Public cloud technology-based network access method, and cloud system

WO2026066367A1PCT designated stage Publication Date: 2026-04-02HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-06-27
Publication Date
2026-04-02

Smart Images

  • Figure CN2025104763_02042026_PF_FP_ABST
    Figure CN2025104763_02042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of cloud services, and discloses a public cloud technology-based network access method, and a cloud system. The cloud system comprises a cloud management platform and infrastructure. The infrastructure comprises access objects obtained on the basis of the infrastructure, and a data subsystem for data transmission between different access objects. The cloud management platform is used for configuring application endpoints for a plurality of access objects in the cloud system, configuring identifiers for the application endpoints, and acquiring an access request sent by a first access object for a second access object, wherein a source address of the access request is an identifier of a first application endpoint of the first access object, a destination address of the access request is an identifier of a second application endpoint of the second access object, and the first access object and the second access object are two of the plurality of access objects; and then, on the basis of the identifier of the second application endpoint, the access request is sent to the second access object by using the infrastructure. The present application achieves a minimalistic unified network model.
Need to check novelty before this filing date? Find Prior Art

Description

Network access method and cloud system based on public cloud technology

[0001] The present application claims priority to Chinese Patent Application No. 202411388119.0, filed on September 30, 2024, entitled "Network control method and device based on public cloud technology", and to Chinese Patent Application No. 202510130903.X, filed on January 27, 2025, entitled "Network access method and cloud system based on public cloud technology", the contents of which are incorporated herein by reference in their entirety. TECHNICAL FIELD

[0002] The present application relates to the technical field of cloud services, in particular to a network access method and cloud system based on public cloud technology. BACKGROUND

[0003] Current network protocols, including internet protocol (IP) protocol, infiniBand (IB) protocol, and RDMA over converged ethernet (RoCE) protocol, are all constructed according to the seven-layer network model of open system interconnection (OSI). Each layer has not only data forwarding function, but also rich network control function according to different protocols and the development of protocols. In the public cloud network, the network service protocol stack and the network service model are also constructed by referring to the model of the traditional network protocol stack, especially the IP protocol stack.

[0004] Based on this, the current cloud network model of the public cloud is based on a virtual private cloud (VPC), plus a subnet, a security group, and a network access control list (ACL), to provide each tenant with the interconnection capability and access control capability based on the VPC virtual network. In order to realize the rich connection function of the network, various gateway capabilities are also provided, including elastic load balancing (ELB), network address translation (NAT), trunk gateway (TGW), and multiple gateway services to adapt to the networking needs of different customers. On the server side of the cloud, there are customer virtual machines (VMs) and virtual switch interfaces (OVSs) responsible for the cloud infrastructure, the OVSs only have the capability of Layer 3 (L3) forwarding and part of the port-based network access security control, and the socket protocol stack is inside the customer virtual machine, so the transmission control, congestion control, and other functions of the transmission control protocol (TCP) protocol stack all belong to the protocol stack code inside the customer VM.

[0005] However, the current cloud network exposes a lower network protocol stack level to the computing resources, resulting in a complex cloud network model and complex implementation. SUMMARY

[0006] The present application provides a network access method and cloud system based on public cloud technology. The present application realizes an extremely simple unified network model. The technical solutions provided by the present application are as follows:

[0007] In a first aspect, the present application provides a network access method based on public cloud technology. The method is applied to a cloud system. The cloud system includes a cloud management platform and an infrastructure. The infrastructure includes access objects based on the infrastructure and a data subsystem for data transmission between different access objects. The cloud management platform is used to manage the infrastructure. The access objects are used to provide cloud services to tenants. The method includes: the cloud management platform configures application endpoints for a plurality of access objects in the cloud system, and configures identifiers for the application endpoints, and establishes a connection channel between different access objects; the cloud management platform obtains an access request sent by a first access object to a second access object, the source address of the access request is the identifier of the first application endpoint of the first access object, the destination address of the access request is the identifier of the second application endpoint of the second access object, and the first access object and the second access object are two of the plurality of access objects; and the cloud management platform sends the access request to the second access object based on the identifier of the second application endpoint by using the data subsystem.

[0008] In the present application, since the source address of the access request is the identifier of the first application endpoint of the first access object, the destination address of the access request is the identifier of the second application endpoint of the second access object, and the cloud management platform sends the access request to the second access object based on the identifier of the second application endpoint, the cloud network seen from the computing resource is no longer an Ethernet interface + MAC + IP protocol stack and other low-order network protocol stacks, but a network interface, an AEP identifier and a transaction layer protocol stack directly exposed in the form of AEP. In this way, the protocol surface exposed to the customer by the data is upgraded from the traditional data link layer to the transaction layer for processing transactions. As can be seen, the present application improves the protocol stack level exposed to the customer by using a high-order protocol stack and a network service model, hides multiple protocols and underlying network details from the customer, and realizes an extremely simple unified network model.

[0009] In a possible implementation, the cloud management platform includes a management subsystem, the access objects are connected to the connection channel through a connection module, and the cloud management platform sends the access request to the second access object based on the identifier of the second application endpoint by using the data subsystem, including: the management subsystem provides the connection module of the first access object with indication information required for transmitting the access request by using the data subsystem based on the access request; the data subsystem receives the indication information provided by the connection module of the first access object and target data indicated by the access request for transmission; and the data subsystem sends the access request to the second access object according to the indication of the indication information.

[0010] Through the elastic application stack (EAS) of the application, the management subsystem can provide the connection module of the first access object with the indication information required for the data subsystem to transmit the access request, and then the data subsystem can transmit the access request to the second access object according to the indication of the indication information. In this way, one-hop direct transmission of the data plane can be realized, and the decoupling of the control and data is realized, thereby improving the transmission performance of the data plane.

[0011] In a possible implementation, the data subsystem transmits the access request to the second access object according to the indication of the indication information, including: the data subsystem copies the access request to the second access object through device pass-through according to the indication of the indication information. In this way, one-hop direct transmission of the data plane and high-performance transmission can be realized.

[0012] In a possible implementation, the management subsystem can also perform permission management. The management subsystem provides the connection module of the first access object with the indication information required for the data subsystem to transmit the access request based on the access request, including: the management subsystem provides the connection module of the first access object with the indication information when the access management policy indicates that the first access object has the permission to access the second access object.

[0013] In a possible implementation, the indication information is used to indicate one or more of the following: parameters required for link establishment negotiation and resources required for link establishment; the parameters required for link establishment negotiation include one or more of the following: a maximum transmission unit (MTU) used for transmitting the access request, a congestion control policy, or a transmission layer identifier allocation parameter; the resources required for link establishment include one or more of the following: a network layer forwarding table item, a transmission layer forwarding table item, or a transaction layer forwarding table item used for transmitting the access request.

[0014] Further, when the second access object is a cloud service and the cloud service is provided through a plurality of service backends, the indication information is also used to indicate: a target service backend in the plurality of service backends that provides the cloud service for the first access object based on the access request.

[0015] In a possible implementation, the cloud management platform can also perform zero-trust security access control for the access request. Then the method further includes: the cloud management platform acquires multi-dimensional information of the application endpoint of the first access object, the multi-dimensional information including network information, and the multi-dimensional information further including one or more of the following: location information, environment information, and identity information, the location information of the application endpoint being used to indicate a physical location where hardware providing hardware capability for the application endpoint is located, the environment information of the application endpoint being used to indicate an environment used by the application endpoint to prevent virus infection or repair existing virus damage, and the identity information of the application endpoint being used to indicate an account to which the application endpoint belongs. Correspondingly, the cloud management platform sends, by using the data subsystem, the access request to the second access object based on the identifier of the second application endpoint, including: in a case where the multi-dimensional information indicates that the first access object has the access right to the second access object, the cloud management platform sends, by using the infrastructure, the access request to the second access object based on the identifier of the second application endpoint.

[0016] In the present application, the connection channels between the access objects are implemented differently according to different deployment modes of the access objects. The present application takes the following several cases as examples for illustration.

[0017] In the first implementation, the first access object and the second access object are respectively deployed in different cloud resource deployment areas managed by the cloud management platform, and the connection channel is implemented through the network inside the cloud system.

[0018] In the second implementation, the first access object and the second access object are respectively deployed in different availability zones of the same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through the network inside the cloud system.

[0019] In the third implementation, the first access object and the second access object are deployed in the same availability zone of the same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through the network inside the cloud system.

[0020] In the fourth implementation, the first hardware providing hardware capability for the first access object and the second hardware providing hardware capability for the second access object are connected through a high-speed interconnection bus, and the connection channel is implemented through the high-speed interconnection network provided by the high-speed interconnection bus. According to different types of hardware providing hardware capability for the access object, the fourth implementation can be divided into multiple sub-scenarios. The following three sub-scenarios are taken as examples for illustration.

[0021] Sub-scenario one: communication between external devices connected by ScaleUp, such as neural network processing units (NPUs) or graphics processing units (GPUs), i.e., so-called device-to-device (D2D) communication.

[0022] Sub-scenario two: communication between external devices connected by ScaleUp, such as CPUs and NPUs, i.e., so-called device-to-host (D2H) communication.

[0023] Sub-scenario three: communication between CPUs connected by ScaleUp, i.e., so-called host-to-host (H2H) communication.

[0024] In a fifth implementation manner, the connection channel is implemented through a network inside the cloud system, a high-speed interconnection network, and an intermediary network between the two.

[0025] In a possible implementation manner, the first access object and / or the second access object are further configured with a virtual network card obtained by virtualization based on an Internet Protocol (IP) network card, and the virtual network card is used to connect a network outside the cloud system and / or a network resource owned by a tenant of the cloud system. In the case where the access object is further configured with the virtual network card obtained by virtualization based on the IP network card, the access object can continue to use the IP protocol stack and continue to use a traditional network, thereby realizing compatibility between the EAS and the traditional network.

[0026] In a possible implementation manner, the types of the plurality of access objects include one or more of the following: a hardware device in the infrastructure, an instance, or a cloud service provided by the instance.

[0027] In a second aspect, the present application provides a cloud system. The cloud system includes a cloud management platform and an infrastructure. The infrastructure includes: an access object obtained based on the infrastructure and a data subsystem for data transmission between different access objects. The cloud management platform is used to manage the infrastructure, and the access object is used to provide a cloud service to a tenant. Wherein, the cloud management platform is further used to configure an application endpoint for a plurality of access objects in the cloud system, and configure an identifier for the application endpoint, and a connection channel is established between different access objects; the cloud management platform is further used to obtain an access request sent by a first access object to a second access object, a source address of the access request is an identifier of a first application endpoint of the first access object, a destination address of the access request is an identifier of a second application endpoint of the second access object, and the first access object and the second access object are two of the plurality of access objects; and the cloud management platform is further used to send the access request to the second access object based on the identifier of the second application endpoint by using the infrastructure.

[0028] In a possible implementation, the cloud system comprises a management subsystem, and the access object is connected with the connection channel through the connection module. The management subsystem is further configured to provide, based on the access request, the connection module of the first access object with indication information required for transmitting the access request by using the data subsystem; the data subsystem is configured to receive the indication information and the target data indicated by the access request provided by the connection module of the first access object; and the data subsystem is further configured to transmit, according to the indication information, the access request to the second access object.

[0029] In a possible implementation, the data subsystem is specifically configured to copy, according to the indication information, the access request to the second access object by using device pass-through.

[0030] In a possible implementation, the management subsystem is specifically configured to provide the connection module of the first access object with the indication information when the access management policy indicates that the first access object has the access right to the second access object.

[0031] In a possible implementation, the indication information is used to indicate one or more of the following: parameters required for link establishment negotiation and resources required for link establishment. The parameters required for link establishment negotiation include one or more of the following: a maximum transmission unit (MTU) used for transmitting the access request, a congestion control policy, or a transmission layer identifier allocation parameter. The resources required for link establishment include one or more of the following: a network layer forwarding table item, a transmission layer forwarding table item, or a transaction layer forwarding table item used for transmitting the access request.

[0032] In a possible implementation, when the second access object is a cloud service and the cloud service is provided by a plurality of service backends, the indication information is further used to indicate a target service backend in the plurality of service backends that provides the cloud service for the first access object based on the access request.

[0033] In a possible implementation, the cloud management platform is further configured to acquire multi-dimensional information of the application endpoint of the first access object, and the multi-dimensional information comprises network information and further comprises one or more of the following: location information, environment information, and identity information. The location information of the application endpoint is used to indicate a physical location where a hardware providing a hardware capability for the application endpoint is located. The environment information of the application endpoint is used to indicate an environment used by the application endpoint for preventing virus infection or repairing existing virus damage. The identity information of the application endpoint is used to indicate an account to which the application endpoint belongs. Accordingly, the cloud management platform is specifically configured to transmit, based on the identity of the second application endpoint, the access request to the second access object by using the infrastructure when the multi-dimensional information indicates that the first access object has the access right to the second access object.

[0034] In a possible implementation, the first access object and the second access object satisfy: the first access object and the second access object are respectively deployed in different cloud resource deployment areas managed by the cloud management platform, and the connection channel is implemented through an internal network of the cloud system; or the first access object and the second access object are respectively deployed in different availability zones of a same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through an internal network of the cloud system; or the first access object and the second access object are deployed in a same availability zone of a same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through an internal network of the cloud system; or a first hardware providing hardware capability for the first access object and a second hardware providing hardware capability for the second access object are connected through a high-speed interconnection bus, and the connection channel is implemented through a high-speed interconnection network provided by the high-speed interconnection bus; the connection channel is implemented through the internal network of the cloud system, the high-speed interconnection network, and an intermediary network between the internal network of the cloud system and the high-speed interconnection network.

