Message processing method, and electronic device and computer-readable storage medium

By using IPv6 as the overlay encapsulation format in the cloud network, and combining it with the underlay address and tenant information, the problems of insufficient flexibility in traffic engineering and difficulty in Netflow parsing in the integration of cloud network overlay and physical network underlay are solved. This achieves simplified design of tenant isolation and traffic engineering, and improves network performance and stability.

WO2026081835A1PCT designated stage Publication Date: 2026-04-23CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
Filing Date
2025-09-25
Publication Date
2026-04-23

AI Technical Summary

Technical Problem

In existing technologies, the integration of cloud network overlay and physical network underlay has problems such as poor flexibility in traffic engineering, uneven traffic hashing, difficulty in Netflow parsing, and excessive traffic carried by a single route, which affects network performance and stability.

Method used

Using IPv6 as the overlay encapsulation format, cloud tenant data packets are encapsulated as payloads within IPv6 packets. This encapsulation combines the Receiver CGW's Underlay address, Underlay TE service identifier, and Overlay tenant information to achieve tenant isolation and tenant packet transmission on the cloud gateway, and supports traffic engineering in the underlying network.

Benefits of technology

It enables tenant isolation and tenant packet transmission between cloud gateways, simplifies physical network traffic engineering design, improves network performance and stability, and solves the problems of insufficient flexibility in traffic engineering and difficulty in Netflow parsing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025124186_23042026_PF_FP_ABST
    Figure CN2025124186_23042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the field of computers and the technical field of cloud computing. Disclosed are a message processing method, and an electronic device and a computer-readable storage medium. The method comprises: acquiring a cloud tenant data message to be forwarded; encapsulating the cloud tenant data message and network convergence information, so as to obtain a target network protocol message, wherein the network convergence information is determined by means of a basic network address, a basic network traffic engineering service identifier and overlay network tenant information of a target cloud network gateway corresponding to the cloud tenant data message, the basic network address is used for determining a sending object of the cloud tenant data message, the basic network traffic engineering service identifier is used for determining a segment routing policy to be used by the cloud tenant data message during forwarding, and the overlay network tenant information is used for determining a sending source of the cloud tenant data message; and forwarding the target network protocol message to the target cloud network gateway. The present application solves the technical problem in the related art of limitations in the convergence of a cloud network Overlay and a physical network Underlay.
Need to check novelty before this filing date? Find Prior Art

Description

Message processing methods, electronic devices and computer-readable storage media Technical Field

[0001] This disclosure relates to the fields of computer technology and cloud computing technology, and more specifically, to a message processing method, an electronic device, and a computer-readable storage medium. Background Technology

[0002] With the widespread adoption of cloud computing, enterprises have increasingly higher demands for networks, requiring more flexible and efficient network solutions to meet business needs. Traditional Internet Protocol version 4 (IPv4) networks can no longer meet the growing traffic demands. Since Internet Protocol version 6 (IPv6) networks offer a larger address space and better security, the direction of basic network evolution is to simplify the network and implement a segmented routing IPv6 (SRv6) service network based on a single IPv6 protocol stack.

[0003] Currently, in cloud networks, traffic between overlays is Virtual Extensible LAN (VXLAN) traffic encapsulated with IPv4 as the outer layer, carried on the physical network serving as the underlying network. Forwarding decisions by devices in the physical network are based solely on the outer IPv4 address, the outer Differentiated Services Code Point (DSCP), the protocol filed, and the source / destination User Datagram Protocol (UDP) ports. However, this framework suffers from problems such as poor flexibility in traffic engineering, uneven traffic hashing, difficulties in Netflow parsing, and excessive traffic carried by a single route. In other words, there are currently some issues and limitations in the integration of cloud overlays and physical underlays, requiring further improvement and optimization.

[0004] There is currently no effective solution to the above problems. Summary of the Invention

[0005] This disclosure provides a message processing method, an electronic device, and a computer-readable storage medium to at least address the technical problem of limitations in the integration of cloud network overlay and physical network underlay in related technologies.

[0006] According to one aspect of the present disclosure, a message processing method is provided, comprising: acquiring a cloud tenant data packet to be forwarded; encapsulating the cloud tenant data packet with network fusion information to obtain a target network protocol packet, wherein the network fusion information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet, the basic network address is used to determine the sending object of the cloud tenant data packet, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data packet during forwarding, and the overlay network tenant information is used to determine the sending source of the cloud tenant data packet; and forwarding the target network protocol packet to the target cloud network gateway.

[0007] According to another aspect of the embodiments of this disclosure, a message processing method is provided, comprising: obtaining a target network protocol message to be forwarded, wherein the target network protocol message is obtained by encapsulating a cloud tenant data message and network fusion information, the network fusion information being determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data message, the basic network address being used to determine the sending object of the cloud tenant data message, the basic network traffic engineering identifier being used to determine the segmentation routing strategy to be adopted by the cloud tenant data message during forwarding, and the overlay network tenant information being used to determine the sending source of the cloud tenant data message; performing route matching on the target network protocol message to obtain a matching result; and determining the forwarding method of the target network protocol message based on the matching result.

[0008] According to another aspect of the embodiments of this disclosure, a message processing method is provided, comprising: obtaining a target network protocol message to be forwarded, wherein the target network protocol message is obtained by encapsulating a cloud tenant data message and network fusion information, the network fusion information being determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data message, the basic network address being used to determine the sending object of the cloud tenant data message, the basic network traffic engineering identifier being used to determine the segmentation routing strategy to be adopted by the cloud tenant data message during forwarding, and the overlay network tenant information being used to determine the sending source of the cloud tenant data message; performing address matching between the basic network address and the network address locally configured on the target cloud network gateway to obtain a matching result; and processing the target network protocol message in response to the matching result indicating that the basic network address matches the locally configured network address.

[0009] According to another aspect of the embodiments of this disclosure, a message processing system is provided, comprising: a source cloud network gateway, configured to acquire cloud tenant data packets to be forwarded, and encapsulate the cloud tenant data packets with network fusion information to obtain target network protocol packets, wherein the network fusion information is determined by the base network address, base network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packets; the base network address is used to determine the sending object of the cloud tenant data packets; the base network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data packets during forwarding; and the overlay network tenant information is used to determine the sending source of the cloud tenant data packets; a base network edge device, configured to acquire the target network protocol packets, perform route matching on the target network protocol packets to obtain a matching result, and determine the forwarding method of the target network protocol packets based on the matching result; and a target cloud network gateway, configured to acquire the target network protocol packets, perform address matching between the base network address and the network address configured locally on the target cloud network gateway to obtain a matching result, and process the target network protocol packets in response to the matching result indicating that the base network address matches the locally configured network address.

[0010] According to another aspect of the present disclosure, an electronic device is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes any of the above-described message processing methods during runtime.

[0011] According to another aspect of the embodiments of this disclosure, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is executed, it controls the device where the computer-readable storage medium is located to perform any of the above-described message processing methods.

[0012] According to another aspect of the present disclosure, a computer program product is also provided, including a computer program that, when executed by a processor, implements any of the above-described message processing methods.

[0013] In this embodiment, by acquiring the cloud tenant data packet to be forwarded and encapsulating the cloud tenant data packet with network convergence information, a target network protocol packet is obtained. That is, the cloud tenant data packet is encapsulated as a payload in an IPv6 packet, and the Underlay address of the Receiver CGW, the Underlay TE service identifier, and the Overlay tenant information are encapsulated in the IPv6 header, thereby obtaining the encapsulated IPv6 packet. Finally, the target network protocol packet is forwarded to the target cloud network gateway. This achieves the purpose of proposing a new Overlay+Underlay encapsulation format. By using IPv6 as the Overlay encapsulation, tenant isolation on the cloud gateway and the transmission of tenant packets between cloud gateways (i.e., Overlay network function) are realized. It also realizes the technical effect of traffic engineering in the basic network (i.e., an Underlay network that supports traffic engineering), and can greatly simplify the design and implementation of physical network traffic engineering. This solves the technical problem of limitations in the integration of cloud network Overlay and physical network Underlay in related technologies.

[0014] It is worth noting that the above general description and the following detailed description are merely for illustrative and explanatory purposes and do not constitute a limitation thereof. Attached Figure Description

[0015] The accompanying drawings, which are included to provide a further understanding of this disclosure and form part of this disclosure, illustrate exemplary embodiments of the present disclosure and are used to explain the disclosure, but do not constitute an undue limitation of the disclosure. In the drawings:

[0016] Figure 1 is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a message processing method according to an embodiment of the present disclosure;

[0017] Figure 2 is a flowchart of a message processing method according to an embodiment of the present disclosure;

[0018] Figure 3 is a topology diagram of the message forwarding process according to an embodiment of the present disclosure;

[0019] Figure 4 is a schematic diagram of a message encapsulation format according to an embodiment of the present disclosure;

[0020] Figure 5 is a flowchart of a message processing method according to an embodiment of the present disclosure;

[0021] Figure 6 is a flowchart of a message processing method according to an embodiment of the present disclosure;

[0022] Figure 7 is a schematic diagram of a message processing system according to an embodiment of the present disclosure;

[0023] Figure 8 is a schematic diagram of a message processing apparatus according to an embodiment of the present disclosure;

[0024] Figure 9 is a schematic diagram of another message processing apparatus according to an embodiment of the present disclosure;

[0025] Figure 10 is a schematic diagram of another message processing apparatus according to an embodiment of the present disclosure;

[0026] Figure 11 is a structural block diagram of an electronic device according to an embodiment of the present disclosure. Detailed Implementation

[0027] To enable those skilled in the art to better understand the present disclosure, the technical solutions of the present disclosure will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present disclosure, and not all embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present disclosure.

[0028] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0029] First, some nouns or terms that appear in the description of the embodiments of this disclosure shall be interpreted as follows:

[0030] Virtual Extensible LAN (VXLAN) is a virtualization network technology used to separate network traffic from the physical network and encapsulate it for transmission within a virtual network. VXLAN allows the creation of an overlay network on top of existing network infrastructure, enabling virtual machines in data center or cloud environments to communicate across different physical networks and geographical locations.

[0031] Overlay encapsulation: Overlay encapsulation is a technique that encapsulates data packets between different network layers for communication between multiple networks.

[0032] Service Router Version 6 (SRv6) is a segment routing technology based on IPv6 addressing and data plane forwarding.

[0033] IPv6 packets / IPv4 packets: IPv6 packets refer to data packets transmitted in an IPv6 network; IPv4 packets refer to data packets transmitted in an IPv4 network.

[0034] Service chaining is a technique that combines multiple services to accomplish a specific task.

[0035] Traffic engineering (TE) is a technique used to control the forwarding path of traffic in a network.

[0036] Color: A field used to identify and implement network traffic engineering intentions.

[0037] Segment Routing Policy (SR Policy): This is a source routing forwarding logic used to control forwarding paths in an SRv6 network.

[0038] Multiprotocol Label Switching Segment Routing (MPLS SR): A routing technique in Multiprotocol Label Switching (MPLS) used for routing and address resolution in MPLS networks.

[0039] Segment Routing Traffic Engineering (SRTE) refers to the traffic engineering mechanisms and frameworks implemented using segment routing technology.

[0040] Cloud Gateway (CGW): A gateway in a cloud network, responsible for encapsulating and decapsulating cross-regional traffic of cloud tenants.

[0041] Basic network: refers to the Internet Protocol (IP) network that connects cloud gateways and carries traffic between them.

[0042] NetFlow is a network traffic analysis technology that allows network administrators to monitor and collect IP traffic information passing through network devices such as routers, switches, and firewalls. NetFlow provides a method to track data transmission in a network, including the source and destination of packets, the protocol used, the amount of data transmitted, and the transmission time.

[0043] Payload: This refers to the actual data portion carried in a data packet, message, or message. This data is the information that the end user or application needs to transmit. The payload is the opposite of the header information of the data packet, which typically contains metadata used for data transmission and processing, such as source address, destination address, and protocol type.

