Method for managing network traffic and electronic device using same

WO2026116527A1PCT designated stage Publication Date: 2026-06-04NETLOX CO LTD

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
NETLOX CO LTD
Filing Date
2024-11-27
Publication Date
2026-06-04

Smart Images

  • Figure KR2024019050_04062026_PF_FP_ABST
    Figure KR2024019050_04062026_PF_FP_ABST
Patent Text Reader

Abstract

An electronic device according to various embodiments may comprise the operations of: switching from a first proxy mode to a second proxy mode on an open source platform; in the second proxy mode, directly processing a network packet in a kernel plane on the basis of an eBPF; and, in the second proxy mode, managing traffic on the basis of IPVS rules. Other embodiments are also possible.
Need to check novelty before this filing date? Find Prior Art

Description

Network traffic management method and electronic device using the same

[0001] Various embodiments of the present invention relate to a network traffic management method and an electronic device using the same.

[0002] In the Fourth Industrial Revolution, which is a hot topic today, various types of data can be hyper-connected through various devices. In this environment, the market for innovative convergence new products and service solutions that reflect user needs may expand, and to support this, it may be necessary to build a network infrastructure capable of processing various types of data without loss.

[0003] To enhance Kubernetes network performance, an eBPF-based load balancer can be used in service proxy mode. The load balancer can replace the existing Kubernetes network proxy (kube-proxy) to manage network traffic more efficiently and improve performance, scalability, and security even in situations of large-scale traffic.

[0004] According to various embodiments, a method of an electronic device may include: switching from a first proxy mode to a second proxy mode on an open source platform; processing network packets directly in the kernel plane based on eBPF in the second proxy mode; and managing traffic based on IPVS rules in the second proxy mode.

[0005] According to various embodiments of the present invention, a load balancer can be deployed as a DaemonSet in a Kubernetes cluster and can serve as a substitute for a Kubernetes network proxy. The load balancer can efficiently process packets by implementing data paths based on eBPF. Through this, the load balancer can perform load balancing, apply granular network policies, and provide visibility into network traffic.

[0006] FIG. 1 is a block diagram of an electronic device in a network environment according to various embodiments of the present invention.

[0007] FIG. 2 is a block diagram of a program according to various embodiments of the present invention.

[0008] FIG. 3 is a schematic diagram showing Kubernetes cluster nodes through a load balancer according to various embodiments of the present invention.

[0009] FIG. 4 is a schematic diagram illustrating the provision of a service proxy on a Kubernetes node through a load balancer according to various embodiments of the present invention.

[0010] FIG. 5 is a schematic diagram illustrating the flow of providing a service proxy of a load balancer according to various embodiments of the present invention.

[0011] FIG. 6 is a schematic diagram illustrating a method for processing packets using a service proxy mode of a load balancer according to various embodiments of the present invention.

[0012] FIG. 1 is a block diagram of an electronic device (101) in a network environment (100) according to various embodiments. Referring to FIG. 1, in the network environment (100), the electronic device (101) may communicate with an electronic device (102) through a first network (198) (e.g., a short-range wireless communication network) or with an electronic device (104) or a server (108) through a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) through a server (108). According to one embodiment, the electronic device (101) may include a processor (120), memory (130), input device (150), sound output device (155), display device (160), audio module (170), sensor module (176), interface (177), haptic module (179), camera module (180), power management module (188), battery (189), communication module (190), subscriber identification module (196), or antenna module (197). In some embodiments, at least one of these components (e.g., display device (160) or camera module (180)) may be omitted from the electronic device (101), or one or more other components may be added. In some embodiments, some of these components may be implemented as a single integrated circuit. For example, a sensor module (176) (e.g., fingerprint sensor, iris sensor, or light sensor) can be implemented embedded in a display device (160) (e.g., display).