[0035] In a possible implementation, the first access object and / or the second access object are further configured with a virtual network card obtained through virtualization of an Internet Protocol (IP) network card, and the virtual network card is used to connect an external network of the cloud system and / or a network resource owned by a tenant of the cloud system.

[0036] In a possible implementation, the types of the plurality of access objects include one or more of the following: a hardware device in the infrastructure, an instance, or a cloud service provided by the instance.

[0037] In a third aspect, the present application provides a computing device, including a memory and a processor, the memory storing program instructions, and the processor executing the program instructions to perform the method provided in the first aspect of the present application and any possible implementation thereof.

[0038] In a fourth aspect, the present application provides a computing device cluster, including a plurality of computing devices, the plurality of computing devices including a plurality of processors and a plurality of memories, the plurality of memories storing program instructions, and the plurality of processors executing the program instructions to cause the computing device cluster to perform the method provided in the first aspect of the present application and any possible implementation thereof.

[0039] In a fifth aspect, the present application provides a computer-readable storage medium, which is a non-volatile computer-readable storage medium, and includes program instructions, which, when executed on a computing device, cause the computing device to perform the method provided in the first aspect of the present application and any possible implementation thereof.

[0040] In a sixth aspect, the present application provides a computer program product containing instructions, which, when executed on a computer, cause the computer to perform the method provided in the first aspect of the present application and any possible implementation thereof. Attached Figure Description

[0041] Figure 1 is a structural diagram of an implementation scenario involving a network access method based on public cloud technology provided in an embodiment of this application;

[0042] Figure 2 is a schematic diagram of the deployment of basic resources provided in an embodiment of this application;

[0043] Figure 3 is a schematic diagram of a resource presented to a client according to an embodiment of this application;

[0044] Figure 4 is a schematic diagram of a network service model corresponding to EAS provided in an embodiment of this application;

[0045] Figure 5 is a schematic diagram of EAS and traditional network interconnection provided in an embodiment of this application;

[0046] Figure 6 is a schematic diagram of another EAS interconnection with a traditional network provided in an embodiment of this application;

[0047] Figure 7 is a schematic diagram of the deployment of an access object provided in an embodiment of this application;

[0048] Figure 8 is a schematic diagram of the deployment of another access object provided in an embodiment of this application;

[0049] Figure 9 is a schematic diagram of the deployment of another access object provided in an embodiment of this application;

[0050] Figure 10 is a schematic diagram of the deployment of another access object provided in an embodiment of this application;

[0051] Figure 11 is a schematic diagram of the deployment of another access object provided in an embodiment of this application;

[0052] Figure 12 is a schematic diagram of a cloud system provided in an embodiment of this application;

[0053] Figure 13 is a schematic diagram of an EAS provided in an embodiment of this application;

[0054] Figure 14 is a flowchart of a network access method based on public cloud technology provided in an embodiment of this application;

[0055] Figure 15 is a schematic diagram of a process for processing an access request provided in an embodiment of this application;

[0056] Figure 16 is a flowchart of a cloud management platform according to an embodiment of this application sending an access request to a second access object based on the identifier of a second application endpoint using a data subsystem;

[0057] Figure 17 is a flowchart of another network access method based on public cloud technology provided in an embodiment of this application;

[0058] FIG. 18 is a schematic diagram of obtaining environment information according to an embodiment of the present application;

[0059] FIG. 19 is a schematic diagram of numerical control separation according to an embodiment of the present application;

[0060] FIG. 20 is a schematic diagram of a scenario of customer VPC accessing high-order services based on a traditional cloud IP network according to the present application;

[0061] FIG. 21 is a schematic diagram of EAS accessing high-order services according to the present application;

[0062] FIG. 22 is a schematic diagram of a scenario of customer VPC accessing cloud native service mesh based on a traditional cloud IP network according to the present application;

[0063] FIG. 23 is a schematic diagram of a scenario of EAS accessing cloud native service mesh according to the present application;

[0064] FIG. 24 is a schematic diagram of the structure of a computing device according to an embodiment of the present application;

[0065] FIG. 25 is a schematic diagram of the structure of a computing device cluster according to an embodiment of the present application;

[0066] FIG. 26 is a schematic diagram of another structure of a computing device cluster according to an embodiment of the present application. DETAILED DESCRIPTION

[0067] In order to make the purpose, technical scheme and advantages of the present application clearer, the embodiments of the present application will be described in further detail below with reference to the drawings.

[0068] In order to facilitate understanding, the technologies and backgrounds involved in the embodiments of the present application will be introduced first.

[0069] Cloud computing: Cloud computing is a kind of distributed computing, which refers to a network that uniformly manages and schedules a large number of computing resources and storage resources, and provides on-demand services to users. The computing resources and storage resources are provided by a cluster of computing devices set in a data center. Moreover, cloud computing can provide multiple types of service types for users, for example, it can provide infrastructure as a service (IaaS), platform as a service (PaaS) and software as a service (SaaS) and the like. The role of infrastructure as a service is to provide virtual machines or other resources as services to tenants. The role of platform as a service is to provide a development platform as a service to tenants. The role of software as a service is to provide an application (App, also known as application) as a service to customers.

[0070] An internet data center (IDC) is a facility and related service system that provides operation and maintenance for centralized collection, storage, processing and transmission of data based on the Internet network. Conceptually, it can be understood as a public commercial Internet "machine room", and it is also an IT professional service and an important infrastructure of the IT industry. IDC is not only a service concept, but also a network concept, which constitutes part of the network infrastructure, just like the backbone network and the access network, providing a high-end data delivery service and high-speed access service. Generally, the tenant's offline IDC can be understood as the tenant's offline machine room, which is a standardized telecom professional machine room environment built by the tenant using existing Internet communication lines and bandwidth resources, used to provide server hosting, rental and related value-added services. A cloud data center is an Internet data center deployed using the infrastructure owned by a cloud vendor.

[0071] A resource pool is a collection of various hardware resources and software resources involved in a cloud data center. Generally, according to the type of resources, the resources in the resource pool can be divided into computing resources, storage resources and network resources, etc.

[0072] Physical machine (PM): A physical resource used to carry virtualization technology. A host is also referred to as a physical machine. Generally, a host used to deploy a virtual instance is a physical server. A physical machine has multiple physical devices. For example, a physical server has physical devices such as a processor and a memory. Multiple virtual instances can be deployed in a host. Multiple virtual instances deployed on the same host share the physical resources of the host. According to different use cases, the multiple virtual instances deployed in a host can belong to the same tenant or belong to different tenants, respectively.

[0073] Virtualization is a resource management technology. Virtualization can abstract and convert various entity resources of a host, such as computing resources, network resources, and storage resources, to break the barriers between the entity structures of the host, so that a tenant can use these resources in a better way than the original configuration. The resources obtained through virtualization are referred to as virtualized resources, which are not limited by the setup method, setting region, or physical configuration of the existing entity resources.

[0074] Virtualized resources are usually provided to tenants in the form of virtual instances. A virtual instance can use the hardware resources of a host and run on an operating system (OS) of the host. An application runs in the virtual instance, and the application is used to implement a service of a tenant. The hardware resources of the host can be used by one or more tenants in the granularity of a virtual instance. Different virtual instances are isolated from each other, so that tenants can conveniently and flexibly use physical resources under the premise of secure isolation, and the utilization rate of physical resources can be greatly improved. Generally, a virtual instance can be a virtual machine, a container, or an independent process (for example, a function). A virtual instance can also be referred to as an elastic compute service (ECS) or an elastic instance (different cloud service providers have different names).

[0075] Virtual machine (VM): refers to a complete computer system that has complete hardware system functions, runs in a completely isolated environment, and is simulated by virtualization technology. Part of the instructions of the virtual machine can be processed in the host machine, and the other part of the instructions can be executed in an emulated manner. The virtual machine is also called a virtual server. The virtual machine can be regarded as a collection of a plurality of virtual devices, which has complete hardware system functions and runs in a completely isolated environment. The virtual device is virtually obtained based on a physical device that can be shared by resources through virtualization technology. For example, a virtual processor virtually obtained based on a processor through virtualization technology is a virtual device. For another example, a training card virtually obtained based on a field-programmable gate array (FPGA) through virtualization technology is also a virtual device. For example, the virtual machine in the present application can be a kernel-based virtual machine (KVM). The work that can be completed in a server can be implemented in a virtual machine. When a virtual machine is created in a server, part of the hard disk and memory capacity of the entity machine need to be used as the hard disk and memory capacity of the virtual machine. Each virtual machine has an independent hard disk and operating system, and the tenant of the virtual machine can operate the virtual machine like using a server. The running environment (such as a virtual machine application, an operating system, and virtual hardware) in different virtual machines is completely isolated, and communication between different virtual machines needs to be forwarded through a network message of a virtual manager.

[0076] The container uses the namespace and cgroup technologies supported by the Linux kernel to isolate the application APP process and its dependent packages (running environment bins / libs, specifically all files required to run the APP) in an independent running environment. The container provides a lightweight virtual running environment. The container can be obtained by packaging all the codes, libraries and dependencies of the tenant's application into an image. When the image is executed, the image runs in a virtual running environment. At this time, the container is the runtime instance of the image, similar to a lightweight sandbox, which can be started, started, stopped and deleted. The infrastructure of the container can be the hardware of the server or a virtual machine on the cloud (that is, a container can also be deployed in a virtual machine), and the operating system uses the Linux kernel, supports namespace and cgroup, wherein the namespace is used to realize the isolation between processes, and the cgroup is used to realize the allocation of process resources, and the resources are specifically virtual processors and memories allocated to the process. The container engine is similar to the virtual machine manager and runs in the operating system to manage the container. Compared with the characteristics of the virtual machine with the operating system, the container does not exist the operating system, and the container runs as a process in the operating system of the host computer, so the starting speed of the container is faster than that of the virtual machine, and the container is particularly suitable for lightweight applications, and a host computer can simultaneously run thousands of containers (processes).

[0077] The bare metal service (BMS) is a computing service with the performance of elastic cloud servers and physical machines, which is used to provide exclusive physical servers on the cloud, and provides excellent computing performance and data security for core databases, key application systems, high-performance computing and big data.

[0078] Orchestration in the computer field refers to the automatic arrangement, coordination and management for describing complex computer systems, middleware and services. Orchestration usually involves three aspects: 1) resource orchestration, responsible for resource allocation; 2) workload orchestration, responsible for sharing workloads between resources and managing their life cycle; 3) service orchestration, responsible for service discovery and high availability, etc.

[0079] Direct memory access (DMA): also known as direct memory operation or group data transfer mode, refers to a data interaction mode in which an external device directly accesses data from the memory of a computer without passing through the central processing unit (CPU) of the computer. When transmitting data in DMA mode, the CPU of the computer issues an instruction to the DMA controller to instruct the DMA controller to control the transmission of data, and the DMA controller feeds back information on the completion of transmission to the CPU after completing the transmission of data. As can be seen, in the process of transmitting data in this way, the CPU of the computer does not need to perform data transmission operations, and the operations of the CPU of the computer such as fetching instructions, fetching data and sending data can be omitted, thereby reducing the resource occupancy rate of the CPU of the computer and saving system resources.

[0080] DMA can include remote DMA (RDMA) and local DMA. RDMA refers to a data transmission mode in which data is directly transmitted from the memory of one computer to another computer through a network without the intervention of the operating systems of both parties. Local DMA refers to a data transmission mode without the need for network transmission. Since RDMA does not pass through the operating system, it not only saves a large amount of CPU resources, but also improves system throughput and reduces system network communication delay, and is widely used in large-scale parallel computer clusters.

[0081] Peripheral component interconnect express (PCIe) bus: a high-speed serial computer expansion bus.

[0082] Compute express link (CXL) bus: a high-speed computer express connection bus.

[0083] Network card: also known as network interface controller (NIC), network adapter, or local area network receiver, is a computer hardware designed to allow a host or computing device to communicate on a network.

[0084] Memory: also known as memory or main memory, its function is to temporarily store the operation data in the CPU and exchange data with external storage such as a hard disk.

[0085] Resource pooling refers to integrating multiple computing and storage resources together to form a unified resource pool for unified dynamic allocation and management. Resource pooling can realize high sharing of resources, improve resource utilization, simplify resource management, and provide flexible services for users according to demand allocation.

[0086] The cloud container instance service is a Kubernetes-based serverless container engine compatible with Kubernetes and Docker native interfaces.

[0087] The resource horizontal elasticity domain (ScaleOut domain) is used to realize large-scale resource interconnection at the AZ and Region levels based on a traditional DCN network, and the application does not need to perceive the topology.

[0088] The resource vertical elasticity domain (ScaleUp domain) is used to realize resource interconnection of CPUs, MENs, GPUs, etc. at a super-node level based on bus network technology (NVLink, CXL, UB, etc.), and realize hardware resource pooling.

[0089] The landing zone is based on a cloud account and a permission system, so that customers can build a secure and compliant multi-account operating environment and cloud IT governance system, and can realize unified control of multi-account resource sharing and human, financial, material and legal rights.

[0090] The extension and discovery service (xDS) protocol is a transmission protocol for the mesh data plane to obtain mesh dynamic configuration from the Istio control plane under the Istio service mesh architecture.

