Elastic IP address configuration method based on hybrid cloud scenario, and public cloud system

By creating cloud gateways and network connection channels in the public cloud system, elastic public IP access points are provided for tenants' on-premises resources, solving the problem of communication between on-premises resources and the public network, realizing diversified public network access services, and improving tenants' public network access experience.

WO2026097890A1PCT designated stage Publication Date: 2026-05-15HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
Filing Date
2025-06-28
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

In cloud computing scenarios, tenants' on-premises resources have difficulty communicating with the public network, which fails to meet the increasingly complex business needs of tenants.

Method used

By leveraging the cloud management platform of a public cloud system, a cloud gateway is created and a network connection channel is established, providing elastic public IP access points and cloud gateways to enable communication between on-premises resources and the public network.

Benefits of technology

To meet tenants' on-premises resource business needs, provide diversified public network access services, and improve tenants' public network access experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025105076_15052026_PF_FP_ABST
    Figure CN2025105076_15052026_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses an elastic IP address configuration method based on a hybrid cloud scenario, and a public cloud system, which can improve the public network access experience of tenants to a certain extent. The method of the present application comprises: a tenant can provide, to a cloud management platform, access point information of an elastic IP address used by an off-cloud resource, and cloud gateway creation information, wherein the access point information is used for indicating a target cloud data center where an access point of the elastic IP address is located, and the cloud gateway creation information is used for indicating a cloud gateway which is to be created and is bound to the elastic IP address; the cloud management platform can create said cloud gateway in the target data center, and establish a network connection channel between said cloud gateway and the off-cloud resource; and when the remaining tenants in the public network send, to the access point, a first packet of which a destination address is the elastic IP address, the access point can notify said cloud gateway to send the first packet to the off-cloud resource of the tenant by means of the network connection channel, so that the off-cloud resource of the tenant processes the first packet.
Need to check novelty before this filing date? Find Prior Art

Description

A method for configuring elastic public IP addresses and a public cloud system based on hybrid cloud scenarios

[0001] This application claims priority to Chinese patent application filed on November 8, 2024, with application number 202411598994.1 and title "A Method for Elastic Public IP Configuration and Public Cloud System Based on Hybrid Cloud Scenarios", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of cloud technology, and in particular to a method for configuring elastic public IP addresses and a public cloud system based on a hybrid cloud scenario. Background Technology

[0003] In cloud computing scenarios, tenants have a need to access and be accessed by the public network for cloud resources deployed in the infrastructure of cloud providers. Therefore, cloud providers provide public network resource access services, which include elastic public IPs (EIPs) and bandwidth.

[0004] In related technologies, cloud providers can provide access points to the public network for tenants' cloud resources. These access points can provide tenants' cloud resources with public network resources such as elastic public IP addresses and bandwidth. Therefore, tenants' cloud resources can use the public network resources such as elastic public IP addresses and bandwidth provided by the access points to access the public network or be accessed by the public network, thereby meeting the tenants' business needs.

[0005] However, since tenants' services can be deployed on either cloud resources or on-premises resources, how to enable tenants' on-premises resources to communicate with the public network in order to meet the increasingly complex business needs of tenants has become an urgent problem for cloud vendors to solve. Summary of the Invention

[0006] This application provides a method for configuring elastic public IP addresses and a public cloud system based on a hybrid cloud scenario, which can provide tenants with diversified public network access services, thereby improving the tenants' public network access experience to a certain extent.

[0007] The first aspect of this application provides a method for configuring elastic public IP addresses in a hybrid cloud scenario. This method can be implemented through a public cloud system, which includes infrastructure and a cloud management platform for managing this infrastructure, including multiple cloud data centers. The method includes:

[0008] When a tenant needs its on-premises resources (data centers not belonging to the public cloud system, etc.) to communicate with the public network, the tenant can input the access point information of the elastic public IP used by the on-premises resources and the cloud gateway creation information into the configuration interface provided by the cloud management platform. The access point information can be used to indicate the target cloud data center of multiple cloud data centers in the public cloud system where the access point is set, and the cloud gateway creation information is used to indicate the cloud gateway to be created bound to the elastic public IP.

[0009] Based on the access point information and the cloud gateway information, the cloud management platform can create a cloud gateway in the target cloud data center and establish a network connection channel between the cloud gateway and the tenant's on-premises resources. The cloud gateway records a first forwarding rule, which instructs the cloud gateway to send packets with a destination address of an Elastic Public IP address to the tenant's on-premises resources.

[0010] When other tenants on the public network send a first packet with the destination address of the Elastic Public IP to the access point, the access point can use the first packet as an inner packet of the first overlay packet and send the first overlay packet to the cloud gateway. Due to the existence of the first forwarding rule, the cloud gateway can send the first packet in the first overlay packet to the tenant's on-premises resources through the network connection channel, so that the tenant's on-premises resources can process the first packet, thereby meeting the business needs between the tenant and other tenants.

[0011] As can be seen from the above methods, the cloud management platform can provide tenants with access points for elastic public IPs that can be used by the on-premises resources, as well as cloud gateways bound to those elastic public IPs, according to the tenants' needs. This allows the tenants' on-premises resources to communicate with the public network using the access points and cloud gateways, thus meeting the tenants' business needs for on-premises resources, providing tenants with diversified public network access services, and thereby improving the tenants' public network access experience to a certain extent.

[0012] In one possible implementation, the cloud gateway also records a second forwarding rule, which instructs the cloud gateway to send packets with a destination address of the Internet to the access point. The method further includes: the cloud gateway receiving a second packet sent by the data center through a network connection channel, the destination address of the second packet being a public IP address outside the infrastructure, and the source address being an elastic public IP address; the cloud gateway generating a second overlay packet based on the second packet, and sending the second overlay packet to the access point according to the second forwarding rule, wherein the inner packet of the second overlay packet is the second packet; the access point receiving the second overlay packet and sending the second packet to the Internet. In the aforementioned implementation, the cloud gateway also records a second forwarding rule, which instructs the cloud gateway to send packets with a destination address of the Internet to the access point. When a tenant's on-premises resources send a second packet with a destination address of a public IP address to the cloud gateway through the network connection channel, due to the existence of the second forwarding rule, the cloud gateway can use the second packet as the inner packet of the second overlay packet and send the second overlay packet to the access point. Then, the access point can send the second message in the second overlay message to other tenants in the public network so that the other tenants can process the second message, thereby meeting the business needs between the tenant and the other tenants.

[0013] In one possible implementation, the method further includes: the cloud gateway recording the traffic of the network connection channel. In the aforementioned implementation, the cloud gateway can record the traffic of the network connection channel between the cloud gateway and the tenant's on-premises resources in real time, and report this traffic to the cloud management platform.

[0014] In one possible implementation, the method further includes: the cloud management platform charging tenants based on traffic. In the aforementioned implementation, after receiving the traffic reported by the cloud gateway, the cloud management platform can calculate the fee payable by the tenant based on the traffic and notify the tenant to pay the fee.

