Cloud cross-region service access method, cloud cross-region service publishing method, system, and storage medium

By leveraging the synergy of resource hosting network components and virtual network components, the complexities of cross-regional access to cloud services are resolved, enabling efficient and stable cross-regional service access.

WO2025224542A1PCT designated stage Publication Date: 2025-10-30CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2025/053452
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-25
Filing Date
2025-04-02
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

Existing cloud services cannot be accessed across regions, which complicates access operations and reduces access efficiency and quality.

Method used

Access requests for cross-regional services are obtained through resource hosting network components, and the access requests are forwarded to service provider network components in different regions through virtual network components using shared computing resources, thereby enabling cross-regional service access operations.

Benefits of technology

It has enabled stable cross-regional service access, improved access quality and efficiency, reduced operational difficulty, and enhanced user experience and platform stickiness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2025053452_30102025_PF_FP_ABST
    Figure IB2025053452_30102025_PF_FP_ABST
Patent Text Reader

Abstract

Provided are a cloud cross-region service access method, a cloud cross-region service publishing method, a system, and a storage medium. The access method is applied to a resource hosting network component which is communicatively connected to at least one user network component and a first virtual network component. The access method comprises: acquiring, from the at least one user network component, an access request for a cross-region service; determining a shared computing resource in a resource hosting network component, wherein the shared computing resource is used for the at least one user network component to realize a cross-region access operation; and on the basis of the shared computing resource, forwarding the access request to a second virtual network component by means of the first virtual network component, so that the second virtual network component performs a cross-region service access operation on the basis of the access request, wherein the first virtual network component and the second virtual network component are located in different regions.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Access methods, deployment methods, systems, and storage media technologies for cross-regional services in the cloud.

[0002]

[0001] This disclosure relates to the field of network technology, and more particularly to a method, method, system, and storage medium for accessing and publishing cross-regional services in the cloud. Background Art

[0003]

[0002] With the rapid development of cloud technology, cloud products are being used more and more widely. Cloud platforms can publish cloud services for users to access. Currently, users often cannot access these services across regions, and the service connections are all point-to-point, meaning users can only access published cloud services within the same region. Because access to cloud services is restricted by region, accessing cloud services across regions becomes complex, reducing the efficiency of cloud service access. (Summary of the Invention)

[0004]

[0003] This disclosure provides a method, publishing method, system and storage medium for accessing cross-regional services in the cloud, which can solve the problem that cross-regional access operations of cloud services become complicated due to regional restrictions, stably realize cross-regional service access operations, and ensure the access quality and efficiency of cloud services.

[0005]

[0004] In a first aspect, embodiments of this disclosure provide a method for accessing cross-regional services in the cloud, applied to a resource-hosted network component, wherein the resource-hosted network component is communicatively connected to at least one user network component and a first virtual network component, and the at least one user network component, the first virtual network component, and the resource-hosted network component are located in the same region; the method includes: obtaining an access request for cross-regional services from at least one user network component; determining a shared computing resource in the resource-hosted network component, the shared computing resource being used to enable the at least one user network component to perform cross-regional access operations; and forwarding the access request to a second virtual network component through the first virtual network component based on the shared computing resource, so that the second virtual network component performs cross-regional service access operations based on the access request, wherein the first virtual network component and the second virtual network component are located in different regions.

[0006]

[0005] In a second aspect, embodiments of this disclosure provide a resource hosting network component, which is communicatively connected to at least one user network component and a first virtual network component. The at least one user network component, the first virtual network component, and the resource hosting network component are located in the same region. The resource hosting network component includes: a first acquisition module, configured to acquire a cross-regional service access request from at least one user network component; a first determination module, configured to determine a shared computing resource in the resource hosting network component, the shared computing resource being used to enable the at least one user network component to perform cross-regional access operations; and a first processing module, configured to forward the access request to a second virtual network component through the first virtual network component based on the shared computing resource, so that the second virtual network component performs cross-regional service access operations based on the access request, wherein the first virtual network component and the second virtual network component are located in different regions.

[0007]

[0006] In a third aspect, embodiments of this disclosure provide an electronic device, including: a memory and a processor; wherein the memory is used to store one or more computer instructions, wherein when the one or more computer instructions are executed by the processor, the method for accessing cross-regional cloud services as described in the first aspect is implemented.

[0008]

[0007] In a fourth aspect, embodiments of the present invention provide a computer storage medium for storing a computer program, wherein the computer program enables a computer to implement the cloud cross-region service access method described in the first aspect above when executed.

[0009]

[0008] In a fifth aspect, embodiments of the present invention provide a computer program product, including: a computer program, which, when executed by a processor of an electronic device, causes the processor to perform the steps in the cloud cross-region service access method described in the first aspect above.

[0010]

[0009] In a sixth aspect, embodiments of this disclosure provide a method for publishing cross-regional services in the cloud, applied to a service provider network component. The method includes: obtaining service publishing information for cross-regional services; determining a second service node in the service provider network component, wherein the service provider network component is communicatively connected to a resource hosting network component through a second virtual network component and a first virtual network component, the service provider network component and the second virtual network component are located in the same region, and the first virtual network component and the second virtual network component are located in different regions; sending the service publishing information to the second virtual network component through the second service node, so that the second virtual network component sends the service publishing information to the resource hosting network component through the first virtual network component, so that the resource hosting network component utilizes the included shared computing resources to implement the cross-regional service publishing operation.

[0011]

[0010] In a seventh aspect, embodiments of this disclosure provide a service provider network component, including: a second acquisition module, configured to acquire service publishing information for cross-regional services; a second determination module, configured to determine a second service node in the service provider network component, wherein the service provider network component is communicatively connected to a resource hosting network component through a second virtual network component and a first virtual network component, the service provider network component and the second virtual network component are located in the same region, and the first virtual network component and the second virtual network component are located in different regions; and a second processing module, configured to send the service publishing information to the second virtual network component through the second service node, so that the second virtual network component sends the service publishing information to the resource hosting network component through the first virtual network component, so that the resource hosting network component utilizes the included shared computing resources to implement cross-regional service publishing operations.

[0012]

[0011] In an eighth aspect, embodiments of this disclosure provide an electronic device, including: a memory and a processor; wherein the memory is used to store one or more computer instructions, wherein when the one or more computer instructions are executed by the processor, the method for publishing cross-regional cloud services as described in the sixth aspect above is implemented.

[0013]

[0012] In a ninth aspect, embodiments of the present invention provide a computer storage medium for storing a computer program, wherein the computer program enables a computer to implement the cloud cross-region service publishing method described in the sixth aspect above when executed.

[0014]

[0013] In a tenth aspect, embodiments of the present invention provide a computer program product, including: a computer program, which, when executed by a processor of an electronic device, causes the processor to perform the steps in the cloud cross-region service publishing method described in the sixth aspect above.

[0015]

[0014] In an eleventh aspect, embodiments of the present invention provide a cloud-based cross-regional service access system, comprising: a resource hosting network component, at least one user network component, a first virtual network component, a second virtual network component, and a service provider network component. The at least one user network component, the first virtual network component, and the resource hosting network component are located in the same region. The first virtual network component and the second virtual network component are located in different regions. The second virtual network component and the service provider network component are located in the same region. The resource hosting network component is communicatively connected to the at least one user network component and the first virtual network component, and is used to obtain cross-regional service access requests from the at least one user network component, determine shared computing resources in the resource hosting network component, and provide the shared computing resources for the at least one user network component to perform cross-regional access operations. Based on the shared computing resources, the access request is forwarded to the second virtual network component through the first virtual network component, so that the second virtual network component performs cross-regional service access operations based on the access request. The second virtual network component is communicatively connected to the service provider network component, and is used to obtain the access request through the first virtual network component and transmit the access request to the service provider network component corresponding to the cross-regional service. Enables cross-regional service access operations.

[0016]

[0015] The cloud-based cross-regional service access method, publishing method, and system provided in this disclosure obtain cross-regional service access requests from at least one user network component; determine shared computing resources in the resource hosting network component; and then forward the access request to a second virtual network component through the first virtual network component based on the shared computing resources, so that the second virtual network component can perform cross-regional service access operations based on the access request. This effectively realizes cross-regional service access operations. In addition, since the shared computing resources are located in the resource hosting network component, and the user network component does not need to prepare and determine computing resources for forwarding access requests to realize cloud-based cross-regional service access operations, users can achieve stable access operations to cross-regional services with one click through the user network component. This not only ensures the quality and efficiency of cross-regional service access and the good user experience of cross-regional service access operations, but also reduces the difficulty and operational complexity of cross-regional service access, which is conducive to improving user stickiness to the cloud-based cross-regional service access platform and further improves the practicality of the method. (See attached figures)

[0017]

[0016] In order to more clearly illustrate the technical solutions in the embodiments of this disclosure, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018]

[0017] Figure 1 is a schematic diagram of the principle of a method for accessing cross-regional services in the cloud provided by an embodiment of this disclosure;

[0019]

[0018] Figure 2 is a flowchart illustrating a method for accessing cross-regional services in the cloud according to an embodiment of this disclosure;

[0020]

[0019] Figure 3 is a schematic diagram of the process of forwarding the access request to the second virtual network component through the first virtual network component using the forwarding computing resources provided in the embodiment of this disclosure;

[0021]

[0020] Figure 4 is a flowchart illustrating a method for publishing cross-regional services in the cloud according to an embodiment of this disclosure;

[0022]

[0021] Figure 5 is a schematic diagram of the principle of the cloud cross-region service access method provided in the application embodiment of this disclosure;

[0022] Figure 6 is a schematic diagram of the structure of a resource hosting network component provided in the embodiment of this disclosure;

[0023]

[0023] Figure 7 is a schematic diagram of the structure of an electronic device corresponding to the resource hosting network component provided in the embodiment shown in Figure 6;

[0024]

[0024] Figure 8 is a schematic diagram of the structure of a service provider network component provided in an embodiment of this disclosure;

[0025]

[0025] Figure 9 is a schematic diagram of the structure of an electronic device corresponding to the service provider network component provided in the embodiment shown in Figure 8;

[0026]

[0026] Figure 10 is a schematic diagram of the structure of a cloud-based cross-regional service access system provided in an embodiment of this disclosure. Detailed Description

[0027]

[0027] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of this disclosure, but not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.

