch may include: obtaining the address segments corresponding to each second virtual switch; analyzing and matching the address segments corresponding to each second virtual switch with the service access address to determine the target address segment corresponding to the service access address; and then determining the second virtual switch corresponding to the target address segment as the second target virtual switch. This effectively ensures the accuracy and reliability of determining the second target virtual switch.

[0109] Step S404: Sending the access request to the service-side network card in the service provider network component based on the second target virtual switch and the service access address.

[0110] After determining the second target virtual switch, an access request can be sent to the service side network card in the service provider's network component based on the second target virtual switch and the service access address. After the service side network card in the service provider's network component obtains the access request, the access request can be sent to the server corresponding to the service provider to realize cross-regional service access operations.

[0111] In some other instances, the virtual internet network component in this embodiment may further include: a second security component communicatively connected to the service provider network component and the second virtual switch; at this time, before the first virtual switch sends the access request to the service side network card in the service provider network component based on the service access address and the second virtual switch, this embodiment may perform a legitimacy identification operation on the access request. Specifically, the method in this embodiment may further include: identifying whether the access request is a legitimate request through the second security component; when the access request is a legitimate request, allowing the first virtual switch to send the access request to the service side network card in the service provider network component based on the service access address and the second virtual switch; when the access request is an illegal request, prohibiting the first virtual switch from sending the access request to the service side network card in the service provider network component based on the service access address and the second virtual switch.

[0112] Before the first virtual switch sends the access request to the service-side network card in the service provider's network component based on the service access address and the second virtual switch, the second security component can first obtain the access request through the first virtual switch and analyze and identify the access request to determine whether the access request is a legitimate request. Specifically, the specific implementation method of legitimacy identification of the access request is similar to the specific implementation method of legitimacy identification of the access request mentioned above. For details, please refer to the above statement and will not be repeated here.

[0113] When it is determined that the access request is a legal request, it means that the access request at this time can realize the legal access operation to the cross-regional service, and then the first virtual switch is allowed to obtain the access request to the cross-regional service through the user-side network card in the user network component; when it is determined that the access request is an illegal request, it means that the access request at this time can realize the illegal access operation to the cross-regional service, and then the first virtual switch is prohibited from obtaining the access request to the cross-regional service through the user-side network card in the user network component, thereby effectively ensuring the security and reliability of the access operation to the cross-regional service.

[0114] The present embodiment provides a point-to-point method for accessing cross-regional services on the cloud. The method obtains an access request for a cross-regional service through a user-side network card in a user network component through a first virtual switch, and determines a service access address corresponding to the access request. A second target virtual switch is then determined in at least one second virtual switch based on the service access address. The access request is sent to the service-side network card in the service provider's network component based on the second target virtual switch and the service access address. Since the first virtual switch is communicatively connected to at least one second virtual switch, and the region corresponding to the first virtual switch is different from the region corresponding to the second virtual switch, cross-regional service access operations are effectively implemented. That is, users can quickly and flexibly access services in different regions according to application requirements. This not only ensures the quality and efficiency of cloud service access, but also improves the user's good experience of cross-regional access to cloud services, which is conducive to market promotion and application.

[0115] FIG5 is a flow chart of another method for accessing cross-region services on a point-to-point cloud provided by an embodiment of the present disclosure. Referring to FIG5 , this embodiment provides a method for accessing cross-region services on a point-to-point cloud. The execution subject of the access method may be a service provider network component, that is, the access method may be applied to the service provider network component. The service provider network component is communicatively connected to at least one virtual internet component. The service provider network component is used to implement the deployment operation of the service provider network. The service provider network may be a service provider shared network or a service provider private network. Similarly, the virtual internet component is used to implement the deployment operation of the virtual internet network. The virtual internet network may also be a virtual shared internet network or a virtual private internet network. Those skilled in the art may flexibly configure the service provider network component and the virtual internet component according to specific application scenarios. Specifically, the method may include:

[0116] Step S501: Obtain service publishing information of a cross-region service, where the service publishing information includes at least: a service identifier, a service port, identification information of a service provider's network component, and a service detection strategy.

[0117] Among them, when the service provider has a service publishing demand, the service provider can perform service publishing operations through the service provider network component. At this time, the service provider network component can obtain service publishing information of cross-regional services. As for the service publishing information, it can include service identification, service port, identification information of the service provider network component and service detection strategy. The above-mentioned service detection strategy is used to detect and identify the running status of the application service.

[0118] In some instances, service publishing information of cross-regional services is obtained through human-computer interaction operations. At this time, obtaining the service publishing information of cross-regional services may include: displaying a human-computer interaction interface, obtaining execution operations input by the user in the human-computer interaction interface, and generating and obtaining service publishing information of cross-regional services based on the execution operations.

[0119] In other instances, service publishing information of cross-regional services is obtained through a preset device. In this case, obtaining the service publishing information of cross-regional services may include: determining a preset device (which may be a client or a third-party device) that is communicatively connected to a user network component, wherein the service publishing information of the cross-regional service is stored in the preset device; the service publishing information of the cross-regional service can be actively or passively obtained through the preset device, thereby effectively ensuring the accuracy and reliability of obtaining the service publishing information of the cross-regional service.