[0044] The following drawbacks exist in the related technologies where VXLAN traffic encapsulated with IPv4 as the outer layer is used as the traffic carrier between overlays on the underlay.

[0045] Defect 1: Traffic engineering lacks flexibility and cannot effectively manage and optimize network traffic transmission paths. Specifically, traffic engineering is a forwarding mechanism in a network that replaces the Equal Cost Multi-Path (ECMP) algorithm in IP networks, which constructs forwarding paths that satisfy certain "optimization objectives" and "constraints." In backbone networks, forwarding specific traffic along paths that satisfy specific Service Level Agreements (SLAs) (e.g., the path with the shortest cumulative latency) requires a traffic engineering mechanism. Currently, some backbone networks have traffic engineering capabilities based on the Segment Routing framework and can deploy SR policies that satisfy different SLAs. However, the mechanism for associating specific traffic with specific SR policies can only rely on Differentiated Services Code Points (DSCPs). Since DSCP is essentially an identifier for Differentiated Services (Diffserv) rather than an identifier for traffic engineering, the value of DSCP in existing networks is very limited and has already been allocated and occupied according to the Diffserv partition. This brings great difficulties to the implementation of traffic engineering, resulting in poor flexibility of traffic engineering.

[0046] Defect 2: Uneven traffic hashing leads to overload on some paths, affecting network performance and stability. Specifically, under IPv4 VXLAN encapsulation, backbone network devices can only hash using either "outer IP source / destination address + UDP source port + inner IP source / destination address" or "outer IP source / destination address + UDP source port". Some devices only support the latter mode, which results in uneven hashing.

[0047] Defect 3: Netflow resolution is difficult, making traffic monitoring and analysis challenging. Specifically, in existing networks, when performing Netflow on the overlay traffic of a group tenant, it is impossible to resolve the traffic of different business units (BUs) or application groups within the group. This is because the information of BUs / application groups is identified by the inner source / destination IP pairs of VXLAN, while the existing Netflow template generated on network devices (the template is the structure used to define the data format in NetFlow packets) can only count the outer source / destination IP address + port, thus leading to difficulties in Netflow resolution.

[0048] Defect 4: Excessive traffic carried by a single route can easily cause network congestion and bottlenecks. Specifically, currently, a CGW cluster uses a fixed / 32 IPv4 address as the outer encapsulation of VXLAN. The traffic carried by a single VXLAN tunnel can reach the terabits per second (Tbps) level. This huge traffic volume and the ultra-large granularity of routing put enormous pressure on the carrying, migration, scheduling, and troubleshooting of overlay traffic on the backbone network, resulting in excessively high traffic volume on a single route.

[0049] To address the aforementioned deficiencies, no effective solution has been proposed prior to this disclosure.

[0050] According to embodiments of this disclosure, a message processing method is provided. It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowcharts, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0051] The method embodiment provided in this disclosure can be executed in a mobile terminal, computer terminal, or similar computing device. Figure 1 is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a message processing method according to an embodiment of this disclosure. As shown in Figure 1, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) (processor 102 may include, but is not limited to, a microprocessor (MCU) or a field-programmable gate array (FPGA) or other processing device), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a Universal Serial Bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. It will be understood by those skilled in the art that the structure shown in Figure 1 is merely illustrative and does not limit the structure of the above-described electronic device. For example, computer terminal 10 may also include more or fewer components than shown in FIG1, or have a different configuration than shown in FIG1.

[0052] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuitry are generally referred to herein as "data processing circuitry". This data processing circuitry may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in embodiments of this disclosure, the data processing circuitry serves as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).

[0053] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the message processing method in this embodiment of the present disclosure. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby implementing the aforementioned message processing method. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0054] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0055] The display can be, for example, a touchscreen liquid crystal display (LCD), which allows the user to interact with the user interface of the computer terminal 10 (or mobile device).

[0056] In the above operating environment, this disclosure provides a message processing method as shown in Figure 2. Figure 2 is a flowchart of a message processing method according to an embodiment of this disclosure. As shown in Figure 2, the method may include the following steps:

[0057] Step S21: Obtain the cloud tenant data packet to be forwarded;

[0058] Step S22: Encapsulate the cloud tenant data packet and network convergence information to obtain the target network protocol packet. The network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet. The basic network address is used to determine the sending object of the cloud tenant data packet, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data packet during forwarding, and the overlay network tenant information is used to determine the sending source of the cloud tenant data packet.

[0059] Step S23: Forward the target network protocol message to the target cloud network gateway.

[0060] In network communication, the Sender Cloud Gateway (Sender CGW) and Receiver Cloud Gateway (Receiver CGW) are two cloud gateway devices or services responsible for sending and receiving data, respectively. Typically, the Sender CGW retrieves data from the local network (e.g., an enterprise intranet) or application and sends it to the target network or service. During this process, the Sender CGW performs source-side network address translation, protocol encapsulation, and security encryption. The Receiver CGW receives data from the Sender CGW or other sources and delivers it to the target network or application. During this process, the Receiver CGW performs destination-side decapsulation, data verification, and routing.

[0061] In this embodiment of the disclosure, the executing entity can be the Sender CGW, and the cloud tenant data packet to be forwarded can be understood as a data packet that is about to be forwarded from the Sender CGW to the Receiver CGW in a virtual network managed by a cloud service provider in a cloud computing environment. Exemplarily, the cloud tenant data packet to be forwarded can be a standard IPv4 packet or a standard IPv6 packet, depending on the actual situation, and is not limited here.

[0062] In network communication, the Sender CGW acquires cloud tenant data packets to be forwarded, and then encapsulates these acquired cloud tenant data packets with network convergence information to obtain the target network protocol packet. In this embodiment, the target network protocol packet is illustrated using an IPv6 packet as an example. It is understood that as the network continues to evolve, the target network protocol packet may use a newer Internet Protocol packet, which is not limited here.

[0063] It is important to note that the cloud tenant data packet to be forwarded will be encapsulated as a payload within the data packet during network encapsulation. That is, the cloud tenant data packet to be forwarded will be encapsulated as a payload within an IPv6 protocol data packet, i.e., it will be encapsulated as a payload within an IPv6 packet.

[0064] Network convergence information can be understood as the additional information that needs to be encapsulated in data packets during network encapsulation. This information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant's data packet. The target cloud network gateway is the Receiver CGW.

[0065] The base network address of the target cloud network gateway is used to determine the recipient of cloud tenant data packets. It can be understood that the base network address of the target cloud network gateway is the Underlay address of the Receiver CGW, which is also the IPv6 address of the Receiver CGW.

[0066] For example, when the Sender CGW sends a packet, it can fill this basic network address field with the IPv6 address of the Receiver CGW in the service forwarding logic, while the target cloud network gateway only needs the IPv6 prefix of the IPv6 packets it is listening to. For example, if the IPv6 prefix mask is 64, the Receiver CGW will listen for the IPv6 prefix and use the longest match rule on the IPv6 packets it listens to. As long as the first 64 bits of the IPv6 packet match a locally configured / 64 IPv6 address, the Receiver CGW will process the packet even if it contains more bits.

[0067] The Basic Network Traffic Engineering Service Identifier (BMI) is used to determine the segmentation routing strategy to be adopted for cloud tenant data packets during forwarding. It can be understood as the Underlay TE service identifier. In this embodiment, cloud tenant data packets are encapsulated based on the SRv6 framework during forwarding.

[0068] For example, when the Sender CGW sends a packet, it can fill in this basic network traffic engineering service identifier field according to the traffic engineering service level agreement (TE SLA) that the service needs to consume in the service forwarding logic, while the Receiver CGW can ignore this field when processing the packet.

[0069] Overlay tenant information is used to determine the source of cloud tenant data packets. It can be understood as the same as overlay tenant information, i.e., tenant identifier.

[0070] For example, when the Sender CGW sends a packet, it can fill this field with the Virtual Network Identifier (VNI) information from the service forwarding logic, and the Receiver CGW uses this field as the VNI information when processing the packet.

[0071] It is understood that, in this embodiment of the disclosure, when performing network encapsulation, the Sender CGW encapsulates the cloud tenant data packet together with the target cloud network gateway's basic network address, basic network traffic engineering service identifier, and overlay network tenant information to obtain the target network protocol packet. That is, when performing network encapsulation, the Sender CGW encapsulates the cloud tenant data packet as payload within an IPv6 packet, and encapsulates the Receiver CGW's Underlay address, Underlay TE service identifier, and Overlay tenant information in the IPv6 header to obtain the encapsulated IPv6 packet.

[0072] Finally, the Sender CGW will forward the encapsulated target network protocol message to the target cloud network gateway, which means forwarding the encapsulated IPv6 message to the Receiver CGW.

[0073] It is important to note that the network encapsulation described above is a standard IP-to-IP encapsulation operation. This network encapsulation behavior can occur on a server or on a cloud network gateway. The standard Linux kernel program on the server supports this encapsulation operation, and the cloud gateway device also supports this encapsulation operation.

[0074] As can be seen, this disclosure proposes a new Overlay+Underlay encapsulation format for encapsulating tenant packets exchanged between cloud network gateways. This new encapsulation format is based on the standard SRv6 framework and uses IPv6 as the Overlay encapsulation. It can encapsulate Underlay reachability information (i.e., the Underlay address of the Receiver CGW), Underlay traffic engineering information (i.e., the Underlay TE service identifier), and Overlay tenant information in a single IPv6 header. This not only enables tenant isolation on the cloud gateway and the transmission of tenant packets between cloud gateways (i.e., Overlay network functionality), but also enables traffic engineering in the underlying network (i.e., an Underlay network supporting traffic engineering).

[0075] Furthermore, the embodiments of this disclosure employ IPv6 as the overlay encapsulation, which fully leverages the advantages of the IPv6 address space, providing independent overlay paths for more tenants across more cloud gateways, while also aligning with the historical trend of network evolution towards IPv6. Moreover, for cross-regional and cross-Availability Zone (AZ) traffic, the encapsulation format proposed in these embodiments can more easily provide SLA guarantees using SR Policies deployed on the physical network. Simultaneously, the encapsulation format proposed in these embodiments can incorporate service orchestration and control logic, thereby reducing the complexity of service adjustments. Finally, the encapsulation format proposed in these embodiments supports network service chaining for VXLAN packets with IPv4 as the outer IP header and VXLAN packets with IPv6 as the outer IP.

[0076] The message processing method provided in this disclosure can be applied, but is not limited to, to application scenarios involving the encapsulation of tenant messages exchanged between cloud network gateways in fields such as e-commerce services, education services, legal services, medical services, conference services, social networking services, financial product services, logistics services, and navigation services. For example, application scenarios involving the encapsulation of e-commerce tenant messages exchanged between cloud network gateways, application scenarios involving the encapsulation of education-related tenant messages exchanged between cloud network gateways, application scenarios involving the encapsulation of medical-related tenant messages exchanged between cloud network gateways, etc., and is not limited here.

[0077] By employing the embodiments of this disclosure, cloud tenant data packets to be forwarded are obtained, and the cloud tenant data packets are encapsulated with network convergence information to obtain target network protocol packets. That is, the cloud tenant data packets are encapsulated as payloads in IPv6 packets, and the Underlay address of the Receiver CGW, the Underlay TE service identifier, and the Overlay tenant information are encapsulated in the IPv6 header, thereby obtaining the encapsulated IPv6 packets. Finally, the target network protocol packets are forwarded to the target cloud network gateway. This achieves the purpose of proposing a new Overlay+Underlay encapsulation format. By using IPv6 as the Overlay encapsulation, tenant isolation on the cloud gateway and the transmission of tenant packets between cloud gateways (i.e., Overlay network function) are realized. It also realizes the technical effect of traffic engineering in the basic network (i.e., Underlay network that supports traffic engineering), and can greatly simplify the design and implementation of physical network traffic engineering. This solves the technical problem in related technologies where training video generation models based on network data results in poor video quality generated by the trained video generation models, which does not meet user expectations.