[0028]

[0028] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the disclosure. The singular forms “a,” “said,” and “the” used in the embodiments of this disclosure and the appended claims are also intended to include the plural forms. Unless the context clearly indicates otherwise, “multiple” generally includes at least two, but does not exclude the inclusion of at least one.

[0029]

[0029] It should be understood that the term "and / or" used herein is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. In addition, the character '7' in this document generally indicates that the related objects before and after are in an "or" relationship.

[0030]

[0030] Depending on the context, the words “if” or “suppose” as used herein can be interpreted as “when” or “when” or “in response to determination” or “in response to detection”. Similarly, depending on the context, the phrases “if determination” or “if detection” (the stated condition or event) can be interpreted as “when determination” or “in response to determination” or “when detection (the stated condition or event)” or “in response to detection (the stated condition or event)”.

[0031]

[0031] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a product or system comprising a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a product or system. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the product or system that includes that element.

[0032]

[0032] Furthermore, the timing sequence of the steps in the following method embodiments is merely an example and not a strict limitation. Terminology Definitions

[0033]

[0033] Cross-region connection: also known as cross-region interconnection, refers to the network connection between applications in virtual private networks (VPCs) distributed in two different regions.

[0034]

[0034] Managed mode: Also known as Managed mode, in this mode, users do not need to pay extra computing resources. The computing resources are provided by the product itself to simplify the product model and reduce costs.

[0035]

[0035] Access point: is an abstract concept used to connect service providers or users to the virtual Internet. In some instances, the user side can use the terminal node of PrivateLink as an access point. Access points have the characteristic of high availability within the same availability zone. In addition, service providers can also use PrivateLink to achieve high availability operation on the service access side.

[0036]

[0036] Service publishing: Services deployed on computing resources within a VPC are typically provided in the form of IP addresses, and the underlying layer can be an Elastic Compute Service (ECS) or a Server Load Balancer (SLB).

[0037]

[0037] Private network access: Compared to public network access, private network access provides a private IP address of the cloud VPC. Other VPCs and public network environments cannot access it. Private network access ensures the security and stability of the service.

[0038]

[0038] In order to facilitate understanding of the implementation process and implementation principle of each step in the cloud cross-region service access method, publishing method, system and storage medium in this embodiment, the relevant technologies will be briefly explained below.

[0039]

[0039] Currently, available cloud products cannot publish services across regions, and the service connections built are all point-to-point. That is, the existing PrivateLink product can only be published within the same region and the same availability zone. Such cloud products have the following defects.

[0040]

[0040] (1) The complexity of publishing services across the entire region: Service providers need to be familiar with a wide range of cloud products, such as Virtual Private Network (VPC), Virtual Switch (VSW), European Committee for Standardization (CEN), Virtual Private Network, Network Peer Interconnection (VPC Peering), billing policies, etc., in order to build and connect the underlying service network based on these products.

[0041]

[0041] (2) Cost issues of service providers deploying services on the cloud: Service providers need not only technology, process and operation and maintenance costs to build cross-regional release capabilities, but also need to apply for additional independent cloud resources in each release region, which requires a lot of cost.

[0042]

[0042] (3) Problem of not supporting elastic resource adjustment: When adding new areas, when regional traffic surges, or during off-peak hours, it is necessary to manage the resources of the published service areas, which is extremely costly.

[0043]

[0043] In order to solve the above technical problems, this embodiment provides a method for accessing, publishing, system and storage medium for cross-regional services in the cloud. The execution subject of the method for accessing cross-regional services in the cloud is an access system. As shown in FIG1, the access system may include a resource hosting network component, at least one user network component that is communicatively connected to the resource hosting network component, a first virtual network component that is communicatively connected to the user network component, a second virtual network component that is communicatively connected to the first virtual network component, and a service provider network component that is communicatively connected to the second virtual network component. The at least one user network component, the first virtual network component and the resource hosting network component are located in region 1, and the second virtual network component and the service provider network component are located in region 2. Region 1 and region 2 are different regions.

[0044]

[0044] The user network component can communicate with the client so that the user can access the user network through the client and the user network component. The user network can be a shared network or a private network. The first virtual network component communicates with the user network component, and the first virtual network component communicates with the second virtual network component to realize cross-regional network transmission operations. The second virtual network component can communicate with the server through the service provider network component so that the server can realize corresponding cross-regional service access operations based on the transmitted access requests.

[0045]

[0045] In addition, for the client communicating with the user's network component, the client is used by the user to perform applications to generate or obtain access requests for cross-regional services. The aforementioned client can be any computing device with a certain data transmission capability. Specifically, the client can be a mobile phone, a personal computer (PC), a tablet computer, a configuration application, etc. Furthermore, the basic structure of the client can include: at least one processor. The number of processors depends on the client's configuration and type. The client can also include memory, which can be volatile, such as random access memory (RAM), or non-volatile, such as read-only memory (ROM), flash memory, etc., or both types can be included simultaneously. The memory typically stores the operating system (OS), one or more applications, and can also store program data, etc. In addition to the processing unit and memory, the client also includes some basic configurations, such as a network card chip, an I / O bus, a display component, and some peripheral devices, etc. Optionally, some peripheral devices may include, for example, a keyboard, mouse, stylus, printer, etc. Other peripheral devices are well known in the art and will not be described in detail here.

[0046]

[0046] A server refers to a device that can provide service access operations in a network virtual environment, typically referring to a device that uses a network for information planning and service access operations. In physical implementation, a server can be any device capable of providing computing services, responding to access requests, and performing cross-regional service access operations based on those requests. Examples include cluster servers, regular servers, cloud servers, cloud hosts, virtual centers, etc. The main components of a server include processors, hard disks, memory, system buses, etc., similar to a general computer architecture.

[0047]

[0047] In the above embodiment, a network connection is established between the client and the user network component, and between the server and the service provider network component. This network connection can be a wireless or wired network connection. If the connection between the client and the user network component, and between the server and the service provider network component, is a communication connection, the network standard of the mobile network can be any one of 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), 4G+ (LTE+), WiMax, 5G, 6G, etc.

[0048]

[0048] In this embodiment of the disclosure, the client is used by the user to generate or obtain access requests for cross-regional services. Specifically, the client can display an interactive interface, and the user can perform operations on the interactive interface to generate or obtain access requests for cross-regional services. After obtaining the access request for cross-regional services, in order to perform access operations for cross-regional services on the cloud, the access request for cross-regional services can be sent to the user network component. After the user network component obtains the access request, it can send the access request to the resource hosting network component for analysis and processing.

[0049]

[0049] A resource hosting network component is communicatively connected to at least one user network component and a first virtual network component. The at least one user network component, the first virtual network component, and the resource hosting network component are located in the same region. When a user has a need to access cross-regional services in the cloud, the user can obtain the cross-regional service access request from at least one user network component. The resource hosting network component includes shared service resources for at least one user network component to perform cross-regional access operations. In order to accurately perform cross-regional service access operations in the cloud, shared computing resources in the resource hosting network component can be determined. These shared computing resources are used to perform cross-regional access operations for at least one user network component.

[0050] After acquiring shared computing resources, the access request can be forwarded to the second virtual network component through the first virtual network component based on the shared computing resources. This allows the second virtual network component to perform cross-regional service access operations based on the access request, effectively realizing cross-regional service access operations. The first and second virtual network components are located in different regions.

[0050]

[0051] The service provider network component, the second virtual network component mentioned above, is located in the same region as the service provider network component. It is used to obtain access requests through the second virtual network component and then send the access requests to the server. Specifically, the access request can be sent to the corresponding server through the user-side network card located in the service provider network component. Since the server belongs to a different region than the client, cross-regional service access operation is thus realized.

[0051]

[0052] In this embodiment, by acquiring cross-regional service access requests, then determining the shared computing resources in the resource hosting network component, and forwarding the access requests to the second virtual network component through the first virtual network component based on the shared computing resources, cross-regional service access operations are effectively realized. This not only effectively expands the applicability of cloud services and ensures the access quality and efficiency of cross-regional cloud services, but also improves the user experience for cross-regional service access operations.

[0052]

[0053] The following detailed description of some embodiments of the present invention is provided in conjunction with the accompanying drawings. Where there is no conflict between the embodiments, the following embodiments and features can be combined with each other. Furthermore, the timing of the steps in the following method embodiments is merely an example and not a strict limitation.

[0053]

[0054] Figure 2 is a flowchart illustrating a method for accessing cross-regional services in the cloud according to an embodiment of this disclosure. Referring to Figure 2, this embodiment provides a method for accessing cross-regional services in the cloud. The executing entity of this access method can be a resource-hosted network component, meaning the access method can be applied to the resource-hosted network component. The resource-hosted network component is communicatively connected to at least one user network component and a first virtual network component. The at least one user network component, the first virtual network component, and the resource-hosted network component are located in the same region, which can refer to the same city, the same network coverage area, etc. Based on the above-mentioned resource-hosted network component, access to cross-regional services in the cloud can be realized. Specifically, the method may include the following steps.

[0054]

[0055] Step S201: Obtain access requests for cross-regional services from at least one user network component.

[0055]

[0056] Step S202: Identify the shared computing resources in the resource hosting network component, which are used to enable cross-regional access operations for at least one user network component.

[0056]

[0057] Step S203: Based on the shared computing resources, the access request is forwarded to the second virtual network component through the first virtual network component, so that the second virtual network component can perform cross-regional service access operation based on the access request, wherein the first virtual network component and the second virtual network component are located in different regions.

