Network creation method based on cloud management platform and cloud management platform

Through the cloud management platform, select access points in the cloud backbone network to create a virtual gateway, and directly build communication connections between virtual gateways, solving the problem of high communication delay of tenants clusters and achieving efficient cluster interoperability.

WO2025131033A1PCT designated stage expired Publication Date: 2025-06-26HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/140854
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-29
Filing Date
2024-12-20
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

In the existing cloud backbone network, the communication delay between the tenants' clusters is high because the cluster traffic needs to bypass a certain geographical area.

Method used

Through the network creation interface provided by the cloud management platform, tenants can select multiple access points to build branch networks. The cloud management platform creates a virtual gateway on the selected access points, directly building communication connections between the virtual gateways to avoid traffic circulating the geographical area.

Benefits of technology

Direct communication between tenant clusters is realized, communication delay is reduced, and interoperability between clusters is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024140854_26062025_PF_FP_ABST
    Figure CN2024140854_26062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a network creation method based on a cloud management platform and a cloud management platform, for use in improving a communication delay between clusters for tenants. The method of the present application comprises: when a tenant needs to create a branch network, the tenant may send configuration information of the branch network to a cloud management platform; then, on the basis of the configuration information, the cloud management platform may create a first virtual gateway at a first access point selected by the tenant, and create a second virtual gateway at a second access point selected by the tenant; and the cloud management platform may construct the branch network between the first virtual gateway and the second virtual gateway. Because the first access point and a first cluster for the tenant are located in a first geographic region, and the second access point and a second cluster for the tenant are located in a second geographic region, the tenant can enable the first cluster to access the branch network by means of the first virtual gateway, and enable the second cluster to access the branch network by means of the second virtual gateway. Therefore, the communication between the first cluster and the second cluster can be implemented by means of the branch network.
Need to check novelty before this filing date? Find Prior Art

Description

A network creation method based on cloud management platform and cloud management platform

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 22, 2023, with application number 202311791810.9 and invention name “A network architecture based on access gateway device”, and claims priority to the Chinese patent application filed with the State Intellectual Property Office on February 29, 2024, with application number 202410231518.X and invention name “A network creation method and cloud management platform based on cloud management platform”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The embodiments of the present application relate to the field of cloud technology, and in particular to a network creation method based on a cloud management platform and a cloud management platform. Background Art

[0003] With the rapid development of cloud technology, cloud vendors have built cloud backbone networks across the world for tenants to use. Tenants can use the cloud backbone networks provided by cloud vendors to achieve interoperability between their multiple physical server clusters, making it easier for tenants to build distributed data centers.

[0004] In related technologies, cloud backbone networks built independently by cloud vendors typically provide multiple parent access points, each of which is connected to multiple child access points for tenants. Different parent access points are located in different geographic regions, and different child access points are also located in different geographic regions. When a tenant needs to connect two of its clusters, they can select two child access points close to the two clusters from a number of access points and have the two clusters connect to the two child access points, respectively. This allows the two clusters to achieve communication connectivity through the child access points, parent access points, and finally the cloud backbone network.

[0005] In the above process, the tenant's cluster traffic first flows into the child access point, then passes through the child access point's parent access point, and finally enters the cloud backbone network. Therefore, the cluster traffic cannot directly enter the cloud backbone network from the child access point and must pass through the parent access point to enter the cloud backbone network. This means that it must circumvent a certain geographical area, which results in higher communication latency between tenant clusters. Summary of the Invention

[0006] The embodiments of the present application provide a network creation method and a cloud management platform based on a cloud management platform, which can enable cluster traffic to communicate with each other without having to detour through geographical areas, thereby improving the communication latency between clusters of tenants.

[0007] A first aspect of an embodiment of the present application provides a network creation method based on a cloud management platform. The cloud management platform used to implement the method manages multiple access points that can be used to build a branch network of a tenant. The multiple access points are located in different geographical areas. The method includes:

[0008] When a tenant needs to create a branch network for the tenant's first cluster and the tenant's second cluster (both the first cluster and the second cluster contain multiple physical servers), the cloud management platform can provide the tenant with a network creation interface, which can display multiple access points to the tenant. After the tenant browses the multiple access points, since the tenant already knows that the first cluster is located in the first geographical area and the second cluster is located in the second geographical area, the tenant can select the first access point that is also located in the first geographical area and the second access point that is located in the second geographical area from the multiple access points, and input the configuration information of the branch network into the network creation interface. The configuration information is used to indicate the first access point and the second access point. In this way, the cloud management platform can receive the configuration information of the branch network through the network creation interface.

[0009] After obtaining the branch network configuration information, the cloud management platform can determine, based on this configuration information, that the tenant needs to establish a branch network between the first access point and the second access point. The cloud management platform can then create a first virtual gateway specifically serving the tenant in the first physical gateway of the first access point, and a second virtual gateway specifically serving the tenant in the second physical gateway of the second access point.

[0010] After obtaining the first and second virtual gateways, the cloud management platform can establish the branch network between the first and second virtual gateways. Because the first access point where the first virtual gateway resides and the tenant's first cluster are both located in the first geographic area, and the second access point where the second virtual gateway resides and the tenant's second cluster are both located in the second geographic area, the tenant can enable the first cluster to access the branch network through the first virtual gateway and the second cluster to access the branch network through the second virtual gateway. In this way, the first and second clusters can communicate through the branch network.

[0011] The above method demonstrates that the cloud management platform can create virtual gateways (i.e., the first and second virtual gateways) at several access points selected by the tenant (i.e., the first and second access points mentioned above) to build a tenant-specific branch network between the virtual gateways of the access points. Since the access points are selected by the tenant based on the geographic regions where the clusters (i.e., the first and second clusters mentioned above) to be connected are located, that is, the geographic regions where the access points are located (i.e., the first and second geographic regions) respectively overlap with the geographic regions where the tenant's clusters are located (i.e., the first and second geographic regions mentioned above). Therefore, after the tenant's clusters are connected to the tenant's branch network through the virtual gateways of the access points to achieve intercommunication, the cluster traffic does not need to circumvent the geographic region when communicating between the tenant's clusters, thereby improving the communication latency between the tenant's clusters.

[0012] In one possible implementation, the configuration information includes an identifier of a branch network, an identifier of a first access point, and an identifier of a second access point; the identifier of a branch network includes an identity document (ID) of the branch network and a structure of the branch network; the identifier of the first access point includes an ID of a first geographic region, an ID of a first virtual gateway, and an ID of the first access point; and the identifier of the second access point includes an ID of a second geographic region, an ID of a second virtual gateway, and an ID of the second access point. In the aforementioned implementation, the configuration information of a tenant's branch network may include an identifier of the tenant's branch network, an identifier of the first access point, and an identifier of the second access point. The identifier of a branch network may include various information set by the tenant for its branch network, such as an ID set by the tenant for its branch network and a structure set by the tenant for its branch network. The identifier of the first access point may include various information that can be used to represent the first access point selected by the tenant, such as an ID of the first geographic region in which the first access point is located, an ID of a first virtual gateway that can be created at the first access point, and an ID of the first access point itself. The identifier of the second access point may include various information that can be used to represent the second access point selected by the tenant, such as the ID of the second geographical area where the second access point is located, the ID of a second virtual gateway that can be created at the second access point, and the ID of the second access point itself. Therefore, since the configuration information of the tenant's branch network includes the aforementioned information, the configuration information can be used to indicate the first access point and the second access point selected by the tenant for constructing the tenant's branch network.

[0013] In one possible implementation, the structure of the branch network is an end-to-end structure, and the cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway, including: the cloud management platform constructs a communication connection between the first virtual gateway and the second virtual gateway to obtain the branch network. In the aforementioned implementation, if the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is an end-to-end structure, the cloud management platform can use the first virtual gateway and the second virtual gateway as the two endpoints of the tenant's branch network to directly construct a communication connection between the first virtual gateway and the second virtual gateway, thereby obtaining the tenant's branch network. It can be seen from this that tenants can customize their branch networks into an end-to-end structure, and the cloud management platform can build the tenant's branch network according to the tenant's needs, thereby meeting the tenant's needs for branch network settings to adapt to the tenant's needs in different scenarios.