[0120] Step S502: Determine a service-side network card deployed in the cloud server and a second virtual switch communicatively connected to the service-side network card, wherein the second virtual switch is located in a virtual internetwork component, and the virtual internetwork component further includes a first virtual switch communicatively connected to the second virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch.

[0121] In order to accurately implement the point-to-point cross-regional service publishing operation on the cloud, after obtaining the service publishing information of the cross-regional service, in order to be able to send the service publishing information of the cross-regional service from the service provider network to the virtual Internet, it can be determined that the service side network card deployed on the cloud server located in the service provider network is located, that is, the service provider network includes a cloud server, and the cloud server is configured with a service side network card that is communicatively connected to the client and at least one virtual Internet path component, wherein the virtual Internet network component includes a second virtual switch that is communicatively connected to the service side network card and a first virtual switch that is communicatively connected to the second virtual switch, and the service publishing information can be transmitted through the first virtual switch and the second virtual switch.

[0122] For the first virtual switch and the second virtual switch, in order to accurately implement the cross-region service publishing operation, the area corresponding to the second virtual switch can be the same as the area corresponding to the service publishing information, and the area corresponding to the second virtual switch is different from the area corresponding to the first virtual switch. In this way, the cross-region service can be published across regions through the first virtual switch and the second virtual switch.

[0123] Step S503: Sending the service publishing information to the second virtual switch through the service-side network card, so that the second virtual switch sends the service publishing information to the configuration unit for service publishing operation, wherein the configuration unit is communicatively connected to virtual switches corresponding to multiple different areas.

[0124] After determining the service-side network card deployed in the cloud server and the second virtual switch communicatively connected to the service-side network card, the service publishing information can be sent to the second virtual switch through the service-side network card. After the second virtual switch obtains the service publishing information, the service publishing information can be sent to the configuration unit for service publishing operations. Since the configuration unit can be communicatively connected to multiple virtual switches, the multiple virtual switches can include a first virtual switch and a second virtual switch, and the regions corresponding to the multiple virtual switches can be different, when the configuration unit performs a service publishing operation, other regions can also access the services published by the configuration unit through the virtual switch, thereby effectively realizing cross-service publishing operations, thereby effectively ensuring the accuracy and reliability of cross-regional publishing of cloud services.

[0125] The present embodiment provides a point-to-point cross-regional service publishing method on the cloud, which obtains service publishing information of the cross-regional service, and then determines the service-side network card deployed in the cloud server and the second virtual switch communicatively connected to the service-side network card based on the service publishing information, and sends the service publishing information to the second virtual switch through the service-side network card, so that the second virtual switch sends the service publishing information to the configuration unit for service publishing operation. Since the configuration unit is communicatively connected with virtual switches corresponding to multiple different regions, the configuration unit can synchronize the service publishing information to other virtual switches, thereby effectively realizing the cross-regional service publishing operation, that is, users can quickly and flexibly access services in different regions according to application requirements, which not only ensures the quality and efficiency of cloud service publishing, but also improves the user's good experience of cross-regional access to cloud services, which is conducive to market promotion and application.

[0126] FIG6 is a flow chart of another method for accessing a point-to-point cross-region service on a cloud provided by an embodiment of the present disclosure. Based on the above embodiment, with reference to FIG6 , before obtaining service publishing information of the cross-region service, a service-side network card may be deployed in the service provider network component. In this case, the method in this embodiment may further include:

[0127] Step S601: Acquire network card configuration information corresponding to the virtual internetwork component, where the network card configuration information at least includes: a network identifier and second virtual switch information.

[0128] Step S602: Based on the network card configuration information, deploy a service-side network card in the service provider network component, wherein the service-side network card is communicatively connected to the second virtual switch in the virtual interconnection network component.

[0129] Before obtaining the service publishing information of the cross-region service, in order to realize the cross-region service publishing operation based on the service-side network card, the service-side network card configuration operation can be performed first. Since the service-side network card is communicated with the second virtual switch in the virtual interconnection network component, it is necessary to perform the service-side network card configuration operation based on the virtual interconnection network component, that is, to obtain the network card configuration information corresponding to the virtual interconnection network component, and the network card configuration information at least includes the network identifier and the second virtual switch information; in some instances, the network card configuration information can be obtained through human-computer interaction or transmission through a preset device (virtual interconnection network component). When the network card configuration information is stored in the preset device, the network card configuration information corresponding to the virtual interconnection network component can be actively or passively obtained through the virtual interconnection network component, thereby effectively ensuring the accuracy and reliability of the acquisition of the network card configuration information.

[0130] Since the service-side network card needs to communicate and connect with the second virtual switch in the virtual interconnect network component, and the service-side network card needs to be deployed in the service provider network component, the network card configuration information at least includes: the network identifier corresponding to the virtual interconnect network component and the second virtual switch information. After obtaining the network card configuration information, the service-side network card is deployed in the service provider network component based on the network card configuration information, thereby effectively completing the configuration operation of the service-side network card.

[0131] In other instances, the network card configuration information may include not only the network identifier and the second virtual switch information, but also the second security component information, wherein the second security component information corresponds to the second security component. At this time, when the service-side network card is deployed in the service provider's network component based on the network card configuration information, the deployed service-side network card can communicate with the second virtual switch through the second security component corresponding to the second security component information, thereby also realizing the configuration operation of the user-side network card.