[0057]

[0058] The following provides a detailed explanation of the specific implementation process and effects of each of the above steps.

[0058]

[0059] Step S201: Obtain access requests for cross-regional services from at least one user network component.

[0059]

[0060] The resource hosting network component has a communication connection with at least one user network component. When there is an access requirement for cross-region services on the cloud, the resource hosting network component can obtain cross-region service access requests from at least one user network component. The number of access requests obtained can be one or more, and each access request includes at least the identifier information of the service to be accessed, the access address of the service to be accessed, etc. In some instances, cross-region service access requests can be obtained through human-computer interaction. In this case, obtaining cross-region service access requests can include: displaying a human-computer interaction interface, obtaining the execution operation input by the user in the human-computer interaction interface, and generating and obtaining cross-region service access requests based on the execution operation.

[0060]

[0061] In other instances, cross-regional service access requests can be obtained not only through human-computer interaction but also through a pre-defined device. In this case, obtaining the cross-regional service access request can include: identifying a pre-defined device (which can be a client or a third-party device) that is communicatively connected to the resource hosting network component; wherein the pre-defined device stores the cross-regional service access request. The pre-defined device can actively or passively obtain the cross-regional service access request, thereby effectively ensuring the accuracy and reliability of obtaining the cross-regional service access request.

[0061]

[0062] Taking the client as the default device as an example, the client can communicate and connect with the resource hosting network component through the user network component. The user network component can include a security group for validating access requests. The security group can then be used to perform validity checks on access requests to identify whether the access request is legitimate. If the access request is determined to be legitimate, access to cross-regional cloud services based on the access request is allowed; if the access request is determined to be illegitimate, access to cross-regional cloud services based on the access request is prohibited.

[0062]

[0063] In some other instances, before obtaining access requests for cross-regional services, in order to accurately implement cross-regional service access operations on the cloud, the nodes used to implement the communication connection between the resource hosting network component and the user network component can be configured. In this case, the method in this embodiment may further include: obtaining configuration information of a first node corresponding to the user network component, wherein the first node configuration information includes at least: a network identifier; based on the first node configuration information, deploying a user-side access point in the user network component, and determining a first service node corresponding to the user network component in the resource hosting network component, wherein the user-side access point and the first service node are connected in communication.

[0063]

[64] Specifically, in order to enable stable request transmission operations between the resource hosting network component and the user network component, before obtaining the access request for cross-regional services, the first node configuration information corresponding to the user network component can be obtained first. In some instances, the first node configuration information can be obtained through human-computer interaction, or the first node configuration information can be stored in a preset device. The first node configuration information corresponding to the user network component can be obtained by accessing the preset device. The first node configuration information includes at least the network identifier corresponding to the user network component. The network identifier can refer to the network name, network identity identifier, etc., corresponding to the user network component. It should be noted that the first node configuration information can include not only the above-mentioned network identifier, but also other related configuration data used to implement access point configuration operations, such as: the regional identifier corresponding to the user network component, the network access port in the user network component, the network access port in the resource hosting network component, the access point address of the resource hosting network component, the access point address of the user network component, network domain name information, service access address, etc.

[0064]

[65] After obtaining the configuration information of the first node, the resource hosting network component can deploy a user-side access point in the user network component based on the configuration information of the first node, and can determine the first service node corresponding to the user network component in the resource hosting network component. Furthermore, the user-side access point deployed in the user network component communicates with the first service node deployed in the resource hosting network component. In this way, the communication connection operation between the user network component and the resource hosting network component can be stably realized through the user-side access point and the first service node.

[0065]

[66] In addition, to ensure the security and legitimacy of cross-regional service access, the first node configuration information may include not only the network identifier corresponding to the user network component, but also security component information. In this case, the method in this embodiment may further include: deploying a first virtual switch and a security component corresponding to the first virtual switch in the user network component based on the first node configuration information. The security component is attached to the first virtual switch or the user access point. The first virtual switch is used to implement the communication connection between the user network component and the resource hosting network component. The security component includes rules or conditions for legitimacy detection of access requests to ensure legitimate access operations for cross-regional services on the cloud.

[0066]

[67] At this time, after obtaining the cross-regional service access request, the security component can be used to perform a legality check operation. After passing the legality check operation, the access request can be sent to the user-side access point through the first virtual machine switch. Then the user-side access point can send the access request to the first service node in the resource hosting network component to realize the cross-regional service access operation.

[0067]

[68] Similarly, before obtaining the cross-regional service access request, in order to accurately realize the cross-regional service access operation on the cloud, it is necessary not only to configure the node used to realize the communication connection between the resource hosting network component and the user network component, but also to configure the node used to realize the communication connection between the service provider network component and the resource hosting network component. At this time, the method in this embodiment may further include: obtaining the second node configuration information corresponding to the service provider network component, the second node configuration information including at least: network identifier; based on the second node configuration information, deploying a second service node in the service provider network component, and deploying a service-side access point that communicates with the second service node in the second virtual network component, wherein the service-side access point communicates with the first virtual network component.

[0068]

[69] Specifically, in order to enable stable data transmission between the resource hosting network component and the service provider network component, before obtaining access requests for cross-regional services, the second node configuration information corresponding to the service provider network component can be obtained first. In some instances, the second node configuration information can be obtained through human-computer interaction, or the second node configuration information can be stored in a preset device. The second node configuration information corresponding to the service provider network component can be obtained by accessing the preset device. The second node configuration information includes at least the network identifier corresponding to the service provider network component. The network identifier can refer to the network name, network identity identifier, etc., corresponding to the service provider network component. It should be noted that the second node configuration information can include not only the above-mentioned network identifier, but also other related configuration data used to implement access point configuration operations, such as: the regional identifier corresponding to the service provider network component, the network access port in the service provider network component, the network access port in the second virtual network component, the access point address of the service provider network component, the access point address of the second virtual network component, network domain name information, service access address, etc.

[0069]

[70] After obtaining the configuration information of the second node, the resource hosting network component can deploy the second service node in the service provider network component based on the configuration information of the second node, and deploy a service-side access point in the second virtual network component that communicates with the second service node. Furthermore, the service-side access point deployed in the second virtual network component communicates with the second service node deployed in the service provider network component. In this way, cross-regional communication connection operations can be realized through the service-side access point, the second service node, the user network component, the first virtual network component, and the second virtual network component, further improving the stability and reliability of the method.

[0071] Step S202: Determine the shared computing resources in the resource hosting network component. The shared computing resources are used to enable at least one user network component to perform cross-regional access operations.

[0070]

[0072] The resource hosting network component is configured with shared computing resources for at least one user network component to perform cross-regional access operations. That is, when the resource hosting network component has multiple user network components in communication connection, the access requests corresponding to multiple user network components can be implemented through different computing resources in the shared computing resources to perform cross-regional cloud service access operations. For the shared computing resources, it can include at least one of the following: CPU resources, memory resources, etc. In addition, for the above-mentioned shared computing resources, it can be stored in a preset area (e.g., local storage chip, local storage disk, cloud storage disk, cloud storage server, etc. in the resource hosting network component). At this time, after obtaining the cross-regional service access request, the shared computing resources in the resource hosting network component can be determined by accessing the preset area.

[0071]

[0073] For shared computing resources, in order to meet the access requirements in different application scenarios, users can flexibly expand or shrink the shared computing resources in the resource hosting network component according to application requirements. In this case, the method in this embodiment may further include: determining the access requirements of cross-regional services based on cross-regional service access requests; identifying that the shared computing resources in the resource hosting network component can meet the access requirements of cross-regional services; when the shared computing resources in the resource hosting network component meet the access requirements of cross-regional services, it can be determined that the shared computing resources in the resource hosting network component remain unchanged; or, based on the access requirements and shared computing resources, determining the spare resource balance of the shared computing resources; when the spare resource balance is greater than or equal to a preset threshold, a shrinking operation can be performed on the spare resources in the shared computing resources based on the spare resource balance; when the spare resource balance is less than the preset threshold, it can be determined that the shared computing resources in the resource hosting network component remain unchanged; when the shared computing resources in the resource hosting network component do not meet the access requirements of cross-regional services, a scaling-up operation can be performed on the shared computing resources in the resource hosting network component to obtain the scaled-up shared computing resources. This effectively enables flexible scaling up and down of shared computing resources in the resource-hosted network component based on different access requirements, further improving the flexibility and reliability of the method.

[0072]

[0074] Step S203: Based on the shared computing resources, the access request is forwarded to the second virtual network component through the first virtual network component, so that the second virtual network component can perform cross-regional service access operation based on the access request, wherein the first virtual network component and the second virtual network component are located in different regions.

[0073]

[0075] Since the first virtual network component communicates with the service provider network component through the second virtual network component, and the first and second virtual network components are located in different regions, these different regions can refer to different cities, areas covered by different networks, etc. For example, the first virtual network component is deployed in Beijing, and the second virtual network component is deployed in Hangzhou; or, the first virtual network component is deployed in Shanghai, and the second virtual network component is deployed in Nanjing, etc. In order to realize cross-regional service access operations, after obtaining shared computing resources, the access request can be forwarded to the second virtual network component through the first virtual network component using the shared computing resources. Specifically, after the first virtual network component obtains the access request, it can send the obtained access request to the second virtual network component. After the second virtual network component obtains the access request, it can transmit the obtained access request to the service provider network component corresponding to the cross-regional service, thereby realizing cross-regional service access operations.

[0074]

[0076] In some instances, since the forwarding resources required for access requests differ in different scenarios, in order to ensure stable access to cross-regional services, a forwarding resource adapted to the access request can be selected from the shared computing resources first, and then the access request operation can be implemented using the forwarding resource. In this case, forwarding the access request to the second virtual network component through the first virtual network component based on the shared computing resource may include: determining the forwarding computing resource corresponding to the access request in the shared computing resources; using the forwarding computing resource to forward the access request to the second virtual network component through the first virtual network component, so that the second virtual network component transmits the access request to the service provider network component corresponding to the cross-regional service, wherein the second virtual network component and the service provider network component are located in the same region.