[0078] In an optional embodiment, in step S22, the cloud tenant data packet and network convergence information are encapsulated to obtain the target network protocol packet, including the following method steps:

[0079] Step S221: Determine the header encapsulation format to be used in the target network protocol message, wherein the header encapsulation format shall at least include a destination address field and a payload field;

[0080] Step S222: Encapsulate the cloud tenant data packet into the payload field and encode the network convergence information into the destination address field to obtain the target network protocol packet.

[0081] In this embodiment of the disclosure, when encapsulating cloud tenant data packets and network fusion information to obtain target network protocol packets, the header encapsulation format to be used by the target network protocol packets is first determined. The header encapsulation format includes at least a destination address field and a payload field.

[0082] The packet header encapsulation format can be understood as the encapsulation format of the target network protocol message, that is, the encapsulation format of IPv6 messages. In the embodiments of this disclosure, the packet header encapsulation format includes at least a destination address field and a payload field.

[0083] The Destination Address field indicates the destination address of the IPv6 packet, i.e., the destination IPv6 address. For example, when a target network protocol packet is sent to the network, the network device determines which host or network device to deliver the packet to based on the destination address indicated by this field, thus achieving the purpose of data communication.

[0084] The payload field is the portion of the target network protocol message used to carry data, transmitting and storing the actual data to be transmitted. For example, the payload field contains the actual information content, such as transmitted text, images, and video data. The content of the payload field can vary depending on the specific communication protocol and application requirements, and is not limited here.

[0085] In this embodiment of the disclosure, after determining the header encapsulation format to be used for the target network protocol packet, the cloud tenant data packet is encapsulated into the payload field, and the network convergence information is encoded into the destination address field to obtain the target network protocol packet. This can be understood as encapsulating the tenant data packet into the payload field of the IPv6 packet as the actual data to be transmitted, while simultaneously encoding the Receiver CGW's Underlay address, Underlay TE service identifier, and Overlay tenant information from the network convergence information into the Destination Address field, thereby obtaining the IPv6 packet.

[0086] As can be seen, compared to the traditional message encapsulation format where the Destination Address field is only used to indicate the destination address, in this embodiment of the disclosure, the Underlay address of the Receiver CGW, the Underlay TE service identifier, and the Overlay tenant information in the network convergence information are encoded into the Destination Address field. This enables the target network protocol message encapsulated by the encapsulation format of this embodiment of the disclosure to simultaneously realize the Overlay network function and support the Underlay network for traffic engineering.

[0087] In an optional embodiment, in step S222, the network fusion information is encoded into the destination address field, including the following method steps:

[0088] Step S2221: Divide the destination address field into a destination prefix field, a color value field, and a virtual network identifier field;

[0089] Step S2222: Encode the basic network address into the destination prefix field, encode the basic network traffic engineering identifier into the color value field, and encode the overlay network tenant information into the virtual network identifier field.

[0090] In this embodiment of the disclosure, when encoding network fusion information into the destination address field, the destination address field can be divided into a destination prefix field, a color value field, and a virtual network identifier field. That is, the Destination Address field in the traditional encapsulation format is further divided into a destination prefix field, a color value field, and a virtual network identifier field (VNI Value).

[0091] The Destination Prefix field is used to specify a particular network segment in the IPv6 address. In this embodiment, the Destination Prefix field is used to indicate the IPv6 address of the Receiver CGW. For example, the Destination Prefix field may include 64 bits, i.e., bits 0-63 of the Destination Address field, but this is not limited here.

[0092] The Color Value field is used to indicate the TE service identifier of the Underlay network. For example, the Color Value field can include 32 bits, that is, bits 64-95 of the Destination Address field. The format of the Color Value field can adopt the ext-community color format of the Border Gateway Protocol (BGP), which is not limited here.

[0093] The Virtual Network Identifier (VNI) field is used to indicate the tenant's identity. For example, the VNI field may include 24 bits, which are bits 96-120 of the Destination Address field, but this is not limited here.

[0094] Understandably, a reserved field can also be defined in the Destination Address field. The reserved field is used to reserve extended functions or reserved bits that may be used in the future, and there are no restrictions on this.

[0095] In this embodiment of the disclosure, after dividing the destination prefix field, color value field, and virtual network identifier field, the basic network address is encoded into the destination prefix field, the basic network traffic engineering identifier is encoded into the color value field, and the overlay tenant information is encoded into the virtual network identifier field. This can be understood as encoding the Receiver CGW's Underlay address into the Destination Prefix field, the Underlay TE service identifier into the Color Value field, and the Overlay tenant information into the VNI Value field.

[0096] As can be seen, this embodiment uses IPv6 as the overlay encapsulation method. A CGW cluster uses a / 64 IPv6 prefix as its address. Based on this, a 32-bit color value can be added to different traffic streams to split the traffic across multiple routes. This reduces the granularity of the overlay traffic carried by a single route, thereby reducing routing pressure. Furthermore, the IPv6 overlay encapsulation method proposed in this embodiment can be used as a standard measure combined with SLA requirements, or as a temporary measure in engineering projects. This effectively solves defect 4 in related technologies, namely, the problem of excessive traffic carried by a single route, which easily causes network congestion and bottlenecks.

[0097] In an optional embodiment, in step S2222, encoding the base network address into the destination prefix field includes the following method steps:

[0098] Step S22221: In response to the underlying network address being the target version of Internet Protocol (IP) address of the target cloud network gateway, the target version of IP address is encoded into the destination prefix field.

[0099] In this embodiment of the disclosure, when encoding the base network address into the destination prefix field, if the cloud network environment uses the target version of the Internet Protocol (IPv6), then the base network address is the target version of the IPv6 address of the target cloud network gateway, i.e., the IPv6 address of the Receiver CGW. In this case, encoding the target version of the IPv6 address of the target cloud network gateway into the destination prefix field means encoding the IPv6 address of the Receiver CGW into the Destination Prefix field. That is, when the Sender CGW sends a packet, it can fill the Destination Prefix field with the IPv6 address of the Receiver CGW in the service forwarding logic.

[0100] In an optional embodiment, in step S2222, the basic network traffic engineering identifier is encoded into the color value field, including the following method steps:

[0101] Step S22222: Based on the traffic engineering service level protocol to be consumed during the forwarding of cloud tenant data packets, the basic network traffic engineering identifier is encoded into the color value field. There is a mapping relationship between the transmission service guaranteed by the traffic engineering service level protocol and the color value corresponding to the color value field.

[0102] In this embodiment of the disclosure, when encoding the basic network traffic engineering identifier into the color value field, the basic network traffic engineering identifier can be encoded into the color value field based on the traffic engineering service level protocol to be consumed during the forwarding process of the cloud tenant data packet. There is a mapping relationship between the transport service guaranteed by the traffic engineering service level protocol and the color value corresponding to the color value field. This mapping relationship can be understood as a mapping relationship and logic of "stream - transport service - color value".

[0103] In other words, when the Sender CGW sends a packet, it fills the Color value field with the TE SLA (Traffic Engineering Service Level Agreement) that the service needs to consume in the service forwarding logic, and encodes the Underlay TE service identifier into the Color value field.

[0104] As can be seen, this embodiment uses IPv6 as the overlay encapsulation and introduces a Color Value as a TE identifier. This allows the Sender CGW to encode a 32-bit Color Value in the Destination Address of the sent message as a TE selector, consuming various SLA-guaranteed transport services deployed on the backbone network. Simultaneously, the definitions, availability status, and bound Color Values ​​of various transport services are provided to the CGW's service orchestration control system by the backbone network's supporting service center via an Application Programming Interface (API). Furthermore, the mapping relationship between "stream-transport service-Color value" is controlled by the CGW's service orchestration and control system, thereby setting the CGW's forwarding table entries. The CGW can flexibly establish the "stream-transport service-Color value" mapping relationship based on various tuples it possesses, such as VNI, DSCP, inner IP addresses, and ports, thereby achieving flexible and fine-grained SLA service control. Furthermore, the IPv6 header decouples the "Traffic Class" field, which identifies Diffserv (i.e., the priority of packet loss during congestion), from the "Color Value" field, which identifies TE (i.e., the SLA type of the path, such as latency, congestion level, etc.). This avoids the confusion that can easily arise from using the DSCP field in IPv4 packets to simultaneously identify Diffserv and TE. Finally, it allows for a smooth fallback to a normal path in the event of an SR Policy path failure, ensuring service continuity and reliability. This effectively addresses the first deficiency in related technologies: poor flexibility in traffic engineering and the inability to effectively manage and optimize network traffic transmission paths.

[0105] In an optional embodiment, in step S2222, the overlay network tenant information is encoded into the virtual network identifier field, including the following method steps:

[0106] Step S22223: Based on the cross-regional virtual network identifier information of the cloud tenant data packet during the forwarding process, the overlay network tenant information is encoded into the virtual network identifier field.

[0107] In this embodiment of the disclosure, when encoding the overlay tenant information into the virtual network identifier field, the overlay tenant information can be encoded into the virtual network identifier field based on the cross-region virtual network identifier information during the forwarding process of the cloud tenant data packet. That is, when the Sender CGW sends a packet, it fills the VNI Value field according to the cross-region VNI (i.e., cross-region virtual network identifier) ​​information in the service forwarding logic, and encodes the overlay tenant information into the VNI Value field.

[0108] In an optional embodiment, step S23, forwarding the target network protocol message to the target cloud network gateway, includes the following method steps:

[0109] Step S231: The target network protocol message is forwarded to the target cloud network gateway sequentially via the basic network edge device corresponding to the source cloud network gateway, the basic network core device, and the basic network edge device corresponding to the target cloud network gateway.

[0110] In this embodiment of the disclosure, when forwarding a target network protocol message to a target cloud network gateway, the target network protocol message can be forwarded to the target cloud network gateway sequentially via the basic network edge device corresponding to the source cloud network gateway, the basic network core device, and the basic network edge device corresponding to the target cloud network gateway.

[0111] In this system, the source cloud network gateway is the Sender CGW, and the target cloud network gateway is the Receiver CGW. The underlying network edge device corresponding to the source cloud network gateway can be understood as the physical network (underlay) edge device corresponding to the Sender CGW. Similarly, the underlying network edge device corresponding to the target cloud network gateway can be understood as the physical network edge device corresponding to the Receiver CGW.

[0112] Physical network edge devices are used to connect physical networks and virtual networks, enabling the transmission and forwarding of data packets. For example, physical network edge devices typically include network devices such as switches, routers, and firewalls, responsible for processing data packets from virtual machines or containers in the virtual network and routing them to other devices in the physical network or forwarding them over the Internet.

[0113] Basic network core equipment can be understood as physical network core equipment. Physical network core equipment is typically high-performance, high-reliability network equipment used to carry large amounts of data traffic and is responsible for efficient data forwarding and routing within the network. For example, physical network core equipment typically includes advanced switches, routers, fiber optic switches, etc., used to connect different network areas, data centers, and communicate with other networks.

[0114] For example, Figure 3 is a topology diagram of the packet forwarding process according to an embodiment of this disclosure. As shown in Figure 3, the source cloud network gateway is the Sender CGW, and the target cloud network gateway is the Receiver CGW. It can be seen that when the Sender CGW forwards the target network protocol packet (IPv6 packet) to the Receiver CGW, the Sender CGW first determines the next-hop destination address based on the destination prefix and routing table information in the received IPv6 packet, and then sends the data packet to the corresponding basic network edge device. After receiving the data packet, the basic network edge device forwards the data packet to the basic network core device according to its own routing table and forwarding policy. After receiving the data packet, the basic network core device forwards the data packet to the next target device, i.e., the basic network edge device corresponding to the Receiver CGW, according to the network topology and routing rules. After receiving the data packet, the basic network edge device corresponding to the Receiver CGW forwards the data packet to the Receiver CGW according to the destination prefix and routing table information.

[0115] In other words, the IPv6 packets need to be forwarded sequentially through the basic network edge device corresponding to the Sender CGW, the basic network core device, and the basic network edge device corresponding to the Receiver CGW in order to forward the IPv6 packets to the Receiver CGW, thereby ensuring that the target network protocol packets are transmitted securely and efficiently to the target cloud network gateway.

