Direct connect-based cloud storage service access method and apparatus, and electronic device
By creating virtual private clouds and subnets in cloud storage services, and utilizing dedicated storage gateways for Self-Twice-NAT mapping and VxLAN tunnel optimization, the problem of users being unable to customize IP addresses is solved, achieving highly secure and flexible cloud storage access.
Patent Information
- Application Number
- PCT/CN2025/136458
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-12-03
- Filing Date
- 2025-11-20
- Publication Date
- 2026-06-11
Smart Images

Figure CN2025136458_11062026_PF_FP_ABST
Abstract
Description
A method, apparatus, and electronic device for accessing cloud storage services based on cloud private lines.
[0001] Cross-references to related applications
[0002] This application claims priority to Chinese Patent Application No. 202411761754.9, filed on December 3, 2024, entitled "A method, apparatus and electronic device for accessing cloud storage services based on cloud private lines", the entire contents of which are incorporated herein by reference. Technical Field
[0003] This application relates to the field of cloud computing technology, and in particular to a cloud storage service access method based on a cloud private line, a cloud storage service access device based on a cloud private line, an electronic device, and a computer-readable medium. Background Technology
[0004] A cloud leased line is a dedicated connection channel that establishes a connection between a user's on-premises data center and a cloud service provider's Virtual Private Cloud (VPC). Strictly speaking, a cloud leased line is a service where one end of the physical leased line connects to the user's on-premises data center's local gateway device, and the other end connects to the cloud computing center's leased line gateway, connecting the customer's on-premises data center's internal LAN to the cloud computing center's access point, and then interfacing with the cloud computing center's Virtual Private Network (VPC). Compared to accessing cloud systems and applications via the internet, cloud leased lines offer advantages such as security, high speed, low latency, and stability and reliability.
[0005] Cloud storage is a network storage technology built on cloud computing; it's a cloud computing system centered on data storage and management. Cloud storage provides storage to users as a network service, offering immense convenience and is commonly used for storing images, videos, or various static files. For users, cloud storage doesn't refer to a single, specific storage device, but rather a storage system comprised of numerous physical or virtual servers and storage devices. Strictly speaking, cloud storage is a service that provides users with storage and access services.
[0006] Currently, the only way for users to access cloud storage services from their local data centers is through standard internet access; users cannot customize the IP (Internet Protocol) address of the storage service. Summary of the Invention
[0007] This application provides a cloud storage service access method, a cloud storage service access device, an electronic device, and a computer-readable storage medium based on a cloud dedicated line, to solve the problem that in the prior art, when accessing cloud storage services through the standard Internet, users cannot customize the IP address of the storage service.
[0008] This application discloses a method for accessing cloud storage services based on a cloud private line, including:
[0009] S1: Create a virtual private cloud and subnet for cloud storage services;
[0010] S2: Virtual private cloud and subnet based on cloud storage service, with cloud storage service enabled;
[0011] S3: Based on the virtual private cloud and subnet of cloud storage services, apply for the IP address of cloud storage services and the real IP address of cloud storage services to build a dedicated storage gateway;
[0012] S4: Activate cloud dedicated line service, specify the local data center network segment, and access the virtual private cloud and subnet of cloud storage service based on dedicated line storage gateway.
[0013] This application discloses a cloud storage service access device based on a cloud private line, including:
[0014] Create modules for creating virtual private clouds and subnets for cloud storage services;
[0015] Enable the module for virtual private clouds and subnets based on cloud storage services, and enable cloud storage services;
[0016] The building module is used to construct a dedicated storage gateway based on the virtual private cloud and subnet of cloud storage services, apply for the IP address of cloud storage services, and the real IP address of cloud storage services.
[0017] The access module is used to activate cloud dedicated line services, specify the local data center network segment, and access the virtual private cloud and subnet of cloud storage services based on the dedicated line storage gateway.
[0018] This application also discloses an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;
[0019] Memory, used to store computer programs;
[0020] When a processor executes a program stored in memory, it implements a cloud storage service access method based on a cloud private line, as described in the embodiments of this application.