[0075]

[0077] Specifically, after obtaining the shared computing resources and the access request, the forwarding computing resources corresponding to the access request can be determined from the shared computing resources. In some instances, the forwarding computing resources can be implemented through a preset polling algorithm. In this case, determining the forwarding computing resources corresponding to the access request from the shared computing resources may include: determining multiple computing containers for implementing cross-regional access operations based on the shared computing resources; performing a polling operation on the multiple computing containers based on the access request and the preset polling algorithm to obtain the forwarding container corresponding to the access request, thereby effectively achieving the accuracy and reliability of determining the forwarding computing resources corresponding to the access request.

[0076]

[0078] In other instances, forwarding computing resources can be determined not only through a preset polling algorithm but also through a preset mapping relationship. In this case, determining the forwarding computing resource corresponding to the access request in the shared computing resources may include: obtaining a preset mapping relationship for analyzing and processing the access request; and using the preset mapping relationship to determine the forwarding computing resource corresponding to the access request in the shared computing resources, thereby effectively ensuring the stability and reliability of determining the forwarding computing resource.

[0079] In yet another instance, the forwarding computing resource corresponding to the access request can be determined not only through a preset mapping relationship but also through the address information and load information corresponding to the computing resource. In this case, determining the forwarding computing resource corresponding to the access request in the shared computing resources may include: obtaining the server group corresponding to the shared computing resource; determining the address information and load information corresponding to each server in the server group; and determining the forwarding server corresponding to the access request in the server group based on the address information and load information.

[0077]

[0080] Specifically, in order to accurately determine the forwarding computing resources corresponding to the access request, after obtaining the shared computing resources, the shared computing resources can be analyzed and processed to obtain the server group corresponding to the shared computing resources. The number of obtained server groups can be one or more, and each server group can include one or more servers used for analyzing and processing access requests. Since each server in different server groups can correspond to different address information and load information, in order to ensure the accuracy and reliability of forwarding access requests, and to ensure the data processing quality and effect of each server group, after obtaining the server group corresponding to the shared computing resources, the address information and load information corresponding to each server in the server group can be determined.

[0078]

[0081] After obtaining the address information and load information corresponding to each server, the address information and load information can be analyzed and processed. Specifically, the round-robin algorithm and the address information corresponding to each server are used to perform a round-robin operation on each server, and the load balancing algorithm is used to analyze and process the load information corresponding to each server to obtain the load status of each server. Then, based on the load status of each server, the forwarding server corresponding to the access request can be determined in the server group. This also ensures the accuracy and reliability of determining the forwarding server.

[0079]

[0082] The cloud-based cross-regional service access method provided in this embodiment obtains a cross-regional service access request from at least one user network component; determines the shared computing resources in the resource hosting network component; and then forwards the access request to a second virtual network component through the first virtual network component based on the shared computing resources, so that the second virtual network component performs cross-regional service access operations based on the access request. This effectively realizes the cross-regional service access operation. In addition, since the shared computing resources are located in the resource hosting network component, and the user network component does not need to prepare and determine the computing resources used to forward the access request to realize the cloud-based cross-regional service access operation, users can realize a stable one-click access operation to the cross-regional service through the user network component. This not only ensures the quality and efficiency of cross-regional service access and the good user experience of cross-regional service access operations, but also reduces the difficulty and operational complexity of cross-regional service access, which is conducive to improving the stickiness of users to the cloud-based cross-regional service access platform and further improves the practicality of the method.

[0080]

[0083] Figure 3 is a schematic diagram of the process of forwarding an access request to a second virtual network component using forwarding computing resources according to an embodiment of this disclosure; Based on the above embodiments, referring to Figure 3, this embodiment provides an implementation scheme for forwarding access requests based on the transmission protocol type and request transmission type of the access request. In this case, forwarding the access request to the second virtual network component using forwarding computing resources according to the first virtual network component may include the following steps.

[0081]

[0084] Step S301: Obtain the transport protocol type and the request transport type corresponding to the access request.

[0082]

[0085] Different access requests may correspond to different transmission protocol types and request transmission types. For example, the transmission protocol type corresponding to the access request may include any one of the following: Hypertext Transfer Protocol (HTTP) - Hypertext Transfer Protocol Secure (HTTPS); the request transmission type corresponding to the access request may include any one of the following: transparent transmission type, non-transparent transmission type; and different transmission protocol types and request transmission types may correspond to different forwarding transmission methods. In order to accurately perform transmission operations on the access request, after obtaining the access request, the access request can be analyzed and processed to obtain the transmission protocol type and request transmission type corresponding to the access request.

[0083]

[0086] In some instances, the transmission protocol type and the request transmission type can be obtained through human-computer interaction. In this case, obtaining the transmission protocol type and the request transmission type corresponding to the access request may include: displaying the human-computer interaction interface; obtaining the execution operation input by the user in the human-computer interaction interface for the access request; and obtaining the transmission protocol type and the request transmission type corresponding to the access request based on the execution operation.

[0084]

[0087] In other instances, the transport protocol type and request transport type can be obtained not only through human-computer interaction but also through analysis and processing of the request domain name corresponding to the access request. In this case, obtaining the transport protocol type corresponding to the access request may include: obtaining the request domain name corresponding to the access request; and determining the transport protocol type corresponding to the access request based on the request domain name. Similarly, obtaining the request transport type corresponding to the access request may include: obtaining the request domain name corresponding to the access request; and determining the request transport type corresponding to the access request based on the request domain name.

[0085]

[0088] Wherein, determining the request transmission type corresponding to the access request based on the request domain name may include: obtaining a preset whitelist for analyzing and processing the access request, the preset whitelist including: a legitimate request domain name and a pass-through type corresponding to the legitimate request domain name; when a legitimate request domain name corresponding to the request domain name exists in the preset whitelist, the pass-through type corresponding to the legitimate request domain name is determined as the request transmission type corresponding to the access request; when a legitimate request domain name corresponding to the request domain name does not exist in the preset whitelist, the request transmission type corresponding to the access request is determined as a non-pass-through type, thus effectively achieving accurate and reliable determination of the request transmission type.

[0086]

[0089] Step S302: Determine the access address corresponding to the second virtual network component based on the transmission protocol type and the request transmission type.

[0087]

[0090] After obtaining the transmission protocol type and the request transmission type, the transmission protocol type and the request transmission type can be analyzed and processed to determine the access address corresponding to the second virtual network component. The access address corresponding to the second virtual network component is the destination address for forwarding the access request. In some instances, the access address corresponding to the second virtual network component can be determined through a preset mapping relationship. In this case, determining the access address corresponding to the second virtual network component based on the transmission protocol type and the request transmission type may include: obtaining a pre-configured preset mapping relationship used to identify the transmission protocol type, the request transmission type, and the access address; after obtaining the transmission protocol type and the request transmission type, the preset mapping relationship can be used to determine the access address corresponding to the second virtual network component.

[0088]

[0091] In other instances, the access address corresponding to the second virtual network component can be determined not only by a preset mapping relationship, but also by the address resolution module in the resource hosting network component. In this case, determining the access address corresponding to the second virtual network component based on the transmission protocol type and the request transmission type may include: determining the address resolution module in the resource hosting network component corresponding to the access request based on the transmission protocol type and the request transmission type. The address resolution module includes: multiple registered access addresses corresponding to the second virtual network components and the registration service corresponding to each registered access address. The registration service may include the cross-regional service corresponding to the access request. The access request is processed using the address resolution module to determine the access address corresponding to the second virtual network component.

[0089]

[0092] Specifically, the resource hosting network component may include address resolution modules corresponding to different transmission protocol types (e.g., Hypertext Transfer Protocol Secure (HTTPS), Hypertext Transfer Protocol (HTTP)) and request transmission types. The address resolution module is used to perform address resolution operations on access requests of different transmission types and request transmission types. It may include: a first address resolution module for performing address resolution operations on access requests in transparent transmission scenarios, and a second address resolution module for performing address resolution operations on access requests in non-transparent transmission scenarios. Therefore, after obtaining the transport protocol type and request transmission type corresponding to the access request, these can be analyzed to determine the address resolution module included in the resource hosting network component corresponding to the access request. Specifically, determining the address resolution module based on the transport protocol type and request transmission type can include: when the transport protocol type is a first transport protocol (e.g., HTTPS) and the request transmission type is a transparent type, the address resolution module corresponding to the access request is determined to be the first address resolution module; when the transport protocol type is a second transport protocol (e.g., HTTP) or the request transmission type is a non-transparent type, the address resolution module corresponding to the access request is determined to be the second address resolution module.

[0090]

[0093] For the address resolution module corresponding to the access request, the address resolution module includes the registration access address corresponding to multiple second virtual network components and the registration service corresponding to each registration access address; After the address resolution module is determined, the access request can be analyzed and processed by the address resolution module to determine the access address corresponding to the second virtual network component, thus effectively ensuring the accuracy and reliability of determining the access address corresponding to the second virtual network component.

[0091]

[0094] Step S303: Based on the forwarding computing resources and the access address, forward the access request to the second virtual network component through the first virtual network component.

[0092]

[0095] Wherein, the access address is the destination address corresponding to the access request. The forwarding computing resource is used to forward the access request. After obtaining the forwarding computing resource and the access address, the access request can be forwarded to the second virtual network component through the first virtual network component based on the forwarding computing resource and the access address. This effectively realizes the forwarding operation of the access request.