[0091] Current network protocols, including IP protocol, IB protocol, RoCE protocol, are built according to the OSI seven-layer network model, each layer has not only data forwarding function, but also rich network control function according to the difference of protocol and the development of protocol. In the public cloud network, the network service protocol stack and the network service model are also built according to the traditional network protocol stack, especially the model of IP protocol stack. Based on this, the current public cloud cloud network model is based on VPC, plus Subnet, security group, network ACL, to provide each tenant with the interconnection ability and access control ability based on VPC virtual network. In order to realize the rich connection function of network, various gateway capabilities are also provided, including ELB, NAT, TGW and other gateway services, which are suitable for the networking needs of different customers. And on the server side of the cloud, there are customer's VM virtual machines and OVS responsible for cloud infrastructure, OVS only has the ability of L3 forwarding and part of the network access security control based on port, while the Socket protocol stack is inside the customer's virtual machine, so the transmission control, congestion control and other functions of TCP protocol stack belong to the protocol stack code inside the customer's VM.

[0092] But this leads to the following problems of the current public cloud cloud network model:

[0093] 1. The public cloud network service model is complex and difficult to use. Multiple gateways coexist, becoming a bottleneck for forwarding.

[0094] 2. Coupling of network data plane and control plane: leading to complex forwarding logic of OVS and gateway, such as NAT gateway, ELB gateway, each gateway has its own unique complex logic; and the forwarding has state, which leads to the need for state synchronization within the cluster, ultimately limiting the scale of the gateway cluster, making it difficult to scale up and down.

[0095] 3. Distributed table items are distributed to all forwarding units, the control plane has high complexity and affects the speed of elastic scaling of computing resources such as containers: due to the complexity of the network model, all media access control (MAC) tables, routing tables, ACLs, security groups, etc. need to be distributed to all computing nodes, resulting in a large amount of content and a wide range of distribution. Therefore, the control plane has a heavy load and the elastic scaling performance is affected.

[0096] 4. Complex and inefficient high-level service access: because high-level services are also developed based on virtual networks, the IP addresses of the virtual networks where high-level services are located must not overlap with customer addresses and must be able to interwork with customer networks, so various types of gateways have been gradually developed to support different types of services.

[0097] 5、Weak zero trust network model: During the forwarding process of network packets, only the information contained in the packet header and payload can be carried, and more context information such as visitor, location, and environment cannot be carried, which cannot be used for rich zero trust security policies.

[0098] 6、Weak network scheduling / monitoring / operation and maintenance capability: Because a large part of the network protocol stack is located in the customer virtual machine, the transmission algorithm of the customer protocol stack cannot be controlled, resulting in different customers choosing different congestion control algorithms, which will cause unfair use of network bandwidth; some customers simply use protocols such as user datagram protocol (UDP) to perform a multi-punch attack of multiple VMs to one VM, causing switch congestion and affecting other customers. In addition, during the process of building a chain by the customer, the cloud network does not know the context information of the network, so it does not know the application scenario of the business, and therefore cannot schedule according to the characteristics of the business.

[0099] 7、Address planning and application coupling: When the current customer uses the cloud network, because the VPC / Subnet model needs to configure IP addresses, the customer needs to perform detailed address planning, and develop complex security policies based on network addresses and ports according to the deployment of the application.

[0100] 8、Not suitable for high-performance networks: The existing network model is only suitable for IPv4 / IPv6 protocol stack, which is a ScaleOut network plane. However, with the emergence of high-performance networks, the network has become more complex, and ScaleOut networks also have vRoCE high-performance networks, and ScaleUP networks have NVLink, CXL, and UB bus network technologies for high-speed interconnection between GPUs and CPUs. Such VPC, Subnet, ELB, VPCEP, and other network models are seriously unsuitable for the protocol stack and business model of high-performance networks in the ScaleOut and ScaleUp domains, resulting in the need for other network models and business control logic in these scenarios, which are separate from the original VPC+IPv4 / IPv6+multi-gateway network model, resulting in multiple parallel network models and implementations, which are more complex.

[0101] The main reason is that the following two core problems of cloud network technology have led to the above problems:

[0102] First, the current cloud network exposes a lower network protocol stack level to computing resources, resulting in complex cloud network models and complex implementation. For example, the cloud network uses a VPC and Subnet model, and an Elastic Network Interface (ENI) needs to be allocated within the Subnet. The cloud network needs to allocate an IP address and a MAC address for this ENI within the Subnet, which results in complex cloud network models and complex forwarding tables. That is, the forwarding table needs to focus on MAC link layer forwarding and IP network layer forwarding. The cloud network also supports security group and ACL security policies based on ENI and Subnet, which results in the cloud network also having a state and being based on TCP and UDP sessions, and forwarding based on sessions. In addition, in order to adapt to different scenarios, various cloud gateways are generated, such as a NAT gateway responsible for address translation, an ELB gateway responsible for L4 load balancing, a VPCEP gateway responsible for providing services across VPCs, a Transit Gateway gateway responsible for intercommunication across VPCs, and the like. Since many of these gateways have a state, HyperPlane and other technologies are generated, which further results in the cloud network becoming more and more complex.

[0103] Second, in the current network protocol stack, the transmission of the network is coupled with many business logics, and the network data plane bears too many control capabilities that are irrelevant to data transmission itself, resulting in the generation of various cloud network gateways and complex implementation. For example, in addition to the most basic network data transmission logic, the network data also integrates many functions that need to be completed in the control plane in the band: Overlay routing and addressing, access control, business control, and zero-trust security. These functions are referred to as in-band control logic of the network protocol stack.

[0104] For Overlay routing and addressing, each customer network has its own MAC forwarding table of Subnet, VPC routing table, VPC subnet routing table, and enterprise router (ER) routing table, which all need to be sent to the forwarding plane, including the virtual switch (OVS) of the computing node and the gateway node, resulting in an increase in the complexity of the data plane.

[0105] For access control, it is used to determine whether a TCP or UDP connection is allowed and can be accessed through the VPC (VPN) boundary, security group, and ACL policy, which results in the data plane saving a large number of rules and TCP and UDP session tables, and the data plane has extremely high complexity.

[0106] For service control, it includes the L4 / L7 ELB function required by the service cluster elastic scaling, which is also required when the ELB gateway builds a link in the data plane. The LB operation is performed to determine which service backend the link is distributed to. Of course, it also includes other microservice gateways in the industry, which perform business control logic in the data plane. For example, service control also includes domain name system (DNS) service discovery and ANC / Sidecar microservice control.

[0107] For zero trust security, in network service access, in order to perform LandingZone service access control, the network data plane carries a lot of Metadata data of access paths, which is used for LandingZone policy control. For example, the VPCEP gateway carries EPID and Source VPC IP, which is convenient for the service side to form g:SrouceVpce and g:VpcSourceIP parameter LandingZone parameters, so as to perform VPCEP service security, ANC microservice security and AVA network access security.

[0108] In view of this, the embodiment of the present application provides a network access method based on public cloud technology. The method is applied to a cloud system. The cloud system includes a cloud management platform and an infrastructure. The infrastructure includes an access object obtained based on the infrastructure and a data subsystem for data transmission between different access objects. The cloud management platform is used to manage the infrastructure. The access object is used to provide cloud services to tenants. In the method, the cloud management platform configures application endpoints for a plurality of access objects in the cloud system, and configures identifiers for the application endpoints, and a connection channel is established between different access objects; the cloud management platform obtains an access request sent by a first access object to a second access object, the source address of the access request is the identifier of the first application endpoint of the first access object, the destination address of the access request is the identifier of the second application endpoint of the second access object, and the first access object and the second access object are two of the plurality of access objects; then, the cloud management platform sends the access request to the second access object based on the identifier of the second application endpoint by using the data subsystem.

[0109] Since the source address of the access request is the identifier of the first application end point of the first access object, the destination address of the access request is the identifier of the second application end point of the second access object, and the cloud management platform sends the access request to the second access object based on the identifier of the second application end point, the cloud network seen from the computing resource is no longer an Ethernet interface + MAC + IP protocol stack and other low-order network protocol stacks, but a network interface, an AEP identifier and a transaction layer protocol stack in the form of an application end point (AEP) are directly exposed. In this way, the protocol surface exposed to the customer by the data surface is upgraded from the traditional data link layer to the transaction layer for processing transactions. As can be seen, the application improves the protocol stack level exposed to the customer by using a high-order protocol stack and a network service model, hides multiple protocols and underlying network details from the customer, and realizes an extremely simple unified network model.

[0110] The technical solutions of the application are described in detail from the aspects of implementation scenarios, method flows, hardware devices, software devices and the like.

[0111] The implementation scenario of the embodiments of the application is described below.

[0112] FIG. 1 is a structural schematic diagram of an implementation scenario involved in a network access method based on a public cloud technology according to an embodiment of the application. As shown in FIG. 1, the implementation scenario includes a cloud system 1 and a client 2. The cloud system 1 and the client 2 can establish a communication connection through a network. Optionally, the network can be the Internet, or can be other networks, which are not limited by the embodiments of the application. A tenant can interact with the cloud system 1 through the client 2. For example, the tenant can send cloud service request information and the like to the cloud system 1 through the client 2. The cloud system 1 is configured to respond based on the information sent by the client 2.

[0113] As shown in FIG. 1, the cloud system 1 comprises a cloud management platform and an infrastructure. The cloud management platform and the infrastructure are connected through an internal network of the cloud system. In another implementation, the cloud management platform is optionally arranged in the infrastructure. The cloud management platform is used to manage the infrastructure. The infrastructure is used to provide public cloud services. The infrastructure comprises at least one data center (DC). The cloud management platform can be connected with the at least one data center. At this time, the cloud management platform is used to manage the at least one data center. A large number of cloud resources, such as computing resources, storage resources and network resources, etc., owned by a cloud service provider are deployed in the data center. The computing resources can be computing devices (such as servers, etc.) capable of providing computing capabilities. For example, as shown in FIG. 1, a plurality of servers are deployed in the data center. The cloud services are optionally deployed in the servers. The cloud services are implemented by running virtual instances, and thus are also referred to as virtual instance deployments for implementing tenant businesses in the servers. A tenant can send a cloud service request and related information to the server through a client 2 used by the tenant, the server can process the cloud service request and related information, and provide the cloud service to the tenant based on the processed cloud service request and related information.

[0114] The cloud management platform can be logically divided into a tenant console, a computing management service, a network management service, a storage management service, an authentication service and an image management service. The tenant console provides an interface or an application program interface (API) to interact with the tenant. The computing management service is used to manage servers running virtual instances and bare metal servers. The network management service is used to manage network services (such as gateways, firewalls, etc.). The storage management service is used to manage storage services (such as data bucket services). The authentication service is used to manage the account and password of the tenant. The image management service is used to manage the images of the virtual instances.

[0115] In the implementation scenario shown in FIG. 1, a plurality of servers are arranged in one data center. The server comprises a hardware layer and a software layer. The hardware layer is a conventional configuration of the server. The hardware layer is deployed with hardware devices such as processors, memories, network cards, disks and buses. The software layer comprises an operating system installed and running on the server. The operating system of the virtual machine can be referred to as a host operating system. A virtual machine manager (also referred to as a Hypervisor) is running in the host operating system. The function of the virtual machine manager is to implement computing virtualization, network virtualization and storage virtualization of the virtual machine, and to manage the virtual machine.

[0116] The cloud management platform client can receive the control plane command sent by the cloud management platform, create a virtual instance on the server according to the control plane control command, and perform full life cycle management on the virtual instance. For example, the cloud management platform client can detect the use of hardware resources of the server in real time and report to the cloud management platform. When the cloud management platform confirms to create a virtual instance on a server, it will send a virtual instance creation command to the cloud management platform client on the server, and the cloud management platform client will create a virtual instance on the server after receiving the command. In this way, tenants can create, manage, log in and operate virtual instances through the cloud management platform.

[0117] The server can be used to run virtual machines of different specifications. Virtual machine specifications include general computing, memory optimization, and super memory, etc. Each type has specific specifications. After the tenant selects a virtual machine specification, the cloud management platform selects a server in the data center that supports the specification and determines that the server has sufficient idle hardware resources, and then creates a virtual machine with the specification on the server. By configuring the server through the cloud management platform, the analysis and planning of server hardware resources can be realized, and the corresponding computing products of physical hardware can be planned according to the hardware performance of the server, such as planning virtual machines of different specifications to meet the differentiated demands of different tenants. Moreover, according to the performance difference of virtual machines of different specifications, a differentiated pricing strategy can be implemented. For example, virtual instances of high-performance specifications are sold at a higher price, and virtual instances of ordinary performance specifications are sold at a lower price, so that tenants can purchase virtual instances on demand.

[0118] In an implementation, as shown in FIG. 2, the location of the infrastructure can be described by cloud resource deployment regions and availability zones (AZs). A tenant can select to deploy cloud services based on resources in a specific region and AZ. A region is divided from the dimensions of geographical location and network latency. The same resource pool is used in the same region, which can be understood as sharing public services such as elastic computing, block storage, object storage, virtual private cloud (VPC) network, elastic internet protocol (EIP) address, and image. A region is divided into general regions and dedicated regions. A general region refers to a region that provides general cloud services to public tenants. A dedicated region refers to a region that carries the same type of business or provides business services to specific tenants. A region usually includes multiple AZs. Multiple AZs in a region are connected by high-speed optical fibers to meet the needs of tenants to build high-availability systems across AZs. The resources such as computing, network, and storage in an AZ are logically divided into multiple clusters.

[0119] A tenant can send instructions to the cloud management platform through a client 2 used by the tenant to create, manage, log in to, and operate virtual instances in a server, and use cloud services provided by the virtual instances. For example, the cloud management platform can provide an access interface. The access interface can be provided in the form of an interface or an API. A tenant can remotely access the access interface to register a cloud account and a password with the cloud management platform and log in to the cloud management platform using the cloud account and the password. The cloud management platform can also authenticate the cloud account and the password. After successful authentication, the tenant can further select and pay for a virtual instance of a specific specification (processor, memory, disk) in the cloud management platform. After the tenant successfully pays for the virtual instance, the cloud management platform provides the tenant with a remote login account and a password of the purchased virtual instance. The tenant can use the remote login account and the password to remotely log in to the virtual instance, install and run an application of the tenant in the virtual instance, and implement the business of the tenant through the application.