[0014] In one possible implementation, the branch network has a mesh structure, and the configuration information further indicates a third access point for establishing the branch network. The cloud management platform establishing the branch network between the first virtual gateway and the second virtual gateway includes: the cloud management platform establishing communication connections between the first virtual gateway, the second virtual gateway, and a third virtual gateway of the third access point to obtain the branch network; wherein the third virtual gateway is used to provide access to the branch network for a third cluster of the tenant, the third cluster comprising multiple physical servers, and the third cluster being located in a third geographical region where the third access point is located. In the aforementioned implementation, if the configuration information of the tenant's branch network indicates that the tenant's branch network has a mesh structure, and the configuration information indicates not only the first and second access points selected by the tenant for establishing the branch network, but also the third access point selected by the tenant for establishing the branch network, the cloud management platform may further create a third virtual gateway on the third physical gateway of the third access point. The cloud management platform may then use the first, second, and third virtual gateways as any interoperable endpoints in the tenant's branch network to establish communication connections between the first, second, and third virtual gateways, thereby obtaining the tenant's branch network. Subsequently, the tenant can connect the first cluster to the branch network through the first virtual gateway, the second cluster to the branch network through the second virtual gateway, and the third cluster to the branch network through the third virtual gateway. In this way, the first, second, and third clusters can communicate through the branch network. This shows that tenants can customize their branch networks into a mesh structure, and the cloud management platform can build the tenant's branch network according to their needs, thereby meeting the tenant's branch network configuration needs and adapting to the tenant's needs in different scenarios.

[0015] In one possible implementation, the branch network has a hybrid structure, and the configuration information is further used to indicate a third access point for constructing the branch network. The cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway, including: the cloud management platform establishes a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and a third virtual gateway of a third access point, to obtain the branch network; wherein the third virtual gateway is used to provide access to the branch network for the tenant's third cluster, the third cluster including multiple physical servers, and the third cluster being located in a third geographical area where the third access point is located. In the aforementioned implementation, if the configuration information of the tenant's branch network indicates that the tenant's branch network has a hybrid structure, and the configuration information is used not only to indicate the first and second access points selected by the tenant for constructing the branch network, but also to indicate the third access point selected by the tenant for constructing the branch network, the cloud management platform may further create a third virtual gateway on the third physical gateway of the third access point. Then, the cloud management platform can use the first virtual gateway, the second virtual gateway, and the third virtual gateway as endpoints connected in sequence in the tenant's branch network to build a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and the third virtual gateway, thereby obtaining the tenant's branch network. Subsequently, the tenant can enable the first cluster to access the branch network through the first virtual gateway, the second cluster to access the branch network through the second virtual gateway, and the third cluster to access the branch network through the third virtual gateway. In this way, the first cluster, the second cluster, and the third cluster can communicate through the branch network. It can be seen from this that tenants can customize their branch networks into a hybrid structure, and the cloud management platform can build the tenant's branch network according to the tenant's needs, thereby meeting the tenant's needs for branch network settings to adapt to the tenant's needs in different scenarios.

[0016] In one possible implementation, the branch network has a star structure, and the configuration information is further used to indicate a third access point for constructing the branch network. The cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway, including: the cloud management platform establishes a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and a third virtual gateway of the third access point, to obtain the branch network; wherein the third virtual gateway is used to provide access to the branch network for the tenant's third cluster, the third cluster including multiple physical servers, and the third cluster being located in a third geographical area where the third access point is located. In the aforementioned implementation, if the configuration information of the tenant's branch network indicates that the tenant's branch network has a star structure, and the configuration information indicates not only the first and second access points selected by the tenant for constructing the branch network, but also the third access point selected by the tenant for constructing the branch network, the cloud management platform may further create a third virtual gateway on the third physical gateway of the third access point. Then, the cloud management platform can use the first virtual gateway as the center point in the tenant's branch network, and the second virtual gateway and the third virtual gateway as extension points in the branch network to build a communication connection between the first virtual gateway and the second virtual gateway, as well as a communication connection between the first virtual gateway and the third virtual gateway, thereby obtaining the tenant's branch network. Subsequently, the tenant can enable the first cluster to access the branch network through the first virtual gateway, the second cluster to access the branch network through the second virtual gateway, and the third cluster to access the branch network through the third virtual gateway. In this way, the first cluster, the second cluster, and the third cluster can communicate through the branch network. It can be seen from this that tenants can customize their branch networks into a star structure, and the cloud management platform can build the tenant's branch network according to the tenant's needs, thereby meeting the tenant's needs for branch network settings to adapt to the tenant's needs in different scenarios.

[0017] In one possible implementation, the communication connections between the first virtual gateway, the second virtual gateway, and the third virtual gateway are all implemented based on a cloud backbone network.

[0018] In a possible implementation, the first access point and the second access point are any one of the following: a region, an availability zone, a data center, and an equipment room.

[0019] A second aspect of an embodiment of the present application provides a cloud management platform, which is used to manage multiple access points that can build a branch network of a tenant, and the multiple access points are located in different geographical areas. The cloud management platform includes: a receiving module, which is used to receive configuration information of the branch network sent by the tenant through a network creation interface, and the configuration information is used to indicate the first access point and the second access point selected by the tenant from the multiple access points for building the branch network; a creation module, which is used to create the tenant's first virtual gateway in the first physical gateway of the first access point based on the configuration information, and create the tenant's second virtual gateway in the second physical gateway of the second access point; a construction module, which is used to build a branch network between the first virtual gateway and the second virtual gateway; wherein the first virtual gateway is used for the tenant's first cluster to access the branch network, and the second virtual gateway is used for the tenant's second cluster to access the branch network, the first cluster and the second cluster both include multiple physical servers, the first cluster is located in the first geographical area where the first access point is located, and the second cluster is located in the second geographical area where the second access point is located.

[0020] In one possible implementation, the configuration information includes an identifier of the branch network, an identifier of the first access point, and an identifier of the second access point; the identifier of the branch network includes an identity identification number ID of the branch network and a structure of the branch network; the identifier of the first access point includes an ID of the first geographic area, an ID of the first virtual gateway, and an ID of the first access point; the identifier of the second access point includes an ID of the second geographic area, an ID of the second virtual gateway, and an ID of the second access point.

[0021] In a possible implementation, the structure of the branch network is an end-to-end structure, and the construction module is used to establish a communication connection between the first virtual gateway and the second virtual gateway to obtain the branch network.

[0022] In one possible implementation, the structure of the branch network is a mesh structure, and the configuration information is also used to indicate the construction of a third access point for the branch network, and a construction module is used to establish communication connections between the first virtual gateway, the second virtual gateway, and the third virtual gateway of the third access point to obtain the branch network; wherein the third virtual gateway is used for the tenant's third cluster to access the branch network, the third cluster includes multiple physical servers, and the third cluster is located in a third geographical area where the third access point is located.

[0023] In one possible implementation, the structure of the branch network is a hybrid structure, and the configuration information is also used to indicate a third access point for constructing the branch network. The construction module is used to establish a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and a third virtual gateway of the third access point to obtain the branch network; wherein the third virtual gateway is used for a third cluster of the tenant to access the branch network, the third cluster includes multiple physical servers, and the third cluster is located in a third geographical area where the third access point is located.

[0024] In one possible implementation, the structure of the branch network is a star structure, and the configuration information is also used to indicate a third access point for constructing the branch network. The construction module is used to establish a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and a third virtual gateway of the third access point, so as to obtain the branch network; wherein the third virtual gateway is used for a third cluster of the tenant to access the branch network, the third cluster includes multiple physical servers, and the third cluster is located in a third geographical area where the third access point is located.

[0025] In one possible implementation, the communication connection is implemented based on a cloud backbone network.

[0026] In a possible implementation, the first access point and the second access point are any one of the following: a region, an availability zone, a data center, and an equipment room.

[0027] A third aspect of an embodiment of the present application provides a computing device cluster, which includes at least one computing device, each computing device including a processor and a memory: the memory is used to store instructions; the processor is used to enable the computing device cluster to execute the method described in the first aspect or any possible implementation method of the first aspect according to the instructions.

[0028] A fourth aspect of an embodiment of the present application provides a computer storage medium storing one or more instructions, which, when executed by one or more computers, enables the one or more computers to implement the method described in the first aspect or any possible implementation method of the first aspect.

[0029] A fifth aspect of the embodiments of the present application provides a computer program product, which stores instructions. When the instructions are executed by a computer, the computer implements the method described in the first aspect or any possible implementation method of the first aspect.