[0021] This application also discloses one or more computer-readable media storing instructions that, when executed by one or more processors, cause the processors to perform the cloud storage service access method based on cloud private lines as described in this application.
[0022] The embodiments of this application have the following advantages:
[0023] This application utilizes a dedicated storage gateway to enable simultaneous source-destination address translation for traffic in the same direction on the same gateway device. Users can flexibly customize the IP address of their cloud storage service. Users only need to access the customized storage service IP, preventing attackers from directly locating the storage service's real IP, thus enhancing storage service security. It supports binding the same storage service's real IP address to multiple custom IPs, thereby meeting the access needs of different subnets, tenants, or business modules. In the event of network failure or changes to the storage service IP, users only need to adjust the mapping relationship of the custom IPs without modifying local network configurations, thereby enhancing the system's disaster recovery capabilities and flexibility. Attached Figure Description
[0024] Figure 1 is a flowchart of the steps of a cloud storage service access method based on a cloud private line provided in an embodiment of this application;
[0025] Figure 2 is a diagram of a dedicated cloud network architecture provided in an embodiment of this application;
[0026] Figure 3 is a network architecture diagram of a cloud host accessing cloud storage service provided in an embodiment of this application;
[0027] Figure 4 is a network architecture diagram of a local data center or a cloud storage service for accessing a cloud computing center from a different cloud, provided in an embodiment of this application.
[0028] Figure 5 is a block diagram of a cloud storage service access device based on a cloud private line provided in an embodiment of this application;
[0029] Figure 6 is a block diagram of an electronic device provided in an embodiment of this application;
[0030] Figure 7 is a schematic diagram of a computer-readable medium provided in an embodiment of this application. Detailed Implementation
[0031] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0032] Referring to Figure 1, a flowchart of the steps of a cloud storage service access method based on a cloud private line provided in an embodiment of this application is shown.
[0033] The method for accessing cloud storage services based on cloud private lines may include the following steps:
[0034] S1: Create a virtual private cloud and subnet for cloud storage services.
[0035] Virtual Private Cloud (VPC) is a completely isolated, user-customizable virtual network environment provided by cloud service providers. VPC allows users to build their own network topology in the cloud, similar to an independent data center.
[0036] This refers to the network partitioning units within a VPC, used to further subdivide the IP address range of the VPC. Each subnet belongs to a VPC and shares the same CIDR (Classless Inter-Domain Routing) range with it.
[0037] It should be noted that virtual private clouds and subnets can help users build flexible, secure, and scalable cloud network architectures.
[0038] S2: Virtual private cloud and subnet based on cloud storage service, with cloud storage service enabled.
[0039] Cloud storage services are a network storage technology based on cloud computing, providing users with secure, efficient, and scalable data storage solutions. Users do not need to worry about the underlying storage hardware; instead, they access storage services via the network to store, manage, and access data.
[0040] S3: Based on the virtual private cloud and subnet of cloud storage services, apply for the IP address of cloud storage services and the real IP address of cloud storage services to build a dedicated storage gateway.
[0041] Specifically, based on Virtual Private Clouds (VPCs) and subnets for cloud storage services, subnets are created within the VPC and custom IP addresses for the storage services are assigned. These custom IP addresses are then mapped to the actual IP addresses of the storage services via a dedicated storage gateway (CS-NATGW, Customer Storage-Network Address Translation Gateway) using NAT (Network Address Translation). Self-Twice-NAT technology is used to simultaneously translate the source and destination addresses of traffic. A VxLAN (Virtual Extensible Local Area Network) tunnel is established between the CS-NATGW and the Tenant Gateway (TGW, Tencent Gateway), and backhaul routing and load balancing rules are configured. This enables users' local data centers to access cloud storage services efficiently and securely via dedicated lines, while also supporting flexible IP address management and traffic distribution.
[0042] S4: Activate cloud dedicated line service, specify the local data center network segment, and access the virtual private cloud and subnet of cloud storage service based on dedicated line storage gateway.