[0013] The processor (120) can control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) by executing software (e.g., a program (140)), for example, and can perform various data processing or operations. According to one embodiment, as at least part of the data processing or operations, the processor (120) can load commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) into volatile memory (132), process the commands or data stored in volatile memory (132), and store the resulting data in non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) and an auxiliary processor (123) (e.g., a graphics processing unit, an image signal processor, a sensor hub processor, or a communication processor) that can operate independently or together with the main processor (121). Additionally or generally, the auxiliary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a designated function. The auxiliary processor (123) may be implemented separately from the main processor (121) or as part thereof.

[0014] The auxiliary processor (123) can control at least some of the functions or states associated with at least one component of the electronic device (101) (e.g., display device (160), sensor module (176), or communication module (190)) on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. According to one embodiment, the auxiliary processor (123) (e.g., image signal processor or communication processor) may be implemented as part of another functionally related component (e.g., camera module (180) or communication module (190)).

[0015] The memory (130) can store various data used by at least one component of the electronic device (101) (e.g., processor (120) or sensor module (176)). The data may include, for example, input data or output data for software (e.g., program (140)) and related commands. The memory (130) may include volatile memory (132) or non-volatile memory (134).

[0016] The program (140) may be stored as software in memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).

[0017] The input device (150) can receive commands or data to be used for a component of the electronic device (101) (e.g., processor (120)) from outside the electronic device (101) (e.g., user). The input device (150) may include, for example, a microphone, a mouse, or a keyboard.

[0018] The sound output device (155) can output a sound signal to the outside of the electronic device (101). The sound output device (155) may include, for example, a speaker or a receiver. The speaker may be used for general purposes such as multimedia playback or recording playback, and the receiver may be used to receive incoming calls. According to one embodiment, the receiver may be implemented separately from the speaker or as part thereof.

[0019] The display device (160) can visually provide information to an external (e.g., user) of the electronic device (101). The display device (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling said device. According to one embodiment, the display device (160) may include a touch circuitry configured to detect a touch, or a sensor circuitry configured to measure the intensity of the force generated by said touch (e.g., a pressure sensor).

[0020] The audio module (170) can convert sound into an electrical signal or, conversely, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through an input device (150) or output sound through an audio output device (155) or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphones) that is directly or wirelessly connected to the electronic device (101).

[0021] The sensor module (176) can detect the operating state of the electronic device (101) (e.g., power or temperature) or the external environmental state (e.g., user state) and generate an electrical signal or data value corresponding to the detected state. According to one embodiment, the sensor module (176) may include, for example, a gesture sensor, a gyroscope sensor, a barometric pressure sensor, a magnetic sensor, an accelerometer sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biosensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0022] The interface (177) may support one or more specified protocols that can be used for the electronic device (101) to be connected directly or wirelessly to an external electronic device (e.g., electronic device (102)). According to one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0023] The connection terminal (178) may include a connector through which the electronic device (101) can be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0024] The haptic module (179) can convert an electrical signal into a mechanical stimulus (e.g., vibration or movement) or an electrical stimulus that the user can perceive through tactile or kinesthetic senses. According to one embodiment, the haptic module (179) may include, for example, a motor, a piezoelectric element, or an electric stimulation device.

[0025] The camera module (180) can capture still images and video. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.

[0026] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (388) can be implemented, for example, as at least part of a power management integrated circuit (PMIC).

[0027] The battery (189) can supply power to at least one component of the electronic device (101). According to one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0028] The communication module (190) can support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between an electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may include one or more communication processors that operate independently of the processor (120) (e.g., application processor) and support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., cellular communication module, short-range wireless communication module, or GNSS (global navigation satellite system) communication module) or a wired communication module (194) (e.g., LAN (local area network) communication module, or power line communication module). The corresponding communication module among these communication modules can communicate with an external electronic device through a first network (198) (e.g., a short-range communication network such as Bluetooth, Wi-Fi Direct, or IrDA (infrared data association)) or a second network (199) (e.g., a cellular network, the Internet, or a long-range communication network such as a computer network (e.g., LAN or WAN). These various types of communication modules may be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can identify and authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) using subscriber information (e.g., International Mobile Subscriber Identifier (IMSI)) stored in the subscriber identification module (196).