[0015] In one possible implementation, the network connection channel includes a leased network channel and / or a VPN network channel. In the aforementioned implementation, when the cloud gateway is a leased network gateway instance, the network connection channel between the cloud gateway and the tenant's on-premises resources is a leased network channel; when the cloud gateway is a VPN gateway instance, the network connection channel between the cloud gateway and the tenant's on-premises resources is a VPN network channel.

[0016] In one possible implementation, the data center is either a local data center or a cloud data center of a third-party public cloud system. In the aforementioned implementation, the tenant's on-premises resources refer to data centers that do not belong to a public cloud system. These data centers may include the tenant's local data center and the cloud data center of a third-party public cloud system, etc. It should be noted that the public cloud system provided in this application is different from the third-party public cloud system mentioned herein.

[0017] A second aspect of this application provides a public cloud system, including a cloud management platform and infrastructure. The cloud management platform manages the infrastructure, which includes multiple cloud data centers. Specifically: the cloud management platform receives access point information of elastic public IPs input by tenants of the infrastructure. This access point information includes location information of the access point bound to the elastic public IP, indicating the target cloud data center where the access point is located within the multiple cloud data centers. The cloud management platform also receives cloud gateway creation information input by tenants, indicating the elastic public IP to be bound to the cloud gateway to be created. It is also used to create a cloud gateway in the target cloud data center. The cloud gateway establishes a network connection channel with the data center that does not belong to the public cloud system. The cloud gateway records a first forwarding rule, which is used to instruct the cloud gateway to send packets with a destination address of an Elastic Public IP to the data center. The cloud gateway is used to receive a first superimposed packet sent by the access point. The inner packet of the first superimposed packet is a packet received by the access point from the Internet outside the infrastructure. The destination address of the inner packet of the first superimposed packet is an Elastic Public IP. The cloud gateway is also used to send a first packet to the data center through the network connection channel according to the first forwarding rule. The first packet is the inner packet of the first superimposed packet.

[0018] In one possible implementation, the cloud gateway also records a second forwarding rule, which instructs the cloud gateway to send packets with a destination address of the Internet to the access point; the cloud gateway is also used to receive second packets sent by the data center through a network connection channel, where the destination address of the second packet is a public IP address outside the infrastructure and the source address is an elastic public IP address; the cloud gateway is also used to generate a second overlay packet based on the second packet and send the second overlay packet to the access point according to the second forwarding rule, wherein the inner packet of the second overlay packet is the second packet; the access point is used to receive the second overlay packet and send the second packet to the Internet.

[0019] In one possible implementation, the cloud gateway is also used to record the traffic of the network connection channel.

[0020] In one possible implementation, the cloud management platform is also used to charge tenants based on traffic.

[0021] In one possible implementation, the network connection channel includes a leased network channel and / or a VPN network channel.

[0022] In one possible implementation, the data center can be a local data center or a cloud data center of a third-party public cloud system.

[0023] A third aspect of this application provides a cloud management platform, which is set up in a public cloud system. The public cloud system also includes infrastructure, which includes multiple cloud data centers. The cloud management platform includes: a first receiving module for receiving access point information of elastic public IPs input by infrastructure tenants, wherein the access point information includes the location information of the access point bound to the elastic public IP, and the location information is used to indicate the target cloud data center where the access point is located in multiple cloud data centers; a second receiving module for receiving cloud gateway creation information input by tenants, wherein the cloud gateway creation information is used to indicate the elastic public IP that the cloud gateway to be created needs to be bound to; and a creation module for creating a cloud gateway in the target cloud data center, wherein the cloud gateway establishes a network connection channel with the data center that is not part of the public cloud system, and the cloud gateway records a first forwarding rule, which is used to instruct the cloud gateway to send packets with the destination address being the elastic public IP to the data center; wherein the cloud gateway is used to: receive a first superimposed packet sent by the access point, wherein the inner packet of the first superimposed packet is a packet received by the access point from the Internet outside the infrastructure, and the destination address of the inner packet of the first superimposed packet is the elastic public IP; and send the first packet to the data center through the network connection channel according to the first forwarding rule, wherein the first packet is the inner packet of the first superimposed packet.

[0024] In one possible implementation, the cloud gateway also records a second forwarding rule, which instructs the cloud gateway to send packets with a destination address of the Internet to the access point; the cloud gateway is also used to: receive a second packet sent by the data center through a network connection channel, wherein the destination address of the second packet is a public IP address outside the infrastructure and the source address is an elastic public IP address; generate a second superimposed packet based on the second packet, and send the second superimposed packet to the access point according to the second forwarding rule, wherein the inner packet of the second superimposed packet is the second packet; the access point is used to receive the second superimposed packet and send the second packet to the Internet.

[0025] In one possible implementation, the cloud gateway is also used to record the traffic of the network connection channel.

[0026] In one possible implementation, the cloud management platform also includes a billing module for charging tenants based on traffic.

[0027] In one possible implementation, the network connection channel includes a leased network channel and / or a VPN network channel.

[0028] In one possible implementation, the data center can be a local data center or a cloud data center of a third-party public cloud system.

[0029] A fourth aspect of this application provides a computing device cluster, the computing device cluster including at least one computing device, each computing device including a processor and a memory: the memory is used to store instructions; the processor is used to cause the computing device cluster to perform the method described in the first aspect or any possible implementation of the first aspect according to the instructions.

[0030] A fifth aspect of this application provides a computer storage medium storing one or more instructions that, when executed by one or more computers, cause the one or more computers to perform the method described in the first aspect or any possible implementation of the first aspect.

[0031] A sixth aspect of this application provides a computer program product storing instructions that, when executed by a computer, cause the computer to perform the method described in the first aspect or any possible implementation of the first aspect.

[0032] In this embodiment, when a tenant needs to enable its on-premises resources to communicate with the public network, the tenant can provide the cloud management platform with the access point information of the elastic public IP used by the on-premises resources and the cloud gateway creation information. Since the access point information indicates the target cloud data center where the access point of the elastic public IP is located, and the cloud gateway creation information indicates the cloud gateway to be created bound to the elastic public IP, and since the target cloud data center has already created the access point of the elastic public IP, the cloud management platform can create the cloud gateway in the target data center and create a network connection channel between the cloud gateway and the on-premises resources. Then, when other tenants on the public network send a first packet with the destination address of the elastic public IP to the access point, the access point can use the first packet as an inner packet of a first overlay packet and send the first overlay packet to the cloud gateway. This allows the cloud gateway to send the first packet in the first overlay packet to the tenant's on-premises resources through the network connection channel, enabling the tenant's on-premises resources to process the first packet. Therefore, the cloud management platform can provide tenants with access points for elastic public IPs that can be used by the on-premises resources, as well as cloud gateways bound to those elastic public IPs, according to the tenants' needs. This allows the tenants' on-premises resources to communicate with the public network using the access points and cloud gateways, thus meeting the tenants' business needs for on-premises resources, providing diversified public network access services, and thereby improving the tenants' public network access experience to a certain extent. Attached Figure Description

[0033] Figure 1 is a schematic diagram of the structure of a public cloud system provided in an embodiment of this application;

[0034] Figure 2 is another structural schematic diagram of the public cloud system provided in the embodiment of this application;

[0035] Figure 3 is another structural schematic diagram of the public cloud system provided in the embodiment of this application;

[0036] Figure 4 is a schematic diagram of a VXLAN message provided in an embodiment of this application;

[0037] Figure 5 is a flowchart illustrating an elastic public IP configuration method based on a hybrid cloud scenario provided in an embodiment of this application.