[0043] Specifically, the process involves creating a VPC and subnet in the cloud service provider's management console, applying for and activating a dedicated cloud line service, specifying the local data center's network segment (e.g., 192.168.1.0 / 24), configuring a dedicated storage gateway (CS-NATGW) within the VPC and performing NAT binding, configuring the physical dedicated line and VxLAN tunnel between the local and cloud POP switches, setting up routing to ensure correct traffic forwarding, and finally verifying the connection to ensure that the local data center can access cloud storage services through a custom storage service IP address. This process ensures an efficient, secure, and reliable network connection.
[0044] In one possible implementation, the leased storage gateway is used to perform NAT binding between the IP address of the user requesting cloud storage services and the actual IP address of the cloud storage services.
[0045] It should be noted that, through NAT technology, users can flexibly customize the IP address of cloud storage services for local data center access.
[0046] In one possible implementation, the leased storage gateway is also used to simultaneously translate the source and destination addresses of packets using Self-Twice-NAT technology.
[0047] Self-Twice-NAT is an advanced NAT (Network Address Translation) technology used to simultaneously translate the source and destination addresses of data packets on the same gateway device. Compared to traditional one-way NAT (which only translates the source or destination address), Self-Twice-NAT is more suitable for complex network scenarios, such as multi-tenant isolation and cross-network communication. In Self-Twice-NAT, when data packets enter and leave the gateway, the gateway device performs the following two operations simultaneously: Source NAT (SNAT) and Destination NAT (DNAT).
[0048] Source Address Translation (SNAT) refers to replacing the source address of a data packet with a specified address, such as converting the address of a user's local data center to a virtual address in the cloud.
[0049] Destination Address Translation (DNAT) refers to replacing the destination address of a data packet with the actual address of the cloud storage service, such as converting a custom IP address to the actual address of the cloud storage service.
[0050] Specifically, Self-Twice-NAT technology enables simultaneous translation of the source and destination addresses of packets. Users in local data centers or external clouds do not need to directly access the real address of the cloud computing center's storage service. They only need to define a custom address within the VPC connected by the dedicated line, and then perform NAT binding with the real address of the cloud computing center's storage service. By accessing the custom address, they can then access the cloud computing center's storage service.
[0051] In this application, Self-Twice-NAT technology not only improves the security and flexibility of cloud storage services, but also optimizes network performance, simplifies network management, and supports load balancing and disaster recovery, providing users with a more efficient and reliable cloud storage access solution.
[0052] It should be noted that this application defines a new leased-line storage NAT gateway (CS-NATGW) and its message processing flow, which fulfills the needs of local data centers or accessing cloud storage services from other clouds.
[0053] Furthermore, multiple pairs of CS-NATGW leased storage gateway clusters can be deployed within the same resource pool, theoretically supporting unlimited horizontal scaling. Additionally, users can apply for different service IPs from different subnets within the same storage service VPC as IPs for accessing the storage, or they can apply for different service IPs from subnets within different storage service VPCs as IPs for accessing the storage. All these different IPs can be NAT-mapped to the same real storage IP.
[0054] Furthermore, this application integrates existing cloud private line services and cloud storage services, and proposes a solution for local data centers to access cloud storage services of cloud computing centers through VxLAN tunnel technology, including network architecture and network element configuration model.
[0055] In one possible implementation, an SDN controller is configured at the bottom layer of the leased storage gateway. Through the gateway migration function of the SDN controller, traffic accessing different storage service IPs can be distributed to different CS-NATGW leased storage gateway clusters, which can achieve both traffic load balancing and disaster recovery.
[0056] The SDN (Software-Defined Networking) controller is one of the core components of the SDN architecture. Through centralized management and control, it enables dynamic network configuration and automated management. The DN controller can use gateway migration functionality to distribute traffic accessing different storage service IPs to different CS-NATGW leased storage gateway clusters.
[0057] Specifically, when a CS-NATGW cluster is under high load, the SDN controller can automatically migrate some traffic to other CS-NATGW clusters with lower load to achieve load balancing.
[0058] In this application, by configuring an SDN controller at the underlying layer of the dedicated storage gateway, centralized management and dynamic configuration of the CS-NATGW cluster can be achieved, effectively improving the network's load balancing capabilities and disaster recovery performance. The SDN controller not only simplifies network management but also enhances network performance and security, providing users with a more efficient and reliable cloud storage access solution.