[0030] In an embodiment of the present application, when a tenant needs to create a branch network for the tenant's first cluster and the tenant's second cluster, the tenant can input the branch network configuration information into the network creation interface provided by the cloud management platform, so that the cloud management platform can receive the branch network configuration information through the network creation interface. The configuration information is used to indicate the first access point and the second access point selected by the tenant from multiple access points. Then, based on the configuration information, the cloud management platform can create a first virtual gateway specifically serving the tenant in the first physical gateway of the first access point, and create a second virtual gateway specifically serving the tenant in the second physical gateway of the second access point. The cloud management platform can then establish a tenant-specific branch network between the first virtual gateway and the second virtual gateway. Because the first access point where the first virtual gateway is located and the tenant's first cluster are both located in the first geographic area, and the second access point where the second virtual gateway is located and the tenant's second cluster are both located in the second geographic area, the tenant can enable the first cluster to access the branch network through the first virtual gateway and the second cluster to access the branch network through the second virtual gateway. In this way, the first cluster and the second cluster can communicate through the branch network. In the above process, the cloud management platform can create virtual gateways (i.e., the first virtual gateway and the second virtual gateway) at several access points selected by the tenant (i.e., the first access point and the second access point) to build a tenant-exclusive branch network between the virtual gateways of the several access points. Since these several access points are selected by the tenant according to the geographical areas where the several clusters (i.e., the first cluster and the second cluster) that the tenant needs to connect are located, that is, the geographical areas where these several access points are located (i.e., the first geographical area and the second geographical area) respectively overlap with the geographical areas where the tenant's several clusters are located (i.e., the first geographical area and the second geographical area). Therefore, after the tenant's several clusters respectively access the tenant's branch network through the virtual gateways of these several access points to achieve interconnection, when the tenant's clusters communicate with each other, the cluster traffic does not need to detour through the geographical area, which can improve the communication latency between the tenant's clusters. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] FIG1 is a schematic diagram of the structure of a cloud service system provided in an embodiment of the present application;

[0032] FIG2 is a schematic diagram of multiple access points provided in an embodiment of the present application;

[0033] FIG3 is another schematic diagram of the structure of the cloud service system provided in an embodiment of the present application;

[0034] FIG4 is a flow chart of a network creation method based on a cloud management platform according to an embodiment of the present application;

[0035] FIG5 is a schematic diagram of a tenant interface provided in an embodiment of the present application;

[0036] FIG6 is another schematic diagram of a tenant interface provided in an embodiment of the present application;

[0037] FIG7 is another schematic diagram of a tenant interface provided in an embodiment of the present application;

[0038] FIG8 is another schematic diagram of a tenant interface provided in an embodiment of the present application;

[0039] FIG9 is a schematic diagram of a branch network provided in an embodiment of the present application;

[0040] FIG10 is another schematic diagram of a branch network provided in an embodiment of the present application;

[0041] FIG11 is another schematic diagram of a branch network provided in an embodiment of the present application;

[0042] FIG12 is another schematic diagram of a branch network provided in an embodiment of the present application;

[0043] FIG13 is a schematic diagram of the structure of a cloud management platform provided in an embodiment of the present application;

[0044] FIG14 is a schematic diagram of the structure of a computing device provided in an embodiment of the present application;

[0045] FIG15 is a schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application;

[0046] FIG16 is a schematic diagram of computer devices in a computer cluster provided by an embodiment of the present application being connected via a network. DETAILED DESCRIPTION

[0047] The network creation method and cloud management platform based on the cloud management platform can ensure that when tenants' clusters communicate with each other, the cluster traffic does not need to detour through geographical areas, thereby improving the communication latency between tenants' clusters.

[0048] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, and this is merely a way of distinguishing the objects of the same attributes when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment.

[0049] With the rapid development of cloud technology, cloud vendors have built global backbone networks for tenants to use. Tenants can use the backbone networks provided by cloud vendors to achieve interoperability between their multiple physical server clusters, making it easier for tenants to build distributed data centers.

[0050] In related technologies, cloud backbone networks built independently by cloud vendors typically provide multiple parent access points, each of which is connected to multiple child access points for tenants. Different parent access points are located in different geographic regions, and different child access points are also located in different geographic regions. When a tenant needs to connect two of its clusters, it can select two child access points close to the two clusters from a number of access points and connect the two clusters to the two child access points, respectively, so that the two clusters can achieve communication connection through the child access points, parent access points, and cloud backbone network in sequence. For example, suppose the backbone network has parent access point A in Guangzhou and parent access point B in Hong Kong. Parent access point A is connected to child access point A1 in Tianhe District and child access point A2 in Yuexiu District. Parent access point B is connected to child access point B1 in the New Territories and child access point B2 in Kowloon. The tenant's cluster 1 is close to child access point A1, and cluster 2 is close to child access point B2. The tenant can connect cluster 1 to child access point A1 and cluster 2 to child access point B2. In this way, cluster 1 establishes a communication connection with cluster 2 via child access point A2, parent access point A, backbone network, parent access point B, and child access point B2 in sequence.

[0051] In the above process, the tenant's cluster traffic first flows into the child access point, then passes through the child access point's parent access point, and finally enters the cloud backbone network. Therefore, the cluster traffic cannot directly enter the cloud backbone network from the child access point and must pass through the parent access point to enter the cloud backbone network. This means that it must circumvent a certain geographical area, which results in higher communication latency between tenant clusters.

[0052] To address the above issues, the present application provides a network creation method based on a cloud management platform. This method can be implemented through a cloud service system. Figure 1 is a schematic diagram of the structure of the cloud service system provided by the present application. As shown in Figure 1, the cloud service system includes an infrastructure that can provide cloud services and a cloud management platform that manages the infrastructure. The cloud management platform and infrastructure are introduced separately below:

[0053] The cloud management platform can coordinate and manage the infrastructure of the entire cloud service system (for example, selecting a number of access points from the multiple access points included in the infrastructure according to the tenant's instructions to build a tenant-specific branch network (site network), etc.), and can also be open to tenants outside the cloud service system and respond to their requests. For example, the cloud management platform can provide various interfaces such as a login interface and a network creation interface for access by tenant clients (for example, a terminal device used by the tenant or a browser on the terminal device, etc.). The cloud management platform can authenticate the tenant's client through the login interface and, after successful authentication, allow the tenant's client to log in to the cloud management platform. For another example, the cloud management platform can also provide the tenant's client with multiple access points that can build the tenant's branch network through the network creation interface, so that the tenant's client can display these multiple access points for the tenant to view and select, where these multiple access points are located in different geographical areas. For another example, the cloud management platform can also allow the tenant's client to send the tenant's branch network configuration information to the cloud management platform through the network creation interface. Then, based on the configuration information, the cloud management platform can determine several access points selected by the tenant from multiple access points, and build the tenant's branch network between these access points. In this way, several clusters of the tenant located in different geographical areas can access the branch network through these access points respectively to achieve intercommunication between clusters in different locations.

[0054] The infrastructure includes multiple access points (also referred to as access sites) that are directly connected to the cloud backbone network. These multiple access points can be used to build branch networks for tenants. It should be noted that these multiple access points are usually located in different geographical areas. For any of these multiple access points, the geographical area where the access point is located can be a certain block, a certain city under a certain block, a certain district, county, or town under a certain city, etc. The size of the geographical area where the access point is located can be set according to actual needs and is not limited here. Since these multiple access points are all directly connected to the cloud backbone network, these multiple access points no longer form a distinction between parent access points and child access points based on the subordinate relationship of geographical areas. In other words, the cloud backbone network directly opens a larger number of access points to tenants, and the relationship between these multiple access points is equal. For example, as shown in Figure 2 (Figure 2 is a schematic diagram of multiple access points provided in an embodiment of the present application), the cloud backbone network spread across the world can provide a large number of access points in various places, for example, an access point located in Huaxin Park, Guangzhou, an access point located in Qili Lake, Guiyang, an access point located in Tseung Kwan O, Hong Kong, etc.