[0038] Figure 6 is a schematic diagram of a tenant interface provided in an embodiment of this application;

[0039] Figure 7 is another structural schematic diagram of the public cloud system provided in the embodiment of this application;

[0040] Figure 8 is another structural schematic diagram of the public cloud system provided in the embodiment of this application;

[0041] Figure 9 is a schematic diagram of the structure of a cloud management platform provided in an embodiment of this application;

[0042] Figure 10 is a schematic diagram of a computing device provided in an embodiment of this application;

[0043] Figure 11 is a schematic diagram of a computing device cluster provided in an embodiment of this application;

[0044] Figure 12 is a schematic diagram of computer devices in a computer cluster connected via a network according to an embodiment of this application. Detailed Implementation

[0045] This application provides a method for configuring elastic public IP addresses and a public cloud system based on a hybrid cloud scenario, which can provide tenants with diversified public network access services, thereby improving the tenants' public network access experience to a certain extent.

[0046] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms are interchangeable where appropriate; this is merely a way of distinguishing objects with the same attributes in the embodiments of this application. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion, so that a process, method, system, product, or apparatus that comprises a series of elements is not necessarily limited to those elements, but may include other elements not explicitly listed or inherent to those processes, methods, products, or apparatuses.

[0047] First, some of the terms and related technologies used in this application will be explained in conjunction with the accompanying drawings to facilitate understanding by those skilled in the art.

[0048] Elastic IP (EIP): Provides independent public IP resources, including public IP address and public bandwidth, which can be bound to and unbound from cloud resources such as virtual machines, bare metal servers, virtual IPs, elastic load balancers, NAT gateways, containers, and dedicated hosts.

[0049] Access point: The location of the elastic public IP resource, corresponding to the cloud provider's point of presence (POP) or region. The access point is located in the cloud provider's data center.

[0050] Point of Presence (POP): In the cloud computing field, the point of presence is located at the edge of the cloud network provided by the cloud vendor, and external access can be made to the cloud network through the point of presence.

[0051] Cloud resources: Cloud resources include one or any combination of virtual machines, containers, bare metal servers, and dedicated servers.

[0052] Region: The location of the data center. A region contains multiple areas.

[0053] Region: The location of a data center. Regions are typically defined by geographical location and network latency, and are also called geographical areas. Within the same region, public services such as elastic computing are shared. In one embodiment provided in this application, regions may include, for example, North China, East China, or North China-Beijing I, East China-Shanghai I.

[0054] Availability Zone (AZ): The location of a data center. An availability zone is a collection of one or more independent physical data centers within the same area, sharing power and network infrastructure. Multiple availability zones within an area are interconnected via high-speed fiber optic cables. In one embodiment provided in this application, availability zones include, for example, Beijing Availability Zone A and Beijing Availability Zone B.

[0055] Cloud management platform and infrastructure: The cloud management platform is used to manage the cloud vendor's infrastructure, which includes multiple data centers located in different regions, with at least one data center in each region. The cloud management platform can provide interfaces related to cloud computing services, such as configuration pages or application program interfaces (APIs), for tenants to access cloud services. Tenants can log in to the cloud management platform with a pre-registered account and password, and after successful login, select and purchase cloud services provided by the data centers in the designated regions. Cloud services include object storage services, virtual machine services, container services, or other known cloud services.

[0056] Tenant: The top-level object used to manage cloud services and / or cloud resources. Tenants register tenant accounts and set tenant passwords on the cloud management platform through local clients (such as browsers). Local clients remotely log in to the cloud management platform through the tenant account and set tenant password. The cloud management platform provides a configuration interface or API for tenants to configure and use cloud services, where cloud services are specifically provided by the infrastructure managed by the cloud management platform as described above.

[0057] In cloud computing scenarios, tenants have a need to access and be accessed by the public network for cloud resources deployed in the infrastructure of cloud providers. Therefore, cloud providers provide public network resource access services, which include elastic public IPs (EIPs) and bandwidth.

[0058] In related technologies, cloud providers can provide access points to the public network for tenants' cloud resources. These access points can provide tenants' cloud resources with public network resources such as elastic public IP addresses and bandwidth. Therefore, tenants' cloud resources can use the public network resources such as elastic public IP addresses and bandwidth provided by the access points to access the public network or be accessed by the public network, thereby meeting the tenants' business needs.

[0059] However, since tenants' services can be deployed on either cloud resources or on-premises resources, how to enable tenants' on-premises resources to communicate with the public network in order to meet the increasingly complex business needs of tenants has become an urgent problem for cloud vendors to solve.

[0060] To address the aforementioned issues, this application provides a method for configuring elastic public IP addresses in a hybrid cloud scenario. This method can be implemented through a public cloud system. Figure 1 is a schematic diagram of the structure of a public cloud system provided in this application embodiment. As shown in Figure 1, the public cloud system includes infrastructure that can provide cloud services and a cloud management platform that manages this infrastructure. The cloud management platform and the infrastructure are described in detail below:

[0061] A cloud management platform can centrally manage the infrastructure across the entire public cloud system (for example, according to a tenant's instructions, it can determine access points for data centers that are not part of the public cloud system, enabling these data centers to communicate with other tenants' clients on the public network using the public network resources provided by the access points). The cloud management platform can also be open to tenants outside the cloud service system and respond to their requests. For example, the cloud management platform can provide various interfaces such as login and configuration interfaces for tenant clients (e.g., the terminal devices used by the tenant or the browsers on those devices). Specifically, the cloud management platform can authenticate a tenant's client through the login interface, allowing the tenant's client to log in to the cloud management platform upon successful authentication. For example, the cloud management platform can also configure interfaces to allow the tenant's clients to send public network resource configuration requests to the cloud management platform for data centers that are not part of the public cloud system (e.g., the tenant's on-premises data center or a cloud data center serving a third-party public cloud system). This request may include access point information for a specific elastic public IP address and cloud gateway creation information. Since the access point information includes the location information of the access point bound to that elastic public IP address, indicating the target cloud data center among the multiple cloud data centers in the infrastructure where the access point is located, and the cloud gateway creation information indicating the elastic public IP address to be bound to the cloud gateway to be created, and since the target cloud data center already has an access point for that elastic public IP address, the cloud management platform can create the cloud gateway in the target cloud data center and establish a network connection channel between the cloud gateway and the data center not part of the public cloud system. In this way, based on the access point, the cloud gateway, and the network connection channel, communication between the data center not part of the public cloud system and the clients of other tenants on the public network can be achieved.