[0059] In one possible implementation, the network architecture of the cloud storage service includes: a user's local data center, a cloud computing center, and cloud computing resources.
[0060] In some embodiments of this application, the cloud computing center network adopts a Spine Leaf topology network architecture, with physical servers attached to the Server-Leaf, and virtual machines can be created on the physical servers.
[0061] Leaf-spine topology is a modern data center network design aimed at providing high-performance, highly reliable, and highly scalable network infrastructure. This architecture is widely used in large data centers and cloud computing environments to support high-density virtual machines, containers, and other distributed applications. In leaf-spine topology, the maximum hop count between any two leaf nodes is 2 (i.e., through a spine node), ensuring very low network latency. When a leaf node receives a data packet, it looks up its routing table based on the destination MAC address or IP address to determine which spine node the packet should be forwarded to. The packet is then forwarded through the spine node to the destination leaf node, ultimately reaching the target device.
[0062] The user's local data center communicates with cloud computing resources through the cloud computing center.
[0063] The user's local data center includes: local network, local leaf switch, and local POP switch.
[0064] Point-of-Presence (POP) switches are an important component of networks, especially in the networks of telecommunications and Internet Service Providers (ISPs). POP switches are primarily used to connect different types of network devices and network segments, providing high-bandwidth and low-latency communication. In data center and cloud service environments, POP switches also play a crucial role, particularly when connecting user-local data centers to cloud service provider networks.
[0065] The cloud computing center includes: cloud POP switches, cloud leaf switches, spine switches, and server leaf switches.
[0066] Cloud computing resources include: tenant gateway clusters, dedicated line storage gateway clusters, physical servers, and virtual machines.
[0067] In some embodiments of this application, the Tenant Gateway Cluster (TGW) is a primary / backup cluster gateway, which can be deployed physically or virtually. TGWs are divided into dedicated and shared types. A dedicated TGW is the gateway for all VPCs under a single tenant, while a shared TGW is the gateway for all VPCs under certain tenants.
[0068] The local network communicates with the local POP switch via a physical leased line through the local leaf switch.
[0069] The local POP switch communicates with the cloud-based POP switch via a physical leased line.
[0070] It's important to note that physical leased lines provide dedicated high-bandwidth connections, ensuring efficient data transmission and avoiding the congestion and instability of the public internet. The direct connection characteristic of physical leased lines reduces the number of data hops, lowering network latency and making them suitable for latency-sensitive applications such as real-time data processing and high-performance computing. Connecting to cloud POP switches via local leaf switches and local POP switches through physical leased lines on the local network not only provides high-bandwidth and low-latency communication but also ensures high network reliability, security, and controllability. The dedicated nature of physical leased lines simplifies network management, simplifies troubleshooting, and optimizes overall network performance. This design is particularly suitable for applications with high performance and security requirements, such as data center interconnects, cloud service access, and real-time data processing.
[0071] The cloud-based POP switch communicates with the tenant gateway cluster and the leased storage gateway cluster via cloud-based leaf switches, spine switches, and server leaf switches in sequence using VxLAN tunnels.
[0072] The tenant gateway cluster and the leased storage gateway cluster communicate and connect via VxLAN tunnels to link traffic forwarding paths.
[0073] Tenant gateway clusters and leased storage gateway clusters communicate with physical servers via VxLAN tunnels, and virtual machines are configured on the physical servers.
[0074] VxLAN (Virtual Extensible LAN) is a network virtualization technology designed to address scalability and isolation issues in large-scale data center networks. VxLAN achieves Layer 2 network connectivity across different physical networks by encapsulating Layer 2 Ethernet frames on a Layer 3 network (IP network). This technology is particularly well-suited for cloud computing and virtualization environments because it provides highly scalable, flexible network segmentation, and cross-data center connectivity.
[0075] Furthermore, VxLAN can establish Layer 2 network connections between different physical data centers, enabling virtual machine migration and load balancing across data centers, improving resource utilization and business continuity. VxLAN allows for the transparent extension of Layer 2 networks over Layer 3 networks without reconfiguring physical network equipment. This simplifies network management and maintenance and reduces operating costs. VxLAN packets can be transmitted over multiple physical links, achieving load balancing. Network devices can use ECMP (Equal Cost Multipath) technology to evenly distribute traffic across different links, improving network bandwidth utilization.