[0093]

[0096] In this embodiment, by obtaining the transmission protocol type and request transmission type corresponding to the access request, and then determining the access address corresponding to the second virtual network component based on the transmission protocol type and request transmission type, and forwarding the access request to the second virtual network component through the first virtual network component based on the forwarding computing resources and the access address, the quality and effect of forwarding the access request are effectively realized, and the stability and reliability of accessing cross-regional services on the cloud are further improved.

[0094]

[0097] Figure 4 is a flowchart illustrating a method for publishing cross-regional services in the cloud according to an embodiment of this disclosure; Referring to Figure 4, this embodiment provides a method for publishing cross-regional services in the cloud. The execution subject of this publishing method can be a service provider network component, that is, the publishing method can be applied to a service provider network component; Based on the above-mentioned service provider network component, access operations for cross-regional services in the cloud can be stably realized. Specifically, the method may include the following steps.

[0095]

[0098] Step S401: Obtain service publication information for cross-regional services.

[0096]

[0099] When a service provider has a need to publish cross-regional services on the cloud, the service provider's network component can obtain the service publishing information of the cross-regional service. The service publishing information includes at least: a service identifier, the identifier information of the service provider's network component, and an access address. In some instances, the service publishing information of the cross-regional service is obtained through human-computer interaction. In this case, obtaining the service publishing information of the cross-regional service may include: displaying a human-computer interaction interface, obtaining the execution operation input by the service provider in the human-computer interaction interface, and generating and obtaining the service publishing information of the cross-regional service based on the execution operation.

[0097]

[0100] In other instances, service publishing information for cross-regional services is obtained through a preset device. In this case, obtaining service publishing information for cross-regional services may include: determining a preset device (e.g., a server) that is connected to the service provider's network component, wherein the preset device stores service publishing information for cross-regional services; the service publishing information for cross-regional services can be obtained actively or passively through the preset device, thereby effectively ensuring the accuracy and reliability of obtaining service publishing information for cross-regional services.

[0098]

[0101] Step S402: Determine the second service node in the service provider network component, wherein the service provider network component communicates with the resource hosting network component through the second virtual network component and the first virtual network component, the service provider network component and the second virtual network component are located in the same area, and the first virtual network component and the second virtual network component are located in different areas.

[0099]

[0102] In order to stably implement cross-regional service publishing operations, before obtaining cross-regional service publishing information, the method in this embodiment may further include: obtaining node deployment information sent by the resource hosting network component. This node deployment information may be node deployment information corresponding to the second service node in the service provider network component, generated by the resource hosting network component based on the node configuration information obtained by the resource hosting network component; after obtaining the node deployment information, a second service node may be deployed in the service provider network component based on the node deployment information. This second service node can communicate through a service-side access point deployed in a second virtual network component, and the second virtual network component communicates with the first virtual network component to realize the cross-regional service publishing operation.

[0100]

[0103] Specifically, after obtaining the service publishing information of cross-regional services, since it is necessary to transmit the service publishing information to other regions, in order to accurately perform the transmission operation of the service publishing information, a second service node in the service provider network component can be determined. The second service node can be determined by a preset mapping relationship or transmission protocol type.

[0101]

[0104] Step S403: Send the service publishing information to the second virtual network component through the second service node, so that the second virtual network component sends the service publishing information to the resource hosting network component through the first virtual network component, so that the resource hosting network component can use the shared computing resources included to realize the cross-regional service publishing operation.

[0102]

[0105] After determining the second service node and service publishing information in the service provider network component, the service publishing information can be sent to the second virtual network component through the second service node. In some instances, sending the service publishing information to the second virtual network component through the second service node may include: determining the service-side access point in the second virtual network component, wherein the service-side access point is communicatively connected to the second service node; and sending the service publishing information to the second virtual network component through the second service node and the service-side access point.

[0103]

[0106] The second virtual network component is pre-configured with a service-side access point for communicating with the second service node. The service-side access point can be configured and deployed through the resource hosting network component. After the second virtual network component obtains the service publishing information, it can send the obtained service publishing information to the resource hosting network component through the first virtual network component, so that the resource hosting network component can use the shared computing resources included to perform the service publishing operation, thereby effectively realizing the cross-regional service publishing operation.

[0104]

[0107] It should be noted that the resource hosting network component includes shared computing resources for one or more service provider network components to perform service publishing operations. When there is service publishing information that needs to be analyzed and processed, the target computing resource corresponding to the service publishing information can be determined in the shared computing resources for different service publishing information. Then, the target computing resource and service publishing information can be used to perform service publishing operations, thereby effectively realizing cross-regional service publishing operations.

[0105]

[0108] The cloud cross-region service publishing method provided in this embodiment obtains service publishing information for cross-region services; determines a second service node in the service provider network component; and then sends the service publishing information to a second virtual network component through the second service node, so that the second virtual network component sends the service publishing information to the resource hosting network component through the first virtual network component, so that the resource hosting network component can use the shared computing resources it includes to realize the cross-region service publishing operation. This effectively enables service providers to realize the cloud cross-region service publishing operation with one click, which not only reduces the difficulty and complexity of service publishing, but also improves the convenience and reliability of service publishing operations for service providers, further ensuring the method.

[0109] In specific applications, this application embodiment provides a point-to-multipoint cloud cross-region service access method, wherein "point-to-multipoint" means that a user can access all services published to the virtual internet plane through a single access point, without needing to establish a dedicated connection for each service as in point-to-point connections. This method has the ability to provide service providers with the ability to deploy services in a single region and publish them across the entire cloud region, and also has the ability to provide service users with the ability to access all service provider services through a single access point; The execution subject of this method can realize a point-to-multipoint cloud cross-region service access system. Referring to Figure 5, the access system may include: a user network component (user VPC), a resource hosting network component (ACK VPC), a first virtual network component (first interconnected VPC), a second virtual network component (second interconnected VPC), and a service provider network component (ISV VPC). The user network component communicates with the client, and the service provider network component communicates with the server. The above access system can provide a point-to-multipoint cloud cross-region service access link. This access link starts from the user access side (i.e., the user end) and sequentially passes through the service access point, The system comprises the first service node, NLB, and forwarding instance resources (Pods). It also includes the first virtual network component, the second virtual network component, the service provider's network component's endpoint nodes, endpoint services, and service provider service instances. Specifically, each component in the above access system can perform the following functions:

[0106]

[0110] User network component: Located in region A, used for communication connection with the client, including a service access point (ep) for communication connection with the resource hosting network component, so as to communicate with the resource hosting network component through the service access point (ep). That is, the service access point (ep) is the access node for the user network component to access cross-region services. At this time, when the user has access needs, the access request can be obtained through the client and the access request can be transmitted to the resource hosting network component through the service access point.

[0107]

[0111] The user network component deploys a user-side application (User App), a first switch, and a service access point (ep) to enable access to cross-regional services. Specifically, the user can generate an access request through the User App and send it to the service access point via the first switch. The service access point then forwards the access request to the resource hosting network component. Furthermore, to enable secure access to cross-regional services, a security group can be deployed in the user network component. This security group can be attached to the first switch and is used to manage the traffic of the network interface cards (NICs) attached to the user network component, and to perform security control operations based on the traffic.

[0108]

[0112] Furthermore, access requests can be transmitted through different access protocols, such as HTTPS and HTTP. Users can use either HTTPS or HTTP to access cross-regional services and transmit data. Additionally, access requests can be transmitted using different transmission modes, such as transparent transmission mode and non-transparent transmission mode. Users can flexibly choose the transmission mode for transmitting access requests based on application scenarios or transmission requirements.

[0109]

[0113] Resource Hosting Network Component: Located in Region A, it communicates with the User Network Component and is used to prepare forwarding computing resources and deploy forwarding instance resources in Region A.

[0110]

[0114] The resource hosting network component includes multiple first service nodes for communicating with one or more user network components. Specifically, when the resource hosting network component detects an access request for a cross-regional service obtained through a service access point, it can automatically determine the first service node that is compatible with the user network component based on the regional information corresponding to the access request. This effectively enables the automatic selection of terminal node services for the user network component to perform access operations, thereby reducing the cost for users to access cross-regional services.

[0111]

[0115] In addition, in order to ensure the stability and reliability of forwarding instance resources, a K8S load balancing management system (not shown in the figure) is deployed in the resource hosting network component. The K8S load balancing management system has the ability to elastically expand resources. Specifically, the resource hosting network component deploys shared computing resources (i.e., shared hosting service resources) for all user network components to achieve cross-region access operations. In this way, the resource hosting network component can provide shared computing resources (e.g., CPU resources, memory resources, etc.) for all users in the same region. The shared computing resources can include multiple container resources pods. The K8S load balancing management system can obtain CPU utilization and memory utilization, and then use CPU utilization and memory utilization to perform elastic scaling operations on container resources pods, further improving the accuracy and reliability of accessing cross-region services on the cloud.

[0112]

[0116] In addition, in order to stably realize point-to-point cross-regional cloud service access operations, the resource hosting network component may include a network load balancing module (NLB) for supporting high availability and elastic scaling. The network load balancing module (NLB) is communicatively connected to the first service node and is used to obtain access requests through the first service node and determine the forwarding computing resources (e.g., forwarding Pods) used to analyze and process the access requests. Specifically, the forwarding computing resources corresponding to the access requests can be determined by the user's access volume, or the forwarding computing resources corresponding to the access requests can be scaled up or down to realize cross-regional service access operations.

[0113]

[0117] First virtual network component: Located in region A, it is communicatively connected to the resource hosting network component and the second virtual network component, and is used to realize cross-region service access operations.

[0114]

[0118] The first virtual network component includes a security component and a switch. When an access request is obtained through the resource hosting network component, and the security component performs a legality detection operation on the access request, if the access request is a legal request, the access request is allowed to be transmitted to the second virtual network component through the switch; if the access request is an illegal request, the access request is prohibited from being transmitted to the second virtual network component through the switch.