[0116] In an optional embodiment, the packet header encapsulation format further includes a flow label field, and the message processing method further includes the following steps:

[0117] Step S223: Calculate the target factor based on the target network address and the target port. The target network address includes the base network address of the source cloud network gateway or the base network address of the target cloud network gateway. The target port is the source port of the source cloud network gateway. The target factor is the hash factor to be used in the forwarding process of the cloud tenant data packet.

[0118] Step S224: Encode the target factor into the stream label field.

[0119] In this embodiment of the disclosure, the packet header encapsulation format also includes a flow label field, which is used to identify the data stream to which the data packet belongs. For example, the flow label field may include 20 bits, but this is not a limitation.

[0120] When encapsulating packets, the Sender CGW disclosed herein also calculates a target factor based on the target network address and target port. The target network address includes either the base network address of the source cloud network gateway or the base network address of the target cloud network gateway, i.e., it includes either the source address or the destination address. For example, taking a cloud tenant data packet as an IPv6 packet, the base network address of the source cloud network gateway is the IPv6 address of the Sender CGW, and the base network address of the target cloud network gateway is the IPv6 address of the Receiver CGW. Correspondingly, taking a cloud tenant data packet as an IPv4 packet, the base network address of the source cloud network gateway is the IPv4 address of the Sender CGW, and the base network address of the target cloud network gateway is the IPv4 address of the Receiver CGW.

[0121] The destination port is the source port of the originating cloud network gateway, and the destination factor is the hash factor to be used during the forwarding of the cloud tenant's data packet. For example, the Sender CGW calculates the hash factor based on the source / destination address of the inner IPv4 / IPv6 header to be encapsulated and the source port of the originating cloud network gateway.

[0122] In this embodiment of the disclosure, after the target factor is calculated, the target factor is encoded into the Flow Label field, that is, the obtained hash factor is encoded into the Flow Label field.

[0123] As can be seen, when this embodiment uses IPv6 as the overlay encapsulation, the Flow Label in the IPv6 encapsulation is a hash factor for IPv6 packet forwarding defined in the Request for Comments (RFC). Compared to the uneven traffic hashing defects in related technologies, the 20-bit Flow Label in the IPv6 header of this disclosure is more favorable for the packet parsing depth of forwarding devices, thus making the traffic hashing more uniform. This effectively solves defect 2 in related technologies, namely, uneven traffic hashing leading to excessive load on some paths, affecting network performance and stability.

[0124] In an optional embodiment, the packet header encapsulation format further includes a source address field and a flow label field, and the packet processing method further includes the following steps:

[0125] Step S225: Encapsulate the tenant address information corresponding to the cloud tenant data packet into the source address field or the flow label field. The tenant address information includes the cloud tenant source address and the cloud tenant destination address. The tenant address information is used to perform traffic analysis on the target network protocol packet.

[0126] In this embodiment of the disclosure, the packet header encapsulation format also includes a source address field and a flow label field. The source address field, also known as the source address field in the IPv6 data packet, is used to identify the IPv6 address of the host or device that sent the data packet, which is also used to identify the IPv6 address of the sender CGW.

[0127] Tenant address information can be understood as the tenant's IP address. It includes the cloud tenant's source address and destination address, which are the cloud tenant's source IP address and destination IP address. Tenant address information is used for traffic analysis of target network protocol packets, specifically for Netflow analysis of IPv6 packets.

[0128] When encapsulating packets, the Sender CGW disclosed herein also encapsulates the tenant address information corresponding to the cloud tenant data packet into the source address field or flow label field. This can be understood as encoding the cloud tenant's source IP address and destination IP address into the source address field or flow label field. For example, the cloud tenant's IP address (i.e., the inner IP) can be encoded into the IPv6 encapsulation that Netflow can collect.

[0129] In an optional embodiment, in step S225, the tenant address information corresponding to the cloud tenant data packet is encapsulated into the source address field or the flow tag field, including one of the following method steps:

[0130] Step S2251: Copy the cloud tenant source address and cloud tenant destination address to the source address field;

[0131] Step S2252: Obtain the first hash value corresponding to the source address of the cloud tenant and the second hash value corresponding to the destination address of the cloud tenant, and encode the first hash value and the second hash value together into the source address field;

[0132] Step S2253: Obtain the third hash value corresponding to both the cloud tenant's source address and the cloud tenant's destination address, and encode the third hash value into the stream label field.

[0133] In this embodiment of the disclosure, when encapsulating the tenant address information corresponding to the cloud tenant data packet into the source address field or the flow tag field, there are three encapsulation methods.

[0134] Encapsulation Method 1: Copy the cloud tenant's source and destination addresses to the source address field. For example, when performing outer encapsulation, Sender CGW can directly copy the tenant's source / destination IP addresses (32 bits each) to the last 64 bits of the Source Address field in the IPv6 packet header. It should be noted that choosing this encapsulation method requires consideration of potential security concerns.

[0135] Encapsulation Method Two involves obtaining the first hash value corresponding to the cloud tenant's source address and the second hash value corresponding to the cloud tenant's destination address, and then encoding both hash values ​​into the source address field. For example, when performing outer encapsulation, Sender CGW hashes the tenant's source / destination IP addresses (each 32 bits) into separate 32-bit hash values ​​(i.e., the first hash value and the second hash value), and then encapsulates both hash values ​​together into the last 64 bits of the Source Address field in the IPv6 packet header. It's important to note that the hash values ​​must be unique. Choosing this second encapsulation method provides better security but places higher demands on the supporting system.

[0136] Encapsulation Method 3: Obtain the third hash value corresponding to both the cloud tenant's source address and destination address, and encode this third hash value into the Flow Label field. For example, when performing outer encapsulation, the Sender CGW hashes the tenant's source / destination IP addresses (each 32 bits) into a 20-bit hash value (i.e., the third hash value), and encodes this hash value into the 20 bits of the Flow Label field in the IPv6 packet header. It is important to note that the hash value must be unique. Choosing this third encapsulation method also provides good security, but it places higher demands on the supporting system.

[0137] As can be seen, by encoding the cloud tenant's IP address into the IPv6 encapsulation that Netflow can collect, this embodiment enables Netflow to be applied to backbone network devices or metropolitan area network devices for both cross-regional overlay traffic (i.e., virtual network traffic between different regions through overlay network technology, where the overlay network is a virtual network built on top of the existing physical network (Underlay)) and cross-AZ traffic within the same region (i.e., data flow between different availability zones within the same cloud service provider's region). This allows for the resolution of the data flow (flow) with the specific source / destination IP address of the group tenant on the backbone network devices or metropolitan area network devices, thereby solving the problem of defect 3 in related technologies, namely, the difficulty in Netflow resolution and the difficulty in traffic monitoring and analysis.

[0138] Figure 4 is a schematic diagram of the message encapsulation format according to an embodiment of the present disclosure. As shown in Figure 4, the structure of an IPv6 message includes an IPv6 header and a payload. The IPv6 header is a fixed part of the IPv6 message, with a fixed length of 40 bytes. The IPv6 header includes the following fields.

[0139] The Version field specifies the protocol version number, which is used to distinguish between IPv4 and IPv6 packets.

[0140] The Traffic Engineering field, also known as the Traffic Class field, is used to specify the priority or quality of service of data packets.

[0141] The Flow Label field is used to identify the data stream to which a data packet belongs.

[0142] The Payload Length field is used to specify the length of the payload.

[0143] The Next Header field indicates the type of the next extended header or payload following the current IPv6 header.

[0144] The maximum hop count field, or Hop Limit field, specifies the maximum number of hops a data packet can traverse in the network.

[0145] The Source Address field indicates the source IPv6 address, which is the IPv6 address of the sender CGW. It's important to understand that the Source Address is not a routable field in the network; it can be directly filled with the / 64 IPv6 address from the CGW, or it can encode other information—there are no restrictions here.

[0146] The Destination Prefix field indicates the destination IPv6 address, i.e., the IPv6 address of the Receiver CGW. For example, the Destination Prefix field may include 64 bits, i.e., bits 0-63 of the Destination Address field, but this is not a limitation.

[0147] The Color Value field is used to indicate the Underlay network TE service identifier. For example, the Color Value field may include 32 bits, that is, bits 64-bit 95 of the Destination Address field, without limitation.

[0148] The Virtual Network Identifier field, or VNI Value field, is used to indicate the tenant identifier. For example, the Virtual Network Identifier field may include 24 bits, that is, bits 96-120 of the Destination Address field, without limitation.

[0149] The Reserved field is used to reserve extended features or reserved bits that may be used in the future; there are no restrictions on this.

[0150] The payload is the part following the IPv6 header, i.e., the data portion of the IPv6 packet. The payload contains the actual data to be transmitted, i.e., the cloud tenant data packets to be forwarded. The Next Header field in the IPv6 header indicates the data type in the payload so that the receiving end can correctly parse and process the data. The encapsulation format proposed in this disclosure supports all protocol packets supported by the Next Header field of the IPv6 packet header as payload.

[0151] As can be seen, this disclosure presents a new IPv6-based encapsulation format that encapsulates a cloud tenant's IPv4 or IPv6 packet as a payload in a 40-byte IPv6 header, and encodes the Receiver CGW's Underlay address, Underlay TE service identifier, and Overlay tenant information into the Destination Address field in the IPv6 header.

[0152] It should be noted that, for service chaining scenarios with two or more VXLAN headers appearing in the overlay encapsulation in the existing network, the encapsulation format proposed in this disclosure only encodes the information of the outermost VXLAN, and treats the second and subsequent VXLAN as payload.

[0153] Table 1 compares the possible centralized evolution modes of the encapsulation format proposed in this disclosure and existing encapsulation formats. As shown in Table 1, Mode 1 is VXLAN with IPv4 as the outer IP, i.e., the current network mode; Mode 2 is VXLAN with IPv6 as the outer IP, i.e., the IPv6 version of the current network mode; Mode 3 is the end-to-end converged version of IPv4 VXLAN, which establishes an IP-in-IPv6 tunnel by encapsulating a service anchor IPv6 header outside IPv4, terminating at the local backbone edge device, removing the service anchor IPv6 header, and guiding the exposed IPv4 packet to a specific SR policy for forwarding, passing through the backbone network with SLA guarantees, and thus reaching the remote gateway (XGW); Mode 4 is the end-to-end converged version of IPv6 VXLAN, which establishes an IPv6-in-IPv6 tunnel by encapsulating a service anchor IPv6 header outside IPv6. The IPv6 tunnel terminates at the local backbone edge device. After removing the service anchor IPv6 packet header, the exposed IPv6 packet is guided to a specific SR policy for forwarding. It then passes through the backbone network with an SLA guarantee and reaches the remote XGW. Mode 5, namely the IPv6-based overlay encapsulation format (denoted as Magic IPv6) proposed in this disclosure, uses a single IPv6 packet header that encapsulates all overlay function fields for overlay encapsulation.

[0154] Table 1

[0155] As can be seen, the Magic IPv6 encapsulation format proposed in this disclosure is 4 bytes longer than the existing IPv4 VXLAN encapsulation format, but saves 16-56 bytes compared to other encapsulation formats on other evolution paths. That is, the Magic IPv6 encapsulation format proposed in this disclosure is equivalent to 4% of the average standard Internet packet length (about 400 bytes), thus effectively saving packet header overhead and consequently saving 4% in long-distance bandwidth leasing costs.

[0156] It is easy to understand that the beneficial effects of the message processing method provided in this disclosure include the following points.