[0132] In this embodiment, the network card configuration information corresponding to the virtual Internet network component is obtained, and then based on the network card configuration information, the service-side network card is deployed in the service provider network component, thereby effectively ensuring the stability and reliability of the configuration of the service-side network card. Then, the service publishing information transmission operation can be performed based on the configured service-side network card, thereby improving the quality and efficiency of the cross-regional service publishing operation.

[0133] In specific application, referring to Figure 7, this application embodiment provides a point-to-point cross-regional cloud interconnection method, the execution subject of this method can be a cross-regional cloud interconnection system, and the cross-regional cloud interconnection system can include three types of private networks, namely: user private network VPC, service provider private network ISV VPC and at least one virtual internet network VPC, wherein at least one virtual internet network VPC can be communicated with the user private network VPC and the service provider private network ISV VPC, and the regions and address segments (IPv6 address segments or IPv4 address segments) corresponding to any two virtual internet network VPCs are different, and any two virtual internet network VPCs are communicated, wherein the address segments allocated to multiple virtual internet network VPCs in communication connection constitute an interconnection plane, and the scope of the interconnection plane is the address segments allocated by all virtual internet network VPCs, thereby building a virtual Internet cluster for the entire region.

[0134] It should be noted that the address segment of the user private network deployed through the user network component 200 and the address segment of the service provider private network deployed through the service provider network component 300 can be the same or different. For example, the address segment of the user private network can be 172.16.0.0 / 16, and the address segment of the service provider private network can also be 172.16.0.0 / 16. This will not affect the access operation of cross-regional services.

[0135] Based on the above-mentioned cross-region interconnection system on the cloud, cross-region service publishing and access operations can be implemented. Specifically, the cross-region service publishing operation on the cloud may include the following steps:

[0136] Step 1: The service provider generates a service publishing request through the service provider private network (ISV) VPC and sends the service publishing request to the virtual Internet VPC through the service-side network interface (ENI).

[0137] Among them, before sending the service publishing request to the virtual Internet VPC through the service-side network card ENI, the virtual Internet VPC can first create a service-side network card ENI and a second security component for communication with the ISV VPC. Specifically, when creating the service-side network card ENI, the network identifier of the service provider's private network VPC, the cloud server located in the service provider's private network VPC, and the service provider's identity identifier can be obtained. Then, based on the network identifier, cloud server, and service provider's identity identifier, the service-side network card ENI and the second security group can be created, the second security group can be deployed in the virtual Internet VPC, and the service-side network card ENI can be deployed in the service provider's private network ISV VPC.

[0138] Furthermore, for ISV VPCs, at least one cloud server is pre-configured. Different service-side network interfaces (ENIs) can be deployed on different cloud servers. These different cloud servers are used by different service providers to publish services and access different services. Therefore, when a service provider needs to publish a service, it can send a service publishing request to the virtual internet VPC via the service-side network interface (ENI). This service publishing request can include service identification information, service port information, network identification information for the service provider's private network (VPC), and a service health policy for health testing of application services.

[0139] Step 2: The second security component in the virtual Internet VPC obtains the service publishing request and can identify the legitimacy of the service publishing request. When it is determined that the service publishing request is a legitimate request, it allows the service publishing request to be sent to the second virtual switch; when it is determined that the service publishing request is an illegal request, it prohibits the service publishing request from being sent to the second virtual switch.

[0140] Among them, the second security group is configured with security group information for analyzing and processing service release requests. The security group information can allow the transmission operation of the service release request when the service release request is a legal request; when the service release request is an illegal request, the transmission operation of the service release request is prohibited, thereby effectively ensuring the security control operation of the service release request.

[0141] Step 3: After the second virtual switch obtains the service publishing request, it may send the service publishing request to the configuration unit to perform a service publishing operation based on the configuration unit.

[0142] Step 4: After the second virtual switch obtains the service publishing request, it can determine the service identifier and resolved domain name of the service to be published, and send the service identifier and resolved domain name to the configuration unit so that the configuration unit can register and configure the domain name information.

[0143] Specifically, the service provider can predict the service domain name based on the published service information, thereby obtaining a domain name information table between the service domain name information and the IP address information, so that users can access the published services based on the domain name information table.

[0144] To access published services in the system, users can perform cross-region access operations on the cloud based on their needs. Specifically, service access operations can include the following steps:

[0145] Step 11: The user can generate a service access request through the user private network VPC.

[0146] Step 12: The user private network VPC can determine the service access domain name corresponding to the service access request.

[0147] Step 13: Perform a recursive query operation on the service access request through the configuration unit and the service access domain name to obtain a service access address corresponding to the service access request. The service access address can be an IPv6 address or an IPv4 address.

[0148] Specifically, the configuration unit may obtain a domain name information table for analyzing and processing the service access request, and perform a recursive query operation on the domain name information table and the service access domain name to obtain a service access address corresponding to the service access request.