[0115]

[0119] Second virtual network component: Located in region B, it communicates with the first virtual network component through VPC Peering, and is used to establish a cross-regional communication transmission link at the underlying level to realize cross-regional service access operations.

[0116]

[0120] The second virtual network component includes a switch and a service access point (ep). After the second virtual network component obtains the access request through the switch, it can send the access request to the service provider network component through the service access point to realize cross-regional service access operation.

[0117]

[0121] Service Provider Network Component: Located in Region B, it communicates with the second virtual network component and the server to enable cross-regional service access operations.

[0118]

[0122] The service provider network component includes a second service node for communicating with the second virtual network component, so as to obtain access requests through the second service node and determine the resource information corresponding to the access requests, so as to realize cross-regional service access operations based on the resource information.

[0119]

[0123] The following uses HTTPS transmission protocol and SSL pass-through method as examples to illustrate the access process of cross-region services in the cloud. The prerequisite for implementing cross-region service access operations in the cloud is:

[0120] (1) The service provider publishes a service deployed within the service provider's network components to the private network interconnection network;

[0121] (2) The domain name defined by the service provider for publishing the service is: msg.isv.aliyunnest.com;

[0122] (3) The second virtual network component in the same area creates a service access point and a switch to communicate with the first virtual network component;

[0123] (4) Create data forwarding logic within the cross-regional resource hosting resource component to enable data forwarding operations via SSL pass-through;

[0124] (5) Within the user network component, configure the resolution address of the service domain name to point to the terminal node of the second virtual network component.

[0125]

[0124] Specifically, the access method may include the following steps.

[0126]

[0125] Step 1: The user App initiates an access request from the user network component. The domain name information corresponding to this access request can be https: / / msg.isv.aliyunnest.com.

[0127]

[0126] Step 2: The access request is forwarded through the switch in the user network component to the service access point ep pointed to by the domain name address.

[0128]

[0127] The service access point ep is connected to the security group. After receiving the access request, it can use the preset detection rules configured in the security group to perform a legality detection operation on the access request to ensure the legality of cross-regional services on the cloud.

[0129]

[0128] Step 3: The service access point ep can use the Overlay protocol to encapsulate the access request and forward the encapsulated access request to the first service node, and then forward it to the NLB module associated with the first service node.

[0130]

[0129] Specifically, after obtaining the access request, the access request can be encapsulated with the virtual machine's attribute information and the virtual address of the user's network component using the Overlay protocol, thereby obtaining the encapsulated access request.

[0131]

[0130] Step 4: After the NLB module receives the access request, it determines the forwarding Pod corresponding to the access request based on the server IP of its own backend server group through a preset round-robin algorithm, so as to realize the forwarding operation of the access request.

[0132]

[0131] Step 5: Use the resource hosting network component to forward the access request so that the first virtual network component can obtain the access request.

[0133]

[0132] The resource hosting network component can forward access requests based on different communication protocols and different ports, which may specifically include the following steps.

[0134]

[0133] After obtaining the access request, the corresponding forwarding resource pod can be determined, and then the communication transmission protocol of the access request can be obtained. If the communication transmission protocol is HTTPS, the access request can be obtained through the preset port 443. Then, the Hello data packet of the HTTPS protocol SSL handshake can be parsed, the domain name host of the access request can be found from the extended field, and forwarded to the matching module (SNIMatch) indicated by the server name. Similarly, if the communication transmission protocol is HTTP, the access request can be obtained through the preset port 80.

[0135]

[0134] After obtaining the access request through port 443, the transmission mode of the access request can be identified. The transmission mode can be determined by a preset whitelist. Identifying the transmission mode of the access request can include: obtaining a preset whitelist for analyzing and processing the access request; determining the access request address of the access request using the server name indication matching module (SNIMatch); identifying the transmission mode of the access request based on the access request address and the preset whitelist. If the access request address of the access request is included in the preset whitelist, the transmission mode of the access request is determined to be a transparent transmission mode; if the access request address of the access request is not included in the preset whitelist, the transmission mode of the access request is determined to be a non-transparent transmission mode.

[0136]

[0135] When the transmission mode is transparent mode, the SSL transparent address resolution module (i.e. SSL transparent Upstream) in the resource hosting network component can be determined so that the SSL transparent address resolution module can be used to perform address resolution processing on the access request to obtain the access address and destination address of the access request; when the transmission mode is non-transparent mode, the access request can be transmitted to port 442 so that the access request can be forwarded through port 442.

[0137]

[0136] After obtaining the access request on port 80, the access request can be forwarded to port 442 for SSL redirection. This is a processing strategy to convert the HTTPS access request obtained on port 80 into an HTTP access request. For the access request obtained on port 442, a second address resolution module (second address upstream, i.e., standard ordinary upstream) can be determined for analyzing and processing the access request. Then, the second address resolution module can be used to determine the access address and destination address corresponding to the access request.

[0138]

[0137] After obtaining the access address and destination address corresponding to the access request, since the destination address can be the IP address of the service access point in the second virtual network component, the access request can be forwarded to the second virtual network component through the first virtual network component using the routing policy module in the forwarding resource pod.

[0139]

[0138] Step 6: Based on the first virtual network component and VPC Peering, forward the access request to the second virtual network component in the region where the cross-regional service provider network component is located.

[0140]

[0139] For access requests to the resource hosting network component, the access request can be forwarded to the second virtual network component in the region where the cross-regional service provider network component is located according to the routing policy, the first virtual network component, and VPC Peering, thereby realizing the cross-regional transmission operation of the access request.

[0141]

[0140] Step 7: After the second virtual network component obtains the access request, it can forward the access request to the first service node in the service provider network component through the terminal node corresponding to the private network interconnection of the service provider network component.

[0142]

[0141] Step 8: After the first service node obtains the access request, it can forward the access request to the backend resource xLB (including: ACK server, ASK server, ECS server, etc.).

[0143]

[0142] Step 9: The xLB resource selects a backend server request processing resource through a pre-configured backend server selection algorithm (consistent hashing algorithm, round-robin scheduling algorithm). The processing resource can be used to analyze and process the access request to complete the request processing operation, obtain the request processing result, and return the request processing result to the user's network component application App through a simple TCP connection, thereby completing the access operation of cross-regional services on the cloud.

[0144]

[0143] Through the above operations, a highly available, elastic, scalable, and low-cost hosting model for cross-regional service publishing and access can be achieved. This method has the following advantages:

[0145]

[0144] (1) The resource hosting network component has a shared hosting forwarding link, which can build a hosted and shared network forwarding link so that all users in the same area can share resources, thereby achieving extremely low-cost customer access. Compared with the resource-exclusive mode, the customer acceptance is higher. This method can not only provide access service providers and service access users with lower-cost hosting services, but also improve the user experience and willingness to use the resource management system and increase stickiness. In addition, through the shared forwarding link in the resource hosting network component, resource pooling operations can be performed from a global perspective, which effectively reduces the cost of resource management.

[0146]

[0145] (2) A single network across the entire region: By interconnecting the network components across the entire region and reasonably allocating the IPv4 and IPv6 addresses of each network component, a single network across the entire region is achieved, realizing extremely simple cross-regional interconnection operations. Specifically, the cross-regional interconnection link can be established based on the network's native Layer 3 network, which can support efficient access to services across regions and availability zones. For service providers, they can access any nearby region to realize the publishing operation of services that can be provided across the entire region. This not only improves network transmission efficiency but also improves the quality and effect of service publishing.

[0147]

[0146] (3) SSL pass-through: It can be located based on the origin address of SNI, and can use the proxy node in the resource hosting network component to realize the transmission operation of access request without handshaking with the user side, that is, it realizes the four-layer transparent proxy transmission, thereby simplifying the complexity of HTTPS certificate management;

[0148]

[0147] (4) IP conflict problem: This solution can make the VPC IP addresses of the service provider and the user transparent to each other, without having to consider the address conflict problem;

[0148] (5) Point to surface design: It realizes the connection from point to surface, that is: once the service is connected to the virtual Internet, it can be accessed by all users connected to the private network interconnection plane.

[0149]

[0149] (6) Zero-maintenance deployment: During peak and trough periods of new regions and service traffic, the shared computing resources in the resource-hosted network components can be automatically and elastically scaled up or down. Specifically, the shared computing resources of users can be managed elastically through the k8s management platform. For example, the number of instances corresponding to the forwarding resources can be scaled up or down, and the service provider does not need to participate in any way. The whole process is completed automatically, thereby improving the automation level of the method.

[0150]

[0150] In summary, a cross-regional channel for connecting service providers and customers is realized through private network networking, achieving a low-cost, zero-maintenance, and highly secure cloud-based cross-regional service access system; by constructing a managed and shared network forwarding link, extremely low-cost customer access can be achieved. Specifically, not only can service providers easily access the private network interconnection plane, but they also only need to provide standard service forms such as ECS and SLB, which can be accessed with one click and at zero cost; and convenient access can also be achieved on the user side, which only needs to provide an existing VPC for one-click and zero-cost access, and all computing resources within the VPC can access all services on the private network interconnection plane; in addition, after the user side accesses the virtual internet, they can directly access the services in the service catalog without having to subscribe to services separately, thereby greatly improving the convenience and ease of access for users to cross-regional services, and further improving the practicality of the method.

[0151]

[0151] Figure 6 is a schematic diagram of the structure of a resource hosting network component provided in an embodiment of this disclosure; Referring to Figure 6, this embodiment provides a resource hosting network component, which is communicatively connected to at least one user network component and a first virtual network component. The at least one user network component, the first virtual network component, and the resource hosting network component are located in the same region; The resource hosting network component is used to execute the cloud cross-region service access method shown in Figure 2 above. The resource hosting network component may include: a first acquisition module 11, used to acquire a cross-region service access request from at least one user network component; a first determination module 12, used to determine the shared computing resources in the resource hosting network component, the shared computing resources being used to enable the at least one user network component to perform cross-region access operations; a first processing module 13, used to forward the access request to a second virtual network component through the first virtual network component based on the shared computing resources, so that the second virtual network component performs cross-region service access operations based on the access request, wherein the first virtual network component and the second virtual network component are located in different regions.