[0076] Regarding configuration, both the POP switch and the TGW cluster's Loop port will be configured with an interconnect address within the same network segment. Additionally, the POP switch needs to be configured with a route to the cloud's VPC network segment within a specific VRF, with the next hop being the interconnect address on the TGW cluster's Loop port. Similarly, the TGW cluster also needs to be configured with a route to the user's local data center or a different cloud network segment within a specific VRF, with the next hop being the interconnect address on the POP switch's Loop port. Finally, both the POP switch and the TGW cluster need to be configured with a VxLAN tunnel to the peer VTEP.
[0077] It should be noted that using the above configuration scheme, by configuring interconnecting addresses within the same network segment, simplifies network configuration and reduces the possibility of errors. All related network devices and routing configurations are based on the same network segment, making network management more intuitive and convenient.
[0078] Furthermore, VRF technology can logically isolate the traffic of different tenants or business modules, ensuring that each tenant's traffic is managed independently, reducing configuration complexity, and avoiding network conflicts between different tenants.
[0079] Furthermore, by configuring interconnecting addresses within the same network segment on the Loop ports of the POP switch and TGW cluster, and configuring corresponding routes and VxLAN tunnels within the VRF, network configuration can be simplified, network reliability, performance, and security can be improved, while troubleshooting and management can be simplified. This design is particularly suitable for large-scale data center and cloud service environments, ensuring efficient, flexible, and reliable network connectivity.
[0080] In this application, this network architecture not only improves the communication performance and security between the user's local data center and the cloud computing center, but also simplifies network management and configuration, supports high reliability and high scalability, and provides users with an efficient, flexible and reliable cloud storage access solution.
[0081] Furthermore, VxLAN tunneling technology enables multi-path load balancing, ensuring that traffic is evenly distributed across different links and avoiding single points of failure and bottlenecks.
[0082] Referring to Figure 2, a network architecture diagram of a leased line to the cloud provided by an embodiment of this application is shown.
[0083] In Figure 2, the dashed lines represent the traffic forwarding paths from the user's local data center or external cloud to the VPC cloud computing center. The traffic in circles 1 and 2 is accessed to the cloud computing center via physical leased lines. The traffic in circle 3 is routed from the POP switch to the TGW gateway cluster via a VxLAN tunnel. The traffic in circle 4 is also routed to the host machine of the cloud host within the VPC via a VxLAN tunnel.
[0084] Referring to Figure 3, a network architecture diagram for cloud host access to cloud storage services provided in an embodiment of this application is shown.
[0085] Figure 2 shows the network architecture and traffic forwarding path for VPC cloud hosts accessing storage services within the cloud computing center. S-IGW is the storage intranet gateway, deployed as a physical server. Similar to TGW, it is available in dedicated and shared versions. The dedicated S-IGW handles traffic from cloud hosts within a single tenant's VPC to the storage, while the shared S-IGW handles traffic from cloud hosts within multiple tenants' VPCs to the storage. Cloud hosts within the VPC learn the MAC address of the S-IGW gateway cluster through the ARP proxy flow table on OVS. Then, they encapsulate the packets using VxLAN via the MAC forwarding flow table and forward them to the storage intranet gateway S-IGW. Finally, the storage intranet gateway S-IGW performs sNAT to translate the source address of the packets before forwarding them to the storage-side gateway.
[0086] Referring to Figure 4, a network architecture diagram of a local data center or a cloud storage service for accessing a cloud computing center from another cloud is shown in an embodiment of this application.
[0087] Compared with Figures 2 and 3, it can be seen that this traffic forwarding path actually reuses part of the traffic forwarding path of the user's local data center or other cloud accessing the VPC cloud host in the cloud computing center through a dedicated line, as well as part of the traffic forwarding path from the VPC cloud host in the cloud computing center to the cloud storage service. Then, by establishing a VxLAN tunnel between the tenant gateway cluster TGW and the dedicated line storage gateway cluster CS-NATGW, the two parts of the traffic forwarding path are connected, thereby opening up the network of the user's local data center or other cloud computing center storage service.