[0149] For example 1, when user a in Beijing wants to access the service application "weather" in Hangzhou, user a can generate a service access request a through the client, where the IP address of the client can be Zhangjiakou: 2408:4005:381:f1:: / 56dev eth1. The user can send the obtained service access request a to the user-side network interface card (ENI) in the user VPC through the client. The user-side network interface card (ENI) can then perform a domain name resolution operation through the configuration unit. Specifically, the domain name information table can be obtained, and the domain name information item corresponding to the service access request a can be determined in the domain name information table. For example, the domain name information item is 2408:4005:381:f100:4ab4:6b6:245a:75f5 weather.isv.compnest.aliyuncs.com. The service access request a can then be analyzed and processed using the above domain name information item, thereby determining that the service access address corresponding to the service access request a is 2408:4005:381:f100. The service access request a can then be transmitted and processed based on the above service access address to implement cross-region service access operations.

[0150] Step 14: Based on the service access address, the service access request is sent to the first security component in the virtual internet VPC through the user-side network card ENI located in the user private network VPC.

[0151] Step 13: The first security component in the virtual Internet VPC obtains the service access request and can identify the legitimacy of the service access request. When it is determined that the service access request is a legitimate request, it allows the service access request to be sent to the first virtual switch; when it is determined that the service access request is an illegal request, it prohibits the service access request from being sent to the first virtual switch.

[0152] Step 14: After receiving the service access request, the first virtual switch may send the service access request to the second virtual switch based on the service access address. The first virtual switch and the second virtual switch correspond to different areas.

[0153] Step 15: The second virtual switch can send the service access request to the corresponding service provider private network VPC through the second security component, thereby realizing cross-region service access operations.

[0154] The access system provided by this application embodiment enables users and service providers to conveniently access the access system and perform service access or service publishing operations. Specifically, after the user accesses the virtual internet, the user can directly access services in the service catalog without having to perform separate service subscription operations. Moreover, because the virtual internets (VPCs) in all regions are interconnected and the IP address segments of each virtual internet are automatically allocated, private network connections can be quickly and conveniently implemented across the entire region, facilitating lower-cost point-to-surface interconnection operations. In addition, for the routing policies configured in each network, users can update or adjust the configured routing policies through a preset application (cloud assistant) to ensure stable and reliable data routing. In this way, when a user needs to access cross-regional services, they can access cross-regional services through the created independent service links. The independent service links created in sequence can access all services of the virtual internet, facilitating a better user experience of accessing cross-regional services. When a service provider accesses the virtual internet, cross-regional publishing operations for multiple services can be implemented, thereby reducing service access and service publishing costs and facilitating market promotion and application.

[0155] FIG8 is a schematic diagram of the structure of a user network component provided in an embodiment of the present disclosure. Referring to FIG8 , this embodiment provides a user network component for executing the point-to-point method for accessing cross-region services on the cloud shown in FIG2 . The user network component is communicatively connected to at least one virtual internetwork component. Specifically, the user network component includes:

[0156] A first acquisition module 11 is used to obtain an access request for a cross-region service;

[0157] A first determining module 12 is configured to determine a user-side network card deployed in the cloud server and a first virtual switch communicatively connected to the user-side network card, wherein the first virtual switch is located in a virtual interconnection network component, the virtual interconnection network component further includes at least one second virtual switch communicatively connected to the first virtual switch, and the region corresponding to the first virtual switch is different from the region corresponding to the second virtual switch;

[0158] The first processing module 13 is configured to send the access request to the first virtual switch through the user-side network card, so that the first virtual switch transmits the access request through a target virtual switch in at least one second virtual switch, thereby implementing an access operation for a cross-region service.

[0159] In some instances, before obtaining an access request for a cross-region service, the first obtaining module 11 and the first processing module 13 in this embodiment are configured to perform the following steps:

[0160] A first acquisition module 11 is configured to acquire network card configuration information corresponding to a virtual interconnection network component, the network card configuration information including at least: a network identifier and first virtual switch information;

[0161] The first processing module 13 is configured to deploy a user-side network card in the user network component based on the network card configuration information, wherein the user-side network card is communicatively connected to the first virtual switch in the virtual internetwork component.

[0162] In some instances, the network card configuration information further includes first security component information, and the user-side network card is communicatively connected to the first virtual switch through the first security component corresponding to the first security component information.

[0163] In some instances, when the first processing module 13 sends an access request to the first virtual switch through the user-side network card, the first processing module 13 is used to execute: obtaining domain name information corresponding to the access request and a domain name information table for analyzing and processing the access request through a configuration unit, wherein the configuration unit is communicatively connected to the user network component; determining a service access address corresponding to the access request based on the configuration unit, the domain name information table, and the domain name information; and sending the access request to the first virtual switch based on the service access address.

[0164] The user network component shown in FIG8 can execute the method of the embodiment shown in FIG1-FIG3 and FIG7. For the parts not described in detail in this embodiment, please refer to the relevant description of the embodiment shown in FIG1-FIG3 and FIG7. The execution process and technical effects of this technical solution are described in the embodiment shown in FIG1-FIG3 and FIG7, and will not be repeated here.

[0165] In one possible design, the structure of the user network component shown in FIG8 can be implemented as an electronic device. Referring to FIG9 , the user network component in this embodiment can be implemented as an electronic device that is communicatively connected to at least one virtual internet component; specifically, the electronic device may include: a first processor 21 and a first memory 22. The first memory 22 is used to store a program for the corresponding electronic device to execute the method for accessing the point-to-point cross-regional cloud service provided in the embodiment shown in FIG2 , and the first processor 21 is configured to execute the program stored in the first memory 22.