[0120] The client 2 can be a computer, a personal computer, a laptop computer, a mobile phone, a smartphone, a tablet computer, a cloud host, a portable mobile terminal, a multimedia player, an electronic book reader, a wearable device, a smart home appliance, an artificial intelligence device, a smart wearable device, a smart vehicle device, or an Internet of Things device, etc.

[0121] In an implementation manner, the network access method based on the public cloud technology provided by the embodiments of the present application can be implemented by running an executable program on a computing device in the cloud system 1. When the network access method based on the public cloud technology provided by the embodiments of the present application is applied to a cloud management platform, a server used to implement the cloud management platform can implement the network access method based on the public cloud technology provided by the embodiments of the present application by running the executable program of the network access method based on the public cloud technology provided by the embodiments of the present application. In addition, the executable program for implementing the network access method based on the public cloud technology can be presented in the form of an application installation package. After the server installs the application installation package, the server can implement the network access method based on the public cloud technology provided by the embodiments of the present application by running the executable program in the application installation package.

[0122] It should be understood that the above is an exemplary description of the implementation scenario of the network access method based on the public cloud technology provided by the embodiments of the present application, and does not constitute a limitation on the implementation scenario of the network access method based on the public cloud technology. It can be known by those skilled in the art that the implementation scenario can be adjusted according to application requirements as the business requirements change, and the embodiments of the present application do not make a specific limitation. In addition, when the network access method based on the public cloud technology provided by the embodiments of the present application is applied to other scenarios, the executable program of the method can also be presented in the form of an application installation package or presented in other ways, and the embodiments of the present application do not make a one-by-one enumeration.

[0123] The implementation process of the network access method based on the public cloud technology provided by the embodiments of the present application is exemplarily described below. The network access method is applied to a cloud system. The cloud system includes a cloud management platform and an infrastructure. The infrastructure includes: an access object based on the infrastructure and a data subsystem for data transmission between different access objects, the cloud management platform is used to manage the infrastructure, and the access object is used to provide cloud services to tenants.

[0124] According to the foregoing description, in order to implement network access, the cloud management platform needs to configure an application endpoint and an identifier for the access object, so that the cloud management platform transmits an access request based on the identifier of the application endpoint of the access object by using the infrastructure. In addition, in order to transmit the access request, the cloud system needs to obtain the indication information required for transmitting the access request from the management subsystem of the cloud system, and transmit the access request based on the indication information by using the data subsystem of the cloud system. In the present application, in order to facilitate understanding of the network access process of the present application, the related contents such as the access object, the application endpoint, the management subsystem and the data subsystem involved in the present application will be described first, and then the implementation logic of the network access will be described.

[0125] In this application, the types of multiple access objects include one or more of the following: hardware devices in the infrastructure, instances, or cloud services provided by instances. Application endpoints can be regarded as network interfaces configured by the cloud management platform for access objects. However, application endpoints are different from current virtual network cards. Different application endpoints communicate with each other through the identification of the application endpoints, rather than using IP addresses. When communicating between different access objects, the access objects will establish a communication transaction, so that the cloud network in the cloud system will treat the communication event as a transaction and use the application endpoint of the access object for routing and addressing during processing, to realize communication between access objects.

[0126] In this way, in the traditional IP protocol stack, what is visible to the customer is the content of the data link layer, the network layer, and the interface / address layer, as shown in the dashed box in FIG. 3. In the EAS, what is visible to the customer is the transport layer and the transaction layer, as shown in the dashed box in FIG. 3. That is, the cloud network seen from the computing resource is no longer a low-order network protocol stack such as an Ethernet interface, MAC, IP protocol stack, but a network interface directly exposed in the form of an AEP, an AEP identifier, and a transaction layer protocol stack. The protocol exposed to the customer faces upward from the traditional data link layer to the transaction layer for processing transactions. The transaction layer is between the functional layer and the transport layer, and is used to provide multiple connection modes, multiple transaction operations, and sequencing functions for the functional layer. A transaction refers to a user-initiated memory access or bidirectional communication operation. The minimum execution flow of a transaction includes the transmission and reception of a transaction request message and possibly the transmission and reception of a transaction response message. In this way, the application is equivalent to increasing the protocol stack level exposed to the customer, and shielding the customer from the differences between multiple underlying physical networks and multiple protocol stacks of the network.

[0127] This can be achieved because, with the development of technology, the transaction layer and the transport layer are offloaded on devices such as data processing units (DPUs, also known as intelligent network cards) in the ScaleOut domain, and the transaction layer and the transport layer are offloaded on IODies of CPUs and GPUs in the ScaleUp domain supporting bus network protocols, so various computing resources can directly see the network interface and its name, as well as the transaction layer network interface provided thereby. This makes it unnecessary to have socket protocol stacks, TCP protocol stacks, and IP protocol stacks in the host, and the network interface does not have a network layer link layer address. Instead, the network interface communicates with the opposite end through the name of the network interface.

[0128] From the above, the application provides a protocol stack that can be applied in a cloud system, which has the advantage of being simpler than a traditional protocol stack. Access objects in the cloud system can access other access objects based on the protocol stack. The protocol stack can be referred to as EAS. Accordingly, the access objects in the cloud system can be referred to as access objects in EAS.

[0129] Generally, AEPs belonging to the same tenant account can intercommunicate. AEPs can join a communication domain (Domain), and a domain policy can be used to define whether AEPs in a domain can intercommunicate, and whether AEPs between domains can intercommunicate. At this time, if the domain policy of the domains in which the two AEPs belonging to the same account are located allows, the two AEPs can correspondingly communicate within an AZ, across AZs, and across regions.

[0130] According to different implementation manners of different types of access objects, the functions, location attributes, communication modes, and visibility (also referred to as communication range) of the application end points of different types of access objects are different. The location attribute is used to indicate the physical location to which the AEP belongs. For example, the location attribute indicates that the physical location to which the AEP belongs is the coverage range of the bus network (indicated as XPOD below), an AZ, or a region. The communication mode is used to indicate the mode of communication with the AEP. In the EAS provided in the application, AEPs communicate by taking the identity (such as the name (AEP Name) or identity number (identity, ID)) of the AEP as the target of communication. The visibility is used to indicate in which range the identity of the AEP can be uniquely found and based on which the AEP communicates with the AEP with the identity.

[0131] For example, the following table is an example of the functions, location attributes, communication modes, and visibility of the application end points of several commonly used access objects in a cloud system. Global indicates the entire public cloud. According to the table, the access objects include: CPU computing resource AEP, GPU / XPU AEP, region-level service (service) AEP, AZ-level Service-AZ AEP, Domain, and Domain Policy. Moreover, most AEPs of EAS, especially AEPs in the ScaleOut domain, are globally visible, that is, they can intercommunicate across regions; however, AEPs in the ScaleUp domain can generally intercommunicate within an XPOD or a region.

[0132] In an implementation, when an access object directly uses the function provided by hardware, the cloud management platform configures an application endpoint for the access object, and the application endpoint can be generated by device simulation of the capability of the hardware used by the access object. For example, for hardware devices such as CPU and XPU, and instances such as container, VM and BMS, which directly use the function provided by hardware, the cloud management platform can generate an application endpoint by device simulation of the capability of the hardware used by the access object, and configure the application endpoint for the access object. At this time, it can be considered that an AEP communication device is configured for the access object. Generally, the AEP communication device in the ScaleOut domain is constructed based on DPU, and the AEP communication device in the ScaleUp domain is constructed based on IODie of XPU. In this application, the access object is connected to the connection channel through its own connection module. Here, the DPU / IODie is the connection module of the access object.

[0133] When an access object does not directly use the function provided by hardware, the cloud management platform configures an application endpoint for the access object, which is actually to configure an identifier for the access object. For example, for cloud services, since cloud services are provided through cloud instances, cloud instances need to use the capability of hardware, that is, cloud services indirectly use the capability of hardware, the cloud management platform configures an application endpoint for the cloud service, which is actually to configure an AEP identifier for the cloud service to indicate the cloud service as an access object through the AEP identifier. This is because the cloud service is a virtual service, and the computing resource providing the service is invisible to the customer, so the cloud service does not have a communication device corresponding to the computing resource. However, whether the computing resource has a communication device or the cloud service does not have a communication device, they can communicate through the same communication library and the identifier of the AEP.

[0134] It should be noted that when the cloud management platform configures an application endpoint for an access object, it not only needs to perform the operations described above, but also needs to perform some other necessary operations so that the cloud management platform and the network can bring the application endpoint of the access object into their control range. For example, after the cloud management platform configures an application endpoint and an identifier for the access object, it also needs to manage the life cycle and identifier of the application endpoint, configure the mapping of the application endpoint and the physical network, manage the mapping, add the application endpoint to the Domain, manage the application endpoint with the objects of the Domain, and configure the access policy of the Domain, etc. The embodiments of the present application do not exemplify them one by one.

[0135] The cloud management platform configures application endpoints for multiple access objects in the cloud system, and configures identifiers for the application endpoints, and then a network service model corresponding to the EAS is obtained. For example, FIG. 4 is a schematic diagram of a network service model corresponding to the EAS according to an embodiment of the present application. As shown in FIG. 4, the cloud management platform respectively obtains application endpoints for the VM, CCI, relational database service (RDS) instance, NPU, distributed control system (DCS) instance, and scalable file service (SFS) instance in the cloud system through virtualization, and correspondingly configures identifiers for each application endpoint. Moreover, the AEP of VM1 and the AEP of CCI1 join Domain-1, the AEP of VM2 and the AEP of CCI2, the AEP of RDS instance 1, the AEP of NPU1, the AEP of NPU2, and the AEP of DCS instance 1 join Domain-2, the AEP of VM3 and the AEP of CCI3 join Domain-3, and the AEP of VM4 and the AEP of CCI4, the AEP of RDS instance 2, and the AEP of SFS instance 1 join Domain-4.

[0136] Optionally, the cloud management platform can also configure the access object with a virtual network card obtained through virtualization based on an IP network card. The virtual network card is used to connect a network outside the cloud system and / or network resources owned by a tenant of the cloud system. In the case where the access object is also configured with a virtual network card obtained through virtualization based on an IP network card, the access object can continue to use the IP protocol stack and continue to use the traditional network, thereby realizing compatibility between the EAS and the traditional network. In the present application, the network outside the cloud system is, for example, a backbone network outside a public cloud, such as the Internet, and the network resources owned by the tenant of the cloud system are, for example, the network of a traditional data center room of the tenant.

[0137] At this time, on the cloud, the access objects such as virtual machines, bare machines, and containers can be simultaneously connected to the elastic network interfaces (ENI) of the traditional network protocol stack and the AEP of the EAS, thereby realizing dual-stack interconnection of computing capabilities. In this way, a customer application can use a dual-stack device as a boundary, on one hand, access the traffic of the external network or the customer internet data center (IDC) room through the traditional IP network protocol stack, thereby realizing intercommunication with the traditional network, and on the other hand, communicate with high-performance databases, artificial intelligence (AI) services, and the like inside the cloud network through the EAS, thereby realizing compatibility between the EAS and the traditional network.

[0138] For example, as shown in FIG. 5 and FIG. 6, there are two network domains on the cloud, one network domain is a traditional network area, which uses an IP protocol stack for communication, and the service model is still a traditional cloud network model such as VPC; the other network domain is an EAS network area, which uses the EAS protocol stack provided by the present application for communication.

[0139] In the present application, according to different deployment modes of access objects, the implementation modes of the connection channels between the access objects are different, which will be described below taking the following implementation modes as examples. Among them, the first access object and the second access object are two of the plurality of access objects.

[0140] In the first implementation mode, the first access object and the second access object are respectively deployed in different cloud resource deployment areas managed by the cloud management platform, and the connection channel is implemented through the network inside the cloud system.

[0141] In this implementation mode, the first access object and the second access object are deployed in different regions. At this time, since the first access object and the second access object are both deployed inside the cloud system, the connection channel between them is implemented through the network inside the cloud system. Since the access objects in the present application communicate through the identification of AEP, EAS shields the underlying network for the access objects, therefore the present application does not make specific limitation on the type of the network inside the cloud system. For example, the network can be Ethernet, or the network can be other types of network. For example, as shown in FIG. 7, the VM and the BMS are respectively deployed in region-1 and region-2, and the cloud management platform configures the VM and the BMS with AEP respectively, and the VM and the BMS are connected through Ethernet.

[0142] In the second implementation mode, the first access object and the second access object are respectively deployed in different availability zones of the same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through the network inside the cloud system.

[0143] In this implementation mode, the first access object and the second access object are deployed in different AZs of the same region. At this time, since the first access object and the second access object are both deployed inside the cloud system, the connection channel between them is implemented through the network inside the cloud system. Since the access objects in the present application communicate through the identification of AEP, EAS shields the underlying network for the access objects, therefore the present application does not make specific limitation on the type of the network inside the cloud system. For example, the network can be Ethernet, or the network can be other types of network. For example, as shown in FIG. 7, the VM and the CCI are respectively deployed in AZ1 and AZ2 of region-1, and the cloud management platform configures the VM and the CCI with AEP respectively, and the VM and the BMS are connected through Ethernet.

[0144] In the third implementation, the first access object and the second access object are deployed in the same availability zone of the same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through the network inside the cloud system.