[0088] In one possible implementation, the network architecture of the cloud storage service also includes: backhaul routing.
[0089] The backhaul route is configured within the Virtual Routing and Forwarding (VRF) of the leased storage gateway. The destination network segment of the backhaul route is all zeros, and the next hop is the gateway IP address of all virtual private cloud intranet segments configured on the loopback interface (Loop) of the tenant gateway.
[0090] It's important to note that with backhaul routing, there's no need to concern yourself with the specific source network segment of the user's local data center or external cloud storage access. All backhaul traffic is forwarded to TGW by default, and the routing configuration on the CS-NATGW cluster will not change due to changes in the leased line customer's network segment. This greatly simplifies network configuration and management, reducing the possibility of errors.
[0091] In this application, by configuring backhaul routes within the VRF (Virtual Routing and Forwarding) of CS-NATGW, network configuration can be simplified, flexibility and reliability can be improved, performance can be optimized, troubleshooting can be simplified, and security can be enhanced. This design makes the network architecture more efficient, flexible, and reliable, providing users with a superior cloud storage access experience.
[0092] The embodiments of this application have the following advantages:
[0093] (1) This application enables simultaneous source-destination address translation for traffic in the same direction on the same gateway device through a dedicated storage gateway. Users can flexibly customize the IP address of the cloud storage service. Users only need to access the customized storage service IP, and attackers cannot directly locate the real IP of the storage service, thus enhancing the security of the storage service. It supports binding the real IP address of the same storage service with multiple customized IPs, thereby meeting the access needs of different subnets, tenants, or business modules. In the event of network failure or changes in the storage service IP, users only need to adjust the mapping relationship of the customized IPs without modifying the local network configuration, thereby enhancing the disaster recovery capability and flexibility of the system.
[0094] (2) Integrating existing cloud private line services and cloud storage services, a solution for local data centers to access cloud storage services of cloud computing centers is proposed through VxLAN tunnel technology, including network architecture and network element configuration model.
[0095] (3) A new storage traffic forwarding gateway CS-NATGW is defined, and the source and destination address translation of traffic in the same direction is performed simultaneously on the same gateway device through Self-Twice-NAT technology. Users can also flexibly customize the IP address of cloud storage services for local data center access.
[0096] (4) By using the gateway migration technology of the SDN controller, the traffic load of accessing storage via leased line can be distributed to different leased line storage gateway devices, thereby achieving the effect of disaster recovery.
[0097] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of this application are not limited to the described order of actions, because according to the embodiments of this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also understand that some of the actions involved in the embodiments described in the specification are not necessarily required by the embodiments of this application.
[0098] Additionally, referring to FIG5, a block diagram of a cloud storage service access device based on a cloud private line provided in an embodiment of this application is shown.
[0099] This application discloses a cloud storage service access device 20 based on a cloud private line, including:
[0100] Create module 201 to create a virtual private cloud and subnet for cloud storage services;
[0101] Module 202 is used to enable cloud storage services for virtual private clouds and subnets based on cloud storage services.
[0102] Module 203 is used to build a dedicated storage gateway for virtual private clouds and subnets based on cloud storage services, apply for IP addresses for cloud storage services, and obtain real IP addresses for cloud storage services.
[0103] Access module 204 is used to activate cloud dedicated line services, specify the local data center network segment, and access the virtual private cloud and subnet of cloud storage services based on the dedicated line storage gateway.
[0104] In one possible implementation, the leased storage gateway is used to perform NAT binding between the IP address of the user requesting cloud storage services and the actual IP address of the cloud storage services.
[0105] In one possible implementation, the leased storage gateway is also used to simultaneously translate the source and destination addresses of packets using Self-Twice-NAT technology.
[0106] In one possible implementation, the network architecture of the cloud storage service includes: a user's local data center, a cloud computing center, and cloud computing resources;
[0107] The user's local data center communicates with cloud computing resources through the cloud computing center;
[0108] The user's local data center includes: local network, local leaf switch, and local POP switch;
[0109] The cloud computing center includes: cloud POP switches, cloud leaf switches, spine switches, and server leaf switches.