[0166] The program includes one or more computer instructions, wherein the one or more computer instructions, when executed by the first processor 21, can implement the following steps: obtaining an access request for a cross-region service; based on the access request, determining a user-side network card deployed in a cloud server and a first virtual switch communicatively connected to the user-side network card, wherein the first virtual switch is located in a virtual internetwork component, and the virtual internetwork component also includes at least one second virtual switch communicatively connected to the first virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch; sending the access request to the first virtual switch through the user-side network card, so that the first virtual switch transmits the access request through a target virtual switch in at least one second virtual switch, thereby implementing an access operation for the cross-region service.

[0167] Furthermore, the first processor 21 is further configured to execute all or part of the steps in the embodiment shown in Figure 2. The electronic device may further include a first communication interface 23 for communicating with other devices or a communication network.

[0168] In addition, an embodiment of the present disclosure provides a computer storage medium for storing computer software instructions used by electronic devices, which includes programs involved in executing the point-to-point cloud cross-region service access method in the method embodiment shown in Figure 2 above.

[0169] In addition, an embodiment of the present disclosure provides a computer program product, including: a computer program, which, when executed by a processor of an electronic device, enables the processor to execute the point-to-point cloud cross-region service access method in the method embodiment shown in Figure 2.

[0170] FIG10 is a schematic diagram of the structure of a virtual interconnection network component provided by an embodiment of the present disclosure. Referring to FIG10 , this embodiment provides a virtual interconnection network component for executing the point-to-point method for accessing cross-region services on a cloud as shown in FIG4 . The virtual interconnection network component includes a first virtual switch 31 and at least one second virtual switch 32 communicatively connected to the first virtual switch 31. The first virtual switch 31 corresponds to a different region than the second virtual switch 32. The first virtual switch 31 is used to communicate with the user network component 10, and the second virtual switch 32 is used to communicate with the service provider network component 50. Specifically, the first virtual switch 31 and the second virtual switch 32 are used to execute the following steps:

[0171] The first virtual switch 31 is configured to obtain an access request for a cross-region service through a user-side network card in the user network component 10, determine a service access address corresponding to the access request, and send the access request to the second virtual switch 32 based on the service access address;

[0172] The second virtual switch 32 is used to send the access request to the service-side network card in the service provider network component 50 based on the service access address, so as to implement the access operation of the cross-region service.

[0173] In some instances, the virtual internetwork component further includes: a first security component 33 communicatively coupled to the user network component 10 and the first virtual switch 31;

[0174] Before the first virtual switch 31 obtains an access request for a cross-region service through the user-side network card in the user network component 10, the first security component 33 in this embodiment is used to: identify whether the access request is a legal request; if the access request is a legal request, allow the first virtual switch to obtain the access request for the cross-region service through the user-side network card in the user network component; if the access request is an illegal request, prohibit the first virtual switch from obtaining the access request for the cross-region service through the user-side network card in the user network component.

[0175] In some instances, the virtual internetwork component further includes: a second security component 34 communicatively connected to the service provider network component 50 and the second virtual switch 32; before the first virtual switch sends an access request to the service-side network card in the service provider network component based on the service access address and the second virtual switch, the second security component 34 in this embodiment is used to execute: identifying whether the access request is a legal request through the second security component; when the access request is a legal request, allowing the first virtual switch to send the access request to the service-side network card in the service provider network component based on the service access address and the second virtual switch; when the access request is an illegal request, prohibiting the first virtual switch from sending the access request to the service-side network card in the service provider network component based on the service access address and the second virtual switch.

[0176] The virtual interconnection network component shown in Figure 10 can execute the methods of the embodiments shown in Figures 4 and 7. For parts not described in detail in this embodiment, please refer to the relevant descriptions of the embodiments shown in Figures 4 and 7. The execution process and technical effects of this technical solution are described in the embodiments shown in Figures 4 and 7, and will not be repeated here.

[0177] In one possible design, the structure of the virtual internet network component shown in FIG10 can be implemented as an electronic device. Referring to FIG11 , the virtual internet network component in this embodiment can be implemented as an electronic device, which includes a first virtual switch and at least one second virtual switch communicatively connected to the first virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch, the first virtual switch is used to communicate and connect with the user network component, and the second virtual switch is used to communicate and connect with the service provider network component; specifically, the electronic device may include: a second processor 41 and a second memory 42. The second memory 42 is used to store a program for the corresponding electronic device to execute the point-to-point cloud cross-region service access method provided in the embodiment shown in FIG4 above, and the second processor 41 is configured to execute the program stored in the second memory 42.

[0178] The program includes one or more computer instructions, wherein when the one or more computer instructions are executed by the second processor 41, the following steps can be implemented: obtaining an access request for a cross-regional service through a user-side network card in a user network component; determining a service access address corresponding to the access request; based on the service access address, determining a second target virtual switch in at least one second virtual switch; and sending the access request to a service-side network card in a service provider network component based on the second target virtual switch and the service access address to implement an access operation for the cross-regional service.

[0179] Furthermore, the second processor 41 is further configured to execute all or part of the steps in the embodiment shown in Figure 4. The electronic device may further include a second communication interface 43 for communicating with other devices or a communication network.