[0145] In this implementation, the first access object and the second access object are deployed in the same AZ. At this time, since the first access object and the second access object are both deployed inside the cloud system, the connection channel between the two is implemented through the network inside the cloud system. Since the access objects in the present application communicate through the identification of AEP, the EAS shields the underlying network for the access objects, and therefore the present application does not make specific limitations on the type of the network inside the cloud system. For example, the network can be an Ethernet, or the network is another type of network.

[0146] In the above first to third implementations, it is equivalent to that the first access object and the second access object implement connection through a large-scale interconnected network, which can be referred to as a ScaleOut network. Therefore, the above first to third implementations can be referred to as an implementation mode of intercommunication between different access objects located in the ScaleOut plane, also referred to as an implementation mode of intercommunication between different access objects through the ScaleOut plane.

[0147] In the fourth implementation, the first hardware providing hardware capabilities for the first access object and the second hardware providing hardware capabilities for the second access object are connected through a high-speed interconnection bus, and the connection channel is implemented through the high-speed interconnection network provided by the high-speed interconnection bus.

[0148] In this implementation, the first access object and the second access object implement connection through the high-speed interconnection network provided by the high-speed interconnection bus. The high-speed interconnection network can be referred to as a ScaleUp network. Therefore, this implementation can be referred to as an implementation mode of intercommunication between different access objects located in the ScaleUp plane, also referred to as an implementation mode of intercommunication between different access objects through the ScaleUp plane. The ScaleUp network belongs to the category of high-performance bus networks, and the communication range can be XPOD level, or a larger range.

[0149] Since the access objects in the present application communicate through the identification of AEP, the EAS shields the underlying network from the access objects, and therefore the high-speed interconnection network described above can have various presentations. For example, the high-speed interconnection network can be a peripheral component interconnect express (PCIE) network. For another example, the high-speed interconnection network can also be an infiniBand (IB) network. For yet another example, the high-speed interconnection network can also be a compute express link (CXL) network. For yet another example, the high-speed interconnection network can also be an interconnection network between devices developed by a cloud vendor, and in order to ensure the communication bandwidth between different physical devices, the bandwidth of the network also needs to be no less than 40G / S. Accordingly, the high-speed interconnection device accessed by each physical device can be a communication device based on the PCIE protocol, the CXL protocol, the IB protocol, or a communication protocol developed by the cloud vendor. The high-speed interconnection network has the ability to support bus semantics, which can support communication between physical devices. The bus semantics is, for example, load, store, or DMA, etc. The load is used to load data in the memory into the register. The store is used to store data in the register into the memory. It should be noted that the high-speed interconnection network can also be implemented by other implementation manners, for example, the high-speed interconnection network can also be implemented based on Nvlink, or can also be implemented based on other high-speed network technologies with bus access capability, and the present application embodiment does not make specific limitation thereto. In a possible implementation manner, the hardware (also referred to as a physical device) providing hardware capabilities for the access object is configured with a high-speed network card, and the high-speed network card can be linked to the high-speed interconnection network. For example, the high-speed network card can be an RDMA network card. In this way, the physical device can realize network communication with the high-speed interconnection network through the respective high-speed network card.

[0150] According to different types of hardware providing hardware capabilities for the access object, the ScaleUp plane interworking of the fourth implementation manner can be further divided into various sub-scenarios. The following three sub-scenarios are taken as examples to illustrate them.

[0151] Sub-scenario one: communication between external devices such as neural network processing units (NPUs) or graphics processing units (GPUs) connected through ScaleUp, i.e., device to device (D2D) communication. As shown in FIG. 8, two BMS devices each have two NPUs, and the two NPUs have their own AEP network devices connected to the ScaleUp network. At this time, the NPUs can directly communicate through EAS. Note that the CPU of the BMS does not directly access the ScaleUp network at this time, but is connected to the NPU through an internal bus.

[0152] Sub-scenario two: communication between external devices such as CPUs and NPUs connected through ScaleUp, i.e., device to host (D2H) communication. As shown in FIG. 9, the CPUs of two BMS devices are also connected to the ScaleUp network and have AEP devices. Then, the BMS and the NPU can directly communicate through EAS. In this case, the NPU does not access the CPU in device mode, but communicates with the CPU in a peer-to-peer manner through AEP.

[0153] Sub-scenario three: communication between CPUs connected through ScaleUp, i.e., host to host (H2H) communication. As shown in FIG. 10, the CPUs of two BMS devices are also connected to the ScaleUp network and have AEP devices. Then, the CPUs of the BMS can directly communicate through the EAS protocol stack.

[0154] In a fifth implementation, the connection channel is implemented through a network within the cloud system, a high-speed interconnection network, and an intermediary network between the two.

[0155] In this implementation, the first access object and the second access object are connected through a network within the cloud system, a high-speed interconnection network, and an intermediary network between the two. Therefore, this implementation can be referred to as an implementation of intercommunication between different access objects located in the ScaleUp domain and the ScaleOut domain, respectively, and also as an implementation of communication between different access objects through the ScaleOut domain and the ScaleUp domain.

[0156] According to the above description, the ScaleOut domain can optionally use Ethernet and the like network, and the network topology can be a CLOS architecture and the like for application-agnostic networking. The ScaleUp domain usually uses high-performance bus network technologies such as NVLink or CXL, which have the characteristics of large bandwidth, small latency, and even simplified network protocols. In a possible implementation manner, the intermediate network can be any network that can connect the network inside the cloud system and the high-speed interconnection network. For example, the intermediate network is a relay network implemented by a DPU. For example, as shown in FIG. 11, the CCI located in the ScaleOut domain is connected with the NPU1 located in the ScaleUp domain through the network inside the cloud system, the high-speed interconnection network, and the relay network implemented by the DPU located between the two.

[0157] In a possible implementation manner, as shown in FIG. 12, the cloud system includes a management subsystem (also referred to as a control plane) and a data subsystem (also referred to as a data plane). As shown in FIG. 12, the control plane of the EAS can be divided into an EAS management plane and an EAS control plane. The EAS management plane is mainly used for processing APIs and managing some information configured by a customer that can be persisted. The EAS control plane is mainly used for managing process data generated according to configuration data. The EAS management plane mainly includes the following four modules:

[0158] 1. An AEP management module, used for managing the life cycle of an AEP communication device on various computing resources, a communication name, a context, and a mapping between the communication name and a physical network.

[0159] 2. An access domain management module, used for managing objects of a Domain and a Domain policy. The Domain access policy can also be divided into an outbound policy and an inbound policy (also referred to as an access domain association).

[0160] 3. A service management module, used for supporting service registration (a name and a backend), health check, load balancing scheduling, and the like scheduling process, and supporting a cloud-native ecology of an xDS protocol.

[0161] 4. An application traffic scheduling module, used for configuring a quality of service (Qos) policy and adjusting a business model according to AI training, an inference model, a perception network topology, and load information, and scheduling a network path based on the same.

[0162] Correspondingly, the EAS control plane is used for being responsible for traffic scheduling, service scheduling, access control, health check, name mapping, unified context, network topology, and network state.

[0163] The EAS management plane and the EAS control plane can be optionally deployed in a centralized cluster and achieve cluster load sharing through principles such as multi-tenancy. The EAS module in the service processing unit (SPU) is a newly added module for supporting the EAS. For example, the EAS module is configured to invoke an API of the EAS control plane in the process of delivering an access request, and provide the hardware for executing the access request delivery in the DPU / IODie with the indication information required for delivering the access request based on the calling result of the EAS control plane. In the DPU scenario, the EAS module is deployed on the SPU of the DPU, and in the IODie scenario, the EAS module is deployed on the SPU at the Rack level. The SPU can be regarded as a CPU arranged inside the DPU / IODie of an access object, and is configured to provide the DPU / IODie with computing power. For example, in the DPU scenario, the SPU is a general-purpose CPU.

[0164] Optionally, the EAS control plane comprises three types of external interfaces, namely an API interface, an xDS interface and a data object interface. The three types of external interfaces are described as follows:

[0165] 1) The API interface is configured to provide a northbound public API, and provide API interfaces of the four modules and a software development kit (SDK) for interacting with a console of a cloud system, so as to realize cloud APIization. It should be noted that the present application focuses on network and application related models, and the application traffic scheduling interface is not described herein. The following table provides a description of the management objects of the AEP management module, the access and management module and the service management module.

[0166] 2) The xDS interface is configured to support the xDS protocol. In addition to supporting the API, the service management module also supports the xDS protocol, provides configuration of a service mesh, supports interfacing with the service mesh, and realizes Proxyless microservice access based on the EAS. As shown in FIG. 12, the xDS interface interfaces with a cloud-native console. The cloud-native console is responsible for security policy, service monitoring, service management and management of the service mesh of the cloud-native application.

[0167] 3) Data Object Interface, which is an interface for accessing the EAS management plane by the object. As shown in FIG. 12, the interface between the DPU / IODie of the VM / BMS and the EAS management plane. The data object interface is an innovation in the EAS. When the customer accesses the object and calls the EAS management plane interface, according to different calling purposes, part of the interface calls will be distributed by the SPU in the computing node, and part of the interface calls related to the link establishment will be passed to the EAS management plane through the SPU calling the data object interface for centralized processing. Link establishment refers to the process of obtaining the indication information required by the access process from the EAS management plane when the access occurs. As shown in the following table, the data object interface mainly has the following functions. According to the function of the data object interface, it includes a user interface and a kernel interface.

[0168] As shown in FIG. 12, the DPU, IODie and switching device are provided in the EAS data plane for data forwarding. The EAS data plane can provide the network topology and state to the EAS control plane, and the EAS control plane can provide the forwarding table item to the EAS data plane. The core change of the EAS data plane compared with the traditional data plane is the improvement of the protocol plane level exposed to the customer, that is, from the original data link layer of the device to the transaction layer. In this way, the network can process the access of the access object as a transaction, and directly map the customer transaction layer to the underlying physical network, eliminating the original complex Overlay layer network and Underlay layer network coupling scheme, and the data plane without OU mapping, shielding the differences of multiple underlying physical networks, and shielding multiple protocol stacks of the network.

[0169] As shown in FIG. 13, the left side is a view of the IP protocol stack from the perspective of the VM / BMS. In this view, a process runs in the user space of the VM / BMS, and the process runs based on the glibc library. The socket protocol stack and the TCP / IP protocol stack run in the kernel space of the VM / BMS. In the VM / BMS, the network interface and the MAC address or IP address on the network interface can be seen, and the network interface also provides its own data link layer driver. The host obtains the IP address through the TCP / IP protocol stack, and provides the socket protocol stack for the upper layer application. The feature of this TCP / IP protocol stack is that the control interface (such as socket, bind and connect) and the data plane interface (such as Send and Recieve) of the network use the same channel, that is, the control and data coupling scheme, which leads to a relatively low data plane transmission performance.

[0170] As shown in FIG. 13, the right side is a view of the EAS from the perspective of the VM / BMS. In this view, the MAC address is not visible within the VM / BMS, nor is the address of the TCP / IP stack. What is visible is the AEP identity of the VM / BMS, and communication is through the AEP identity. In this model, the EAS control plane is invoked through the use of the management plane interface of the EAS, but the data plane interface is through device passthrough for DMA zero-copy communication. The process runs in the user space of the VM / BMS, and the process is based on the liburma library. The ubcore and driver that support the EAS run in the kernel space of the VM / BMS. In this way, a control and data decoupling solution is achieved, and the transmission performance of the data plane can be effectively improved.

[0171] The data plane interface of the EAS mainly has the semantics shown in the following table. According to the role of the data plane interface, it includes a user state interface and a kernel state interface.

[0172] In the above data plane interface, there is a context field, and the context describes the QoS level, latency requirement and other information required by the user to send a message. This information is mainly defined by the cloud system, and can also be optionally customized by the user, and can optionally use the JSON format. The information described in the context field is used by the EAS to implement application-level traffic quality assurance and scheduling by the application traffic scheduling module according to this information.

[0173] It should be noted that in this scenario, slave devices of the AEP communication device are also supported, and container scenarios are also supported. The AEP slave device shares the bandwidth and resources of the master AEP device, but can be used by multiple containers through the slave device. For example, a VM is provided with multiple containers, the VM is configured with an AEP, and the multiple containers are respectively configured with an AEP. The AEP of the VM is referred to as an AEP master device, and the AEP of the container is referred to as an AEP slave device.

[0174] In addition, the EAS data plane also supports the following functional characteristics:

[0175] The above describes the access object, application endpoint, management subsystem and data subsystem and other related content involved in the network access process, and the implementation logic of the network access is described below. FIG. 14 is a flowchart of a network access method based on a public cloud technology according to an embodiment of the present application. As shown in FIG. 14, the network access method based on the public cloud technology includes the following steps:

[0176] Step 1401, the cloud management platform configures application endpoints for a plurality of access objects in the cloud system, and configures an identifier for the application endpoints, and establishes a connection channel between different access objects.

[0177] The implementation manner of the cloud management platform configuring the application endpoints for the access objects, and the implementation manner of the connection channel between the access objects have been described in the foregoing content, and will not be described here again.

[0178] Step 1402, the cloud management platform obtains an access request sent by a first access object to a second access object, a source address of the access request is an identifier of a first application endpoint of the first access object, a destination address of the access request is an identifier of a second application endpoint of the second access object, and the first access object and the second access object are two of the plurality of access objects.

[0179] When the first access object has an access demand for the second access object, the first access object can send an access request to the second access object. Since the different access objects in the present application communicate through the identifier of the AEP configured for the access object, the source address of the access request is the identifier of the first application endpoint of the first access object, and the destination address of the access request is the identifier of the second application endpoint of the second access object. Here, the cloud management platform obtains the access request, and actually the management subsystem obtains the access request. The first access object sends the access request to the second access object, and needs to call the management interface, and the management interface will pass the access request to the management subsystem. In this way, the management subsystem can obtain the access request.