[0055] The following introduces multiple access points from the perspective of physical hardware and virtual software respectively. Figure 3 is another structural diagram of the cloud service system provided by an embodiment of the present application. As shown in Figure 3, for any one of the multiple access points, the access point may include multiple physical gateways, and each physical gateway has been connected to the cloud backbone network, that is, a physical tunnel (also referred to as a physical communication channel) has been established between each physical gateway and the cloud backbone network. Then, when a tenant needs to create its own branch network, the cloud management platform can create a virtual gateway of the tenant on the physical gateway of an access point selected by the tenant in accordance with the tenant's instructions, and create another virtual gateway of the tenant on the physical gateway of another access point selected by the tenant, and build a virtual tunnel (also referred to as a virtual communication channel) between the two virtual gateways to connect the two virtual gateways. The virtual tunnel is built based on the physical tunnel between the physical gateway where the two virtual gateways are located and the cloud backbone network, that is, the virtual tunnel passes through the cloud backbone network. Due to the existence of the virtual tunnel, it can be considered that the two virtual gateways have established a communication connection. In this way, the cloud management platform creates the tenant's branch network. The two virtual gateways can allow the tenant's two clusters (these two clusters are respectively located in the geographical areas where the two access points selected by the tenant are located) to access the tenant's branch network, so that the tenant's clusters can communicate with each other through the tenant's branch network (it should be understood that the above example only uses the tenant's selection of two access points to construct its branch network for schematic illustration. In actual applications, the tenant can also select a larger number of access points to construct its branch network, which will not be repeated here).

[0056] In addition, the cloud management platform can create multiple virtual gateways for clusters of multiple tenants on any physical gateway in any access point. These virtual gateways have the following characteristics: (1) Among the multiple virtual gateways of the access point, one virtual gateway can serve the cluster of one tenant, so that isolation between multiple tenants can be achieved on different virtual gateways of the same access point. (2) Among the multiple virtual gateways of the access point, each virtual gateway has a dedicated virtual tunnel to access the cloud backbone network, so that isolation between multiple tenants can be achieved on the virtual tunnel. (3) For any one of the multiple virtual gateways of the access point, any physical server in the cluster connected to the virtual gateway can have two border gateway protocol (BGP) peer modules. These two BGP modules (also called BGP peers) can enable the physical server to access the virtual gateway in different network segments (for example, two network segments that are mutually active and standby, etc.), so that the cluster access virtual gateway can have line disaster recovery capabilities. Furthermore, the cloud management platform can enable the virtual gateway to learn the network segment (route) of any physical server in the cluster connected to the virtual gateway, so as to achieve communication with any physical server in the cluster. (4) For any virtual gateway among the multiple virtual gateways of the access point, the cloud management platform can also enable the virtual gateway to have traffic collection and traffic speed limiting capabilities, so that it can perform traffic billing for the tenant's cluster, etc.

[0057] Furthermore, a physical gateway is essentially a physical instance in a cloud service system, and a physical instance can be presented in a variety of ways. For example, a physical instance can be a physical server selected by the cloud management platform, or a bare metal server selected by the cloud management platform. A virtual gateway on a physical gateway can also be called a global dedicated gateway (GDGW), or a virtual routing forwarding (VRF) instance on the physical gateway. In other words, a virtual gateway is essentially a virtual instance in a cloud service system, and a virtual instance can be presented in a variety of ways. For example, a virtual instance can be a virtual machine (VM) created on a physical server by the cloud management platform using virtualization technology, or a container (Docker) created on a physical server by the cloud management platform using virtualization technology, or a microVM created on a physical server by the cloud management platform using virtualization technology.

[0058] Furthermore, with respect to the multiple access points, the multiple access points may be presented in various forms. For example, the multiple access points may be multiple regions in the infrastructure, or multiple availability zones in the infrastructure, or multiple data centers (DCs) in the infrastructure, or multiple computer rooms in the infrastructure, and so on.

[0059] Based on the above cloud service system, it can be known that for tenants, tenants usually have multiple clusters (also called multiple branches), each cluster can contain multiple physical servers, and the tenant's multiple clusters are usually located in different geographical areas. When the tenant needs to connect these multiple clusters, the cloud management platform can be used to select several access points from multiple access points to create a tenant-exclusive branch network. Since the branch network is built based on virtual gateways of several access points located in different geographical areas, the tenant's multiple clusters can access the branch network through the nearest virtual gateway, thereby achieving intercommunication between these multiple clusters. In this way, the tenant's cluster can directly access the tenant's branch network from the nearest access point to communicate directly through the branch network. In this way, the cluster traffic no longer needs to detour around a certain geographical area, which can reduce the communication delay between the tenant's clusters. To further understand the aforementioned process, the process is further described below in conjunction with FIG3 . FIG4 is a flow chart of a network creation method based on a cloud management platform provided in an embodiment of the present application. As shown in FIG4 , the method can be implemented by the cloud service system shown in FIG1 . The cloud service system includes an infrastructure for providing cloud services and a cloud management platform for managing the infrastructure. The infrastructure includes multiple access points for building a branch network of a tenant, and the multiple access points are located in different geographical areas. The method includes:

[0060] 401. The cloud management platform receives branch network configuration information sent by a tenant through a network creation interface. The configuration information is used to indicate a first access point and a second access point selected by the tenant from a plurality of access points for building the branch network.

[0061] In this embodiment, when the tenant needs to create a branch network for the tenant's first cluster and the tenant's second cluster, the cloud management platform can provide a network creation interface to the tenant's client (for example, the branch network name input field, the branch network structure input field, and the branch network access point information input field, etc. of the tenant interface), and the network creation interface can display multiple access points for the tenant to choose from. After the tenant browses the multiple access points displayed by the network creation interface through its client, since the tenant already knows that the first cluster is located in the first geographical area and the second cluster is located in the second geographical area, the tenant can select the first access point that is also located in the first geographical area and the second access point that is located in the second geographical area from the multiple access points, and input the tenant's branch network configuration information into the network creation interface through its client. The configuration information is used to indicate the first access point and the second access point. In this way, the cloud management platform can receive the tenant's branch network configuration information through the network creation interface.

[0062] Specifically, the configuration information of a tenant's branch network can be presented in the following ways:

[0063] (1) The configuration information of the tenant's branch network may include the identifier of the tenant's branch network, the identifier of the first access point, and the identifier of the second access point. It should be noted that the identifier of the tenant's branch network is usually customized by the tenant and input into the network creation interface, and the network creation interface may provide the tenant with multiple access point identifiers. The tenant may select and input the identifier of the first access point and the identifier of the second access point from the multiple access point identifiers displayed on the network creation interface. Therefore, the network creation interface may generate the configuration information of the tenant's branch network based on the identifier of the branch network, the identifier of the first access point, and the identifier of the second access point input by the tenant, and send it to the cloud management platform.

[0064] The identifier of a branch network may include various information set by the tenant for its branch network, such as the identity document (ID) set by the tenant for its branch network and the structure (e.g., end-to-end structure, etc.) set by the tenant for its branch network. The identifier of a first access point may include various information that can be used to represent the first access point selected by the tenant, such as the ID of the first geographic region where the first access point is located, the ID of a first virtual gateway that can be created on the first access point, and the ID of the first access point itself. The identifier of a second access point may include various information that can be used to represent the second access point selected by the tenant, such as the ID of the second geographic region where the second access point is located, the ID of a second virtual gateway that can be created on the second access point, and the ID of the second access point itself.

[0065] For example, as shown in Figure 5 (Figure 5 is a schematic diagram of a tenant interface provided in an embodiment of the present application), when a tenant needs to build its own branch network, it can log in to the cloud management platform. The cloud management platform can provide a tenant interface for the tenant. The tenant can enter the branch network ID as site-work-fc25 in the branch network name input field of the tenant interface. Assume that the tenant needs to connect cluster 1 and cluster 2. Cluster 1 is located in Qili Lake, Guiyang, and cluster 2 is located in Runze, Beijing. The tenant wants to form an end-to-end network between these two clusters. Therefore, the tenant can select and enter the branch network structure as an end-to-end structure from the multiple structures provided in the branch network structure input field. In this case, the branch network access point information input field can include two input fields. From the multiple access point information provided in the first input field, the tenant can select and enter the ID of the geographical area where access point 1 is located as Southwest-Guiyang-Qili Lake in the first input field, and select and enter the ID of virtual gateway 1 that can be created at access point 1 as er-0818-1 in the second input field. In this case, the first input field will automatically generate the ID of access point 1 as Guiyang 61238 (of course, the tenant can also set and enter it by themselves). Similarly, the tenant can select and enter the ID of the geographical region where Access Point 2 is located as North China-Beijing-Runze in the second input field, and select and enter the ID of Virtual Gateway 2, which can be created at Access Point 2, as er-0818-2 in the second input field. The second input field will automatically generate the ID of Access Point 2 as Beijing 64512. The information entered by the tenant in each input field can then be aggregated into the tenant's branch network configuration information, which can be sent to the cloud management platform through these input fields.