[0157] Beneficial Effects (1): This embodiment uses IPv6 as the overlay encapsulation and introduces a Color Value as a TE identifier. This allows the Sender CGW to encode a 32-bit Color Value in the Destination Address of the sent message as a TE service selector, consuming various SLA-guaranteed transport services deployed on the backbone network. Simultaneously, the definitions, availability status, and bound Color Values ​​of various transport services are provided to the CGW's service orchestration control system by the backbone network's supporting service center through an Application Programming Interface (API). Furthermore, the mapping relationship between "stream-transport service-Color value" is controlled by the CGW's service orchestration and control system, thereby setting the CGW's forwarding table entries. The CGW can flexibly establish the "stream-transport service-Color value" mapping relationship based on various tuples it possesses, such as VNI, DSCP, inner IP addresses, and ports, thereby achieving flexible and fine-grained SLA service control. Furthermore, the IPv6 header decouples the "Traffic Class" field, which identifies Diffserv (i.e., the priority of packet loss during congestion), from the "Color Value" field, which identifies TE (i.e., the SLA type of the path, such as latency, congestion level, etc.). This avoids the confusion that can easily arise from using the DSCP field in IPv4 packets to simultaneously identify Diffserv and TE. Finally, it allows for a smooth fallback to a normal path in the event of an SR Policy path failure, ensuring service continuity and reliability. This effectively addresses the first deficiency in related technologies: poor flexibility in traffic engineering and the inability to effectively manage and optimize network traffic transmission paths.

[0158] Beneficial Effect (2): When using IPv6 as the overlay in the embodiments of this disclosure, the Flow Label in the IPv6 encapsulation is a hash factor for IPv6 packet forwarding defined in the Request for Comments (RFC). Compared with the uneven traffic hashing in related technologies, the 20-bit Flow Label in the IPv6 header of this disclosure is more friendly to the packet parsing depth of the forwarding device, thus making the traffic hashing more uniform. This can effectively solve the defect 2 in related technologies, namely, uneven traffic hashing, which leads to excessive load on some paths and affects network performance and stability.

[0159] Beneficial effect (3): In this embodiment of the present disclosure, by encoding the IP address of the cloud tenant into the IPv6 encapsulation that Netflow can collect, it is possible to perform Netflow on the backbone network equipment or metropolitan area network equipment to resolve the data flow of the group tenant's specific source / destination IP address by the Netflow. This solves the defect 3 in the related technology, namely the difficulty of Netflow resolution and the difficulty of traffic monitoring and analysis.

[0160] Beneficial Effect (4): This embodiment of the present disclosure uses IPv6 as the overlay encapsulation method. A CGW cluster uses a / 64 IPv6 prefix as its address. Based on this, a 32-bit color value can be added to different traffic to split the traffic onto multiple routes, which can reduce the granularity of the overlay traffic carried by a single route, thereby reducing routing pressure. Furthermore, the IPv6 overlay encapsulation method proposed in this embodiment of the present disclosure can be used as a routine measure combined with SLA requirements, or as a temporary measure in engineering. This can effectively solve the defect 4 in the related technology, namely, the problem that the traffic carried by a single route is too large, which can easily cause network congestion and bottlenecks.

[0161] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.

[0162] Furthermore, it should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this disclosure is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this disclosure. Secondly, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this disclosure.

[0163] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this disclosure.

[0164] According to embodiments of this disclosure, a message processing method is also provided as shown in FIG5. FIG5 is a flowchart of a message processing method according to an embodiment of this disclosure. As shown in FIG5, the method includes:

[0165] Step S51: Obtain the target network protocol message to be forwarded. The target network protocol message is obtained by encapsulating the cloud tenant data message and network convergence information. The network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data message. The basic network address is used to determine the sending object of the cloud tenant data message. The basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data message during forwarding. The overlay network tenant information is used to determine the sending source of the cloud tenant data message.

[0166] Step S52: Perform route matching on the target network protocol message to obtain the matching result;

[0167] Step S53: Determine the forwarding method of the target network protocol message based on the matching result.

[0168] In this embodiment of the disclosure, the execution entity can be an edge device, which acquires the target network protocol packet to be forwarded. The target network protocol packet to be forwarded is obtained by encapsulating the cloud tenant data packet and network convergence information. This can be understood as the Sender CGW encapsulating the cloud tenant data packet and network convergence information to obtain the target network protocol packet, i.e., the IPv6 packet.

[0169] Network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet. The target cloud network gateway is the Receiver CGW.

[0170] The base network address of the target cloud network gateway is used to determine the recipient of cloud tenant data packets. It can be understood that the base network address of the target cloud network gateway is the Underlay address of the Receiver CGW, which is also the IPv6 address of the Receiver CGW.

[0171] The Basic Network Traffic Engineering Service Identifier (BMI) is used to determine the segmentation routing strategy to be adopted for cloud tenant data packets during forwarding. It can be understood as the Underlay TE service identifier. In this embodiment, cloud tenant data packets are encapsulated based on the SRv6 framework during forwarding.

[0172] Overlay tenant information is used to determine the source of cloud tenant data packets. It can be understood as the same as overlay tenant information, i.e., tenant identifier.

[0173] After obtaining the target network protocol packet to be forwarded, the edge device performs route matching on the target network protocol packet. The matching result can be understood as the edge device performing a longest match on the IPv6 packet and then obtaining the matching result. For example, the edge device, such as the backbone headend device, can perform a longest match forwarding on the IPv6 routing table for IPv6 packets entering from the metropolitan area network switch; this is not a limitation here.

[0174] After obtaining the matching result, the edge device determines the forwarding method for the target network protocol packet, i.e., the forwarding method for the IPv6 packet, based on the matching result. It is understood that different matching results can correspond to different forwarding methods. For example, the forwarding methods include guiding the packet to the corresponding SR policy for processing, forwarding it according to the next hop in the basic route, and discarding the packet, etc., which are not limited here.

[0175] That is, in this embodiment of the present disclosure, the edge device will obtain the IPv6 packet to be forwarded sent by the Sender CGW, then perform the longest match on the obtained IPv6 packet to obtain the matching result, and finally determine the forwarding method of the IPv6 packet based on the matching result.

[0176] As can be seen, this disclosure proposes a new Overlay+Underlay encapsulation format for encapsulating tenant packets exchanged between cloud network gateways. This new encapsulation format is based on the standard SRv6 framework and uses IPv6 as the Overlay encapsulation. It can encapsulate Underlay reachability information (i.e., the Underlay address of the Receiver CGW), Underlay traffic engineering information (i.e., the Underlay TE service identifier), and Overlay tenant information in a single IPv6 header. This not only enables tenant isolation on the cloud gateway and the transmission of tenant packets between cloud gateways (i.e., Overlay network functionality), but also enables traffic engineering in the underlying network (i.e., an Underlay network supporting traffic engineering).

[0177] Furthermore, the embodiments of this disclosure employ IPv6 as the overlay encapsulation, which fully leverages the advantages of the IPv6 address space, providing independent overlay paths for more tenants across more cloud gateways, while also aligning with the historical trend of network evolution towards IPv6. Moreover, for cross-regional and cross-Availability Zone (AZ) traffic, the encapsulation format proposed in these embodiments can more easily provide SLA guarantees using SR Policies deployed on the physical network. Simultaneously, the encapsulation format proposed in these embodiments can incorporate service orchestration and control logic, thereby reducing the complexity of service adjustments. Finally, the encapsulation format proposed in these embodiments supports network service chaining for VXLAN packets with IPv4 as the outer IP header and VXLAN packets with IPv6 as the outer IP.

[0178] The message processing method provided in this disclosure can be applied, but is not limited to, to application scenarios involving the encapsulation of tenant messages exchanged between cloud network gateways in fields such as e-commerce services, education services, legal services, medical services, conference services, social networking services, financial product services, logistics services, and navigation services. For example, application scenarios involving the encapsulation of e-commerce tenant messages exchanged between cloud network gateways, application scenarios involving the encapsulation of education-related tenant messages exchanged between cloud network gateways, application scenarios involving the encapsulation of medical-related tenant messages exchanged between cloud network gateways, etc., and is not limited here.

[0179] In this embodiment of the disclosure, a target network protocol packet to be forwarded is obtained. This target network protocol packet is obtained by encapsulating a cloud tenant data packet with network convergence information. The network convergence information is determined by the basic network address of the target cloud network gateway corresponding to the cloud tenant data packet, the basic network traffic engineering service identifier, and the overlay network tenant information. The basic network address is used to determine the recipient of the cloud tenant data packet, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted during the forwarding process, and the overlay network tenant information is used to determine the source of the cloud tenant data packet. Then, route matching is performed on the obtained target network protocol packet to obtain the matching result. Finally, based on the matching... The results determined the forwarding method of the target network protocol packets, thus achieving the goal of proposing a new Overlay+Underlay encapsulation format. By using IPv6 as the Overlay encapsulation, tenant isolation on the cloud gateway and the transmission of tenant packets between cloud gateways (i.e., Overlay network function) are realized. It also achieves the technical effect of traffic engineering in the basic network (i.e., Underlay network that supports traffic engineering) and can greatly simplify the design and implementation of physical network traffic engineering. In addition, it solves the technical problem in related technologies where training video generation models based on network data results in poor video quality generated by the trained video generation models, which does not meet user expectations.

[0180] In an optional embodiment, step S52 involves performing route matching on the target network protocol message to obtain a matching result, including the following method steps:

[0181] Step S521: Based on the preset routing table, perform route matching between the basic network address encapsulated in the target network protocol message and the basic network traffic engineering identifier to obtain the matching result.

[0182] In this embodiment of the disclosure, when performing route matching on the target network protocol packet and obtaining the matching result, the underlying network address and underlying network traffic engineering identifier encapsulated in the target network protocol packet can be matched according to a preset routing table to obtain the matching result. That is, the Underlay address of the Receiver CGW encapsulated in the IPv6 packet and the Underlay TE service identifier are matched according to the IPv6 routing table to obtain the matching result.

[0183] In an optional embodiment, step S53, determining the forwarding method of the target network protocol message based on the matching result, includes the following method steps:

[0184] Step S531: In response to the matching result indicating that the basic network address and the basic network traffic engineering identifier both match the border gateway protocol route in the preset routing table, the forwarding method of the target network protocol packet is determined to be: the segmented routing strategy corresponding to the border gateway protocol route is used to forward the target network protocol packet to the target cloud network gateway.

[0185] In this embodiment of the disclosure, when determining the forwarding method of the target network protocol message based on the matching result, if the matching result shows that the basic network address and the basic network traffic engineering identifier both hit the border gateway protocol route in the preset routing table, then the forwarding method of the target network protocol message is determined as follows: the target network protocol message is forwarded to the target cloud network gateway using the segmented routing strategy corresponding to the border gateway protocol route.

[0186] This can be understood as follows: if, during the longest match of an IPv6 packet, the Receiver CGW's Underlay address and Underlay TE service identifier both match a BGP route in the IPv6 routing table, then the IPv6 packet is forwarded to the Receiver CGW using the SR Policy corresponding to the BGP route. Furthermore, if the first 96 (64+32) bits of an IPv6 packet match a BGP route, then the IPv6 packet is directed to the SR policy corresponding to the color ext-community value (which allows network administrators to classify and label routes for matching and processing in routing policies) carried by the matched BGP route.

[0187] In an optional embodiment, step S53, determining the forwarding method of the target network protocol message based on the matching result, includes the following method steps:

[0188] Step S532: In response to the matching result indicating that the basic network address matches the basic route in the preset routing table, the forwarding method of the target network protocol message is determined to be: using the basic route to forward the target network protocol message hop by hop to the target cloud network gateway.

[0189] In this embodiment of the disclosure, when determining the forwarding method of the target network protocol message based on the matching result, if the matching result shows that the basic network address matches the basic route in the preset routing table, then the forwarding method of the target network protocol message is determined to be: using the basic route to forward the target network protocol message hop by hop to the target cloud network gateway.

[0190] This can be understood as follows: if, during the longest match of an IPv6 packet, the Underlay address of the Receiver CGW matches the base route in the preset routing table, then the IPv6 packet is forwarded hop-by-hop to the Receiver CGW using the base route. Furthermore, if the first 64 bits of an IPv6 packet match the base route, it is forwarded according to the next hop in the base route, without entering any SR policy, meaning it does not enjoy the SLA provided by traffic engineering.