[0180] In addition, an embodiment of the present disclosure provides a computer storage medium for storing computer software instructions used by electronic devices, which includes programs involved in executing the point-to-point cloud cross-region service access method in the method embodiment shown in Figure 4 above.

[0181] In addition, an embodiment of the present disclosure provides a computer program product, including: a computer program, which, when executed by a processor of an electronic device, enables the processor to execute the point-to-point cloud cross-region service access method in the method embodiment shown in Figure 4.

[0182] FIG12 is a schematic diagram of the structure of a service provider network component provided in an embodiment of the present disclosure. Referring to FIG12 , this embodiment provides a service provider network component for executing the point-to-point cross-region service publishing method on the cloud shown in FIG5 . The service provider network component is communicatively connected to at least one virtual internetwork component. Specifically, the service provider network component includes:

[0183] The second acquisition module 51 is used to obtain service publishing information of the cross-region service, where the service publishing information includes at least: service identifier, service port, identification information of the service provider network component, and service detection strategy;

[0184] A second determining module 52 is configured to determine a service-side network card deployed in the cloud server and a second virtual switch communicatively connected to the service-side network card, wherein the second virtual switch is located in a virtual interconnection network component, the virtual interconnection network component further includes a first virtual switch communicatively connected to the second virtual switch, and the first virtual switch corresponds to a different region than the second virtual switch.

[0185] The second processing module 53 is configured to send the service publishing information to the second virtual switch through the service-side network card, so that the second virtual switch sends the service publishing information to the configuration unit for performing a service publishing operation.

[0186] In some examples, before obtaining the service publishing information of the cross-region service, the second obtaining module 51 and the second processing module 53 in this embodiment are used to perform the following steps:

[0187] A second acquisition module 51 is configured to acquire network card configuration information corresponding to the virtual interconnection network component, where the network card configuration information includes at least: a network identifier and information about a second virtual switch;

[0188] The second processing module 53 is configured to deploy a service-side network card in the service provider network component based on the network card configuration information, wherein the service-side network card is communicatively connected to the second virtual switch in the virtual interconnection network component.

[0189] In some instances, the network card configuration information further includes second security component information, and the service-side network card is communicatively connected to the second virtual switch through a second security component corresponding to the second security component information.

[0190] The service provider network component shown in FIG12 can execute the method of the embodiment shown in FIG5-FIG7. For the parts not described in detail in this embodiment, please refer to the relevant description of the embodiment shown in FIG5-FIG7. The execution process and technical effects of this technical solution are described in the embodiment shown in FIG5-FIG7, and will not be repeated here.

[0191] In one possible design, the structure of the service provider network component shown in FIG12 can be implemented as an electronic device. Referring to FIG13 , the service provider network component in this embodiment can be implemented as an electronic device that is communicatively connected to at least one virtual internet component; specifically, the electronic device may include: a third processor 61 and a third memory 62. The third memory 62 is used to store a program for the corresponding electronic device to execute the method for publishing point-to-point cross-regional cloud services provided in the embodiment shown in FIG5 , and the third processor 61 is configured to execute the program stored in the third memory 62.

[0192] The program includes one or more computer instructions, wherein the one or more computer instructions, when executed by the third processor 61, can implement the following steps: obtaining service publishing information of a cross-region service, the service publishing information including at least: a service identifier, a service port, identification information of a service provider network component, and a service detection strategy; based on the service publishing information, determining a service-side network card deployed in a cloud server and a second virtual switch communicatively connected to the service-side network card, wherein the second virtual switch is located in a virtual internetwork component, and the virtual internetwork component also includes a first virtual switch communicatively connected to the second virtual switch, and the region corresponding to the first virtual switch is different from the region corresponding to the second virtual switch; sending the service publishing information to the second virtual switch through the service-side network card, so that the second virtual switch sends the service publishing information to a configuration unit for a service publishing operation, wherein the configuration unit is communicatively connected to virtual switches corresponding to multiple different regions.

[0193] Furthermore, the third processor 61 is further configured to execute all or part of the steps in the embodiment shown in Figure 5. The electronic device may further include a third communication interface 63 for communicating with other devices or a communication network.

[0194] In addition, an embodiment of the present disclosure provides a computer storage medium for storing computer software instructions used by electronic devices, which includes a program for executing the method for publishing point-to-face cross-regional cloud services in the method embodiment shown in Figure 5 above.

[0195] In addition, an embodiment of the present disclosure provides a computer program product, including: a computer program, which, when executed by a processor of an electronic device, enables the processor to execute the method for publishing point-to-face cross-regional cloud services in the method embodiment shown in Figure 5.

[0196] FIG14 is a schematic diagram of a structure of a point-to-point cloud-based cross-region service access system provided by an embodiment of the present disclosure. Referring to FIG14 , this embodiment provides a point-to-point cloud-based cross-region service access system. The access system may include: at least one virtual interconnection network component 300 for communicating with a user network component 100 and a service provider network component 200, wherein any two virtual interconnection network components 300 correspond to different regions and address segments; the virtual interconnection network component 300 includes:

[0197] The first virtual switch 3001 is configured to obtain an access request for a cross-region service through a user-side network card in the user network component 100, determine a service access address corresponding to the access request, and send the access request to the second virtual switch 3002 based on the service access address, wherein the user-side network card is deployed on a cloud server;

[0198] The second virtual switch 3002 is communicatively connected to the first virtual switch 3001, wherein the region to which the second virtual switch 3002 belongs is different from the region to which the first virtual switch 3001 belongs. The second virtual switch 3002 is configured to receive an access request sent by the first virtual switch 3001 and send the access request to the service provider network component 200 through the service-side network card in the service provider network component 200 based on the service access address, so as to implement cross-region service access operations, wherein the service-side network card is deployed on a cloud server.