[0110] Cloud computing resources include: tenant gateway clusters, dedicated line storage gateway clusters, physical servers, and virtual machines;
[0111] The local network communicates with the local POP switch via a physical leased line through the local leaf switch.
[0112] The local POP switch communicates with the cloud-based POP switch via a physical leased line.
[0113] The cloud-based POP switch communicates with the tenant gateway cluster and the leased storage gateway cluster via cloud-based leaf switches, spine switches, and server leaf switches in sequence using VxLAN tunnels.
[0114] The tenant gateway cluster and the leased storage gateway cluster communicate and connect via VxLAN tunnels to connect traffic forwarding paths;
[0115] Tenant gateway clusters and leased storage gateway clusters communicate with physical servers via VxLAN tunnels, and virtual machines are configured on the physical servers.
[0116] In one possible implementation, the network architecture of the cloud storage service also includes: backhaul routing;
[0117] The backhaul route is configured within the Virtual Routing and Forwarding (VRF) of the leased storage gateway. The destination network segment of the backhaul route is all zeros, and the next hop is the gateway IP address of all virtual private cloud intranet segments configured on the loopback interface (Loop) of the tenant gateway.
[0118] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.
[0119] The embodiments of this application have the following advantages:
[0120] This application utilizes a dedicated storage gateway to enable simultaneous source-destination address translation for traffic in the same direction on the same gateway device. Users can flexibly customize the IP address of their cloud storage service. Users only need to access the customized storage service IP, preventing attackers from directly locating the storage service's real IP, thus enhancing storage service security. It supports binding the same storage service's real IP address to multiple custom IPs, thereby meeting the access needs of different subnets, tenants, or business modules. In the event of network failure or changes to the storage service IP, users only need to adjust the mapping relationship of the custom IPs without modifying local network configurations, thereby enhancing the system's disaster recovery capabilities and flexibility.
[0121] Additionally, referring to FIG6, a block diagram of an electronic device provided in an embodiment of this application is shown. This application embodiment also provides an electronic device including a processor 1301, a communication interface 1302, a memory 1303, and a communication bus 1304, wherein the processor 1301, the communication interface 1302, and the memory 1303 communicate with each other via the communication bus 1304.
[0122] Memory 1303 is used to store computer programs;
[0123] When processor 1301 executes a program stored in memory 1303, it performs the following steps:
[0124] S1: Create a virtual private cloud and subnet for cloud storage services;
[0125] S2: Virtual private cloud and subnet based on cloud storage service, with cloud storage service enabled;
[0126] S3: Based on the virtual private cloud and subnet of cloud storage services, apply for the IP address of cloud storage services and the real IP address of cloud storage services to build a dedicated storage gateway;
[0127] S4: Activate cloud dedicated line service, specify the local data center network segment, and access the virtual private cloud and subnet of cloud storage service based on dedicated line storage gateway.
[0128] The communication bus mentioned above can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.
[0129] The communication interface is used for communication between the aforementioned terminal and other devices.
[0130] The memory may include random access memory (RAM) or non-volatile memory, such as at least one disk storage device. In some embodiments of this application, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0131] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0132] Referring to Figure 7, a schematic diagram of a computer-readable medium provided in an embodiment of this application is shown. In another embodiment provided in this application, a computer-readable storage medium 1401 is also provided, which stores instructions that, when executed on a computer, cause the computer to perform the cloud storage service access method based on a cloud private line as described in the above embodiments.
[0133] In another embodiment provided in this application, a computer program product containing instructions is also provided, which, when run on a computer, causes the computer to execute the cloud storage service access method based on cloud private lines in the above embodiments.
[0134] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., a solid-state disk (SSD)).
[0135] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes the element.
[0136] Some embodiments in this specification are described in a related manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0137] The above are merely some embodiments of this application and are not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application are included within the scope of protection of this application.