[0180] In a possible implementation manner, the first access object triggers the access request by creating a communication transaction. Before creating the communication transaction, the first access object needs to initialize the context first, create various queues, and then create the communication transaction. For example, the first access object is a VM in a client, which establishes a transaction communication channel by calling the connect or import interface. The operation of creating the communication transaction is centralized processing, which needs to call the management interface, so the information of the operation (that is, the access request) will be passed to the EAS management surface through the management interface. Since the EAS management surface manages the life cycle of the AEP of the first access object, the EAS management surface can obtain the basic information of the AEP of the first access object, such as the physical network address, the account to which the AEP belongs, and the MTU, and create a message based on the basic information and the access request, and add the identifier of the created communication transaction in the message. The basic information of the AEP of the access object can be collected by the EAS management surface in the process of system initialization.

[0181] For example, the connection module of the first access object can provide the access request to the management subsystem, so that the management subsystem processes the access request. For example, FIG. 15 is a process diagram of processing an access request provided by an embodiment of the present application. As shown in FIG. 15, it is assumed that the first access object is a VM in a client, and the second access object is a VM in a server. When the VM in the client needs to access the VM in the server, the VM in the client can trigger an access request indicating access to the VM in the server by performing a specified operation. After the VM in the client triggers the access request, a centralized processing management interface is called, and the interface call enters the driver through the eas_core. Then, the interface call is sent to the DPU by the driver through the AEP communication device (i.e., interface in FIG. 15). In the DPU, the interface call is sent to the SPU through the mailbox message queue. After the SPU receives the interface call, it is determined whether the interface call needs to be processed in the distributed local processing or needs to be processed in the centralized processing of the EAS management plane. When the SPU determines that the interface call needs to be processed in the SPU, the SPU directly processes the interface call. When the SPU determines that the interface call needs to be processed in the centralized processing of the EAS management plane, the data object interface is called to pass the access request to the EAS management plane for processing.

[0182] In step 1403, the cloud management platform uses the data subsystem to send an access request to the second access object based on the identifier of the second application endpoint.

[0183] In a possible implementation, as shown in FIG. 16, the implementation process of step 1403 includes the following steps.

[0184] In step 14031, the management subsystem provides the connection module of the first access object with the indication information required for the data subsystem to transmit the access request based on the access request.

[0185] After the EAS management plane receives the access request, it is determined whether the first access object has the permission to access the second access object. In the case where the first access object has the permission to access the second access object, the indication information required for the data subsystem to transmit the access request is obtained, and the indication information is provided to the connection module (such as the SPU) of the first access object.

[0186] In a possible implementation, the indication information is used to indicate one or more of the following: parameters required for link establishment negotiation and resources required for link establishment. The parameters required for link establishment negotiation are based on the capabilities of the device to which the AEP of the first access object and the AEP of the second access object belong. The resources required for link establishment are based on the source and destination network addresses to which the AEP of the first access object and the AEP of the second access object belong. For example, the parameters required for link establishment negotiation include one or more of the following: a maximum transmission unit (MTU) used for transmitting the access request, a congestion control policy, or a transmission layer identifier allocation parameter. The resources required for link establishment include one or more of the following: a network layer forwarding table item, a transmission layer forwarding table item, or a transaction layer forwarding table item used for transmitting the access request. Further, in the case where the second access object is a cloud service and the cloud service is provided through a plurality of service backends, the indication information is also used to indicate: a target service backend in the plurality of service backends that provides the cloud service for the first access object based on the access request. The target service backend can be determined through a load balancing algorithm in the plurality of service backends. The target service backend can be indicated by a physical network address where the target service backend is located. The physical network address is invisible to the client and can be an address of any underlying network protocol.

[0187] For example, after the EAS management plane receives the access request, the EAS management plane performs the following operations: 1. According to the domain policy, it is determined whether the first access object has the permission to access the second access object. If the first access object does not have the permission to access the second access object, a failure is returned. If the first access object has the permission to access the second access object, operation 2 is performed. 2. Link establishment negotiation is completed: the indication information is determined based on the capabilities of the device to which the AEP belongs and the source and destination network addresses to which the AEP belongs. 3. After obtaining the indication information, the EAS management plane returns the indication information to the SPU of the first access object. Correspondingly, the EAS management plane also needs to provide the second access object with information indicating the resources required for link establishment. For example, the EAS management plane sends the network layer, the transmission layer, and the transaction layer forwarding table items to the SPU where the AEP of the second access object is located. During the process of processing the access request, the EAS management plane also instructs the second access object to create a communication transaction. Before creating the communication transaction, the second access object needs to initialize the context and create various queues, and then create the communication transaction. Information about the operation of the second access object to create the communication transaction is also sent to the EAS management plane. Since the EAS management plane manages the life cycle of the AEP of the second access object, it can obtain the basic information of the physical network address where the AEP of the second access object is located, the account to which the AEP belongs, and the MTU, and obtain the indication information required for the first access request to be transmitted by the data subsystem based on the basic information.

[0188] Step 14032, the data subsystem receives the indication information provided by the connection module of the first access object and the target data of the access request indication transmission.

[0189] After the connection module of the first access object receives the indication information, the connection module needs to provide the indication information to the data subsystem and provide the target data of the access request indication transmission to the data subsystem, so that the data subsystem transmits the target data of the access request indication transmission according to the indication of the indication information. For example, after the EAS management control SPU facing the first access object provides the indication information, the SPU needs to issue the network layer, the transmission layer, and the transaction layer forwarding table item to the DPU data plane or the IODie, so that the hardware connects the data plane based on the forwarding table item. At this time, the customer's data object interface call returns completion, and the first access object can continue to call the data plane interface to formally send data.

[0190] Step 14033, the data subsystem transmits the access request to the second access object according to the indication of the indication information.

[0191] After the data subsystem obtains the indication information and the target data of the access request indication transmission, the data subsystem can transmit the access request to the second access object according to the indication of the indication information. In a possible implementation, the implementation process of step 14033 includes: the data subsystem copies the access request to the second access object through device pass-through according to the indication of the indication information. In this way, one-hop direct and high-performance transmission of the data plane can be achieved.

[0192] Optionally, the cloud system can also perform zero-trust security access control on the access request when performing step 1403. As shown in FIG. 17, before step 1403, the method further includes:

[0193] Step 1404, the cloud management platform obtains multi-dimensional information of the application endpoint of the first access object, the multi-dimensional information includes network information, and the multi-dimensional information further includes one or more of the following: location information, environment information, and identity information. The location information of the application endpoint is used to indicate the physical location of the hardware that provides hardware capabilities for the application endpoint. The environment information of the application endpoint is used to indicate the environment used by the application endpoint to prevent virus infection or repair existing virus damage. The identity information of the application endpoint is used to indicate the account to which the application endpoint belongs.

[0194] In the present application, the EAS management plane will save the location information, identity information (such as account ID, attributes, permissions, organization, etc.), environment information, and other information corresponding to the AEP. In an implementation manner, as shown in FIG. 18, for the environment information, the EAS management plane can provide a security Context reporting interface for the third-party security software (such as Security software in FIG. 18) in the access object to report the state and environment information (such as Security_Context in FIG. 18) of the access object. This environment information can guarantee its integrity and credibility through a certificate. After the access object calls Security_Context, the related Context will be sent to the EAS management plane and saved in the database corresponding to the AEP, so as to be used when doing zero-trust security. Among them, the third-party Context includes the system's antivirus library, health degree, OS version, and other information, which can be used for the zero-trust security policy based on the LandingZone. The zero-trust security policy may, for example, include a location policy, an identity policy, and an environment policy. The location policy is used to indicate the location characteristics that the access object should have when having access permission. For example, the location policy is used to indicate which AEPs of which AZs or sites have access permission. The identity policy is used to indicate the identity characteristics that the access object should have when having access permission. For example, the identity policy is used to indicate which AEPs of which organizations or departments have access permission. The environment policy is used to indicate the environment characteristics that the access object should have when having access permission. For example, the environment policy is used to indicate that the virus version used by the AEP should be above XXX, and the OS patch should be above XXX, to have access permission. Optionally, the third-party Context can be described using a JSON schema, or can be described using other scripts. For example, as shown in FIG. 12, in the high-order service and cloud-native microservice, the LandingZone Policy of the Service object of the EAS management plane can be configured, which can be a PARC script or other types of scripts, and the present application does not make specific limitations on it.

[0195] Corresponding to step 1404, the implementation process of step 1403 further includes:

[0196] Step 1403a, the cloud system sends an access request to the second access object based on the identification of the second application endpoint using the infrastructure in the case that the multi-dimensional information indicates that the first access object has permission to access the second access object.

[0197] After the cloud management platform obtains the multi-dimensional information of the application endpoint of the first access object, it can determine whether the first access object has the permission to access the second access object based on the multi-dimensional information, and in the case that the multi-dimensional information indicates that the first access object has the permission to access the second access object, it sends an access request to the second access object based on the identification of the second application endpoint by using the infrastructure.

[0198] In the traditional protocol stack, since the message is forwarded to the target end service, only the source IP of the visitor can be known, and other related source end visitor information (such as location information, identity information, environment information) cannot be transmitted, so the access policy cannot be made according to the source end visitor information. In the EAS provided in the present application, since the EAS management plane can participate in the key processes of network addressing, link establishment and service access, it can obtain rich context information such as account, location and environment of the communication parties, and can realize data plane zero-trust security based on these context information. Moreover, the zero-trust scheme is suitable for ScaleUp and ScaleOut network planes, and is friendly to high-performance communication.

[0199] In the traditional network, in the process of communication link establishment, whether it is in-band link establishment (such as RoCE CM link establishment) or out-of-band link establishment (such as RoCE Socket link establishment), or whether the transport layer and the transaction layer are separated, in the process of link establishment, the two ends of the communication directly interact, and the in-band or out-of-band protocol performs link establishment operation. According to the above process, it can be seen that in the EAS provided in the present application, the EAS link establishment operation is completely in the form of out-of-band link establishment, and is in the form of out-of-band link establishment participated by the EAS management plane. The parameters required for link establishment negotiation and the resources required for link establishment are all managed by the EAS management plane. Therefore, the present application separates and decouples the in-band management logic of the network protocol stack and the basic logic of the network data transmission. For example, as shown in FIG. 19, the present application hands over the network in-band control logic mentioned above, such as Overlay routing addressing, access control, service control and zero-trust security, to the out-of-band management plane. For example, in the EAS, Overlay routing addressing is not involved, EAS access domain and strategy management is done in access control, EAS service management is done in service control, EAS and LandingZone management is done in zero-trust security, and transaction layer session, transport layer connection and network layer transmission are done in data transmission. Through such a number control separation and control in the out-of-band architecture, the goal of simplifying the network data plane implementation is achieved, so that the management plane can realize rich and flexible business, security and service management capabilities, and maintain the simplicity, high performance and stability of the data plane transmission protocol.

[0200] It should be noted that the process of passing the access request through the AEP identifier can not only be applied to the process of passing the traditional access request, but also can be applied to the passing of the access request in other scenarios. Next, taking the scenario of accessing high-level services and the scenario of accessing cloud-native service mesh as examples, the passing of the access request in these two scenarios will be described.

[0201] FIG. 20 is a schematic diagram of a scenario in which a customer VPC accesses high-level services based on a traditional cloud IP network according to the present application. The high-level services are, for example, object storage services (OBS), DCS, Function Graph services, etc. In this scenario, the use of high-level services requires the use of an IP network environment for construction, and the IP address usage and the customer's IP address are likely to overlap. Therefore, for the purposes of interoperability and network security isolation, many gateways need to be added, such as VPC, Gateway VPCEP, VPCEP, Network VPCEP, and Acess EP, to facilitate customer access to high-level services. However, these gateways will bring many problems. For example, the traffic accessing the services needs to pass through the gateway, which is a centralized bottleneck, causing performance bottlenecks at the gateway and reliability problems, etc. Moreover, for high-performance network protocol stacks such as RoCE, one-hop direct reach is usually required. Therefore, with the gateway, it is very unfriendly to provide high-level service access capabilities through high-performance network protocols such as RoCE.

[0202] FIG. 21 is a schematic diagram of accessing high-level services based on EAS according to the present application. As shown in FIG. 21, after tenant 1 requests the DCS management plane to create a DCS instance, the DCS management plane allocates resources for it, and the DCS management plane registers the service AEP and registers the service resources to the EAS management plane. Then, the EAS management plane determines the resource health degree through the health check of the service management module. After the VM of tenant 1 initiates a request to build a chain to the DCS service AEP, the EAS management plane performs service resource scheduling after completing the access control, and issues a table item to the data plane. It can be seen from this that in the process of accessing high-level services based on EAS, the management subsystem needs to provide the connection module of the access object requesting to access the high-level services with the indication information required for the data subsystem to transmit the access request based on the access request, and then the data subsystem sends the access request to the providing end of the high-level service according to the indication of the indication information. The implementation process is described in the relevant description in the foregoing content, which will not be described here. As can be seen from FIG. 21, the following key points are included in the process of accessing high-level services based on EAS:

[0203] 1) The high-level service needs to register the service instance to the EAS management plane to generate the AEP corresponding to the service instance, so as to pass the access request based on the identifier of the AEP.

[0204] 2) The resource pool of the high-order service needs health check and load balancing scheduling, which can be completed by the EAS management plane.

[0205] 3) The data flow of the client accessing the high-order service can directly reach the provider of the high-order service in one hop without passing through any gateway.

[0206] In addition, in the scenario of accessing the high-order service, single tenancy, multi-tenancy, resource sharding, and non-sharding need to be considered. In these scenarios, the implementation process of accessing based on the EAS is described above, and details are not described here.