[0191] In an optional embodiment, the message processing method further includes the following method steps:

[0192] Step S522: In response to the matching result indicating that the underlying network address does not match any route in the preset routing table, the target network protocol message is discarded.

[0193] In this embodiment of the disclosure, when determining the forwarding method of the target network protocol packet based on the matching result, if the matching result shows that the basic network address does not match any route in the preset routing table, the target network protocol packet is dropped.

[0194] This can be understood as follows: if an IPv6 packet does not meet the conditions for matching a BGP route or a basic route when performing the longest match, then the IPv6 packet is discarded.

[0195] It is worth noting that in this embodiment, the end-to-end implementation of the overlay includes two parts. The first part is the basic reachability of the packets, i.e., the implementation of basic routing, which is achieved by exchanging Destination Prefix routes within the Data Center (DC) network and backbone network and performing IPv6 routing forwarding. Further, the data center switch publishes the Destination Prefix routes ( / 64 IPv6 routes) of the cloud network gateway clusters it connects to the entire DC network and backbone network (the backbone network connects high-speed networks between different data centers, metropolitan area networks, and even countries) via BGPv6 (the IPv6 version of Multi-Border Gateway Protocol, used to support the propagation of IPv6 routing information). The Receiver CGW needs to listen to the bound Destination Prefix and perform a longest match on the Destination IPv6 address of the listened IPv6 packets. If the first 64 bits match a / 64 IPv6 address configured on the local machine, the packet is processed, thereby achieving basic routing.

[0196] The second part is the implementation of backbone network traffic engineering, namely SR Policy and "Color Routing" traffic redirection. Further, the backbone network establishes SR policies for the headend / tailend of SRTEs using network edge devices (such as Cloud Services Routers (CSRs) or Enterprise Services Routers (ESRs)). Between a specific pair of source and destination Availability Zones (AZs), several unidirectional transmission services with SLA guarantees are provided. Each SR policy is bound to a 32-bit color field. Color, as an attribute of the SR policy, is used to distinguish multiple SR policies between the headend and tailend devices of the same SRTE pair (typically referring to the tunnel's ingress (headend) and egress (tailend) devices to control the data packet transmission path), and also characterizes the SLA attribute of the transmission service provided by the SR policy. Simultaneously, the backbone network controller receives the / 64 basic routes (i.e., Fundamental Routing, which refers to the minimum set of routes required to ensure basic connectivity and data transmission in the network) sent by the entire network's CSR, and sends / 96 "color routes" (this "color route" is constructed and generated by the controller according to certain conditions; the first 64 bits of the "color route" are the Destination prefix of the Receiver CGW, followed by 32 bits of color) to the headend devices that have deployed specific SR policies, and carries the BGP ext-community color (the value of which is consistent with the 32 bits of color in the prefix and the value of the color attribute of the SR policy), which is used to guide specific traffic to specific SR policies. Furthermore, backbone network headend devices perform a longest match forwarding process on the IPv6 routing table for IPv6 packets arriving from metropolitan area network switches. If the first 96 bits of the IPv6 packet match a BGP route, the packet is directed to the corresponding SR policy for processing based on the color ext-community value carried in the matched BGP route. If the first 64 bits match a basic route, the packet is forwarded according to the next hop in the basic route without entering any SR policy, meaning it does not benefit from the SLA provided by traffic engineering. If the IPv6 packet does not meet the conditions for matching a BGP route or a basic route, it is discarded.

[0197] It should be noted that the preferred implementation of this embodiment can be found in the relevant descriptions in the foregoing embodiments, and will not be repeated here.

[0198] According to embodiments of this disclosure, a message processing method as shown in FIG6 is also provided. FIG6 is a flowchart of a message processing method according to an embodiment of this disclosure. As shown in FIG6, the method includes:

[0199] Step S61: Obtain the target network protocol message to be forwarded. The target network protocol message is obtained by encapsulating the cloud tenant data message and network convergence information. The network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data message. The basic network address is used to determine the sending object of the cloud tenant data message. The basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data message during the forwarding process. The overlay network tenant information is used to determine the sending source of the cloud tenant data message.

[0200] Step S62: Match the basic network address with the network address configured locally on the target cloud network gateway to obtain the matching result;

[0201] Step S63: In response to the matching result indicating that the base network address matches the locally configured network address, process the target network protocol message.

[0202] In this embodiment, the executing entity can be the target cloud network gateway (Receiver CGW), which acquires the target network protocol packet to be forwarded. This target network protocol packet is obtained by encapsulating cloud tenant data packets with network convergence information. This can be understood as the Sender CGW encapsulating the cloud tenant data packets with network convergence information to obtain the target network protocol packet, i.e., the IPv6 packet. The IPv6 packet acquired by the Receiver CGW can be the IPv6 packet that the Sender CGW encapsulates with cloud tenant data packets and network convergence information and forwards to the edge device, which then forwards it to the Receiver CGW.

[0203] Network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet. The target cloud network gateway is the Receiver CGW.

[0204] The base network address of the target cloud network gateway is used to determine the recipient of cloud tenant data packets. It can be understood that the base network address of the target cloud network gateway is the Underlay address of the Receiver CGW, which is also the IPv6 address of the Receiver CGW.

[0205] The Basic Network Traffic Engineering Service Identifier (BMI) is used to determine the segmentation routing strategy to be adopted for cloud tenant data packets during forwarding. It can be understood as the Underlay TE service identifier. In this embodiment, cloud tenant data packets are encapsulated based on the SRv6 framework during forwarding.

[0206] Overlay tenant information is used to determine the source of cloud tenant data packets. It can be understood as the same as overlay tenant information, i.e., tenant identifier.

[0207] After acquiring the target network protocol packet to be forwarded, the Receiver CGW performs address matching between the base network address and the locally configured network address of the target cloud network gateway to obtain the matching result. If the matching result indicates that the base network address matches the locally configured network address, the target network protocol packet is processed. For example, the Receiver CGW only needs to listen for the IPv6 prefix of the IPv6 packets. For instance, if the IPv6 prefix mask is 64, the Receiver CGW will listen for the IPv6 prefix and apply the longest match rule to the detected IPv6 packets. If the first 64 bits of the IPv6 packet match a locally configured / 64 IPv6 address, the Receiver CGW will process the packet, even if it contains more bits.

[0208] As can be seen, this disclosure proposes a new Overlay+Underlay encapsulation format for encapsulating tenant packets exchanged between cloud network gateways. This new encapsulation format is based on the standard SRv6 framework and uses IPv6 as the Overlay encapsulation. It can encapsulate Underlay reachability information (i.e., the Underlay address of the Receiver CGW), Underlay traffic engineering information (i.e., the Underlay TE service identifier), and Overlay tenant information in a single IPv6 header. This not only enables tenant isolation on the cloud gateway and the transmission of tenant packets between cloud gateways (i.e., Overlay network functionality), but also enables traffic engineering in the underlying network (i.e., an Underlay network supporting traffic engineering).

[0209] Furthermore, the embodiments of this disclosure employ IPv6 as the overlay encapsulation, which fully leverages the advantages of the IPv6 address space, providing independent overlay paths for more tenants across more cloud gateways, while also aligning with the historical trend of network evolution towards IPv6. Moreover, for cross-regional and cross-Availability Zone (AZ) traffic, the encapsulation format proposed in these embodiments can more easily provide SLA guarantees using SR Policies deployed on the physical network. Simultaneously, the encapsulation format proposed in these embodiments can incorporate service orchestration and control logic, thereby reducing the complexity of service adjustments. Finally, the encapsulation format proposed in these embodiments supports network service chaining for VXLAN packets with IPv4 as the outer IP header and VXLAN packets with IPv6 as the outer IP.

[0210] The message processing method provided in this disclosure can be applied, but is not limited to, to application scenarios involving the encapsulation of tenant messages exchanged between cloud network gateways in fields such as e-commerce services, education services, legal services, medical services, conference services, social networking services, financial product services, logistics services, and navigation services. For example, application scenarios involving the encapsulation of e-commerce tenant messages exchanged between cloud network gateways, application scenarios involving the encapsulation of education-related tenant messages exchanged between cloud network gateways, application scenarios involving the encapsulation of medical-related tenant messages exchanged between cloud network gateways, etc., and is not limited here.

[0211] In this embodiment of the disclosure, the target network protocol packet to be forwarded is obtained. The target network protocol packet is obtained by encapsulating cloud tenant data packets and network convergence information. The network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet. The basic network address is used to determine the recipient of the cloud tenant data packet, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted during the forwarding process, and the overlay network tenant information is used to determine the source of the cloud tenant data packet. Then, the basic network address is matched with the network address configured locally on the target cloud network gateway to obtain a matching result. If the matching result indicates that the basic network protocol packet is the target network gateway, the target network gateway will be forwarded. The network address is matched with the locally configured network address to process the target network protocol packets, thereby achieving the goal of proposing a new Overlay+Underlay encapsulation format. IPv6 is used as the Overlay encapsulation, which realizes tenant isolation on the cloud gateway and the transmission of tenant packets between cloud gateways (i.e., Overlay network function). It also realizes the technical effect of traffic engineering in the basic network (i.e., Underlay network that supports traffic engineering) and can greatly simplify the design and implementation of physical network traffic engineering. In addition, it solves the technical problem in related technologies where training video generation models based on network data results in poor video quality generated by the trained video generation models, which does not meet user expectations.

[0212] It should be noted that the preferred implementation of this embodiment can be found in the relevant descriptions in the foregoing embodiments, and will not be repeated here.

[0213] According to an embodiment of this disclosure, a message processing system as shown in FIG7 is also provided. FIG6 is a schematic diagram of a message processing system according to an embodiment of this disclosure. As shown in FIG7, the message processing system includes at least: a source cloud network gateway, a target cloud network gateway, and a basic network edge device.

[0214] The source cloud network gateway is used to obtain cloud tenant data packets to be forwarded, and encapsulate the cloud tenant data packets with network fusion information to obtain target network protocol packets. The network fusion information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet. The basic network address is used to determine the sending object of the cloud tenant data packet, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted in the forwarding process of the cloud tenant data packet, and the overlay network tenant information is used to determine the sending source of the cloud tenant data packet.

[0215] Basic network edge devices are used to acquire target network protocol packets, perform route matching on the target network protocol packets to obtain matching results, and determine the forwarding method of the target network protocol packets based on the matching results;

[0216] The target cloud network gateway is used to obtain target network protocol messages, perform address matching between the basic network address and the network address configured locally on the target cloud network gateway to obtain a matching result, and process the target network protocol messages in response to the matching result indicating that the basic network address matches the locally configured network address.

[0217] In this embodiment, the source cloud network gateway (Sender CGW) encapsulates the acquired cloud tenant data packets to be forwarded with network convergence information to obtain target network protocol packets, and then forwards them to the basic network edge device. After obtaining the target network protocol packets encapsulated by the Sender CGW, the basic network edge device performs route matching on the target network protocol packets to obtain a matching result. Based on the matching result, it determines the forwarding method for the target network protocol packets, that is, it forwards the target network protocol packets to the target cloud network gateway (Receiver CGW) according to the determined forwarding method. After obtaining the target network protocol packets, the Receiver CGW performs address matching between the basic network address and the locally configured network address of the target cloud network gateway to obtain a matching result. If the matching result indicates that the basic network address matches the locally configured network address, the target network protocol packets are processed.

[0218] For a detailed description, please refer to the description of the foregoing embodiments, which will not be repeated here.

[0219] The message processing method provided in this disclosure can be applied, but is not limited to, to application scenarios involving the encapsulation of tenant messages exchanged between cloud network gateways in fields such as e-commerce services, education services, legal services, medical services, conference services, social networking services, financial product services, logistics services, and navigation services. For example, application scenarios involving the encapsulation of e-commerce tenant messages exchanged between cloud network gateways, application scenarios involving the encapsulation of education-related tenant messages exchanged between cloud network gateways, application scenarios involving the encapsulation of medical-related tenant messages exchanged between cloud network gateways, etc., and is not limited here.