[0062] The infrastructure comprises multiple cloud data centers (DCs), which can be deployed across multiple regions. Each region can contain multiple availability zones (AZs), and each AZ can contain several cloud data centers. These cloud data centers can be divided into two parts based on their function: one part is used to deploy access points for elastic public IP addresses, and the other part can be used to deploy tenant cloud resources (e.g., virtual machines, containers, etc.). Unlike the infrastructure of a public cloud system, data centers not belonging to a public cloud system can be either a tenant's on-premises data center or a cloud data center serving a third-party public cloud system (also referred to as another public cloud system's cloud data center). It is important to note that, for ease of explanation, the cloud data centers used to deploy tenant cloud resources within a public cloud system will be referred to as "on-premises resources," while data centers not belonging to a public cloud system will be referred to as "on-premises resources." The ownership of these two types of data centers differs: cloud data centers within the infrastructure of a public cloud system belong to a specific cloud vendor, while data centers not belonging to a public cloud system belong to the tenant or a third-party cloud vendor.

[0063] As shown in Figure 2 (Figure 2 is another structural diagram of the public cloud system provided in this application embodiment), since a tenant's business can include both cloud-based and on-premises services, cloud-based services are typically deployed in the tenant's cloud resources, and on-premises services are typically deployed in the tenant's on-premises resources. To enable both the tenant's cloud-based and on-premises resources to access the public network, according to the tenant's instructions, the cloud management platform can determine the elastic public IP address used by the tenant's cloud-based resources and the cloud data center where the access point of that elastic public IP address is located, as well as the elastic public IP address used by the tenant's on-premises resources and the cloud data center where the access point of that elastic public IP address is located. The elastic public IP addresses used by the cloud-based and on-premises resources are typically different IP addresses. Then, the cloud management platform can create communication channels between the cloud-based resources and the cloud data center where the access point of the elastic public IP address used by the cloud-based resources is located, as well as communication channels between the on-premises resources and the cloud data center where the access point of the elastic public IP address used by the on-premises resources is located. In this way, cloud-based and on-premises resources can respectively utilize their corresponding communication channels and elastic public IP address access points to communicate with the public network.

[0064] It should be noted that the access points of the elastic public IPs used for cloud resources and the access points of the elastic public IPs used on-premises can be located in the same cloud data center or in different cloud data centers, as shown in Figure 2.

[0065] It should also be noted that, since this application focuses on how tenants' on-premises resources access the public network, the following text will focus on the process of on-premises resources accessing the public network, while the process of cloud resources accessing the public network will not be discussed in this application.

[0066] Specifically, when a tenant needs to enable its on-premises resources to communicate with the public network, the tenant can send a public network resource configuration request for its on-premises resources to the cloud management platform. This request may include access point information for the elastic public IP used by the on-premises resources and cloud gateway creation information. Since the access point information includes the location information of the access point bound to the elastic public IP, which indicates the target cloud data center among the multiple cloud data centers in the infrastructure where the access point is located, and the cloud gateway creation information indicates the elastic public IP that the cloud gateway to be created needs to be bound to, and the target cloud data center has already created an access point for the elastic public IP (of course, the access point can also be created in real time), the cloud management platform can create the cloud gateway in the target cloud data center and create a network connection channel between the cloud gateway and the tenant's on-premises resources. In this way, based on the access point, the cloud gateway, and the network connection channel, communication between the tenant's on-premises resources and the clients of other tenants on the public network can be realized. This communication process will not be elaborated on here.

[0067] Furthermore, the network connection channel between the cloud gateway and the tenant's on-premises resources is any one or a combination of a dedicated network channel and a virtual private network (VPN).

[0068] Furthermore, as shown in Figure 3 (Figure 3 is another structural schematic diagram of the public cloud system provided in the embodiment of this application), within the target cloud data center, the messages used for communication between the access point and the cloud gateway are overlay messages. The inner message of the overlay message is a message received by the access point from the public network (Internet) outside the infrastructure of the public cloud system, or the inner message of the overlay message is a message received by the cloud gateway from on-premises resources. Generally, the overlay message can be a generic routing encapsulation (GRE) message or a virtual extensible local area network (VXLAN) message, etc. The following description uses VXLAN messages as an example of overlay messages. As shown in Figure 4 (Figure 4 is a schematic diagram of a VXLAN packet provided in an embodiment of this application), VXLAN is an overlay network technology. A VXLAN packet is an overlay packet obtained by tunneling an inner packet. The VXLAN packet includes a tunnel encapsulation header (also called a packet header) and an inner packet. The inner packet includes an inner Ethernet header, an inner IP header, and the data portion (payload) of the IP packet. The inner Ethernet header records the source MAC address and destination MAC address of the inner packet, and the inner IP header records the source IP address and destination IP address of the inner packet. The tunnel encapsulation header includes an outer Ethernet header, an outer IP header, an outer UDP header, and a VXLAN header. The VXLAN header includes the VXLAN Flags field (8 bits), the Reserved field (24 bits), the VNI (14 bits), and the Reserved field (24 bits).

[0069] Specifically, when the inner packet comes from the public network, the source IP address of the inner packet is a public IP address, and the destination IP address of the inner packet is an elastic public IP address used by the on-premises resource. When the inner packet comes from the on-premises resource, the source IP address of the inner packet is an elastic public IP address used by the on-premises resource, and the destination IP address is a public IP address.

[0070] Furthermore, certain cloud data centers within the infrastructure of a public cloud system deploy cloud resources serving tenants. These cloud resources can be presented in various forms. For example, they can be physical servers in the cloud data center (containing computing, storage, and network resources of a certain specification), or bare-metal servers in the cloud data center (containing computing, storage, and network resources of a certain specification). They can also be virtual machines (VMs) created by a cloud management platform on physical or bare-metal servers in the cloud data center using virtualization technology; containers (Docker) created by a cloud management platform on physical or bare-metal servers in the cloud data center using virtualization technology; or microvirtual machines (microVMs) created by a cloud management platform on physical or bare-metal servers in the cloud data center using virtualization technology, and so on.

[0071] Furthermore, data centers not part of a public cloud system can also deploy resources serving tenants. These resources can take various forms. For example, they can be physical servers in the on-premises data center, or bare-metal servers within the on-premises data center. They can also be virtual machines created by the on-premises management platform using virtualization technology on physical servers or bare-metal servers in the on-premises data center; containers created by the on-premises management platform using virtualization technology on physical servers or bare-metal servers in the on-premises data center; or micro-virtual machines created by the on-premises management platform using virtualization technology on physical servers or bare-metal servers in the on-premises data center, and so on.