[0066] (2) If the tenant needs to build a first cluster, a second cluster, and a third cluster (located in a third geographical area) that can be rented to create a branch network, the tenant can select a first access point that is also located in the first geographical area, a second access point that is located in the second geographical area, and a third access point that is located in the third geographical area from the multiple access points provided by the network creation interface, and send the branch network configuration information to the cloud management platform through the network creation interface. It can be seen that the branch network configuration information can include not only the identifier of the tenant's branch network, the identifier of the first access point, and the identifier of the second access point, but also the identifier of the third access point. It should be noted that the identifier of the tenant's branch network is usually defined by the tenant and input into the network creation interface, and the network creation interface can provide the tenant with multiple access point identifiers. The tenant can select and input the identifier of the first access point, the identifier of the second access point, and the identifier of the third access point from the multiple access point identifiers displayed on the network creation interface. Therefore, the network creation interface can generate the tenant's branch network configuration information based on the identifier of the branch network, the identifier of the first access point, the identifier of the second access point, and the identifier of the third access point input by the tenant, and send it to the cloud management platform.

[0067] The branch network identifier may include various information set by the tenant for its branch network, such as the ID set by the tenant for its branch network and the structure set by the tenant for its branch network (e.g., mesh structure, hybrid structure, star structure, etc.). The first access point identifier may include various information that can be used to represent the first access point selected by the tenant, such as the ID of the first geographical region where the first access point is located, the ID of the first virtual gateway that can be created on the first access point, and the ID of the first access point itself. The second access point identifier may include various information that can be used to represent the second access point selected by the tenant, such as the ID of the second geographical region where the second access point is located, the ID of the second virtual gateway that can be created on the second access point, and the ID of the second access point itself. The third access point identifier may include various information that can be used to represent the third access point selected by the tenant, such as the ID of the third geographical region where the third access point is located, the ID of the third virtual gateway that can be created on the third access point, and the ID of the third access point itself.

[0068] For example, as shown in Figure 6 (Figure 6 is another schematic diagram of the tenant interface provided in an embodiment of the present application), when the tenant needs to build its own branch network, the tenant can log in to the cloud management platform. The cloud management platform can provide a tenant interface for the tenant, and the tenant can enter the branch network ID as site-work-fc25 in the branch network name input field of the tenant interface. Suppose the tenant needs to connect cluster 1, cluster 2, cluster 3 and cluster 4, cluster 1 is located in Qili Lake, Guiyang, cluster 2 is located in Runze, Beijing, cluster 3 is located in XX, Ulanqab, and cluster 4 is located in Huaxin Park, Guangzhou, and the tenant wants to form a mesh network between these four clusters, so the tenant can select and enter the structure of the branch network as a mesh structure from the multiple structures provided in the branch network structure input field. In this case, the branch network access point information input field may include four input fields. From the information about multiple access points provided in the first input field, the tenant can select and enter the ID of the geographic region where access point 1 is located as Southwest-Guiyang-Qilihu in the first input field, and select and enter the ID of Virtual Gateway 1, which can be created at access point 1, as er-0818-1 in the first input field. In this case, the first input field will automatically generate the ID of access point 1 as Guiyang 61238. Similarly, from the information about multiple access points provided in the second input field, the tenant can select and enter the ID of the geographic region where access point 2 is located as North China-Beijing-Runze in the second input field, and select and enter the ID of Virtual Gateway 2, which can be created at access point 2, as er-0818-2 in the second input field. In this case, the second input field will automatically generate the ID of access point 2 as Beijing 64512. Similarly, in the third input field, the tenant can select and enter the geographical region ID of Access Point 3 as North China-Ulanqab-XX and the ID of Virtual Gateway 3, which can be created on Access Point 3, as er-0818-3. The third input field will automatically generate the ID of Access Point 3 as Ulanqab 67892. Similarly, in the fourth input field, the tenant can select and enter the geographical region ID of Access Point 4 as South China-Guangzhou-Huaxinyuan and the ID of Virtual Gateway 4, which can be created on Access Point 4, as er-0818-4. The fourth input field will automatically generate the ID of Access Point 4 as Guangzhou 67788. The information entered by the tenant in each input field can then be aggregated into the tenant's branch network configuration information, which can then be sent to the cloud management platform through these input fields.

[0069] For another example, as shown in Figure 7 (Figure 7 is another schematic diagram of the tenant interface provided in an embodiment of the present application), when the tenant needs to build his own branch network, he can log in to the cloud management platform. The cloud management platform can provide a tenant interface for the tenant, and the tenant can enter the branch network ID as site-work-fc25 in the branch network name input field of the tenant interface. Assume that the tenant needs to connect cluster 1, cluster 2, cluster 3 and cluster 4, cluster 1 is located in Qili Lake, Guiyang, cluster 2 is located in Runze, Beijing, cluster 3 is located in XX, Ulanqab, and cluster 4 is located in Huaxin Park, Guangzhou, and the tenant wants to form a mixed network between these four clusters, so the tenant can select and enter the structure of the branch network as a mixed structure from the multiple structures provided in the branch network structure input field. At this time, the access point information input field of the branch network can include six input fields in pairs, the first input field and the second input field are a pair (indicating that the access points of the two input fields are connected), the third input field and the fourth input field are a pair (indicating that the access points in the two input fields are connected), and the fifth input field and the sixth input field are a pair (indicating that the access points in the two input fields are connected). In the first input field, a tenant can select and enter the ID of the geographic region where access point 1 is located as Southwest-Guiyang-Qilihu, and select and enter the ID of Virtual Gateway 1, which can be created at access point 1, as er-0818-1. In this case, the first input field will automatically generate the ID of access point 1 as Guiyang 61238. Similarly, in the second input field, a tenant can select and enter the ID of the geographic region where access point 2 is located as North China-Beijing-Runze, and select and enter the ID of Virtual Gateway 2, which can be created at access point 2, as er-0818-2. In this case, the second input field will automatically generate the ID of access point 2 as Beijing 64512. It is worth noting that the information in the third input field is the same as that in the second input field and will not be repeated here. Similarly, the tenant can select and enter the ID of the geographical region where access point 3 is located as North China-Ulanqab-XX in the fourth input field, and select and enter the ID of Virtual Gateway 3 that can be created at access point 3 as er-0818-3 in the fourth input field. In this case, the fourth input field will automatically generate the ID of access point 3 as Ulanqab 67892. It is worth noting that the information in the fifth input field is the same as the information in the fourth input field and will not be repeated here. Similarly, the tenant can select and enter the ID of the geographical region where access point 4 is located as South China-Guangzhou-Huaxinyuan in the sixth input field, and select and enter the ID of Virtual Gateway 4 that can be created at access point 4 as er-0818-4 in the sixth input field. In this case, the sixth input field will automatically generate the ID of access point 4 as Guangzhou 67788.Then, the information entered by the tenant in each input field can be aggregated into the configuration information of the tenant's branch network and sent to the cloud management platform through these input fields.

[0070] For another example, as shown in Figure 8 (Figure 8 is another schematic diagram of the tenant interface provided in an embodiment of the present application), when the tenant needs to build its own branch network, the tenant can log in to the cloud management platform. The cloud management platform can provide a tenant interface for the tenant, and the tenant can enter the branch network ID as site-work-fc25 in the branch network name input field of the tenant interface. Suppose the tenant needs to connect cluster 1, cluster 2 and cluster 4, cluster 1 is located in Qili Lake, Guiyang, cluster 2 is located in Runze, Beijing, and cluster 3 is located in XX, Ulanqab, and the tenant wants to form a star-shaped network between these three clusters, so the tenant can select and enter the branch network structure as a star structure from the multiple structures provided in the branch network structure input field. In this case, the branch network access point information input field can contain three fields. The first field is the center field of the star structure, and the second and third fields are the spoke fields of the star structure. Therefore, from the information provided in the first field, the tenant can select and enter the ID of the geographical region where access point 1 is located as Southwest-Guiyang-Qilihu in the first field, and select and enter the ID of Virtual Gateway 1, which can be created at access point 1, as er-0818-1 in the first field. In this case, the first field will automatically generate the ID of access point 1 as Guiyang 61238. Similarly, from the information provided in the second field, the tenant can select and enter the ID of the geographical region where access point 2 is located as North China-Beijing-Runze in the second field, and select and enter the ID of Virtual Gateway 2, which can be created at access point 2, as er-0818-2 in the second field. In this case, the second field will automatically generate the ID of access point 2 as Beijing 64512. Similarly, the tenant can select and enter the ID of the geographical region where access point 3 is located as North China-Ulanqab-XX in the third input field, and select and enter the ID of Virtual Gateway 3, which can be created at access point 3, as er-0818-3. The third input field will automatically generate the ID of access point 3 as Ulanqab 67892. The information entered by the tenant in each input field can then be aggregated into the tenant's branch network configuration information, which can be sent to the cloud management platform through these input fields.