[0220] By employing the embodiments of this disclosure, message encapsulation and forwarding are performed through a message processing system, thereby achieving the goal of proposing a new Overlay+Underlay encapsulation format. IPv6 is used as the Overlay encapsulation, thereby realizing tenant isolation on the cloud gateway and the transmission of tenant messages between cloud gateways (i.e., Overlay network function). It also realizes the technical effect of traffic engineering in the basic network (i.e., Underlay network supporting traffic engineering), and can greatly simplify the design and implementation of physical network traffic engineering. In turn, it solves the technical problem in related technologies where training video generation models based on network data results in poor video quality generated by the trained video generation models, which does not meet user expectations.

[0221] According to embodiments of this disclosure, an apparatus embodiment for implementing the above-described message processing method is also provided. Figure 8 is a schematic structural diagram of a message processing apparatus according to an embodiment of this disclosure. As shown in Figure 8, the apparatus includes:

[0222] The first acquisition module 801 is configured to acquire cloud tenant data packets to be forwarded;

[0223] The encapsulation module 802 is configured to encapsulate cloud tenant data packets and network convergence information to obtain target network protocol packets. The network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet. The basic network address is used to determine the sending object of the cloud tenant data packet, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data packet during forwarding, and the overlay network tenant information is used to determine the sending source of the cloud tenant data packet.

[0224] Forwarding module 803 is configured to forward target network protocol messages to the target cloud network gateway.

[0225] Optionally, the encapsulation module 802 is further configured to: determine the header encapsulation format to be used in the target network protocol message, wherein the header encapsulation format includes at least a destination address field and a payload field; encapsulate the cloud tenant data message into the payload field and encode the network convergence information into the destination address field to obtain the target network protocol message.

[0226] Optionally, the encapsulation module 802 is further configured to: divide the destination address field into a destination prefix field, a color value field, and a virtual network identifier field; encode the basic network address into the destination prefix field; encode the basic network traffic engineering identifier into the color value field; and encode the overlay network tenant information into the virtual network identifier field.

[0227] Optionally, the encapsulation module 802 is further configured to: encode the target version Internet Protocol address into the destination prefix field in response to the underlying network address being the target version Internet Protocol address of the target cloud network gateway.

[0228] Optionally, the above-mentioned encapsulation module 802 is further configured to: encode the basic network traffic engineering identifier into the color value field based on the traffic engineering service level protocol to be consumed during the forwarding of cloud tenant data packets, wherein there is a mapping relationship between the transmission service guaranteed by the traffic engineering service level protocol and the color value corresponding to the color value field.

[0229] Optionally, the above-mentioned encapsulation module 802 is further configured to: based on the cross-regional virtual network identifier information of the cloud tenant data packet during the forwarding process, encode the overlay network tenant information into the virtual network identifier field.

[0230] Optionally, the forwarding module 803 is further configured to forward the target network protocol message to the target cloud network gateway sequentially via the basic network edge device, the basic network core device corresponding to the source cloud network gateway, and the basic network edge device corresponding to the target cloud network gateway.

[0231] Optionally, the packet header encapsulation format also includes a flow label field. The device further includes: a first processing module, configured to calculate a target factor based on the target network address and the target port, wherein the target network address includes: the base network address of the source cloud network gateway or the base network address of the target cloud network gateway, the target port is the source port of the source cloud network gateway, and the target factor is the hash factor to be used by the cloud tenant data packet during forwarding; and the target factor is encoded into the flow label field.

[0232] Optionally, the packet header encapsulation format also includes a source address field and a flow label field. The device further includes a second processing module, configured to encapsulate the tenant address information corresponding to the cloud tenant data packet into the source address field or the flow label field. The tenant address information includes the cloud tenant source address and the cloud tenant destination address. The tenant address information is used for traffic analysis of the target network protocol packet.

[0233] Optionally, the second processing module is further configured to perform one of the following: copying the cloud tenant source address and the cloud tenant destination address to the source address field; obtaining the first hash value corresponding to the cloud tenant source address and the second hash value corresponding to the cloud tenant destination address, respectively, and encoding the first hash value and the second hash value together into the source address field; obtaining the third hash value corresponding to the cloud tenant source address and the cloud tenant destination address, and encoding the third hash value into the stream label field.

[0234] By employing the embodiments of this disclosure, cloud tenant data packets to be forwarded are obtained, and the cloud tenant data packets are encapsulated with network convergence information to obtain target network protocol packets. That is, the cloud tenant data packets are encapsulated as payloads in IPv6 packets, and the Underlay address of the Receiver CGW, the Underlay TE service identifier, and the Overlay tenant information are encapsulated in the IPv6 header, thereby obtaining the encapsulated IPv6 packets. Finally, the target network protocol packets are forwarded to the target cloud network gateway. This achieves the purpose of proposing a new Overlay+Underlay encapsulation format. By using IPv6 as the Overlay encapsulation, tenant isolation on the cloud gateway and the transmission of tenant packets between cloud gateways (i.e., Overlay network function) are realized. It also realizes the technical effect of traffic engineering in the basic network (i.e., Underlay network that supports traffic engineering), and can greatly simplify the design and implementation of physical network traffic engineering. This solves the technical problem in related technologies where training video generation models based on network data results in poor video quality generated by the trained video generation models, which does not meet user expectations.

[0235] It should be noted that the first acquisition module 801, encapsulation module 802, and forwarding module 803 mentioned above correspond to steps S21 to S23 in the embodiments. The three modules and their corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in the above embodiments. It should be noted that the above modules or units can be hardware or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above modules can also be part of the device and run in the computer terminal 10 provided in the embodiments.

[0236] According to embodiments of this disclosure, another apparatus embodiment for implementing the above-described message processing method is also provided. Figure 9 is a schematic structural diagram of another message processing apparatus according to an embodiment of this disclosure. As shown in Figure 9, the apparatus includes:

[0237] The second acquisition module 901 is configured to acquire the target network protocol message to be forwarded. The target network protocol message is obtained by encapsulating the cloud tenant data message and network fusion information. The network fusion information is determined by the basic network address, basic network traffic engineering service identifier and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data message. The basic network address is used to determine the sending object of the cloud tenant data message, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data message during the forwarding process, and the overlay network tenant information is used to determine the sending source of the cloud tenant data message.

[0238] The first matching module 902 is configured to perform route matching on the target network protocol message and obtain the matching result;

[0239] The determination module 903 is configured to determine the forwarding method of the target network protocol message based on the matching results.

[0240] Optionally, the first matching module 902 is further configured to perform route matching on the basic network address and basic network traffic engineering identifier encapsulated in the target network protocol message according to a preset routing table, and obtain the matching result.

[0241] Optionally, the aforementioned determining module 903 is further configured to, in response to the matching result indicating that the basic network address and the basic network traffic engineering identifier both hit the border gateway protocol route in the preset routing table, determine the forwarding method of the target network protocol message as follows: using the segmented routing strategy corresponding to the border gateway protocol route to forward the target network protocol message to the target cloud network gateway.

[0242] Optionally, the aforementioned determining module 903 is further configured to, in response to the matching result indicating that the basic network address matches the basic route in the preset routing table, determine the forwarding method of the target network protocol message as follows: using the basic route to forward the target network protocol message hop-by-hop to the target cloud network gateway.

[0243] Optionally, the device further includes a discard module configured to discard the target network protocol message in response to a matching result indicating that the underlying network address does not match any route in a preset routing table.

[0244] In this embodiment of the disclosure, a target network protocol packet to be forwarded is obtained. This target network protocol packet is obtained by encapsulating a cloud tenant data packet with network convergence information. The network convergence information is determined by the basic network address of the target cloud network gateway corresponding to the cloud tenant data packet, the basic network traffic engineering service identifier, and the overlay network tenant information. The basic network address is used to determine the recipient of the cloud tenant data packet, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted during the forwarding process, and the overlay network tenant information is used to determine the source of the cloud tenant data packet. Then, route matching is performed on the obtained target network protocol packet to obtain the matching result. Finally, based on the matching... The results determined the forwarding method of the target network protocol packets, thus achieving the goal of proposing a new Overlay+Underlay encapsulation format. By using IPv6 as the Overlay encapsulation, tenant isolation on the cloud gateway and the transmission of tenant packets between cloud gateways (i.e., Overlay network function) are realized. It also achieves the technical effect of traffic engineering in the basic network (i.e., Underlay network that supports traffic engineering) and can greatly simplify the design and implementation of physical network traffic engineering. In addition, it solves the technical problem in related technologies where training video generation models based on network data results in poor video quality generated by the trained video generation models, which does not meet user expectations.

[0245] It should be noted that the second acquisition module 901, the first matching module 902, and the determination module 903 mentioned above correspond to steps S51 to S53 in the embodiments. The three modules and the corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in the above embodiments. It should be noted that the above modules or units can be hardware components or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above modules can also be part of the device and run in the computer terminal 10 provided in the embodiments.

[0246] According to embodiments of this disclosure, another embodiment of an apparatus for implementing the above-described message processing method is also provided. FIG10 is a schematic structural diagram of another message processing apparatus according to embodiments of this disclosure. As shown in FIG10, the apparatus includes:

[0247] The third acquisition module 1001 is configured to acquire the target network protocol message to be forwarded. The target network protocol message is obtained by encapsulating the cloud tenant data message and network fusion information. The network fusion information is determined by the basic network address, basic network traffic engineering service identifier and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data message. The basic network address is used to determine the sending object of the cloud tenant data message, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data message during the forwarding process, and the overlay network tenant information is used to determine the sending source of the cloud tenant data message.

[0248] The second matching module 1002 is configured to perform address matching between the basic network address and the network address configured locally on the target cloud network gateway to obtain the matching result.

[0249] The third processing module 1003 is configured to process the target network protocol message in response to a matching result indicating that the underlying network address matches the locally configured network address.

[0250] Using this embodiment, a target network protocol packet to be forwarded is obtained. The target network protocol packet is obtained by encapsulating a cloud tenant data packet with network convergence information. The network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet. The basic network address is used to determine the recipient of the cloud tenant data packet, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted during the forwarding process, and the overlay network tenant information is used to determine the source of the cloud tenant data packet. Then, address matching is performed between the basic network address and the network address configured locally on the target cloud network gateway to obtain a matching result. If the matching result indicates that the basic network... The network address is matched with the locally configured network address to process the target network protocol packets, thereby achieving the goal of proposing a new Overlay+Underlay encapsulation format. IPv6 is used as the Overlay encapsulation, which realizes tenant isolation on the cloud gateway and the transmission of tenant packets between cloud gateways (i.e., Overlay network function). It also realizes the technical effect of traffic engineering in the basic network (i.e., Underlay network that supports traffic engineering) and can greatly simplify the design and implementation of physical network traffic engineering. In addition, it solves the technical problem in related technologies where training video generation models based on network data results in poor video quality generated by the trained video generation models, which does not meet user expectations.

[0251] It should be noted that the third acquisition module 1001, the second matching module 1002, and the third processing module 1003 mentioned above correspond to steps S61 to S63 in the embodiments. The three modules and their corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in the above embodiments. It should be noted that the above modules or units can be hardware or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above modules can also be part of the device and run in the computer terminal 10 provided in the embodiments.

[0252] It should be noted that the preferred implementation schemes involved in the above embodiments of this disclosure are the same as the schemes, application scenarios and implementation processes provided in the embodiments, but are not limited to the schemes provided in the embodiments.

[0253] Embodiments of this disclosure can provide an electronic device, which can be any one of a group of electronic devices. Optionally, in this embodiment, the electronic device can also be replaced by a terminal device such as a mobile terminal. Optionally, in this embodiment, the electronic device can be located in at least one of a plurality of network devices in a computer network.