[0072] Based on the aforementioned cloud service system, when a tenant needs to enable its on-premises resources to communicate with the public network, the tenant can provide the cloud management platform with the access point information of the elastic public IP used by the on-premises resources and the cloud gateway creation information. Since the access point information indicates the target cloud data center where the access point of the elastic public IP is located, and the cloud gateway creation information indicates the cloud gateway to be created and bound to the elastic public IP, and since the target cloud data center already has an access point for the elastic public IP, the cloud management platform can create the cloud gateway in the target data center and establish a network connection channel between the cloud gateway and the on-premises resources. Therefore, since the access point faces the public network and the cloud gateway faces the tenant's on-premises resources, the tenant's on-premises resources can communicate with the public network through the cloud gateway and the access point. Therefore, the cloud management platform can provide tenants with access points for elastic public IP addresses that can be used by their on-premises resources, as well as cloud gateways bound to those elastic public IP addresses, according to the tenants' needs. This allows the tenants' on-premises resources to communicate with the public network using these access points and cloud gateways, thus meeting the tenants' business needs for on-premises resources and providing diversified public network access services, thereby improving the tenants' public network access experience to a certain extent. To further understand the working process of the cloud management platform, the following description, in conjunction with Figure 5, illustrates this process. Figure 5 is a flowchart illustrating an elastic public IP configuration method based on a hybrid cloud scenario provided in this application embodiment. As shown in Figure 5, this method can be implemented through a public cloud system as shown in Figure 1 or Figure 2. The public cloud system includes infrastructure that can provide cloud services to tenants and a cloud management platform that manages this infrastructure. This infrastructure includes multiple cloud data centers. The method includes:

[0073] 501. The cloud management platform receives access point information of elastic public IPs input by the infrastructure tenants. The access point information includes the location information of the access point bound to the elastic public IP. The location information is used to indicate the target cloud data center where the access point is set in multiple cloud data centers.

[0074] 502. The cloud management platform receives cloud gateway creation information input by the tenant, whereby the cloud gateway creation information is used to indicate the elastic public IP that the cloud gateway to be created needs to be bound to.

[0075] In this embodiment, when a tenant needs its on-premises resources (data centers not belonging to the public cloud system, etc.) to communicate with the public network, the cloud management platform can provide a configuration interface to the tenant's client (e.g., the access point information input field and cloud gateway creation field on the tenant's interface). Therefore, the tenant can input its on-premises resource information, the access point information of the elastic public IP used by the on-premises resources, and the cloud gateway creation information into the configuration interface through its client. In this way, the cloud management platform can receive the on-premises resource information, access point information, and cloud gateway creation information sent by the tenant's client through the configuration interface. The on-premises resource information indicates the tenant's on-premises resources; the access point information may include the location information of the access point of the elastic public IP, which indicates the target cloud data center where the access point is located in multiple cloud data centers within the public cloud system; and the cloud gateway creation information indicates the cloud gateway to be created and bound to the elastic public IP.

[0076] Specifically, a tenant's on-premises resources can be used to deploy the tenant's on-premises services, which often need to communicate with other tenants' clients on the public network. Tenants' on-premises resources typically refer to data centers that are not part of a public cloud system. These data centers can include the tenant's local data centers and cloud data centers of third-party public cloud systems, etc. It should be noted that the public cloud system provided in this application and the third-party public cloud systems mentioned herein are cloud service systems developed by different cloud vendors.

[0077] More specifically, the on-premises resource information may include basic information about the tenant's on-premises resources (e.g., specifications, quantity, type, etc.) and the location of the on-premises resources; for example, the location may refer to the geographical location of the tenant's on-premises resources. The access point information may include the elastic public IP address of the access point and the location information of the access point. The location information may include the location of the target cloud data center where the access point is located; for example, the location may refer to the region and / or availability zone where the target cloud data center is located. The cloud gateway creation information may include the type and name of the cloud gateway to be created bound to the elastic public IP address; therefore, the cloud gateway creation information can be used to indicate the cloud gateway to be created.

[0078] For example, as shown in Figure 6 (Figure 6 is a schematic diagram of the tenant interface provided in this application embodiment), when tenant 1 needs to access its on-premises resources to the public network, tenant 1 can log in to the cloud management platform through its client. The cloud management platform can provide tenant 1 with a tenant interface, which may include an access point information input field, a cloud gateway creation field, and an on-premises resource information input field. Then, tenant 1 can enter the location of the access point 1 selected by tenant 1 as the South China region in the access point information input field. Therefore, the cloud management platform can select cloud data center a1 located in availability zone A of the South China region to create access point 1 for tenant 1. Subsequently, the cloud management platform can display multiple elastic public network IPs that access point 1 can provide to the tenant on the tenant interface. After tenant 1 selects a dedicated elastic public network IP 1 from these multiple elastic public network IPs, the cloud management platform can determine that elastic public network IP 1 is the elastic public network IP that tenant 1's on-premises resources can use.

[0079] Next, tenant 1 can enter the name and type of cloud gateway 1 bound to elastic public IP 1 in the cloud gateway creation field. The tenant can set the type of cloud gateway 1 as a leased gateway instance, so the cloud management platform can determine that cloud gateway 1 is the communication bridge between access point 1 and the tenant's on-premises resources.

[0080] Then, tenant 1 can also enter the basic information of the on-premises resources selected by tenant 1 in the on-premises resource information input field (for example, the type of these on-premises resources is local data center, etc.), and the location of these on-premises resources is XX Street, XX District, Guangzhou City.

[0081] 503. The cloud management platform creates a cloud gateway in the target cloud data center. The cloud gateway establishes a network connection channel with the data center that does not belong to the public cloud system. The cloud gateway records the first forwarding rule, which is used to instruct the cloud gateway to send packets with the destination address being an Elastic Public IP to the data center.

[0082] 504. The cloud gateway receives the first superimposed message sent by the access point. The inner message of the first superimposed message is a message received by the access point from the Internet outside the infrastructure. The destination address of the inner message of the first superimposed message is an Elastic Public IP.

[0083] 505. The cloud gateway sends the first message to the data center through the network connection channel according to the first forwarding rule. The first message is the inner message of the first superimposed message.

[0084] After obtaining the on-premises resource information, the access point information, and the cloud gateway creation information, the cloud management platform can determine that the tenant's on-premises resources need to use the elastic public IP address. Since the access point of the elastic public IP address is already set up in the target cloud data center, the cloud management platform can create a cloud gateway bound to the elastic public IP address in the target cloud data center, as well as a network connection channel between the cloud gateway and the tenant's on-premises resources. This network connection channel enables communication between the cloud gateway and the tenant's on-premises resources. It should be noted that the cloud gateway records a first forwarding rule, which instructs the cloud gateway to forward packets with the destination (IP) address of the elastic public IP address to the tenant's on-premises resources.

[0085] When clients of other tenants on the public network (Internet) send a first packet with the destination address of the Elastic Public IP to the access point, the access point can use the first packet as an inner packet of the first overlay packet and send the first overlay packet to the cloud gateway. After receiving the first overlay packet, the cloud gateway can parse the first overlay packet and remove its header to obtain the first packet. Due to the existence of the first forwarding rule and the destination address of the first packet being the Elastic Public IP, the cloud gateway can send the first packet to the tenant's on-premises resources through this network connection channel, enabling the tenant's on-premises resources to process the first packet and thus meet the business needs between the tenant and other tenants.