[0071] 402. The cloud management platform creates a first virtual gateway of the tenant in the first physical gateway of the first access point based on the configuration information, and creates a second virtual gateway of the tenant in the second physical gateway of the second access point.

[0072] After obtaining the tenant's branch network configuration information, the cloud management platform can determine, based on this configuration information, that the tenant needs to build a tenant-specific branch network between the first access point and the second access point. The cloud management platform can then locate the first access point and the second access point from among the multiple access points, create a first virtual gateway specifically serving the tenant in the first physical gateway of the first access point, and create a second virtual gateway specifically serving the tenant in the second physical gateway of the second access point.

[0073] It should be noted that if the cloud management platform determines, based on the configuration information, that the tenant needs to build a tenant-exclusive branch network between the first access point, the second access point, and the third access point, that is, the configuration information is not only used to indicate the first access point and the second access point, but also to indicate the third access point, the cloud management platform can find the first access point, the second access point, and the third access point from multiple access points, create a first virtual gateway specifically serving the tenant in the first physical gateway of the first access point, create a second virtual gateway specifically serving the tenant in the second physical gateway of the second access point, and create a third virtual gateway specifically serving the tenant in the third physical gateway of the third access point.

[0074] 403. The cloud management platform constructs a branch network between the first virtual gateway and the second virtual gateway, wherein the first virtual gateway is used for the tenant's first cluster to access the branch network, and the second virtual gateway is used for the tenant's second cluster to access the branch network. Both the first cluster and the second cluster include multiple physical servers. The first cluster is located in the first geographical area where the first access point is located, and the second cluster is located in the second geographical area where the second access point is located.

[0075] After obtaining the first virtual gateway and the second virtual gateway, the cloud management platform can build a tenant-specific branch network between the first virtual gateway and the second virtual gateway. Since the first virtual gateway (the first access point where it is located) and the tenant's first cluster are both located in the first geographical area, and the second virtual gateway (the second access point where it is located) and the tenant's second cluster are both located in the second geographical area, the tenant can connect the first cluster to the first virtual gateway so that the first cluster can access the tenant's branch network through the first virtual gateway, and connect the second cluster to the second virtual gateway so that the second cluster can access the tenant's branch network through the second virtual gateway. In this way, the first cluster and the second cluster can communicate through the tenant's branch network.

[0076] Specifically, the cloud management platform can create a tenant's branch network between the first virtual gateway and the second virtual gateway in the following ways:

[0077] (1) If the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is an end-to-end structure (also known as a point-to-point structure), the cloud management platform may use the first virtual gateway and the second virtual gateway as the two endpoints of the tenant's branch network to directly establish a communication connection between the first virtual gateway and the second virtual gateway, thereby obtaining the tenant's branch network.

[0078] Still taking the example shown in Figure 5, after receiving the configuration information, since the configuration information indicates that the structure of the tenant's branch network is an end-to-end structure, the cloud management platform can create virtual gateway 1 on a physical gateway of access point 1 indicated by the configuration information, create virtual gateway 2 on a physical gateway of access point 2 indicated by the configuration information, and establish a communication connection between virtual gateway 1 and virtual gateway 2, thereby building a branch network as shown in Figure 9 between virtual gateway 1 and virtual gateway 2. Figure 9 is a schematic diagram of a branch network provided in an embodiment of the present application. Then, the tenant can enable cluster 1 to access the branch network through virtual gateway 1, and enable cluster 2 to access the branch network through virtual gateway 2, so that cluster 1 and cluster 2 can communicate with each other through the branch network.

[0079] (2) If the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is a mesh structure, the cloud management platform may use the first virtual gateway, the second virtual gateway, and the third virtual gateway as any endpoints that are interconnected between any two of the tenant's branch network to establish a communication connection between the first virtual gateway, the second virtual gateway, and the third virtual gateway, thereby obtaining the tenant's branch network.

[0080] Since the first virtual gateway and the tenant's first cluster are both located in the first geographical area, the second virtual gateway and the tenant's second cluster are both located in the second geographical area, and the third virtual gateway and the tenant's third cluster are both located in the third geographical area, the tenant can connect the first cluster to the first virtual gateway so that the first cluster can access the branch network through the first virtual gateway, connect the second cluster to the second virtual gateway so that the second cluster can access the branch network through the second virtual gateway, and connect the third cluster to the third virtual gateway so that the third cluster can access the branch network through the third virtual gateway. In this way, the first cluster, the second cluster, and the third cluster can communicate through the branch network.

[0081] Still referring to the example shown in FIG6 , after receiving the configuration information, since the configuration information indicates that the structure of the tenant's branch network is a mesh structure, the cloud management platform can create virtual gateway 1 on a physical gateway of access point 1 indicated by the configuration information, create virtual gateway 2 on a physical gateway of access point 2 indicated by the configuration information, create virtual gateway 3 on a physical gateway of access point 3 indicated by the configuration information, and create virtual gateway 4 on a physical gateway of access point 4 indicated by the configuration information, and establish communication connections between virtual gateways 1, 2, 3, and 4, thereby building a branch network as shown in FIG10 between virtual gateways 1, 2, 3, and 4. FIG10 is another schematic diagram of a branch network provided in an embodiment of the present application. Then, the tenant can enable cluster 1 to access the branch network through virtual gateway 1, cluster 2 to access the branch network through virtual gateway 2, cluster 3 to access the branch network through virtual gateway 3, and cluster 4 to access the branch network through virtual gateway 4, thereby enabling clusters 1, 2, 3, and 4 to communicate with each other through the branch network.

[0082] (3) If the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is a hybrid structure, the cloud management platform may use the first virtual gateway, the second virtual gateway, and the third virtual gateway as endpoints connected in sequence in the tenant's branch network to establish a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and the third virtual gateway, thereby obtaining the tenant's branch network.

[0083] Still referring to the example shown in FIG7 , after receiving the configuration information, since the configuration information indicates that the structure of the tenant's branch network is a mesh structure, the cloud management platform can create virtual gateway 1 on a physical gateway of access point 1 indicated by the configuration information, create virtual gateway 2 on a physical gateway of access point 2 indicated by the configuration information, create virtual gateway 3 on a physical gateway of access point 3 indicated by the configuration information, and create virtual gateway 4 on a physical gateway of access point 4 indicated by the configuration information, and sequentially establish communication connections between virtual gateway 1, virtual gateway 2, virtual gateway 3, and virtual gateway 4, thereby building a branch network as shown in FIG11 between virtual gateway 1, virtual gateway 2, virtual gateway 3, and virtual gateway 4. FIG11 is another schematic diagram of the branch network provided in an embodiment of the present application. Then, the tenant can enable cluster 1 to access the branch network through virtual gateway 1, cluster 2 to access the branch network through virtual gateway 2, cluster 3 to access the branch network through virtual gateway 3, and cluster 4 to access the branch network through virtual gateway 4, thereby enabling clusters 1, 2, 3, and 4 to communicate with each other through the branch network.

[0084] (4) If the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is a star structure, the cloud management platform may use the first virtual gateway as the center point in the tenant's branch network, and the second virtual gateway and the third virtual gateway as extension points in the branch network to establish a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and the third virtual gateway, thereby obtaining the tenant's branch network.