[0207] FIG. 22 is a schematic diagram of a scenario provided by the present application for a customer VPC accessing a cloud-native service mesh based on a traditional cloud IP network. In a cloud-native scenario, the scheduling, health check, and elastic expansion and contraction of a service mesh are usually implemented using SideCar technology. However, in the process from input traffic to output traffic, this solution requires two proxies to serve as service terminals, resulting in low forwarding efficiency, for example, an increase of 2.65 milliseconds (ms) of latency per proxy, and limited single-flow bandwidth. In addition, each SiderCar also occupies a large amount of resources (such as 0.35 vCPU and 40 MB of memory). Although some improvement technologies are used in the industry, these improvement technologies are still Proxy technologies, which have bandwidth bottlenecks and reliability risks, and result in increased latency. However, as shown in FIG. 23, after Kubernetes allocates resources, the cloud-native service mesh control plane executes the service mesh process, registers APP1 in VM1, APP2 in BMS, and APP2 in VM2, and obtains the corresponding AEP name. Then, the EAS management plane performs health check on APP1 in VM1, APP2 in BMS, and APP2 in VM2 through the service management module. After APP1 in VM1 sends an access request for APP2, the EAS management plane performs service resource scheduling and issues a table item to the data plane. Then, APP1 in VM1 performs direct access to APP2 in BMS based on the table item. As can be seen, by accessing the cloud-native service mesh based on the EAS of the present application, the management subsystem can provide the connection module of the access object requesting to access the cloud-native service mesh with the indication information required for the data subsystem to transmit the access request, and then the data subsystem transmits the access request to the providing end of the cloud-native service mesh according to the indication of the indication information. In this way, one-hop direct access of the data plane can be achieved without any gateway Proxy, and completely Proxyless cloud-native service mesh access is achieved. The implementation process of accessing the cloud-native service mesh based on the EAS is described in detail in the foregoing content, and will not be described here. As can be seen from FIG. 23, in the EAS protocol stack scenario, the microservices accessing the cloud-native service mesh based on the EAS have the following key points:

[0208] 1) The microservice needs to register the service instance to the EAS management plane to generate the AEP corresponding to the service instance, so as to pass the access request based on the identification of the AEP. The microservice registration can be registered through an API or through an xDS protocol.

[0209] 2) The resource pool of the microservice needs to be health checked and load balanced, and these operations can be completed by the EAS management plane.

[0210] 3) Microservice access to microservice data flow, one-hop direct to microservice provider, no need to pass through any gateway Proxy.

[0211] According to the above, the EAS network service model has the following characteristics:

[0212] 1. The EAS network service model is a global interconnection network model: within the EAS network region, the global network is interconnected, that is, the AEP is globally visible; Region data face one-hop direct, cross-Region transit gateway.

[0213] 2. The EAS network service model has a unified communication object, including network interface AEP and service AEP. Network interface AEP, such as VM, BMS, XPU, etc. AEP, has AEP interface and name in ScaleUp or ScaleOut network. Service AEP, such as cloud service instance and customer microservice instance, etc. AEP, all have AEP name. And the EAS network service model has a unified context. The AEP stores the following context information corresponding to it in the management and control plane:

[0214] 1) AEP account, application tag, etc. information;

[0215] 2) Environment information of the AEP belonging system (such as OS of the AEP belonging VM or BMS, installed software, virus library version, device health degree);

[0216] 3) AEP belonging location information (AZ / Region / XPOD / IDC, etc.).

[0217] 3. The EAS network service model can unify access permissions and ensure zero-trust security, which can achieve the following points:

[0218] 1) Access control based on Domain and Domain Policy;

[0219] 2) Combined with LandingZone, implement data boundary security through service resource Policy;

[0220] 3) Through unified context, realize multi-dimensional zero-trust access strategy protection.

[0221] 4. The EAS network service model can interwork with traditional networks. This enables VM or BMS instances to create AEP communication devices and traditional virtual network cards simultaneously, and realize dual-stack interworking with traditional networks through dual interfaces.

[0222] The EAS provided by the application makes the following major changes in the protocol management and control plane and the data plane:

[0223] a) Through high-level protocol stack and network service model, hide multiple protocols and underlying network details, realize the simple unified network model, eliminate the intermediate gateway, and the direct communication of multiple hardware devices.

[0224] b) Through the separation of management and control technology, the management and control face realizes rich and flexible business, security, service management capabilities, while maintaining the simplicity, high performance and stable characteristics of the data face transmission protocol.

[0225] The EAS provided in the application realizes the following core values of cloud network through the above changes:

[0226] 1. Simple cloud network service model: a simple cloud network model, that is, an AEP and access domain network model based on Global interconnection, which greatly simplifies the complex network service models of the original VPC network model, multiple gateway models, and hyperplane network model, making it easier to use cloud networks, and Serverless friendly simple network.

[0227] 2. Simple cloud network protocol stack; a simple transaction-based network protocol stack interface that directly maps the customer transaction layer to the underlying physical network, eliminating the original complex Overlay layer network and Underlay layer network coupling solution, data face without OU mapping, shielding the differences of multiple underlying physical networks, and shielding multiple protocol stacks.

[0228] 3. Gateway-free simple data plane: due to the changes in the EAS technical architecture, no gateway is needed within the EAS cloud network domain, and in all scenarios such as service access and cross-account access, data forwarding one-hop direct access can be achieved, fully utilizing the performance of the underlying physical network (including bus network), making the data face straight-through service access delay based on AEP nearly ten times lower and single-flow bandwidth twenty times higher.

[0229] 4. Large-scale / high-performance management and control plane: based on the EAS separation of management and control architecture and the EAS simple network model, EAS no longer needs to distribute massive forwarding table items to all forwarding devices in a distributed manner, but only needs to be saved in the EAS management and control plane. Therefore, under the EAS cloud network architecture, the AEP issuance speed can be increased by more than twenty times, the single-tenant management and control plane control scale can be increased by more than ten times, and the Global interconnection and management and control function flexible expansion (Context field provides JSON format life of application-level QoS, latency, application version, etc.) can be achieved.

[0230] 5. Multi-dimensional zero-trust security: Since the EAS protocol stack participates in the key processes of network addressing, link building, and service access, it is aware of the rich context of both parties, such as account, location, and environment, and can achieve data plane zero-trust security. The zero-trust solution is suitable for ScaleUp and ScaleOut network planes, i.e., friendly to high-performance communication.

[0231] 6. Unified ScaleOut / Up model: Since the EAS protocol stack uses a high-level network protocol stack and a basic network model, it is suitable for both ScaleUp and ScaleOut network environments. A unified network model can achieve AEP interconnection in the Global range of ScaleOut networks and various device-to-device, device-to-host, and host-to-host communication models in the ScaleUp domain. There is no need to create different network models due to physical network differences and networking differences. This is friendly to AI and other heavy-load network applications.

[0232] 7. Application-oriented network services: EAS has two important modules, service management module and application traffic scheduling model. Through the service management module, high-level service access capabilities, cloud-native application and service publishing capabilities, and cloud-native ecosystem docking can be provided to achieve high-performance one-hop direct access of services. Through the application traffic scheduling module, complex ScaleUp heterogeneous network topology can be used to assist applications in achieving intelligent scheduling according to business demands and improving the utilization efficiency of network resource pools in multi-tenancy and multi-service scenarios.

[0233] 8. Full-stack controllable scheduling and operation and maintenance capabilities: In the original public cloud network, most network protocol stacks run in customer space, which can have a significant impact on shared physical network resources in terms of security and operation and maintenance. The EAS protocol stack enhances the interface dimension of the protocol stack, so that most of the management, control, and monitoring permissions of the protocol stack are controlled in the cloud network system, which can achieve the following benefits: a) Eliminate protocol unfairness and internal attacks through unified protocol stack and transmission control capabilities; b) EAS participates in the key processes of network addressing, link building, and service access, and can perceive full-stack business demands. Based on the context declaration parameters of the EAS protocol stack, it can perceive the full-stack business needs of customers, and through full-stack network monitoring, it can build controllable, visible, schedulable, and operation and maintenance capabilities according to different customer needs, build full-stack automated operation and maintenance scheduling capabilities, and achieve fault self-healing.

[0234] It should be noted that the order of steps of the network access method based on the public cloud technology provided in the embodiments of the present application can be adjusted appropriately, and the steps can be increased or decreased as appropriate. Any person skilled in the art can easily think of changes within the scope of the technology disclosed in the present application, which should be covered within the protection scope of the present application, and thus will not be described again.

[0235] The virtual device of the embodiments of the present application is illustrated below.

[0236] The network access method based on the public cloud technology of the embodiments of the present application is introduced above. Corresponding to the above method, the cloud system is also provided in the embodiments of the present application. The cloud system includes a cloud management platform and an infrastructure. The infrastructure includes: an access object obtained based on the infrastructure and a data subsystem for data transmission between different access objects. The cloud management platform is used to manage the infrastructure, and the access object is used to provide cloud services to tenants.

[0237] The cloud management platform is further configured to configure application endpoints for a plurality of access objects in the cloud system, and configure identifiers for the application endpoints, and establish a connection channel between different access objects; the cloud management platform is further configured to obtain an access request sent by a first access object to a second access object, the source address of the access request being the identifier of the first application endpoint of the first access object, and the destination address of the access request being the identifier of the second application endpoint of the second access object, the first access object and the second access object being two of the plurality of access objects; and the cloud management platform is further configured to use the infrastructure to send the access request to the second access object based on the identifier of the second application endpoint.

[0238] In a possible implementation, the cloud system includes a management subsystem, and the access object is connected to the connection channel through a connection module. The management subsystem is further configured to provide, based on the access request, the connection module of the first access object with indication information required for the first access object to use the data subsystem to transmit the access request; the data subsystem is configured to receive the indication information provided by the connection module of the first access object and the target data indicated by the access request for transmission; and the data subsystem is further configured to send the access request to the second access object according to the indication of the indication information.

[0239] In a possible implementation, the data subsystem is specifically configured to copy the access request to the second access object through device pass-through according to the indication of the indication information.

[0240] In a possible implementation, the management subsystem is specifically configured to provide the connection module of the first access object with the indication information when the access management policy indicates that the first access object has the permission to access the second access object.

[0241] In a possible implementation, the indication information is used to indicate one or more of the following: parameters required for the link establishment negotiation and resources required for the link establishment. The parameters required for the link establishment negotiation include one or more of the following: a maximum transmission unit (MTU) used by the transmission access request, a congestion control policy, or a transmission layer identifier allocation parameter. The resources required for the link establishment include one or more of the following: a network layer forwarding table item, a transmission layer forwarding table item, or a transaction layer forwarding table item used by the transmission access request.

[0242] In a possible implementation, in a case where the second access object is a cloud service and the cloud service is provided through a plurality of service backends, the indication information is further used to indicate: a target service backend in the plurality of service backends that provides the cloud service for the first access object based on the access request.

[0243] In a possible implementation, the cloud management platform is further configured to obtain multi-dimensional information of the application endpoint of the first access object, the multi-dimensional information including network information, and the multi-dimensional information further including one or more of the following: location information, environment information, and identity information, the location information of the application endpoint being used to indicate a physical location where a hardware providing a hardware capability for the application endpoint is located, the environment information of the application endpoint being used to indicate an environment used by the application endpoint to prevent virus infection or repair existing virus damage, and the identity information of the application endpoint being used to indicate an account to which the application endpoint belongs. Correspondingly, the cloud management platform is specifically configured to, in a case where the multi-dimensional information indicates that the first access object has a permission to access the second access object, send, by using the infrastructure and based on the identifier of the second application endpoint, the access request to the second access object.

[0244] In a possible implementation, the first access object and the second access object satisfy: the first access object and the second access object are respectively deployed in different cloud resource deployment areas managed by the cloud management platform, and the connection channel is implemented through a network inside the cloud system; or the first access object and the second access object are respectively deployed in different availability zones of a same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through the network inside the cloud system; or the first access object and the second access object are deployed in a same availability zone of a same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through the network inside the cloud system; or a first hardware providing a hardware capability for the first access object and a second hardware providing a hardware capability for the second access object are connected through a high-speed interconnection bus, and the connection channel is implemented through a high-speed interconnection network provided by the high-speed interconnection bus; and the connection channel is implemented through the network inside the cloud system, a high-speed interconnection network, and an intermediary network between the network inside the cloud system and the high-speed interconnection network.

[0245] In a possible implementation, the first access object and / or the second access object are further configured with a virtual network card obtained through virtualization of an Internet protocol (IP) network card, and the virtual network card is used to connect a network outside the cloud system and / or a network resource owned by a tenant of the cloud system.

[0246] In a possible implementation, the types of the plurality of access objects include one or more of the following: a hardware device in the infrastructure, an instance, or a cloud service provided by the instance.

[0247] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of each component described above can refer to the corresponding content in the foregoing method embodiments, and will not be described here.

[0248] The basic hardware structure related to the embodiments of the present application is described below.

[0249] The present application also provides a computing device 2400. As shown in FIG. 24, the computing device 2400 includes a bus 2402, a processor 2404, a memory 2406, and a communication interface 2408. The processor 2404, the memory 2406, and the communication interface 2408 communicate through the bus 2402. The computing device 2400 can be a server or a terminal device. It should be understood that the present application does not limit the number of processors and memories in the computing device 2400.

[0250] The bus 2402 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, only one line is represented in FIG. 24, but it does not mean that there is only one bus or only one type of bus. The bus 2402 can include a path for transmitting information between various components (for example, the memory 2406, the processor 2404, the communication interface 2408) of the computing device 2400.

[0251] The processor 2404 can include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP), etc.