[0086] As in the example above, as shown in Figure 7 (Figure 7 is another structural diagram of the public cloud system provided in this application embodiment), after receiving various information input by tenant 1, the cloud management platform can select a cloud data center a1 in availability zone A of the South China region as the access point 1 of the elastic public IP 1, and create a cloud gateway 1 bound to the elastic public IP 1 in cloud data center a1, and create a network connection channel between cloud gateway 1 and the tenant's on-premises resources. Since tenant 1 selects the type of cloud gateway 1 as a dedicated line gateway instance, the network connection channel created by the cloud management platform is a dedicated line network channel (if tenant 1 selects the type of cloud gateway 1 as a VPN gateway instance, the network connection channel is a VPN network channel, etc.).

[0087] In addition, cloud gateway 1 has certain forwarding rules. For example, the rule is used to instruct cloud gateway 1 to forward a message to the tenant's on-premises resources when it receives a message with a destination address of Elastic Public IP 1, and to forward a message to access point 1 when it receives a message with a destination address of a public IP.

[0088] When a client of tenant 2 in the public network sends message 1 with a destination address of Elastic Public IP 1 to access point 1, access point 1 can treat message 1 as an inner message of overlay message 1 and send overlay message 1 to cloud gateway 1. Upon receiving overlay message 1, cloud gateway 1 can parse overlay message 1 and remove its header to obtain message 1. It then forwards message 1 to tenant 1's on-premises resources via the network connection channel, enabling tenant 1's on-premises resources to process message 1. In this way, tenant 2's client can communicate with tenant 1's on-premises resources via the public network, thus meeting the business needs between tenants.

[0089] Specifically, the cloud gateway also records a second forwarding rule, which instructs the cloud gateway to send packets with a destination address of the Internet network address (also known as a public IP address) to the access point.

[0090] When a tenant's on-premises resources send a second packet with the source address being the elastic public IP and the destination address being a public IP (i.e., the IP address of the client of another tenant in the public network) to the cloud gateway through this network connection channel, due to the existence of the second forwarding rule, the cloud gateway can treat the second packet as an inner packet of the second overlay packet and send the second overlay packet to the access point. After obtaining the second overlay packet, the access point can parse the second overlay packet and remove its header to obtain the second packet. Since the destination address of the second packet is a public IP, the access point can send the second packet to the client of another tenant in the public network, so that the client of the other tenant can process the second packet, thereby meeting the business needs between the tenant and the other tenants.

[0091] Continuing with the example above, when a tenant's on-premises resource sends packet 2 (source address: elastic public IP1, destination address: the IP address of tenant 2's client in the public network) to cloud gateway 1 via this network connection channel, cloud gateway 1 can treat packet 2 as an inner packet of overlay packet 2 and send the overlay packet 2 to access point 1. Access point 1 can then parse the overlay packet 2 and remove its header to obtain packet 2. Since the destination address of packet 2 is the IP address of tenant 2's client in the public network, access point 1 can send packet 2 to tenant 2's client, enabling the client to process packet 2. In this way, tenant 1's on-premises resource can communicate with tenant 2's client via the public network, thus meeting the business needs between tenants.

[0092] More specifically, the cloud management platform can also perform the following operations:

[0093] The cloud management platform can also obtain real-time traffic data of the network connection channel between the cloud gateway and the tenant's on-premises resources (this traffic can be recorded by the cloud gateway and reported to the cloud management platform), and charge the tenant based on this traffic. Generally, the higher the traffic, the higher the fee charged by the cloud management platform to the tenant, and the lower the traffic, the lower the fee charged by the cloud management platform to the tenant.

[0094] As in the example above, the cloud management platform can monitor the network connection channel between cloud gateway 1 and the tenant's on-premises resources in real time, calculate the fees to be charged to the tenant based on the traffic, and notify the tenant of the fees through one or more means (e.g., SMS reminders or reminders on the tenant's interface, etc.) so that the tenant can pay the fees on the tenant's interface.

[0095] More specifically, tenants can also apply for another Elastic Public IP address for their on-premises resources. The cloud management platform can then create an access point for that Elastic Public IP address and a cloud gateway bound to it for the tenant's on-premises resources. Similarly, a network connection channel is established between the cloud gateway bound to the other Elastic Public IP address and the tenant's on-premises resources. Therefore, whether based on the aforementioned access point and cloud gateway bound to that Elastic Public IP address, or on an access point and cloud gateway bound to another Elastic Public IP address, the tenant's on-premises resources can communicate with the public network.

[0096] It should be noted that for information about the access point of another Elastic Public IP and the cloud gateway bound to that Elastic Public IP, please refer to the relevant sections on the access point of that Elastic Public IP and the cloud gateway bound to that Elastic Public IP mentioned above. They will not be repeated here.

[0097] As in the example above, as shown in Figure 8 (Figure 8 is another structural diagram of the public cloud system provided in this application embodiment), tenant 1 can also enter the location of another access point 2 selected by tenant 1 as the East China region at the access point information input field. Therefore, the cloud management platform can select cloud data center b1 located in availability zone B in the East China region to create access point 2 for tenant 1. Subsequently, the cloud management platform can display multiple elastic public IPs that access point 2 can provide to the tenant on the tenant interface. After tenant 1 selects a dedicated elastic public IP 2 from these multiple elastic public IPs, the cloud management platform can bind the elastic public IP 2 to tenant 1's on-premises resources in the future. In this way, elastic public IP 2 is the elastic public IP that tenant 1's on-premises resources can use.

[0098] Next, tenant 1 can enter the name and type of cloud gateway 2 bound to elastic public IP 2 in the cloud gateway creation field. The tenant can set the type of cloud gateway 2 as a leased gateway instance, so the cloud management platform can determine that cloud gateway 2 is the communication bridge between access point 2 and the tenant's on-premises resources.

[0099] Based on this, the cloud management platform can create a cloud gateway 2 bound to the elastic public IP address 2 in cloud data center b1 of availability zone B in the East China region, and create a network connection channel between cloud gateway 2 and the tenant's on-premises resources. Since tenant 1 selected cloud gateway 2 as a leased gateway instance, the network connection channel created by the cloud management platform is a leased network channel.

[0100] In addition, cloud gateway 2 has certain forwarding rules. For example, the rules are used to instruct cloud gateway 2 to forward a message to the tenant's on-premises resources when it receives a message with a destination address of Elastic Public IP 2, and to forward a message to access point 2 when it receives a message with a destination address of a public IP.

[0101] Regarding the communication process between on-premises resources and the public network implemented by Access Point 2 and Cloud Gateway 2, the process is similar to that implemented by Access Point 1 and Cloud Gateway 1. Therefore, multiple communication channels can exist between a tenant's on-premises resources and the public network (Access Point 1 and Cloud Gateway 1 form one communication channel, and Access Point 2 and Cloud Gateway 2 form another), allowing the tenant's on-premises resources to utilize more public network resources (Elastic Public IP1, Elastic Public IP2, and more bandwidth) to communicate with the public network.

[0102] It should be understood that in this embodiment, the access point and cloud gateway created by the cloud management platform can be either a virtual instance (e.g., a virtual machine or container, etc.) or a physical instance (e.g., a physical server, etc.), and no specific restrictions are imposed here.