[0085] Still referring to the example shown in FIG8 , after receiving the configuration information, since the configuration information indicates that the structure of the tenant's branch network is a star structure, the cloud management platform can create a virtual gateway 1 on a physical gateway of access point 1 indicated by the configuration information, create a virtual gateway 2 on a physical gateway of access point 2 indicated by the configuration information, and create a virtual gateway 3 on a physical gateway of access point 3 indicated by the configuration information, and use virtual gateway 1 as the center of the branch network, virtual gateway 2 and virtual gateway 3 as extensions of the branch network, establish a communication connection between virtual gateway 1 and virtual gateway 2, and establish a communication connection between virtual gateway 1 and virtual gateway 3, thereby building a branch network as shown in FIG12 between virtual gateway 1, virtual gateway 2 and virtual gateway 3. FIG12 is another schematic diagram of the branch network provided in an embodiment of the present application. Then, the tenant can enable cluster 1 to access the branch network through virtual gateway 1, cluster 2 to access the branch network through virtual gateway 2, and cluster 3 to access the branch network through virtual gateway 3, so that clusters 1, cluster 2 and cluster 3 can communicate with each other through the branch network.

[0086] In an embodiment of the present application, when a tenant needs to create a branch network for the tenant's first cluster and the tenant's second cluster, the tenant can input the branch network configuration information into the network creation interface provided by the cloud management platform, so that the cloud management platform can receive the branch network configuration information through the network creation interface. The configuration information is used to indicate the first access point and the second access point selected by the tenant from multiple access points. Then, based on the configuration information, the cloud management platform can create a first virtual gateway specifically serving the tenant in the first physical gateway of the first access point, and create a second virtual gateway specifically serving the tenant in the second physical gateway of the second access point. The cloud management platform can then establish a tenant-specific branch network between the first virtual gateway and the second virtual gateway. Because the first access point where the first virtual gateway is located and the tenant's first cluster are both located in the first geographic area, and the second access point where the second virtual gateway is located and the tenant's second cluster are both located in the second geographic area, the tenant can enable the first cluster to access the branch network through the first virtual gateway and the second cluster to access the branch network through the second virtual gateway. In this way, the first cluster and the second cluster can communicate through the branch network. In the above process, the cloud management platform can create virtual gateways (i.e., the first virtual gateway and the second virtual gateway) at several access points selected by the tenant (i.e., the first access point and the second access point) to build a tenant-exclusive branch network between the virtual gateways of the several access points. Since these several access points are selected by the tenant according to the geographical areas where the several clusters (i.e., the first cluster and the second cluster) that the tenant needs to connect are located, that is, the geographical areas where these several access points are located (i.e., the first geographical area and the second geographical area) respectively overlap with the geographical areas where the tenant's several clusters are located (i.e., the first geographical area and the second geographical area). Therefore, after the tenant's several clusters respectively access the tenant's branch network through the virtual gateways of these several access points to achieve interconnection, when the tenant's clusters communicate with each other, the cluster traffic does not need to detour through the geographical area, which can improve the communication latency between the tenant's clusters.

[0087] Furthermore, in an embodiment of the present application, the cloud management platform provides multiple access points for tenants to choose from through a network creation interface. After selecting an access point, the tenant can also define the structure of the branch network at the network creation interface, such as an end-to-end structure, a mesh structure, a hybrid structure, and a star structure, etc., which can meet the tenant's various branch network setting needs to adapt to the tenant's needs in different scenarios.

[0088] Furthermore, in an embodiment of the present application, the cloud management platform can also present the tenant's branch network in the form of a topology diagram and Json / Yaml template to the tenant for viewing and adjustment through a network creation interface, which is conducive to managing its branch network and improving the tenant's experience.

[0089] The above is a detailed description of the network creation method based on the cloud management platform provided in the embodiment of the present application. The cloud management platform provided in the embodiment of the present application will be introduced below. Figure 13 is a structural schematic diagram of the cloud management platform provided in the embodiment of the present application. As shown in Figure 13, the cloud management platform is used to manage multiple access points that can build a branch network of tenants. The multiple access points are located in different geographical areas. The cloud management platform includes:

[0090] The receiving module 1301 is used to receive the configuration information of the branch network sent by the tenant through the network creation interface, where the configuration information is used to indicate the first access point and the second access point selected by the tenant from multiple access points for building the branch network; for example, the receiving module 1301 is used to implement step 401 in the embodiment shown in Figure 4.

[0091] The creation module 1302 is configured to create a first virtual gateway of the tenant in the first physical gateway of the first access point based on the configuration information, and to create a second virtual gateway of the tenant in the second physical gateway of the second access point; for example, the creation module 1302 is configured to implement step 402 in the embodiment shown in FIG. 4 .

[0092] The construction module 1303 is used to construct a branch network between the first virtual gateway and the second virtual gateway; for example, the construction module 1303 is used to implement step 403 in the embodiment shown in FIG. 4 .

[0093] Among them, the first virtual gateway is used for the tenant's first cluster to access the branch network, and the second virtual gateway is used for the tenant's second cluster to access the branch network. The first cluster and the second cluster both contain multiple physical servers. The first cluster is located in the first geographical area where the first access point is located, and the second cluster is located in the second geographical area where the second access point is located.

[0094] In one possible implementation, the configuration information includes an identifier of the branch network, an identifier of the first access point, and an identifier of the second access point; the identifier of the branch network includes an identity identification number ID of the branch network and a structure of the branch network; the identifier of the first access point includes an ID of the first geographic area, an ID of the first virtual gateway, and an ID of the first access point; the identifier of the second access point includes an ID of the second geographic area, an ID of the second virtual gateway, and an ID of the second access point.

[0095] In a possible implementation, the construction module 1303 is configured to establish a communication connection between the first virtual gateway and the second virtual gateway to obtain a branch network.

[0096] In one possible implementation, the structure of the branch network is a mesh structure, and the configuration information is also used to indicate the construction of a third access point for the branch network. The construction module 1303 is used to establish communication connections between the first virtual gateway, the second virtual gateway, and the third virtual gateway of the third access point to obtain the branch network; wherein the third virtual gateway is used for the tenant's third cluster to access the branch network, the third cluster includes multiple physical servers, and the third cluster is located in a third geographical area where the third access point is located.

[0097] In one possible implementation, the structure of the branch network is a hybrid structure, and the configuration information is also used to indicate a third access point for constructing the branch network. Construction module 1303 is used to establish a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and a third virtual gateway of the third access point to obtain the branch network; wherein the third virtual gateway is used for a third cluster of the tenant to access the branch network, the third cluster includes multiple physical servers, and the third cluster is located in a third geographical area where the third access point is located.

[0098] In one possible implementation, the structure of the branch network is a star structure, and the configuration information is also used to indicate a third access point for constructing the branch network. Construction module 1303 is used to establish a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and a third virtual gateway of the third access point, so as to obtain the branch network; wherein the third virtual gateway is used for a third cluster of the tenant to access the branch network, the third cluster includes multiple physical servers, and the third cluster is located in a third geographical area where the third access point is located.

[0099] In one possible implementation, the communication connection is implemented based on a cloud backbone network.

[0100] In a possible implementation, the first access point and the second access point are any one of the following: a region, an availability zone, a data center, and an equipment room.

[0101] It should be noted that the information interaction, implementation process, etc. between the modules / units of the above-mentioned device are based on the same concept as the method embodiment of the present application, and the technical effects they bring are the same as those of the method embodiment of the present application. For specific contents, please refer to the description in the method embodiment shown above in the embodiment of the present application, and no further details will be given here.

[0102] Please refer to Figure 14, which is a schematic diagram of the structure of a computing device provided in an embodiment of the present application. As shown in Figure 14, the computing device 1400 (which can be used to present the aforementioned cloud management platform) includes: a processor 1401, a memory 1402, a communication interface 1403, and a bus 1404. The processor 1401, the memory 1402, and the communication interface 1403 are coupled via a bus (not labeled in the figure). The memory 1402 stores instructions. When the execution instructions in the memory 1402 are executed, the computing device 1400 executes the method executed by the cloud management platform in the above method embodiment.

[0103] The computing device 1400 may be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), one or more digital signal processors (DSPs), one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For example, when a unit in the apparatus can be implemented in the form of a processing element scheduler, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call a program. For example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0104] The processor 1401 may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0105] Memory 1402 may be volatile memory or nonvolatile memory, or may include both volatile and nonvolatile memory. Nonvolatile memory may be read-only memory (ROM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory may be random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0106] Memory 1402 stores executable program code, and processor 1401 executes the executable program code to implement the functions of the aforementioned receiving module, creation module, and construction module, thereby implementing the aforementioned network creation method based on the cloud management platform. In other words, memory 1402 stores instructions for executing the aforementioned network creation method based on the cloud management platform.

[0107] The communication interface 1403 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1400 and other devices or a communication network.