[0199] The specific execution steps, implementation principles, and implementation effects of each component in the point-to-point cross-region cloud service access system of this embodiment are similar to the specific execution steps, implementation principles, and implementation effects of the point-to-point cross-region cloud service access method shown in Figures 1-7 above. For portions not described in detail in this embodiment, please refer to the relevant description of the embodiments shown in Figures 1-7. The execution process and technical effects of this technical solution are described in the embodiments shown in Figures 1-7 and will not be repeated here.

[0200] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0201] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units. That is, they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0202] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by adding a necessary general hardware platform, and of course can also be implemented by a combination of hardware and software. Based on this understanding, the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a computer product. The present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0203] The present disclosure is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable device to produce a machine, so that the instructions executed by the processor of the computer or other programmable device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.

[0204] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable device to operate in a specific manner, such that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device that implements the functions specified in one or more processes of the flowchart and / or one or more blocks of the block diagram. These computer program instructions may also be loaded onto a computer or other programmable device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes of the flowchart and / or one or more blocks of the block diagram.

[0205] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory. Memory may include non-permanent storage in a computer-readable medium, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.

[0206] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be used to store data using any method or technology. Data can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store data that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.

[0207] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present disclosure, rather than to limit them. Although the present disclosure has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present disclosure.

Claims

1. A point-to-point method for accessing cross-region services on a cloud, wherein: Applied to a user network component, the user network component being communicatively connected to at least one virtual interconnect network component, the method comprising: Get access requests for cross-region services; Based on the access request, determine a user-side network card deployed in the cloud server and a first virtual switch communicatively connected to the user-side network card, wherein the first virtual switch is located in a virtual interconnection network component, the virtual interconnection network component further includes at least one second virtual switch communicatively connected to the first virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch; The access request is sent to the first virtual switch through the user-side network card, so that the first virtual switch transmits the access request through a target virtual switch in at least one second virtual switch, thereby realizing the access operation of the cross-region service.

2. The method according to claim 1, wherein: Before obtaining the access request for the cross-region service, the method further includes: Acquire network card configuration information corresponding to the virtual interconnect network component, the network card configuration information at least including: a network identifier and first virtual switch information; Based on the network card configuration information, a user-side network card is deployed in the user network component, wherein the user-side network card is communicatively connected to a first virtual switch in the virtual interconnect network component.

3. The method according to claim 2, wherein: The network card configuration information also includes first security component information, and the user-side network card is connected to the first virtual switch through a first security component corresponding to the first security component information.

4. The method according to any one of claims 1 to 3, wherein: Sending the access request to the first virtual switch through the user-side network card includes: Acquiring domain name information corresponding to the access request and a domain name information table for analyzing and processing the access request through a configuration unit, wherein the configuration unit is in communication with the user network component; Determine a service access address corresponding to the access request based on the configuration unit, the domain name information table and the domain name information; The access request is sent to the first virtual switch based on the service access address.

5. A point-to-point method for accessing cross-region services on a cloud, wherein: Applied to a virtual interconnection network component, the virtual interconnection network component includes a first virtual switch and at least one second virtual switch that is communicatively connected to the first virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch, the first virtual switch is used to communicate with a user network component, and the second virtual switch is used to communicate with a service provider network component; the method includes: The first virtual switch obtains an access request for the cross-region service through a user-side network card in the user network component; Determining a service access address corresponding to the access request; Based on the service access address, determining a second target virtual switch in at least one second virtual switch; The access request is sent to the service-side network card in the service provider network component based on the second target virtual switch and the service access address to implement cross-region service access operations.

6. The method according to claim 5, wherein: The virtual interconnect network component further includes: a first security component communicatively connected to the user network component and the first virtual switch; Before the first virtual switch obtains the access request for the cross-region service through the user-side network card in the user network component, the method further includes: identifying, by the first security component, whether the access request is a legitimate request; When the access request is a legitimate request, the first virtual switch is allowed to obtain the access request for the cross-region service through the user-side network card in the user network component; When the access request is an illegal request, the first virtual switch is prohibited from obtaining the access request for the cross-region service through the user-side network card in the user network component.

7. The method according to claim 5, wherein: The virtual interconnect network component further includes: a second security component communicatively connected to the service provider network component and the second virtual switch; Before the first virtual switch sends the access request to the service-side network card in the service provider network component based on the service access address and the second virtual switch, the method further includes: identifying, by the second security component, whether the access request is a legitimate request; When the access request is a legitimate request, the first virtual switch is allowed to send the access request to the service-side network card in the service provider network component based on the service access address and the second virtual switch; When the access request is an illegal request, the first virtual switch is prohibited from sending the access request to the service-side network card in the service provider network component based on the service access address and the second virtual switch.