[0103] In this embodiment, when a tenant needs to enable its on-premises resources to communicate with the public network, the tenant can provide the cloud management platform with the access point information of the elastic public IP used by the on-premises resources and the cloud gateway creation information. Since the access point information indicates the target cloud data center where the access point of the elastic public IP is located, and the cloud gateway creation information indicates the cloud gateway to be created bound to the elastic public IP, and since the target cloud data center has already created the access point of the elastic public IP, the cloud management platform can create the cloud gateway in the target data center and create a network connection channel between the cloud gateway and the on-premises resources. Then, when other tenants on the public network send a first packet with the destination address of the elastic public IP to the access point, the access point can use the first packet as an inner packet of a first overlay packet and send the first overlay packet to the cloud gateway. This allows the cloud gateway to send the first packet in the first overlay packet to the tenant's on-premises resources through the network connection channel, enabling the tenant's on-premises resources to process the first packet. Therefore, the cloud management platform can provide tenants with access points for elastic public IPs that can be used by the on-premises resources, as well as cloud gateways bound to those elastic public IPs, according to the tenants' needs. This allows the tenants' on-premises resources to communicate with the public network using the access points and cloud gateways, thus meeting the tenants' business needs for on-premises resources, providing diversified public network access services, and thereby improving the tenants' public network access experience to a certain extent.

[0104] The above is a detailed description of the elastic public IP configuration method based on a hybrid cloud scenario provided in the embodiments of this application. The following will introduce the cloud management platform provided in the embodiments of this application. Figure 9 is a structural diagram of the cloud management platform provided in the embodiments of this application. As shown in Figure 9, the cloud management platform is set up in a public cloud system, which also includes infrastructure, including multiple cloud data centers. The cloud management platform includes:

[0105] The first receiving module 901 is used to receive access point information of the Elastic Public IP input by the tenant of the infrastructure, wherein the access point information includes the location information of the access point bound to the Elastic Public IP, and the location information is used to indicate the target cloud data center where the access point is set in multiple cloud data centers; for example, the first receiving module 901 is used to implement step 501 in the embodiment shown in FIG5.

[0106] The second receiving module 902 is used to receive cloud gateway creation information input by the tenant, wherein the cloud gateway creation information is used to indicate the elastic public IP that the cloud gateway to be created needs to be bound to; for example, the second receiving module 902 is used to implement step 502 in the embodiment shown in Figure 5.

[0107] The creation module 903 is used to create a cloud gateway in the target cloud data center. The cloud gateway has a network connection channel with the data center that does not belong to the public cloud system. The cloud gateway records a first forwarding rule, which is used to instruct the cloud gateway to send packets with a destination address of an elastic public IP to the data center. For example, the creation module 903 is used to implement step 503 in the embodiment shown in Figure 5.

[0108] The cloud gateway is used to: receive a first overlay message sent by an access point, wherein the inner message of the first overlay message is a message received by the access point from the Internet outside the infrastructure, and the destination address of the inner message of the first overlay message is an elastic public IP address; and send the first message to the data center through a network connection channel according to a first forwarding rule, wherein the first message is the inner message of the first overlay message. For example, the cloud gateway is used to implement steps 504 and 505 in the embodiment shown in Figure 5.

[0109] In one possible implementation, the cloud gateway also records a second forwarding rule, which instructs the cloud gateway to send packets with a destination address of the Internet to the access point; the cloud gateway is also used to: receive a second packet sent by the data center through a network connection channel, wherein the destination address of the second packet is a public IP address outside the infrastructure and the source address is an elastic public IP address; generate a second superimposed packet based on the second packet, and send the second superimposed packet to the access point according to the second forwarding rule, wherein the inner packet of the second superimposed packet is the second packet; the access point is used to receive the second superimposed packet and send the second packet to the Internet.

[0110] In one possible implementation, the cloud gateway is also used to record the traffic of the network connection channel.

[0111] In one possible implementation, the cloud management platform also includes a billing module for charging tenants based on traffic.

[0112] In one possible implementation, the network connection channel includes a leased network channel and / or a VPN network channel.

[0113] In one possible implementation, the data center can be a local data center or a cloud data center of a third-party public cloud system.

[0114] It should be noted that the information interaction and implementation process between the modules / units of the above-mentioned device are based on the same concept as the method embodiments of this application, and the resulting technical effects are the same as those of the method embodiments of this application. For details, please refer to the description in the method embodiments shown above in the embodiments of this application, and will not be repeated here.

[0115] Please refer to Figure 10, which is a schematic diagram of a computing device provided in an embodiment of this application. As shown in Figure 10, the computing device 1000 (which can be used to present the aforementioned cloud management platform, access point, or cloud gateway; for ease of explanation, the computing device 1000 is used as a cloud management platform in the following illustrative description) includes: a processor 1001, a memory 1002, a communication interface 1003, and a bus 1004. The processor 1001, memory 1002, and communication interface 1003 are coupled through the bus (not labeled in the figure). The memory 1002 stores instructions. When the execution instructions in the memory 1002 are executed, the computing device 1000 executes the method in the above-described method embodiment.

[0116] The computing device 1000 may be one or more integrated circuits configured to implement the methods described above, such as: one or more application-specific integrated circuits (ASICs), or one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs), or a combination of at least two of these forms of integrated circuits. Furthermore, when the units in the device can be implemented in the form of a processing element scheduler, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor capable of calling programs. Alternatively, these units may be integrated together and implemented as a system-on-a-chip (SOC).

[0117] The processor 1001 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor can be a microprocessor or any conventional processor.

[0118] The memory 1002 can be volatile memory or non-volatile memory, or it can include both. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0119] The memory 1002 stores executable program code, and the processor 1001 executes the executable program code to implement the functions of the aforementioned first receiving module, second receiving module, and creation module, thereby realizing the above-mentioned elastic public IP configuration method based on a hybrid cloud scenario. That is, the memory 1002 stores instructions for executing the above-mentioned elastic public IP configuration method based on a hybrid cloud scenario.

[0120] The communication interface 1003 uses transceiver modules such as, but not limited to, network interface cards and transceivers to enable communication between the computing device 1000 and other devices or communication networks.

[0121] In addition to the data bus, the 1004 bus can also include a power bus, a control bus, and a status signal bus. The bus can be a Peripheral Component Interconnect Express (PCIe) bus, an Extended Industry Standard Architecture (EISA) bus, a Unified Bus (Ubus or UB), a Compute Express Link (CXL) bus, a Cache Coherent Interconnect for Accelerators (CCIX) bus, etc. The bus can be divided into address bus, data bus, and control bus.

[0122] Please refer to Figure 11, which is a schematic diagram of a computing device cluster provided in an embodiment of this application. As shown in Figure 11, the computing device cluster 1100 includes at least one computing device 1000.

[0123] As shown in Figure 11, the computing device cluster 1100 includes at least one computing device 1000. The memory 1002 of one or more computing devices 1000 in the computing device cluster 1100 may store the same instructions for executing the above-described elastic public IP configuration method based on a hybrid cloud scenario.