Claims
1. A cloud storage service access method based on a cloud private line, characterized by, include: S1: Create a virtual private cloud and subnet for cloud storage services; S2: Virtual private cloud and subnet based on cloud storage service, with cloud storage service enabled; S3: Based on the virtual private cloud and subnet of cloud storage services, apply for the IP address of cloud storage services and the real IP address of cloud storage services to build a dedicated storage gateway; S4: Activate cloud dedicated line service, specify the local data center network segment, and access the virtual private cloud and subnet of cloud storage service based on the dedicated line storage gateway. 2.The cloud-bolt-based cloud storage service access method according to claim 1, wherein, The dedicated storage gateway is used to perform NAT binding between the IP address of the cloud storage service request and the actual IP address of the cloud storage service. 3.The cloud-bolt-based cloud storage service access method according to claim 2, characterized in that, The dedicated storage gateway is also used to simultaneously translate the source and destination addresses of packets using Self-Twice-NAT technology. 4.The cloud-bolt-based cloud storage service access method according to claim 1, wherein, The network architecture of the cloud storage service includes: user local data center, cloud computing center and cloud computing resources; The user's local data center communicates with the cloud computing resources through the cloud computing center; The user's local data center includes: a local network, a local leaf switch, and a local POP switch; The cloud computing center includes: cloud POP switches, cloud leaf switches, spine switches, and server leaf switches. The cloud computing resources include: tenant gateway clusters, dedicated line storage gateway clusters, physical servers, and virtual machines; The local network communicates with the local POP switch via the local leaf switch using a physical leased line. The local POP switch is connected to the cloud POP switch via a physical leased line. The cloud-based POP switch communicates with the tenant gateway cluster and the leased storage gateway cluster via the cloud-based leaf switch, the spine switch, and the server leaf switch in sequence using a VxLAN tunnel. The tenant gateway cluster and the leased storage gateway cluster communicate and connect via a VxLAN tunnel to connect traffic forwarding paths; The tenant gateway cluster and the leased storage gateway cluster communicate with the physical server via a VxLAN tunnel, and the virtual machine is configured on the physical server. 5.The cloud-bolt-based cloud storage service access method according to claim 4, characterized in that, The network architecture of the cloud storage service also includes: backhaul routing; The backhaul route is configured within the Virtual Routing and Forwarding (VRF) of the leased storage gateway. The destination network segment of the backhaul route is all zeros, and the next hop is the gateway IP address of all virtual private cloud intranet segments configured on the loopback interface (Loop) of the tenant gateway. 6.A cloud storage service access apparatus based on a cloud line, characterized in that, include: Create modules for creating virtual private clouds and subnets for cloud storage services; Enable the module for virtual private clouds and subnets based on cloud storage services, and enable cloud storage services; The building module is used to construct a dedicated storage gateway based on the virtual private cloud and subnet of cloud storage services, apply for the IP address of cloud storage services, and the real IP address of cloud storage services. The access module is used to activate cloud dedicated line services, specify the local data center network segment, and access the virtual private cloud and subnet of cloud storage services based on the dedicated line storage gateway. 7.The cloud-bolt-based cloud storage service access apparatus according to claim 6, characterized in that, The dedicated storage gateway is used to perform NAT binding between the IP address of the cloud storage service request and the actual IP address of the cloud storage service. 8.The cloud-bolt-based cloud storage service access apparatus according to claim 7, characterized in that, The dedicated storage gateway is also used to simultaneously translate the source and destination addresses of packets using Self-Twice-NAT technology.
9. An electronic device, comprising: It includes a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; The memory is used to store computer programs; When the processor executes the program stored in the memory, it implements the cloud storage service access method based on cloud private lines as described in any one of claims 1-5.
10. A computer readable medium characterized by It stores instructions that, when executed by one or more processors, cause the processors to perform the cloud storage service access method based on any one of claims 1-5.
Citation Information
Patent Citations
Private line network address translation method and device, private line gateway and storage medium
CN111698346A
Communication line creation method, apparatus and device, and readable storage medium
CN114401274A
Two-layer cloud private line networking architecture based on public cloud and communication method
CN116915543A
Method for constructing cloud private line network based on cross-domain collaborative scene
CN117155968A
Cloud storage service access method and device based on cloud private line, and electronic equipment
CN119743454A