8. A method for publishing cross-region services on a point-to-point cloud, wherein: Applied to a service provider network component, the service provider network component is communicatively connected to at least one virtual internetwork component, the method comprising: Obtain service publishing information of the cross-region service, wherein the service publishing information includes at least: a service identifier, a service port, identification information of a service provider network component, and a service detection strategy; Based on the service publishing information, determine a service-side network card deployed in the cloud server and a second virtual switch communicatively connected to the service-side network card, wherein the second virtual switch is located in a virtual interconnection network component, the virtual interconnection network component also includes a first virtual switch communicatively connected to the second virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch; The service publishing information is sent to the second virtual switch through the service side network card, so that the second virtual switch sends the service publishing information to the configuration unit for service publishing operation, wherein the configuration unit is communicatively connected with virtual switches corresponding to multiple different areas.

9. The method according to claim 8, wherein: Before obtaining the service publishing information of the cross-region service, the method further includes: Acquire network card configuration information corresponding to the virtual interconnect network component, the network card configuration information at least including: a network identifier and second virtual switch information; Based on the network card configuration information, a service-side network card is deployed in the service provider network component, wherein the service-side network card is communicatively connected to the second virtual switch in the virtual interconnect network component.

10. The method according to claim 9, wherein: The network card configuration information also includes second security component information, and the service-side network card is communicatively connected to the second virtual switch through a second security component corresponding to the second security component information.

11. A user network component, wherein: The user network component is communicatively connected to at least one virtual interconnect network component, and the user network component includes: A first acquisition module, used to acquire access requests for cross-region services; A first determination module is configured to determine, based on the access request, a user-side network card deployed in the cloud server and a first virtual switch communicatively connected to the user-side network card, wherein the first virtual switch is located in a virtual interconnection network component, the virtual interconnection network component further includes at least one second virtual switch communicatively connected to the first virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch; The first processing module is used to send the access request to the first virtual switch through the user-side network card, so that the first virtual switch transmits the access request through a target virtual switch in at least one second virtual switch to implement an access operation of a cross-region service.

12. A virtual internetwork component, wherein: The virtual interconnection network component includes a first virtual switch and at least one second virtual switch that is communicatively connected to the first virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch, the first virtual switch is used to communicate with the user network component, and the second virtual switch is used to communicate with the service provider network component; The first virtual switch is used to obtain an access request for a cross-region service through a user-side network card in a user network component, determine a service access address corresponding to the access request, and send the access request to the second virtual switch based on the service access address; The second virtual switch is used to send the access request to the service-side network card in the service provider network component based on the service access address to implement the access operation of the cross-region service.

13. A service provider network component, wherein: The service provider network component is communicatively connected to at least one virtual internet network component, and the service provider network component includes: A second acquisition module is used to acquire service publishing information of the cross-region service, wherein the service publishing information at least includes: a service identifier, a service port, identification information of a service provider network component, and a service detection strategy; A second determination module is used to determine, based on the service publishing information, a service-side network card deployed in the cloud server and a second virtual switch communicatively connected to the service-side network card, wherein the second virtual switch is located in a virtual interconnect network component, the virtual interconnect network component also includes a first virtual switch communicatively connected to the second virtual switch, and the area corresponding to the first virtual switch is different from the area corresponding to the second virtual switch; The second processing module is used to send the service publishing information to the second virtual switch through the service side network card, so that the second virtual switch sends the service publishing information to the configuration unit for service publishing operation, wherein the configuration unit is communicatively connected with virtual switches corresponding to multiple different areas.

14. A point-to-point cloud cross-region service access system, wherein: include: At least one virtual Internet network component for communicating with the user network component and the service provider network component, wherein the areas and address segments corresponding to any two virtual Internet network components are different; the virtual Internet network component includes: The first virtual switch is used to obtain an access request for a cross-region service through a user-side network card in the user network component, determine a service access address corresponding to the access request, and send the access request to a second virtual switch based on the service access address, wherein the user-side network card is deployed on a cloud server; A second virtual switch is communicatively connected to the first virtual switch, wherein the area to which the second virtual switch belongs is different from the area to which the first virtual switch belongs, and is used to receive an access request sent by the first virtual switch, and send the access request to the service provider network component through a service side network card in the service provider network component based on the service access address, so as to implement cross-region service access operations, wherein the service side network card is deployed on a cloud server.

15. An electronic device, wherein: include: A memory, a processor; wherein the memory is used to store one or more computer instructions, wherein the one or more computer instructions, when executed by the processor, implement the method as described in any one of claims 1-10.

16. A computer storage medium for storing a computer program, wherein the computer program enables a computer to implement the method according to any one of claims 1 to 4, claims 5 to 7, and claims 8 to 10 when executed.

17. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 4, claims 5 to 7 and claims 8 to 10 is implemented.

Citation Information

Patent Citations

  • Virtual private cloud service configuration method and device

    CN109889621A

  • Network creation method, server, computer readable storage medium and system

    CN110611588A

  • Communication system, method and device, equipment and storage medium

    CN113709016A

  • Virtual switching overlay for cloud computing

    US20110261828A1

  • Data Packet Processing Method, Host, and System

    US20180302243A1