[0252] The memory 2406 can include volatile memory, such as random access memory (RAM), and non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid-state drive (SSD).

[0253] The memory 2406 stores an operating system and executable program code (i.e., executable code) that the processor 2404 executes to implement the network access method based on public cloud technology, respectively. That is, the memory 2406 has instructions for implementing the network access method based on public cloud technology.

[0254] The communication interface 2408 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to enable communication between the computing device 2400 and other devices or communication networks.

[0255] The embodiments of the present disclosure also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a notebook computer, or a smartphone.

[0256] As shown in FIG. 25, the computing device cluster includes at least one computing device 2400. The memory 2406 in one or more computing devices 2400 in the computing device cluster can store the same instructions for implementing the network access method based on public cloud technology.

[0257] In some possible implementations, the memory 2406 of one or more computing devices 2400 in the computing device cluster can also respectively store partial instructions for implementing the network access method based on public cloud technology. In other words, the combination of one or more computing devices 2400 can collectively execute the instructions for implementing the network access method based on public cloud technology.

[0258] It should be noted that the memory 2406 in different computing devices 2400 in the computing device cluster can store different instructions for respectively implementing part of the functions of the network access method based on public cloud technology. That is, the instructions stored in the memory 2406 in different computing devices 2400 can implement part or all of the functions of the network access method based on public cloud technology.

[0259] In some possible implementation, one or more of the computing devices in the cluster of computing devices can be connected through a network. The network can be a wide area network or a local area network, etc. FIG. 26 shows one possible implementation. As shown in FIG. 26, two computing devices 2400A and 2400B are connected through a network. Specifically, the computing devices are connected to the network through the communication interfaces in the computing devices.

[0260] It should be understood that the functions of the computing device 2400A shown in FIG. 26 can also be performed by multiple computing devices 2400. Similarly, the functions of the computing device 2400B can also be performed by multiple computing devices 2400.

[0261] The embodiments of the present application also provide another cluster of computing devices. The connection relationship between the computing devices in the cluster of computing devices can be similar to the connection relationship between the computing devices in the cluster of computing devices shown in FIG. 25 and FIG. 26. The difference is that the same instructions for performing the network access method based on the public cloud technology can be stored in the memory 2406 of one or more of the computing devices 2400 in the cluster of computing devices.

[0262] In some possible implementation, the memory 2406 of one or more of the computing devices 2400 in the cluster of computing devices can also respectively store partial instructions for performing the network access method based on the public cloud technology. In other words, the combination of one or more of the computing devices 2400 can collectively execute the instructions for performing the network access method based on the public cloud technology.

[0263] The embodiments of the present application also provide a computer program product containing instructions. The computer program product can be a software or program product containing instructions, which can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device is caused to perform the network access method based on the public cloud technology.

[0264] The embodiments of the present application also provide a computer readable storage medium. The computer readable storage medium can be any available medium that can be used to store data that can be accessed by a computing device or a data storage device such as a data center containing one or more available media. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk), etc. The computer readable storage medium contains instructions that instruct the computing device to perform the network access method based on the public cloud technology, or instruct the computing device to perform the network access method based on the public cloud technology.

[0265] Those skilled in the art can understand that all or part of the steps of the above-mentioned embodiments can be completed by hardware, or by program instructing relevant hardware to complete, and the program can be stored in a computer readable storage medium. The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk.

[0266] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals involved in the present application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions. For example, the raw data and executable codes involved in the present application are obtained under sufficient authorization.

[0267] In the embodiments of the present application, the terms "first", "second" and "third" are only used for descriptive purposes, and cannot be understood as indicating or implying relative importance. The term "at least one" means one or more, and the term "multiple" means two or more, unless otherwise explicitly limited.

[0268] In the present application, the term "and / or" is only used to describe the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can mean that A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in this paper generally represents that the front and rear associated objects are a "or" relationship.

[0269] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the protection scope of the technical solutions of the embodiments of the present application.

Claims

1. A network access method based on public cloud technology, characterized in that, The method is applied to a cloud system, the cloud system comprising a cloud management platform and an infrastructure, the infrastructure comprising: access objects based on the infrastructure and a data subsystem for data transmission between different access objects, the cloud management platform being configured to manage the infrastructure, the access objects being configured to provide cloud services to tenants, the method comprising: The cloud management platform configures application endpoints for a plurality of access objects in the cloud system and configures identifiers for the application endpoints, and establishes a connection channel between different access objects; The cloud management platform obtains an access request sent by a first access object to a second access object, a source address of the access request being an identifier of a first application endpoint of the first access object, a destination address of the access request being an identifier of a second application endpoint of the second access object, the first access object and the second access object being two of the plurality of access objects; The cloud management platform sends the access request to the second access object based on the identifier of the second application endpoint by using the data subsystem.

2. The method of claim 1, wherein, The cloud management platform comprises a management subsystem, the access objects are connected to the connection channel through a connection module, and the cloud management platform sends the access request to the second access object based on the identifier of the second application endpoint by using the data subsystem, comprising: The management subsystem provides, to the connection module of the first access object, indication information required for transmitting the access request by using the data subsystem based on the access request; The data subsystem receives the indication information and target data indicated by the access request provided by the connection module of the first access object; The data subsystem sends the access request to the second access object according to the indication of the indication information.

3. The method of claim 2, wherein, The data subsystem sends the access request to the second access object according to the indication of the indication information, comprising: The data subsystem copies the access request to the second access object by device pass-through according to the indication of the indication information.

4. The method of claim 2 or 3, wherein, The management subsystem provides, to the connection module of the first access object, indication information required for transmitting the access request by using the data subsystem based on the access request, comprising: The management subsystem provides the indication information to the connection module of the first access object when an access management policy indicates that the first access object has the permission to access the second access object.

5. The method of any one of claims 2 to 4, wherein, The indication information is used to indicate one or more of the following: parameters required for link establishment negotiation and resources required for link establishment; The parameters required for link establishment negotiation comprise one or more of the following: a maximum transmission unit (MTU) used for transmitting the access request, a congestion control policy, or a transmission layer identifier allocation parameter; The resources required for link establishment comprise one or more of the following: a network layer forwarding table item, a transmission layer forwarding table item, or a transaction layer forwarding table item used for transmitting the access request.

6. The method of claim 5, wherein, In a case where the second access object is a cloud service and the cloud service is provided through a plurality of service backends, the indication information further indicates a target service backend in the plurality of service backends that provides the cloud service for the first access object based on the access request.

7. The method of any one of claims 1 to 6, wherein, The method further includes: The cloud management platform obtains multi-dimensional information of an application endpoint of the first access object, the multi-dimensional information including network information, and the multi-dimensional information further including one or more of location information, environment information, and identity information, the location information of the application endpoint indicating a physical location where hardware providing hardware capability for the application endpoint is located, the environment information of the application endpoint indicating an environment used by the application endpoint to prevent virus infection or repair existing virus damage, and the identity information of the application endpoint indicating an account to which the application endpoint belongs; The cloud management platform uses the data subsystem to send the access request to the second access object based on the identifier of the second application endpoint, including: The cloud management platform uses the infrastructure to send the access request to the second access object based on the identifier of the second application endpoint in a case where the multi-dimensional information indicates that the first access object has access rights to the second access object.

8. The method of any one of claims 1 to 7, wherein, The first access object and the second access object satisfy: The first access object and the second access object are respectively deployed in different cloud resource deployment areas managed by the cloud management platform, and the connection channel is implemented through a network inside the cloud system; Or, the first access object and the second access object are respectively deployed in different availability zones of a same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through a network inside the cloud system; Or, the first access object and the second access object are deployed in a same availability zone of a same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through a network inside the cloud system; Or, a first hardware providing hardware capability for the first access object and a second hardware providing hardware capability for the second access object are connected through a high-speed interconnection bus, and the connection channel is implemented through a high-speed interconnection network provided by the high-speed interconnection bus; The connection channel is implemented through the network inside the cloud system, the high-speed interconnection network, and an intermediary network between the network inside the cloud system and the high-speed interconnection network.

9. The method of any of claims 1 to 8, wherein: The first access object and / or the second access object are further configured with a virtual network card obtained through virtualization of an Internet Protocol (IP) network card, and the virtual network card is used to connect a network outside the cloud system and / or a network resource owned by a tenant of the cloud system.

10. The method of any one of claims 1 to 9, wherein, The types of the plurality of access objects include one or more of a hardware device in the infrastructure, the instance, or a cloud service provided by the instance.

11. A cloud system, characterized by The cloud system comprises a cloud management platform and an infrastructure, the infrastructure comprises access objects based on the infrastructure and a data subsystem for data transmission between different access objects, the cloud management platform is configured to manage the infrastructure, and the access objects are configured to provide cloud services for tenants, wherein The cloud management platform is further configured to configure application endpoints for a plurality of access objects in the cloud system and configure identities for the application endpoints, and a connection channel is established between different access objects. The cloud management platform is further configured to obtain an access request sent by a first access object to a second access object, a source address of the access request is an identity of a first application endpoint of the first access object, a destination address of the access request is an identity of a second application endpoint of the second access object, and the first access object and the second access object are two of the plurality of access objects. The cloud management platform is further configured to send the access request to the second access object based on the identity of the second application endpoint by using the infrastructure.

12. The cloud system of claim 11, wherein, The cloud system comprises a management subsystem, and the access objects are connected to the connection channel through a connection module; The management subsystem is further configured to provide, based on the access request, an indication information required for the connection module of the first access object to transmit the access request by using the data subsystem to the connection module of the first access object; The data subsystem is configured to receive the indication information and target data indicated by the access request provided by the connection module of the first access object; The data subsystem is further configured to send the access request to the second access object according to the indication information.

13. The cloud system of claim 12, wherein, The data subsystem is specifically configured to copy the access request to the second access object by device pass-through according to the indication information.

14. The cloud system of claim 12 or 13, wherein, The management subsystem is specifically configured to provide the indication information to the connection module of the first access object when an access management policy indicates that the first access object has the permission to access the second access object.

15. The cloud system of any of claims 12 to 14, wherein, The indication information is configured to indicate one or more of the following: parameters required for link establishment negotiation and resources required for link establishment. The parameters required for link establishment negotiation comprise one or more of the following: a maximum transmission unit (MTU) used for transmitting the access request, a congestion control policy, or a transmission layer identity allocation parameter. The resources required for link establishment comprise one or more of the following: a network layer forwarding table item, a transmission layer forwarding table item, or a transaction layer forwarding table item used for transmitting the access request.

16. The cloud system of claim 15, wherein, When the second access object is a cloud service and the cloud service is provided by a plurality of service backends, the indication information is further configured to indicate a target service backend in the plurality of service backends that provides the cloud service for the first access object based on the access request.

17. The cloud system of any one of claims 11 to 16, wherein The cloud management platform is further configured to acquire multi-dimensional information of an application endpoint of the first access object, the multi-dimensional information comprising network information, and the multi-dimensional information further comprising one or more of the following: location information, environment information, and identity information, the location information of the application endpoint indicating a physical location of hardware providing hardware capability for the application endpoint, the environment information of the application endpoint indicating an environment for preventing virus infection or repairing existing virus damage of the application endpoint, and the identity information of the application endpoint indicating an account to which the application endpoint belongs. The cloud management platform is specifically configured to, in a case where the multi-dimensional information indicates that the first access object has access permission to the second access object, send, based on the identity of the second application endpoint, the access request to the second access object by using the infrastructure.

18. The cloud system of any of claims 11 to 17, wherein, The first access object and the second access object satisfy: The first access object and the second access object are respectively deployed in different cloud resource deployment areas managed by the cloud management platform, and the connection channel is implemented through a network inside the cloud system. Alternatively, the first access object and the second access object are respectively deployed in different availability zones of a same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through a network inside the cloud system. Alternatively, the first access object and the second access object are deployed in a same availability zone of a same cloud resource deployment area managed by the cloud management platform, and the connection channel is implemented through a network inside the cloud system. Alternatively, a first hardware providing hardware capability for the first access object and a second hardware providing hardware capability for the second access object are connected through a high-speed interconnection bus, and the connection channel is implemented through a high-speed interconnection network provided by the high-speed interconnection bus. The connection channel is implemented through the network inside the cloud system, the high-speed interconnection network, and an intermediary network between the network inside the cloud system and the high-speed interconnection network.

19. The cloud system of any one of claims 11 to 18, wherein: The first access object and / or the second access object are further configured with a virtual network card obtained by virtualizing an Internet Protocol (IP) network card, and the virtual network card is used to connect a network outside the cloud system and / or a network resource owned by a tenant of the cloud system.

20. The cloud system of any of claims 11 to 19, wherein, The types of the plurality of access objects comprise one or more of the following: a hardware device in the infrastructure, the instance, or a cloud service provided by the instance.

21. A cluster of computing devices, characterized in that, The computing device cluster comprises a plurality of computing devices, the plurality of computing devices comprising a plurality of processors and a plurality of memories, the plurality of memories storing program instructions, and the plurality of processors executing the program instructions so that the computing device cluster performs the method of any one of claims 1 to 10.

22. A computer-readable storage medium, characterized in that, The program instructions, when executed on a computing device, cause the computing device to perform the method of any one of claims 1 to 10.

23. A computer program product comprising instructions, characterized in that, The instructions, when executed on a computing device cluster, cause the computing device cluster to perform the method of any one of claims 1 to 10.

Citation Information

Patent Citations

  • Access control system and method and computing device cluster

    CN118214565A

  • Virtual instance configuration method based on public cloud and cloud management platform

    CN118473941A

  • Service access method and device, server and storage medium

    CN118573383A

  • Techniques for managing requests in a multi-tenant environment

    US20240214380A1