[0029] The antenna module (197) can transmit a signal or power to or from the outside (e.g., an external electronic device). According to one embodiment, the antenna module (197) may include one or more antennas, from which at least one antenna suitable for a communication method used in a communication network such as a first network 198 or a second network 199 may be selected, for example, by the communication module (190). The signal or power may be transmitted or received between the communication module (190) and the external electronic device through the selected at least one antenna.

[0030] At least some of the above components can be connected to each other via a communication method between peripheral devices (e.g., bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)) and exchange signals (e.g., commands or data) with each other.

[0031] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) through a server (108) connected to a second network (199). Each of the electronic devices (102, 104) may be the same or different type of device as the electronic device (101). According to one embodiment, all or part of the operations performed on the electronic device (101) may be performed on one or more of the external electronic devices (102, 104, or 108). For example, if the electronic device (101) needs to perform a function or service automatically or in response to a request from a user or another device, the electronic device (101) may request one or more external electronic devices to perform at least part of the function or service instead of performing the function or service itself or additionally. One or more external electronic devices that receive the above request may execute at least part of the requested function or service, or additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may provide the result as is or additionally processed as at least part of the response to the request. For this purpose, for example, cloud computing, distributed computing, or client-server computing technology may be used.

[0032] FIG. 2 is a block diagram (200) of a program (140) according to various embodiments. According to one embodiment, the program (140) may include an operating system (142), middleware (144), or an application (146) executable on the operating system (142) for controlling one or more resources of an electronic device (101). The operating system (142) is, for example, Android TM , iOS TM , Windows TM , Symbian TM, Tizen TM , or Bada TM It may include. At least some of the programs (140) may be preloaded into the electronic device (101) at manufacturing time, for example, or downloaded or updated from an external electronic device (e.g., electronic device (102 or 104), or server (108)) in the user's usage environment.

[0033] The operating system (142) can control (e.g., allocate or reclaim) system resources (e.g., processes, memory, or power) of the electronic device (101). The operating system (142) may additionally or substantially include one or more driver programs for driving other hardware devices of the electronic device (101), e.g., an input device (150), an audio output device (155), a display device (160), an audio module (170), a sensor module (176), an interface (177), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197).

[0034] Middleware (144) may provide various functions to the application (146) so that the application (146) can use the functions or information provided by one or more resources of the electronic device (101). Middleware (144) may include, for example, an application manager (201), a window manager (203), a multimedia manager (205), a resource manager (207), a power manager (209), a database manager (211), a package manager (213), a connectivity manager (215), a notification manager (217), a location manager (219), a graphics manager (221), a security manager (223), a call manager (225), or a voice recognition manager (227). The application manager (201) may, for example, manage the lifecycle of the application (146). The window manager (203) may, for example, manage GUI resources used on the screen. The multimedia manager (205) can, for example, identify the format required for the playback of media files and perform encoding or decoding of the media files using a codec that matches the format. The resource manager (207) can, for example, manage the source code or memory space of the application (146). The power manager (209) can, for example, manage the capacity, temperature, or power of the battery and, using the relevant information, determine or provide power information required for the operation of the electronic device (101). According to one embodiment, the power manager (209) can be linked with the BIOS (basic input / output system).