[0254] In this embodiment, the aforementioned electronic device can execute the program code for the following steps in the message processing method: obtaining the cloud tenant data packet to be forwarded; encapsulating the cloud tenant data packet and network convergence information to obtain the target network protocol packet, wherein the network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet; the basic network address is used to determine the sending object of the cloud tenant data packet; the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data packet during the forwarding process; and the overlay network tenant information is used to determine the sending source of the cloud tenant data packet; and forwarding the target network protocol packet to the target cloud network gateway.

[0255] Optionally, FIG11 is a structural block diagram of an electronic device according to an embodiment of the present disclosure. As shown in FIG11, taking electronic device A as an example, electronic device A may include: one or more (only one is shown in the figure) processors 1102, memory 1104, memory controller, and peripheral interface, wherein the peripheral interface is connected to a radio frequency module, an audio module, and a display.

[0256] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the message processing method and apparatus in this embodiment. The processor executes various functional applications and data processing by running the stored software programs and modules, thereby implementing the aforementioned message processing method. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to electronic device A via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0257] The processor can invoke information and applications stored in the memory through the transmission device to perform the following steps: obtain the cloud tenant data packet to be forwarded; encapsulate the cloud tenant data packet and network convergence information to obtain the target network protocol packet, wherein the network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet. The basic network address is used to determine the recipient of the cloud tenant data packet, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data packet during forwarding, and the overlay network tenant information is used to determine the source of the cloud tenant data packet; and forward the target network protocol packet to the target cloud network gateway.

[0258] By employing the embodiments of this disclosure, cloud tenant data packets to be forwarded are obtained, and the cloud tenant data packets are encapsulated with network convergence information to obtain target network protocol packets. That is, the cloud tenant data packets are encapsulated as payloads in IPv6 packets, and the Underlay address of the Receiver CGW, the Underlay TE service identifier, and the Overlay tenant information are encapsulated in the IPv6 header, thereby obtaining the encapsulated IPv6 packets. Finally, the target network protocol packets are forwarded to the target cloud network gateway. This achieves the purpose of proposing a new Overlay+Underlay encapsulation format. By using IPv6 as the Overlay encapsulation, tenant isolation on the cloud gateway and the transmission of tenant packets between cloud gateways (i.e., Overlay network function) are realized. It also realizes the technical effect of traffic engineering in the basic network (i.e., Underlay network that supports traffic engineering), and can greatly simplify the design and implementation of physical network traffic engineering. This solves the technical problem in related technologies where training video generation models based on network data results in poor video quality generated by the trained video generation models, which does not meet user expectations.

[0259] It will be understood by those skilled in the art that the structure shown in Figure 11 is merely illustrative, and electronic device A may also be a smartphone, tablet computer, PDA, mobile internet device (MID), PAD, or other terminal device. Figure 11 does not limit the structure of the aforementioned electronic device. For example, electronic device A may include more or fewer components (such as network interfaces, display devices, etc.) than shown in Figure 11, or may have a different configuration than that shown in Figure 11.

[0260] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0261] Embodiments of this disclosure also provide a computer-readable storage medium. Optionally, in this embodiment, the computer-readable storage medium can be used to store the program code executed by the message processing method provided in Embodiment 1.

[0262] Optionally, in this embodiment, the computer-readable storage medium may be located in any computer terminal in a group of computer terminals in a computer network, or in any mobile terminal in a group of mobile terminals.

[0263] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: obtaining cloud tenant data packets to be forwarded; encapsulating the cloud tenant data packets and network convergence information to obtain target network protocol packets, wherein the network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packets, the basic network address is used to determine the sending object of the cloud tenant data packets, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data packets during forwarding, and the overlay network tenant information is used to determine the sending source of the cloud tenant data packets; and forwarding the target network protocol packets to the target cloud network gateway.

[0264] Embodiments of this disclosure also provide a computer program product comprising a computer program that, when executed by a processor, implements any of the above-described message processing methods.

[0265] Optionally, in this embodiment, when the computer program product is executed by the processor, the program code is used to perform the following steps: obtaining the cloud tenant data packet to be forwarded; encapsulating the cloud tenant data packet and network convergence information to obtain the target network protocol packet, wherein the network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet, the basic network address is used to determine the sending object of the cloud tenant data packet, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data packet during the forwarding process, and the overlay network tenant information is used to determine the sending source of the cloud tenant data packet; and forwarding the target network protocol packet to the target cloud network gateway.

[0266] The sequence numbers of the embodiments disclosed above are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.

[0267] In the above embodiments of this disclosure, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0268] In the several embodiments provided in this disclosure, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.

[0269] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0270] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0271] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0272] The above description is only a preferred embodiment of this disclosure. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principles of this disclosure, and these improvements and modifications should also be considered within the scope of protection of this disclosure.

Claims

1. A message processing method, comprising: Obtain cloud tenant data packets to be forwarded; The cloud tenant data packet and network convergence information are encapsulated to obtain a target network protocol packet. The network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packet. The basic network address is used to determine the sending object of the cloud tenant data packet. The basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data packet during forwarding. The overlay network tenant information is used to determine the sending source of the cloud tenant data packet. The target network protocol message is forwarded to the target cloud network gateway.

2. The packet processing method of claim 1, wherein, Encapsulating the cloud tenant data packet and the network fusion information to obtain the target network protocol packet includes: Determine the header encapsulation format to be used for the target network protocol message, wherein the header encapsulation format includes at least a destination address field and a payload field; The cloud tenant data packet is encapsulated into the payload field, and the network convergence information is encoded into the destination address field to obtain the target network protocol packet.

3. The packet processing method of claim 2, wherein, Encoding the network fusion information into the destination address field includes: The destination address field is divided into a destination prefix field, a color value field, and a virtual network identifier field; The underlying network address is encoded into the destination prefix field, the underlying network traffic engineering identifier is encoded into the color value field, and the overlay network tenant information is encoded into the virtual network identifier field.

4. The packet processing method of claim 3, wherein, Encoding the underlying network address into the destination prefix field includes: In response to the underlying network address being the target version of Internet Protocol (IP) address of the target cloud network gateway, the target version of IP address is encoded into the destination prefix field.

5. The packet processing method of claim 3, wherein, Encoding the basic network traffic engineering identifier into the color value field includes: Based on the traffic engineering service level protocol to be consumed during the forwarding of the cloud tenant data packets, the basic network traffic engineering identifier is encoded into the color value field, wherein there is a mapping relationship between the transmission service guaranteed by the traffic engineering service level protocol and the color value corresponding to the color value field.

6. The packet processing method of claim 3, wherein, Encoding the overlay network tenant information into the virtual network identifier field includes: Based on the cross-regional virtual network identifier information of the cloud tenant data packets during the forwarding process, the overlay network tenant information is encoded into the virtual network identifier field.

7. The packet processing method of claim 1, wherein, Forwarding the target network protocol message to the target cloud network gateway includes: The target network protocol message is forwarded to the target cloud network gateway sequentially via the basic network edge device, the basic network core device corresponding to the source cloud network gateway, and the basic network edge device corresponding to the target cloud network gateway.

8. The packet processing method of claim 2, wherein, The packet header encapsulation format also includes a flow label field, and the message processing method further includes: The target factor is calculated based on the target network address and the target port. The target network address includes either the base network address of the source cloud network gateway or the base network address of the target cloud network gateway. The target port is the source port of the source cloud network gateway. The target factor is the hash factor to be used by the cloud tenant data packet during the forwarding process. The target factor is encoded into the stream label field.

9. The packet processing method of claim 2, wherein, The packet header encapsulation format also includes a source address field and a flow label field, and the packet processing method further includes: The tenant address information corresponding to the cloud tenant data packet is encapsulated into the source address field or the flow label field. The tenant address information includes the cloud tenant source address and the cloud tenant destination address. The tenant address information is used to perform traffic analysis on the target network protocol packet.

10. The packet processing method of claim 9, wherein, Encapsulating the tenant address information corresponding to the cloud tenant data packet into the source address field or the stream label field includes one of the following: Copy the cloud tenant's source address and destination address to the source address field; Obtain the first hash value corresponding to the source address of the cloud tenant and the second hash value corresponding to the destination address of the cloud tenant, and encode the first hash value and the second hash value together into the source address field; Obtain the third hash value that corresponds to both the source address and destination address of the cloud tenant, and encode the third hash value into the stream label field.

11. A message processing method, comprising: Obtain the target network protocol message to be forwarded, wherein the target network protocol message is obtained by encapsulating the cloud tenant data message and network convergence information. The network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data message. The basic network address is used to determine the sending object of the cloud tenant data message. The basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data message during the forwarding process. The overlay network tenant information is used to determine the sending source of the cloud tenant data message. Perform route matching on the target network protocol message to obtain the matching result; The forwarding method of the target network protocol message is determined based on the matching result.

12. The packet processing method of claim 11, wherein, The route matching of the target network protocol message yields the following matching results: Based on a preset routing table, the basic network address encapsulated in the target network protocol message is matched with the basic network traffic engineering identifier to obtain the matching result.

13. The packet processing method of claim 12, wherein, Determining the forwarding method of the target network protocol message based on the matching result includes: In response to the matching result indicating that the basic network address and the basic network traffic engineering identifier both match the border gateway protocol route in the preset routing table, the forwarding method of the target network protocol packet is determined to be: to forward the target network protocol packet to the target cloud network gateway using the segmented routing strategy corresponding to the border gateway protocol route.

14. The packet processing method of claim 12, wherein, Determining the forwarding method of the target network protocol message based on the matching result includes: In response to the matching result indicating that the basic network address matches the basic route in the preset routing table, the forwarding method of the target network protocol message is determined to be: using the basic route to forward the target network protocol message hop-by-hop to the target cloud network gateway.

15. The packet processing method of claim 12, wherein, The message processing method further includes: In response to the matching result indicating that the underlying network address does not match any route in the preset routing table, the target network protocol message is discarded.

16. A message processing method, comprising: Obtain the target network protocol message to be forwarded, wherein the target network protocol message is obtained by encapsulating the cloud tenant data message and network convergence information. The network convergence information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data message. The basic network address is used to determine the sending object of the cloud tenant data message. The basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data message during the forwarding process. The overlay network tenant information is used to determine the sending source of the cloud tenant data message. The basic network address is matched with the network address configured locally on the target cloud network gateway to obtain the matching result; In response to the matching result indicating that the base network address matches the locally configured network address, the target network protocol message is processed.

17. A packet processing system comprising at least: Source cloud network gateway, target cloud network gateway, and basic network edge devices; The source cloud network gateway is used to acquire cloud tenant data packets to be forwarded, and encapsulate the cloud tenant data packets with network fusion information to obtain target network protocol packets. The network fusion information is determined by the basic network address, basic network traffic engineering service identifier, and overlay network tenant information of the target cloud network gateway corresponding to the cloud tenant data packets. The basic network address is used to determine the sending object of the cloud tenant data packets, the basic network traffic engineering identifier is used to determine the segmentation routing strategy to be adopted by the cloud tenant data packets during forwarding, and the overlay network tenant information is used to determine the sending source of the cloud tenant data packets. The basic network edge device is used to acquire the target network protocol message, perform route matching on the target network protocol message to obtain a matching result, and determine the forwarding method of the target network protocol message based on the matching result; The target cloud network gateway is configured to acquire the target network protocol message, perform address matching between the basic network address and the network address configured locally on the target cloud network gateway to obtain a matching result, and process the target network protocol message in response to the matching result indicating that the basic network address matches the network address configured locally.

18. An electronic device comprising: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the message processing method according to any one of claims 1 to 16.

19. A computer readable storage medium comprising a stored executable program, wherein, When the executable program is executed, it controls the device containing the computer-readable storage medium to perform the message processing method according to any one of claims 1 to 16.

20. A computer program product comprising a computer program that, when executed by a processor, implements the message processing method according to any one of claims 1 to 16.

Citation Information

Patent Citations

  • Packet transmission method, information processing method, and related device

    CN109245984A

  • Message forwarding method, head end device, controller, device and storage medium

    CN117118886A

  • Network management service in point of presence

    CN117178534A

  • Cloud Provider, Service, and Tenant Classification in Cloud Computing

    US20160323183A1