[0108] In addition to the data bus, bus 1404 may also include a power bus, a control bus, and a status signal bus. The bus may be a Peripheral Component Interconnect Express (PCIe) bus, an Extended Industry Standard Architecture (EISA) bus, a unified bus (Ubus or UB), a Compute Express Link (CXL), or a Cache Coherent Interconnect for Accelerators (CCIX). Buses can be categorized as address buses, data buses, and control buses.

[0109] Please refer to Figure 15 , which is a schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application. As shown in Figure 15 , the computing device cluster 1500 includes at least one computing device 1400 .

[0110] As shown in Figure 15, the computing device cluster 1500 includes at least one computing device 1400. The memory 1402 in one or more computing devices 1400 in the computing device cluster 1500 may store the same instructions for executing the above-mentioned network creation method based on the cloud management platform.

[0111] In some possible implementations, the memory 1402 of one or more computing devices 1400 in the computing device cluster 1500 may also store partial instructions for executing the aforementioned cloud management platform-based network creation method. In other words, the combination of one or more computing devices 1400 can jointly execute the aforementioned cloud management platform-based network creation method.

[0112] It should be noted that the memory 1402 in different computing devices 1400 in the computing device cluster 1500 may store different instructions, each for executing a portion of the functions of the aforementioned cloud management platform. In other words, the instructions stored in the memory 1402 in different computing devices 1400 may implement the functions of one or more modules such as the receiving module, the creating module, and the constructing module.

[0113] In some possible implementations, one or more computing devices 1400 in the computing device cluster 1500 may be connected via a network, which may be a wide area network or a local area network.

[0114] Please refer to Figure 16, which is a schematic diagram of computer devices in a computer cluster provided by an embodiment of the present application being connected via a network. As shown in Figure 16, two computing devices 1400A and 1400B are connected via a network. Specifically, each computing device is connected to the network via a communication interface in the computing device.

[0115] In one possible implementation, the memory of the computing device 1400A stores instructions for executing functions of a receiving module and the like. Meanwhile, the memory of the computing device 1400B stores instructions for executing functions of a creating module and a building module and the like.

[0116] It should be understood that the functions of the computing device 1400A shown in Figure 16 may also be completed by multiple computing devices. Similarly, the functions of the computing device 1400B may also be completed by multiple computing devices.

[0117] An embodiment of the present application also relates to a computer storage medium, in which a program for signal processing is stored. When the computer storage medium is run on a computer, the computer executes the steps executed by the cloud management platform in the embodiment shown in Figure 4.

[0118] An embodiment of the present application also relates to a computer program product, which stores instructions that, when executed by a computer, enable the computer to execute the steps performed by the cloud management platform in the embodiment shown in FIG4 .

[0119] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0120] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0121] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0122] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0123] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

Claims

1. A network creation method based on a cloud management platform, characterized in that: The cloud management platform is used to manage multiple access points that can build a branch network of a tenant, and the multiple access points are located in different geographical areas. The method includes: The cloud management platform receives the configuration information of the branch network sent by the tenant through the network creation interface, wherein the configuration information is used to indicate the first access point and the second access point selected by the tenant from the multiple access points for building the branch network; The cloud management platform creates a first virtual gateway of the tenant in a first physical gateway of the first access point based on the configuration information, and creates a second virtual gateway of the tenant in a second physical gateway of the second access point; The cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway; The first virtual gateway is used for the first cluster of the tenant to access the branch network, and the second virtual gateway is used for the second cluster of the tenant to access the branch network. The first cluster and the second cluster both include multiple physical servers. The first cluster is located in a first geographical area where the first access point is located, and the second cluster is located in a second geographical area where the second access point is located.

2. The method according to claim 1, characterized in that The configuration information includes an identifier of the branch network, an identifier of the first access point, and an identifier of the second access point; The identification of the branch network includes the identification number ID of the branch network and the structure of the branch network; The identifier of the first access point includes the ID of the first geographical area, the ID of the first virtual gateway and the ID of the first access point; The identifier of the second access point includes the ID of the second geographical area, the ID of the second virtual gateway, and the ID of the second access point.

3. The method according to claim 2, characterized in that The structure of the branch network is an end-to-end structure, and the cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway, including: The cloud management platform establishes a communication connection between the first virtual gateway and the second virtual gateway to obtain the branch network.

4. The method according to claim 2, characterized in that: The structure of the branch network is a mesh structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway, including: The cloud management platform establishes communication connections between the first virtual gateway, the second virtual gateway and the third virtual gateway of the third access point to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.

5. The method according to claim 2, characterized in that: The structure of the branch network is a hybrid structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway, including: The cloud management platform establishes a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and a third virtual gateway of the third access point, so as to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.

6. The method according to claim 2, characterized in that The structure of the branch network is a star structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway, including: The cloud management platform establishes a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and a third virtual gateway of the third access point, so as to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.

7. The method according to any one of claims 3 to 6, characterized in that: The communication connection is realized based on the cloud backbone network.

8. The method according to any one of claims 1 to 7, characterized in that: The first access point and the second access point are any one of the following: a region, an availability zone, a data center, and a computer room.

9. A cloud management platform, characterized in that: The cloud management platform is used to manage multiple access points that can build a branch network of a tenant, and the multiple access points are located in different geographical areas. The cloud management platform includes: A receiving module, configured to receive the configuration information of the branch network sent by the tenant through a network creation interface, wherein the configuration information is used to indicate a first access point and a second access point selected by the tenant from the plurality of access points for building the branch network; a creation module, configured to create a first virtual gateway of the tenant in a first physical gateway of the first access point based on the configuration information, and to create a second virtual gateway of the tenant in a second physical gateway of the second access point; A construction module, configured to construct the branch network between the first virtual gateway and the second virtual gateway; The first virtual gateway is used for the first cluster of the tenant to access the branch network, and the second virtual gateway is used for the second cluster of the tenant to access the branch network. The first cluster and the second cluster both include multiple physical servers. The first cluster is located in a first geographical area where the first access point is located, and the second cluster is located in a second geographical area where the second access point is located.

10. The cloud management platform according to claim 9, characterized in that: The configuration information includes an identifier of the branch network, an identifier of the first access point, and an identifier of the second access point; The identification of the branch network includes the identification number ID of the branch network and the structure of the branch network; The identifier of the first access point includes the ID of the first geographical area, the ID of the first virtual gateway and the ID of the first access point; The identifier of the second access point includes the ID of the second geographical area, the ID of the second virtual gateway, and the ID of the second access point.

11. The cloud management platform according to claim 10, characterized in that: The construction module is used to construct a communication connection between the first virtual gateway and the second virtual gateway to obtain the branch network.

12. The cloud management platform according to claim 10, characterized in that: The structure of the branch network is a mesh structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the construction module is used to construct a communication connection between the first virtual gateway, the second virtual gateway and the third virtual gateway of the third access point, so as to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.

13. The cloud management platform according to claim 10, characterized in that: The structure of the branch network is a hybrid structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the construction module is used to construct a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and a third virtual gateway of the third access point, so as to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.

14. The cloud management platform according to claim 10, characterized in that: The structure of the branch network is a star structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the construction module is used to construct a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and a third virtual gateway of the third access point, so as to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.

15. The cloud management platform according to any one of claims 11 to 14, characterized in that: The communication connection is realized based on the cloud backbone network.

16. The cloud management platform according to any one of claims 9 to 15, characterized in that: The first access point and the second access point are any one of the following: a region, an availability zone, a data center, and a computer room.

17. A computing device cluster, characterized in that: The computing device cluster includes at least one computing device, each computing device including a processor and a memory: The memory is used to store instructions; The processor is configured to cause the computing device cluster to execute the method according to any one of claims 1 to 8 according to the instructions.

18. A computer storage medium, characterized in that: The computer storage medium stores one or more instructions, which, when executed by one or more computers, enable the one or more computers to implement the method of any one of claims 1 to 8.

19. A computer program product, characterized in that The computer program product stores instructions, which, when executed by a computer, enable the computer to implement the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Network creation method based on cloud management platform and cloud management platform

    CN120201026A

  • Method for intercommunication between virtual private cloud VPCs

    CN111030912A

  • Equipment management method and system, readable storage medium and computer

    CN113904911A

  • Communication method between VPCs based on public cloud and related products

    CN117201574A

  • Scalable and on-demand multi-tenant and multi region secure network

    US20220045985A1