[0152]

[0152] In some instances, before obtaining the cross-regional service access request, the first acquisition module 11 and the first processing module 13 in this embodiment are used to perform the following steps: The first acquisition module 11 is used to obtain the first node configuration information corresponding to the user network component; The first processing module 13 is used to deploy a user-side access point in the user network component based on the first node configuration information, and determine the first service node corresponding to the user network component in the resource hosting network component, wherein the user-side access point is communicatively connected to the first service node.

[0153]

[0153] In some instances, before obtaining the cross-regional service access request, the first acquisition module 11 and the first processing module 13 in this embodiment are used to perform the following steps: The first acquisition module 11 is used to obtain the second node configuration information corresponding to the service provider network component, the second node configuration information including at least: network identifier; The first processing module 13 is used to deploy a second service node in the service provider network component based on the second node configuration information, and deploy a service-side access point that communicates with the second service node in the second virtual network component, wherein the service-side access point communicates with the first virtual network component.

[0154]

[0154] In some instances, when the first processing module 13 forwards the access request to the second virtual network component through the first virtual network component based on the shared computing resources, the first processing module 13 is configured to: determine the forwarding computing resource corresponding to the access request in the shared computing resources; and use the forwarding computing resource to forward the access request to the second virtual network component through the first virtual network component, so that the second virtual network component transmits the access request to the service provider network component corresponding to the cross-regional service, wherein the second virtual network component and the service provider network component are located in the same region.

[0155]

[0155] In some instances, when the first determining module 12 determines the forwarding computing resource corresponding to the access request in the shared computing resources, the first determining module 12 is used to: obtain the server group corresponding to the shared computing resource; determine the address information and load information corresponding to each server in the server group; and determine the forwarding server corresponding to the access request in the server group based on the address information and load information.

[0156]

[0156] In some instances, when the first processing module 13 uses forwarding computing resources to forward the access request to the second virtual network component through the first virtual network component, the first processing module 13 is used to perform: obtaining the transport protocol type and request transport type corresponding to the access request; determining the access address corresponding to the second virtual network component based on the transport protocol type and request transport type; and forwarding the access request to the second virtual network component through the first virtual network component based on the forwarding computing resources and the access address.

[0157]

[0157] In some instances, when the first processing module 13 obtains the request transmission type corresponding to the access request, the first processing module 13 is used to perform: obtaining the request domain name corresponding to the access request; and determining the request transmission type corresponding to the access request based on the request domain name.

[0158]

[0158] In some instances, when the first processing module 13 determines the request transmission type corresponding to the access request based on the request domain name, the first processing module 13 is used to perform the following: obtain a preset whitelist for analyzing and processing the access request, the preset whitelist including: a legitimate request domain name and a pass-through type corresponding to the legitimate request domain name; when a legitimate request domain name corresponding to the request domain name exists in the preset whitelist, determine the pass-through type corresponding to the legitimate request domain name as the request transmission type corresponding to the access request; when a legitimate request domain name corresponding to the request domain name does not exist in the preset whitelist, determine the request transmission type corresponding to the access request as a non-pass-through type.

[0159]

[0159] In some instances, when the first processing module 13 determines the access address corresponding to the second virtual network component based on the transmission protocol type and the request transmission type, the first processing module 13 is used to perform: determining the address resolution module included in the resource hosting network component corresponding to the access request based on the transmission protocol type and the request transmission type, wherein the address resolution module includes: multiple registered access addresses corresponding to the second virtual network components and the registration service corresponding to each registered access address, wherein the registration service includes the cross-regional service corresponding to the access request; and processing the access request using the address resolution module to determine the access address corresponding to the second virtual network component.

[0160]

[0160] In some instances, when the first processing module 13 determines the address resolution module corresponding to the access request included in the resource hosting network component based on the transport protocol type and the request transport type, the first processing module 13 is configured to: determine the address resolution module corresponding to the access request as the first address resolution module when the transport protocol type is the first transport protocol and the request transport type is a transparent type; and determine the address resolution module corresponding to the access request as the second address resolution module when the transport protocol type is the second transport protocol or the request transport type is a non-transparent type.

[0161]

[0161] The resource hosting network component shown in Figure 6 can execute the methods of the embodiments shown in Figures 1-3 and Figure 5. For parts not described in detail in this embodiment, please refer to the relevant descriptions of the embodiments shown in Figures 1-3 and Figure 5. The execution process and technical effects of this technical solution are described in the embodiments shown in Figures 1-3 and Figure 5, and will not be repeated here.

[0162]

[0162] In one possible design, the structure of the resource hosting network component shown in FIG6 can be implemented as an electronic device. Referring to FIG7, the resource hosting network component in this embodiment can be implemented as an electronic device, which is communicatively connected to at least one user network component and a first virtual network component. The at least one user network component, the first virtual network component, and the resource hosting network component are located in the same region. Specifically, the electronic device may include: a first processor 21 and a first memory 22. The first memory 22 is used to store a program for the corresponding electronic device to execute the cloud cross-region service access method provided in the embodiment shown in FIG2 above, and the first processor 21 is configured to execute the program stored in the first memory 22.

[0163]

[0163] The program includes one or more computer instructions, wherein when the one or more computer instructions are executed by the first processor 21, they can perform the following steps: obtaining an access request for cross-regional services from at least one user network component; determining a shared computing resource in the resource hosting network component, the shared computing resource being used to enable the at least one user network component to perform cross-regional access operations; forwarding the access request to a second virtual network component through the first virtual network component based on the shared computing resource, so that the second virtual network component performs cross-regional service access operations based on the access request, wherein the first virtual network component and the second virtual network component are located in different regions.

[0164]

[0164] Furthermore, the first processor 21 is also used to execute all or part of the steps in the embodiment shown in FIG2 above. The electronic device may also include a first communication interface 23 for communication between the electronic device and other devices or communication networks.

[0165]

[0165] In addition, embodiments of the present invention provide a computer storage medium for storing computer software instructions used by an electronic device, which includes programs for executing the cloud cross-region service access method in the method embodiment shown in FIG2 above.

[0166]

[0166] In addition, embodiments of the present invention provide a computer program product, including: a computer program, which, when executed by a processor of an electronic device, causes the processor to execute the cloud cross-region service access method in the method embodiment shown in FIG2.

[0167]

[0167] Figure 8 is a schematic diagram of the structure of a service provider network component provided in an embodiment of this disclosure; Referring to Figure 8, this embodiment provides a service provider network component, which is used to execute the cloud cross-region service access method shown in Figure 4 above. Specifically, the service provider network component may include: a second acquisition module 31, used to acquire service publishing information of cross-region services; a second determination module 32, used to determine a second service node in the service provider network component, wherein the service provider network component is communicatively connected to the resource hosting network component through a second virtual network component and a first virtual network component, the service provider network component and the second virtual network component are located in the same region, and the first virtual network component and the second virtual network component are located in different regions; a second processing module 33, used to send the service publishing information to the second virtual network component through the second service node, so that the second virtual network component sends the service publishing information to the resource hosting network component through the first virtual network component, so that the resource hosting network component uses the included shared computing resources to realize the cross-region service publishing operation.

[0168]

[0168] The service provider network component shown in FIG8 can execute the method of the embodiment shown in FIG4-FIG5. For the parts not described in detail in this embodiment, please refer to the relevant description of the embodiment shown in FIG4-FIG5. The execution process and technical effects of this technical solution are described in the embodiment shown in FIG4-FIG5, and will not be repeated here.

[0169]

[0169] In one possible design, the structure of the service provider network component shown in FIG8 can be implemented as an electronic device. Referring to FIG9, the service provider network component in this embodiment can be implemented as an electronic device. The service provider network component is communicatively connected to the resource hosting network component through a second virtual network component and a first virtual network component. The service provider network component and the second virtual network component are located in the same region, and the first virtual network component and the second virtual network component are located in different regions. Specifically, the electronic device may include: a second processor 41 and a second memory 42. The second memory 42 is used to store a program for the corresponding electronic device to execute the cloud cross-region service publishing method provided in the embodiment shown in FIG4 above, and the second processor 41 is configured to execute the program stored in the second memory 42.

[0170]

[0170] The program includes one or more computer instructions, wherein when one or more computer instructions are executed by the second processor 41, they can achieve the following steps: obtaining service publishing information for cross-regional services; determining a second service node in the service provider network component, wherein the service provider network component is communicatively connected to the resource hosting network component through a second virtual network component and a first virtual network component, the service provider network component and the second virtual network component are located in the same region, and the first virtual network component and the second virtual network component are located in different regions; sending the service publishing information to the second virtual network component through the second service node, so that the second virtual network component sends the service publishing information to the resource hosting network component through the first virtual network component, so that the resource hosting network component can use the included shared computing resources to realize the cross-regional service publishing operation.

[0171]

[0171] Furthermore, the second processor 41 is also used to execute all or part of the steps in the embodiment shown in FIG4 above. The electronic device may also include a second communication interface 43 for communication between the electronic device and other devices or communication networks.

[0172]

[0172] In addition, embodiments of the present invention provide a computer storage medium for storing computer software instructions used by electronic devices, which includes programs for executing the cloud cross-region service publishing method in the method embodiment shown in FIG4 above.

[0173]

[0173] In addition, embodiments of the present invention provide a computer program product, including: a computer program, which, when executed by a processor of an electronic device, causes the processor to execute the cloud cross-region service publishing method in the method embodiment shown in FIG4.