[0035] The database manager (211) can, for example, create, search, or modify a database to be used in the application (146). The package manager (213) can, for example, manage the installation or update of an application distributed in the form of a package file. The connectivity manager (215) can, for example, manage a wireless or wired connection between the electronic device (101) and an external electronic device. The notification manager (217) can, for example, provide a function to notify the user of an event that has occurred (e.g., a call, a message, or an alarm). The location manager (219) can, for example, manage location information of the electronic device (101). The graphics manager (221) can, for example, manage graphic effects to be provided to the user or a user interface related thereto. The security manager (223) can, for example, provide system security or user authentication. The telephony manager (225) can, for example, manage voice or video call functions of the electronic device (101). The voice recognition manager (227) may, for example, transmit the user's voice data to the server (108) and receive a command corresponding to a function to be performed on the electronic device (101) based on the voice data, or text data converted based on the voice data. According to one embodiment, the middleware (244) may dynamically delete some existing components or add new components. According to one embodiment, at least a portion of the middleware (144) may be included as part of the operating system (142) or implemented as software separate from the operating system (142).

[0036] The application (146) may include, for example, a home (251), a dialer (253), an SMS / MMS (255), an IM (instant message) (257), a browser (259), a camera (261), an alarm (263), a contact (265), a voice recognition (267), an email (269), a calendar (271), a media player (273), an album (275), a watch (277), a health (279) (e.g., measuring exercise volume or blood sugar, etc.), or an environmental information (281) (e.g., atmospheric pressure, humidity, or temperature information). According to one embodiment, the application (146) may further include an information exchange application (not shown) capable of supporting information exchange between the electronic device (101) and an external electronic device. The information exchange application may include, for example, a notification relay application for transmitting information (e.g., a call, a message, or an alarm) designated to an external electronic device, or a device management application for managing the external electronic device. The notification relay application may, for example, transmit notification information corresponding to an event (e.g., receiving mail) generated in another application of the electronic device (101) (e.g., an email application (269)) to the external electronic device, or receive notification information from the external electronic device and provide it to the user of the electronic device (101). The device management application may, for example, control the power (e.g., turn-on or turn-off) or function (e.g., brightness, resolution, or focus of the display device (160) or camera module (180)) of the external electronic device or some component thereof that communicates with the electronic device (101). A device management application can additionally or substantially support the installation, deletion, or updating of applications running on external electronic devices.

[0037] The electronic device according to the various embodiments disclosed in this document may be of various forms. The electronic device may include, for example, a portable communication device (e.g., a smartphone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a consumer electronics device. The electronic device according to the embodiments of this document is not limited to the devices described above.

[0038] The various embodiments of this document and the terms used therein are not intended to limit the technical features described in this document to specific embodiments, and should be understood to include various modifications, equivalents, or substitutions of such embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of said items unless the relevant context clearly indicates otherwise. In this document, phrases such as "A or B," "at least one of A and B," "at least one of A or B," "A, B or C," "at least one of A, B and C," and "at least one of A, B, or C" may each include any possible combination of items listed together in the corresponding phrase. Terms such as "first," "second," or "first" or "second" may be used simply to distinguish a component from another corresponding component and do not limit the components in any other aspect (e.g., importance or order). Where any (e.g., 1st) component is referred to as “coupled” or “connected” to another (e.g., 2nd) component, with or without the terms “functionally” or “communicationly,” it means that said any component may be connected to said other component directly (e.g., via a wire), wirelessly, or through a third component.

[0039] As used in this document, the term "module" may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be a component formed integrally, or a minimum unit of said component or a part thereof that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0040] Various embodiments of the present document may be implemented as software (e.g., program (140)) comprising one or more instructions stored in a storage medium (e.g., internal memory (136) or external memory (138)) readable by a machine (e.g., electronic device (101)). For example, a processor (e.g., processor (120)) of the machine (e.g., electronic device (101)) may call at least one of the one or more instructions stored in the storage medium and execute it. This enables the machine to be operated to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code that can be executed by an interpreter. The storage medium readable by the machine may be provided in the form of a non-transitory storage medium. Here, 'non-temporary' merely means that the storage medium is a tangible device and does not contain a signal (e.g., electromagnetic waves), and this term does not distinguish between cases where data is stored semi-permanently and cases where it is stored temporarily.

[0041] According to one embodiment, the method according to the various embodiments disclosed herein may be provided by being included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or distributed online (e.g., download or upload) through an application store (e.g., Play Store™) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.