[0124] In some possible implementations, the memory 1002 of one or more computing devices 1000 in the computing device cluster 1100 may also store partial instructions for executing the aforementioned elastic public IP configuration method based on a hybrid cloud scenario. In other words, a combination of one or more computing devices 1000 can jointly execute the aforementioned elastic public IP configuration method based on a hybrid cloud scenario.

[0125] It should be noted that the memory 1002 in different computing devices 1000 within the computing device cluster 1100 can store different instructions, which are used to execute certain functions of the aforementioned cloud management platform. That is, the instructions stored in the memory 1002 of different computing devices 1000 can implement the functions of one or more modules, such as the first receiving module, the second receiving module, and the creation module.

[0126] In some possible implementations, one or more computing devices 1000 in the computing device cluster 1100 can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc.

[0127] Please refer to Figure 12, which is a schematic diagram of computer devices in a computer cluster provided in an embodiment of this application being connected via a network. As shown in Figure 12, two computing devices 1000A and 1000B are connected via a network. Specifically, they are connected to the network through the communication interfaces in each computing device.

[0128] In one possible implementation, the memory in computing device 1000A stores instructions for performing the functions of modules such as the first receiving module and the second receiving module. Meanwhile, the memory in computing device 1000B stores instructions for performing the functions of modules such as the creation module.

[0129] It should be understood that the functions of computing device 1000A shown in Figure 12 can also be performed by multiple computing devices. Similarly, the functions of computing device 1000B can also be performed by multiple computing devices.

[0130] This application also relates to a computer storage medium storing a program for signal processing, which, when run on a computer, causes the computer to perform the steps executed by the cloud management platform in the embodiment shown in FIG5.

[0131] This application also relates to a computer program product that stores instructions that, when executed by a computer, cause the computer to perform the steps performed by the cloud management platform in the embodiment shown in FIG5.

[0132] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0133] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between apparatuses or units through some interfaces, and may be electrical, mechanical, or other forms.

[0134] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0135] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0136] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

Claims

1. A method for configuring elastic public IP addresses in a hybrid cloud scenario, characterized in that, The method is used in a cloud management platform of a public cloud system, the cloud management platform being used to manage the infrastructure of the public cloud system, the infrastructure including multiple cloud data centers, and the method comprising: The cloud management platform receives access point information of elastic public IPs input by the tenants of the infrastructure, wherein the access point information includes the location information of the access point bound to the elastic public IP, and the location information is used to indicate the target cloud data center where the access point is set in the multiple cloud data centers; The cloud management platform receives cloud gateway creation information input by the tenant, wherein the cloud gateway creation information is used to indicate the elastic public IP that the cloud gateway to be created needs to be bound to; The cloud management platform creates the cloud gateway in the target cloud data center. The cloud gateway establishes a network connection channel with the data center that does not belong to the public cloud system. The cloud gateway records a first forwarding rule, which is used to instruct the cloud gateway to send packets with the destination address of the elastic public IP to the data center. The cloud gateway receives a first superimposed message sent by the access point. The inner message of the first superimposed message is a message received by the access point from the Internet outside the infrastructure. The destination address of the inner message of the first superimposed message is the elastic public IP. The cloud gateway sends the first message to the data center through the network connection channel according to the first forwarding rule. The first message is the inner message of the first superimposed message.

2. The method according to claim 1, characterized in that, The cloud gateway also records a second forwarding rule, which is used to instruct the cloud gateway to send packets whose destination address is the network address of the Internet to the access point; The method further includes: The cloud gateway receives a second message sent by the data center through the network connection channel. The destination address of the second message is a public IP address outside the infrastructure, and the source address is the elastic public IP address. The cloud gateway generates a second superimposed message based on the second message, and sends the second superimposed message to the access point according to the second forwarding rule, wherein the inner message of the second superimposed message is the second message; The access point receives the second overlay message and sends the second message to the Internet.

3. The method according to claim 1 or 2, characterized in that, The method further includes: The cloud gateway records the traffic of the network connection channel.

4. The method according to claim 3, characterized in that, The method further includes: The cloud management platform charges the tenant based on the traffic.

5. The method according to any one of claims 1 to 4, characterized in that, The network connection channels include dedicated network channels and / or VPN network channels.

6. The method according to any one of claims 1 to 5, characterized in that, The data center can be a local data center or a cloud data center of a third-party public cloud system.

7. A public cloud system, characterized in that, The public cloud system includes a cloud management platform and infrastructure. The cloud management platform is used to manage the infrastructure, which includes multiple cloud data centers, wherein: A cloud management platform is used to receive access point information of elastic public IPs input by tenants of the infrastructure, wherein the access point information includes the location information of the access point bound to the elastic public IP, and the location information is used to indicate the target cloud data center where the access point is set in the multiple cloud data centers; The cloud management platform is also used to receive cloud gateway creation information input by the tenant, wherein the cloud gateway creation information is used to indicate the elastic public IP that the cloud gateway to be created needs to be bound to; The cloud management platform is also used to create the cloud gateway in the target cloud data center. The cloud gateway establishes a network connection channel with the data center that does not belong to the public cloud system. The cloud gateway records a first forwarding rule, which is used to instruct the cloud gateway to send packets with the destination address of the elastic public IP to the data center. The cloud gateway is used to receive a first superimposed message sent by the access point. The inner message of the first superimposed message is a message received by the access point from the Internet outside the infrastructure. The destination address of the inner message of the first superimposed message is the elastic public IP. The cloud gateway is further configured to send a first message to the data center through the network connection channel according to the first forwarding rule, wherein the first message is an inner message of the first superimposed message.

8. The system according to claim 7, characterized in that, The cloud gateway also records a second forwarding rule, which is used to instruct the cloud gateway to send packets whose destination address is the network address of the Internet to the access point; The cloud gateway is also used to receive a second message sent by the data center through the network connection channel, wherein the destination address of the second message is a public IP address outside the infrastructure and the source address is the elastic public IP address; The cloud gateway is further configured to generate a second superimposed message based on the second message, and send the second superimposed message to the access point according to the second forwarding rule, wherein the inner message of the second superimposed message is the second message; The access point is used to receive the second superimposed message and send the second message to the Internet.

9. The system according to claim 7 or 8, characterized in that, The cloud gateway is also used to record the traffic of the network connection channel.

10. The system according to claim 9, characterized in that, The cloud management platform is also used to charge the tenant based on the traffic.

11. The system according to any one of claims 7 to 10, characterized in that, The network connection channels include dedicated network channels and / or VPN network channels.

12. The system according to any one of claims 7 to 11, characterized in that, The data center can be a local data center or a cloud data center of a third-party public cloud system.

13. A computing device cluster, characterized in that, The computing device cluster includes at least one computing device, each computing device including a processor and memory: The memory is used to store instructions; The processor is configured to, according to the instructions, cause the computing device cluster to perform the method of any one of claims 1 to 6.

14. A computer storage medium, characterized in that, The computer storage medium stores one or more instructions that, when executed by one or more computers, cause the one or more computers to perform the method according to any one of claims 1 to 6.

15. A computer program product, characterized in that, The computer program product stores instructions that, when executed by a computer, cause the computer to perform the method described in any one of claims 1 to 6.