[0174]

[0174] Figure 10 is a schematic diagram of the structure of a cloud cross-region service access system provided in an embodiment of the present disclosure. Referring to Figure 10, this embodiment provides a cloud cross-region service access system, including: a resource hosting network component 51, at least one user network component 52, a first virtual network component 53, a second virtual network component 54, and a service provider network component 55. At least one user network component 52, the first virtual network component 53 and the resource hosting network component 51 are located in the same region, the first virtual network component 53 and the second virtual network component 54 are located in different regions, and the second virtual network component 54 and the service provider network component 55 are located in the same region.

[0175]

[0175] The resource hosting network component 51 is communicatively connected to at least one user network component 52 and a first virtual network component 53, and is used to obtain cross-region service access requests from at least one user network component 52, determine shared computing resources in the resource hosting network component 51, the shared computing resources are used to enable at least one user network component 52 to perform cross-region access operations, and forward the access request to a second virtual network component 54 through the first virtual network component 53 based on the shared computing resources, so that the second virtual network component 54 performs cross-region service access operations based on the access request;

[0176]

[0176] The second virtual network component 54 is communicatively connected to the service provider network component 55 and is used to obtain access requests through the first virtual network component 53 and transmit the access requests to the service provider network component 55 corresponding to the cross-regional service to realize the access operation of the cross-regional service.

[0177]

[0177] The specific execution steps, implementation principles, and effects of each component in the cloud cross-region service access system of this embodiment are similar to the specific execution steps, implementation principles, and effects of the cloud cross-region service access method in Figures 1-5 above. For parts not described in detail in this embodiment, please refer to the relevant descriptions of the embodiments shown in Figures 1-5. The execution process and technical effects of this technical solution are described in the embodiments shown in Figures 1-5, and will not be repeated here.

[0178]

[0178] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0179] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0179]

[0180] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of a necessary general-purpose hardware platform, or by a combination of hardware and software. Based on this understanding, the above technical solutions, in essence or the part that contributes to the related technology, can be embodied in the form of a computer product. This disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0180]

[0181] This disclosure is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable device, create means for implementing the functions specified in one or more flowchart illustrations and / or one or more block diagrams.

[0181]

[0182] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams. These computer program instructions may also be loaded onto a computer or other programmable device to cause a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable device, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.

[0182]

[0183] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory. Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0183]

[0184] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store data using any method or technology. Data can be computer-readable instructions, data structures, modules of a program, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store data accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0184]

[0185] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this disclosure, and are not intended to limit it. Although this disclosure has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this disclosure.

Claims

Claims 1. A method for accessing cross-regional services in the cloud, applied to a resource-hosted network component, wherein the resource-hosted network component is communicatively connected to at least one user network component and a first virtual network component, wherein the at least one user network component, the first virtual network component, and the resource-hosted network component are located in the same region; the method includes: Obtain access requests for cross-region services from at least one user network component; A shared computing resource is identified in the resource hosting network component, which is used to enable the at least one user network component to perform cross-regional access operations. Based on the shared computing resource, the access request is forwarded to a second virtual network component through the first virtual network component, so that the second virtual network component can perform cross-regional service access operations based on the access request, wherein the first virtual network component and the second virtual network component are located in different regions.

2. The method according to claim 1, wherein, Before obtaining the cross-regional service access request, the method further includes: obtaining first node configuration information corresponding to the user network component; deploying a user instance access point in the user network component based on the first node configuration information, and determining a first service node corresponding to the user network component in the resource hosting network component, wherein the user instance access point is communicatively connected to the first service node.

3. The method according to claim 1, wherein, Forwarding the access request to a second virtual network component via the first virtual network component based on the shared computing resources includes: determining a forwarding computing resource corresponding to the access request in the shared computing resources; and using the forwarding computing resource to forward the access request to the second virtual network component via the first virtual network component, so that the second virtual network component transmits the access request to the service provider network component corresponding to the cross-regional service, wherein the second virtual network component and the service provider network component are located in the same region.

4. The method according to claim 3, wherein, Determining the forwarding computing resource corresponding to the access request from the shared computing resources includes: obtaining the server group corresponding to the shared computing resource; determining the address information and load information of each server in the server group; and determining the forwarding server corresponding to the access request from the server group based on the address information and the load information.

5. The method according to claim 3, wherein, Using the forwarding computing resources to forward the access request to the second virtual network component through the first virtual network component includes: obtaining the transport protocol type and request transport type corresponding to the access request; determining the access address corresponding to the second virtual network component based on the transport protocol type and request transport type; and forwarding the access request to the second virtual network component through the first virtual network component based on the forwarding computing resources and the access address.

6. The method according to claim 5, wherein, Obtaining the request transmission type corresponding to the access request includes: obtaining the request domain name corresponding to the access request; and determining the request transmission type corresponding to the access request based on the request domain name.

7. The method according to claim 6, wherein, Based on the requested domain name, determining the request transmission type corresponding to the access request includes: obtaining a preset whitelist for analyzing and processing the access request, the preset whitelist including: legitimate request domain names and pass-through types corresponding to the legitimate request domain names; when a legitimate request domain name corresponding to the requested domain name exists in the preset whitelist, the pass-through type corresponding to the legitimate request domain name is determined as the request transmission type corresponding to the access request; when no legitimate request domain name corresponding to the requested domain name exists in the preset whitelist, the request transmission type corresponding to the access request is determined as a non-pass-through type.

8. The method according to claim 5, wherein, Based on the transmission protocol type and request transmission type, determining the access address corresponding to the second virtual network component includes: determining, based on the transmission protocol type and request transmission type, an address resolution module included in the resource hosting network component corresponding to the access request, wherein the address resolution module includes: multiple registered access addresses corresponding to the second virtual network components and registration services corresponding to each registered access address, wherein the registration services include the cross-regional service corresponding to the access request; and processing the access request using the address resolution module to determine the access address corresponding to the second virtual network component. address.

9. The method according to claim 8, wherein, Based on the transmission protocol type and the request transmission type, the address resolution module corresponding to the access request included in the resource hosting network component is determined, including: when the transmission protocol type is a first transmission protocol and the request transmission type is a transparent transmission type, the address resolution module corresponding to the access request is determined to be a first address resolution module; when the transmission protocol type is a second transmission protocol or the request transmission type is a non-transparent transmission type, the address resolution module corresponding to the access request is determined to be a second address resolution module.

10. A method for publishing cross-regional services in the cloud, applied to a service provider network component, the method comprising: Obtain service publishing information for cross-regional services; A second service node is determined in the service provider network component, wherein the service provider network component communicates with the resource hosting network component through a second virtual network component and a first virtual network component, the service provider network component and the second virtual network component are located in the same region, and the first virtual network component and the second virtual network component are located in different regions; The service publishing information is sent to the second virtual network component via the second service node, so that the second virtual network component sends the service publishing information to the resource hosting network component via the first virtual network component, enabling the resource hosting network component to utilize its shared computing resources to perform cross-regional service publishing operations.

11. A resource hosting network component, wherein, The resource hosting network component is communicatively connected to at least one user network component and a first virtual network component, wherein the at least one user network component, the first virtual network component, and the resource hosting network component are located in the same area; The resource hosting network component includes: a first acquisition module, configured to acquire cross-regional service access requests from at least one user network component; a first determination module, configured to determine shared computing resources in the resource hosting network component, wherein the shared computing resources are used to enable the at least one user network component to perform cross-regional access operations; and a first processing module, configured to forward the access request to a second virtual network component through the first virtual network component based on the shared computing resources, so that the second virtual network component performs cross-regional service access operations based on the access request, wherein the first virtual network component and the second virtual network component are located in different regions.

12. The resource hosting network component according to claim 11, wherein, The first processing module is further configured to: determine a forwarding computing resource corresponding to the access request in the shared computing resources; and use the forwarding computing resource to forward the access request to a second virtual network component through the first virtual network component, so that the second virtual network component transmits the access request to a service provider network component corresponding to the cross-regional service, wherein the second virtual network component and the service provider network component are located in the same region.

13. A service provider network component, comprising: The second acquisition module is used to acquire service publication information for cross-regional services. The second determining module is used to determine the second service node in the service provider network component, wherein the service provider network component is communicatively connected to the resource hosting network component through the second virtual network component and the first virtual network component, the service provider network component and the second virtual network component are located in the same area, and the first virtual network component and the second virtual network component are located in different areas; The second processing module is used to send the service publishing information to the second virtual network component through the second service node, so that the second virtual network component sends the service publishing information to the resource hosting network component through the first virtual network component, so that the resource hosting network component can use the included shared computing resources to realize cross-regional service publishing operations.

14. A cloud-based cross-regional service access system, comprising: The system comprises a resource hosting network component, at least one user network component, a first virtual network component, a second virtual network component, and a service provider network component. At least one user network component, the first virtual network component, and the resource hosting network component are located in the same region. The first virtual network component and the second virtual network component are located in different regions. The second virtual network component and the service provider network component are located in the same region. The resource hosting network component is communicatively connected to the at least one user network component and the first virtual network component. It is used to obtain cross-regional service access requests from the at least one user network component, determine shared computing resources within the resource hosting network component, and provide these shared computing resources for the at least one user network component to perform cross-regional access operations. Based on the shared computing resources, it forwards the access requests through the first virtual network component to the second virtual network component, enabling the second virtual network component to perform cross-regional service access operations based on the access requests. The second virtual network component is communicatively connected to the service provider network component, and is used to obtain the access requests through the first virtual network component and transmit the access requests to the service provider network component corresponding to the cross-regional service, thereby enabling cross-regional service access operations.

15. A computer storage medium for storing computer programs, wherein, The computer program causes the computer to perform the steps of the method of any one of claims 1-10 when executed.

16. A computer program product, comprising: A computer program, wherein when the computer program is executed by a processor of an electronic device, the processor performs the steps of the method of any one of claims 1-10.

Citation Information

Patent Citations

  • Cross-network service access method, device and system and storage medium

    CN111431956A

  • Access method and system

    CN114979262A