[0042] According to various embodiments, each component (e.g., module or program) of the components described above may include a singular or multiple entities. According to various embodiments, one or more of the components or operations among the aforementioned components may be omitted, or one or more other components or operations may be added. Generally or additionally, multiple components (e.g., module or program) may be integrated into a single component. In this case, the integrated component may perform one or more functions of each of the components of the multiple components in the same or similar manner as those performed by the corresponding component among the multiple components prior to the integration. According to various embodiments, operations performed by the module, program, or other components may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

[0043] FIG. 3 is a schematic diagram showing Kubernetes cluster nodes through a load balancer according to various embodiments of the present invention.

[0044] According to various embodiments, with reference to FIG. 300, a Kubernetes cluster node may operate as a Kubernetes network proxy (310) or a service proxy (320) of a load balancer. For example, Kubernetes may correspond to a platform that automatically manages and orchestrates containerized applications.

[0045] According to various embodiments, the Kubernetes network proxy (310) may operate using iptables or IPVS (IP virtual server) at the kernel level. The Kubernetes network proxy (310) may add iptables rules to route and load balance traffic between services and pods within the cluster, thereby forwarding packets to the appropriate pods.

[0046] According to various embodiments, the Kubernetes network proxy (310) can use iptables to create network rules and manage the mapping between the service IP and the pod IP that provides it. This allows for control so that traffic for the service cluster IP is forwarded to the correct pod. For example, if the Kubernetes network proxy (310) uses iptables, the speed may become slower as the number of rules increases, which may lead to performance degradation in large clusters. However, there may be advantages in that it is simple and easy to configure.

[0047] According to various embodiments, the Kubernetes network proxy (310) may also support an IPVS mode, which has higher performance than iptables, and may be efficient, especially in situations where high performance and large volumes of traffic need to be handled. The Kubernetes network proxy (310) can perform load balancing in a more optimized way at the kernel level through IPVS. For example, when the Kubernetes network proxy (310) uses IPVS, it operates at the kernel level, processes network rules faster, and efficiently distributes the load to handle more traffic.

[0048] According to various embodiments, Kubernetes manages network traffic using iptables at the kernel level by default, but can optimize performance by switching to IPVS mode as needed. However, although the Kubernetes network proxy (310) is a core component for handling network traffic between services in Kubernetes, there may be limitations in its performance and scalability. In this case, the Kubernetes node can operate in the service proxy (320) mode of the load balancer.

[0049] According to various embodiments, the service proxy (320) may operate based on eBPF (extended Berkeley packet filter). Specifically, eBPF may correspond to a technology that efficiently processes packets in the Linux kernel and supports additional network functions. Through this, the service proxy (320) can directly process network traffic at the kernel level to increase speed and stability.

[0050] FIG. 4 is a schematic diagram illustrating the provision of a service proxy on a Kubernetes node through a load balancer according to various embodiments of the present invention.

[0051] According to various embodiments, the load balancer (421) may operate in service proxy mode (423) to replace the Kubernetes network proxy and improve speed and throughput by processing network packets directly in the Linux kernel via eBPF. For example, a host (410) may establish a network connection with a Kubernetes node (420) in the service proxy mode (423) of the load balancer (421).

[0052] According to various embodiments, the load balancer (421) can process network packets directly in the kernel using eBPF in service proxy mode (423), so network latency can be reduced and processing speed can be increased.

[0053] According to various embodiments, the load balancer (421) replaces the Kubernetes network proxy in service proxy (423) mode, and can optimize IPVS rules and manage service traffic more effectively.

[0054] According to various embodiments, the load balancer (421) may be compatible with or integrated with existing CNIs (container network interfaces, e.g., Flannel, Calico, etc.) that support Kubernetes networking in service proxy (423) mode. This allows the load balancer (421) to be used without significantly changing the existing network configuration.

[0055] According to various embodiments, the load balancer (421) is deployed as a daemon set in a Kubernetes cluster and can act as a Kubernetes network proxy. The eBPF can implement data paths to efficiently process packets.

[0056] According to various embodiments, the load balancer (421) can perform load balancing and can distribute traffic for ClusterIP, NodePort, and LoadBalancer services at high performance.

[0057] According to various embodiments, the load balancer (421) can apply network policies and enhance security in a fine and efficient manner through eBPF.

[0058] According to various embodiments, the load balancer (421) can track network connections and collect performance metrics through eBPF, thereby providing visibility into network traffic.

[0059] According to various embodiments, the load balancer (421) is installed in a Kubernetes cluster and can be used by setting service rules and IP ranges in the Kubernetes manifest.

[0060] FIG. 5 is a schematic diagram illustrating the flow of providing a service proxy of a load balancer according to various embodiments of the present invention.

[0061] According to various embodiments, a load balancer can replace a Kubernetes network proxy with a service proxy within a Kubernetes cluster in a 511 operation.

[0062] According to various embodiments, the load balancer can process network packets directly in the kernel area using eBPF at the service proxy in 513 operation.

[0063] According to various embodiments, the load balancer can manage traffic by inheriting and optimizing IPVS rules from the service proxy in 515 operation.

[0064] FIG. 6 is a schematic diagram illustrating a method for processing packets using a service proxy mode of a load balancer according to various embodiments of the present invention.

[0065] According to various embodiments, with reference to FIG. 600, a load balancer can process data packets using a service-proxy mode. For example, the load balancer can assign IPVS rules to an eBPF table through the control plane. Subsequently, the load balancer can process packets based on the eBPF table through the data plane.

[0066] According to various embodiments, with reference to FIG. 600, the load balancer can operate in service proxy mode, replacing the kube-proxy. When a user adds a new Kubernetes service, the kube-proxy can add an IPVS rule. The load balancer can acquire the added IPVS rule and translate it into a rule of the load balancer. The load balancer can help process the user's request based on eBPF by optimizing the path with eBPF.

[0067] According to various embodiments, a method of an electronic device may include: switching from a first proxy mode to a second proxy mode on an open source platform; processing network packets directly in the kernel plane based on eBPF in the second proxy mode; and managing traffic based on IPVS rules in the second proxy mode.

[0068] It may include an operation that provides load balancing for ClusterIP, NodePort, and LoadBalancer services.

[0069] It may include operations to reduce the load by applying network policies using eBPF.

[0070] It may include an operation to integrate with the existing CNI of the above open source platform.

[0071] The above open source platform may be Kubenetes.

[0072] The above first proxy mode may be a Kubernetes network proxy.

[0073] The above existing CNI may include Flannel or Calico.

[0074] The above first proxy mode can process network packets using at least one iptable.

Claims

1. In a method of an electronic device, The action of switching from a first proxy mode to a second proxy mode on an open source platform; In the above second proxy mode, an operation of processing network packets directly in the kernel plane based on eBPF; and A method of an electronic device comprising an operation to manage traffic based on IPVS rules in the above-mentioned second proxy mode.

2. In Paragraph 1, A method of an electronic device comprising an operation to provide load balancing for ClusterIP, NodePort, and LoadBalancer services.

3. In Paragraph 2, A method of an electronic device including an operation to reduce load by applying a network policy using eBPF.

4. In Paragraph 3, A method of an electronic device comprising an operation to integrate with an existing CNI of the above-mentioned open source platform.

5. In Paragraph 4, The above open source platform is a method of electronic devices that is Kubenetes.

6. In Paragraph 5, The above first proxy mode is a method of an electronic device that is a Kubernetes network proxy.

7. In Paragraph 6, The above existing CNI is a method of an electronic device including Flannel or Calico.

8. In Paragraph 7, The above first proxy mode is a method of an electronic device that processes network packets using at least one iptable.