Identifying and Handling Threats to Data Compute Nodes in Public Cloud
US-2018063176-A1 · Mar 1, 2018 · US
US10447500B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10447500-B2 |
| Application number | US-201816018861-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jun 26, 2018 |
| Priority date | Dec 19, 2016 |
| Publication date | Oct 15, 2019 |
| Grant date | Oct 15, 2019 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A data packet processing method includes cloud management platform sends virtual private cloud (VPC) network information of a computing instance running on a host to a network processing device, a virtual switch receives a data packet from the computing instance using a virtual port of the computing instance, and the data packet carries a network address of the computing instance and a virtual local area network (VLAN) identifier of the virtual port sending the data packet, the virtual switch sends the data packet according to the VLAN identifier, and routes the data packet to the network processing device, the network processing device determines the VPC network information of the computing instance according to the network address of the computing instance, and performs network function processing on the data packet. Therefore, a VPC network feature of a computing instance can be adjusted according to a requirement, thereby improving management efficiency.
Opening claim text (preview).
What is claimed is: 1. A cloud computing system, comprising: at least one host; and a cloud management platform coupled to the at least one host and configured to send virtual private cloud (VPC) network information of a computing instance running on the at least one host to a network processing device according to a correspondence between a management network Internet Protocol (IP) address of the at least one host and a management network IP address of the network processing device, wherein the at least one host comprises: a virtual switch; and the network processing device coupled to the virtual switch, wherein a plurality of computing instances runs on the at least one host, wherein virtual local area network (VLAN) identifiers are configured for virtual ports of the plurality of computing instances, wherein the VLAN identifiers of the virtual ports of the plurality of computing instances are different from each other, wherein the at least one host communicates with another device in the cloud computing system using the network processing device, wherein the virtual switch is configured to: receive a data packet from the computing instance using a virtual port of the computing instance, wherein the data packet carries a network address of the computing instance and a VLAN identifier of the virtual port sending the data packet; send the data packet according to the VLAN identifier; and route the data packet to the network processing device, and wherein the network processing device is configured to: receive the data packet; determine the VPC network information of the computing instance according to the network address of the computing instance; perform network function processing on the data packet; and send the data packet. 2. The system according to claim 1 , wherein the network processing device is further configured to receive online information from the cloud management platform, and wherein the online information comprises a service network IP address of another network processing device and a network address of a computing instance running on a host coupled to the other network processing device. 3. The system according to claim 2 , wherein the network processing device is further configured to: determine, according to a destination network address of the data packet, a service network IP address of a network processing device corresponding to a destination computing instance of the data packet; establish a tunnel between the network processing device and the network processing device corresponding to the destination computing instance of the data packet; and send the data packet using the established tunnel. 4. The system according to claim 2 , wherein the cloud management platform is further configured to: allocate the management network IP address of the network processing device and a service network IP address to the network processing device; and record the correspondence between the management network IP address of the at least one host and the management network IP address of the network processing device. 5. The system according to claim 2 , wherein the cloud management platform is further configured to send an instance creation request to the at least one host, wherein the instance creation request carries resource configuration information and the network address of the computing instance, and wherein the at least one host is further configured to: create the computing instance and the virtual port of the computing instance according to the resource configuration information and the network address of the computing instance; and return, to the cloud management platform, an indication message indicating that the computing instance is successfully created, wherein the indication message carries the management network IP address of the at least one host and the network address of the computing instance, wherein the cloud management platform is further configured to allocate the VLAN identifier to the virtual port of the created computing instance, and wherein the allocated VLAN identifier is different from a VLAN identifier of any existing virtual port on the at least one host. 6. The system according to claim 2 , wherein the network processing device is further configured to: create, according to the received VPC network information, a virtual network element that provides a network processing function for the computing instance; and determine, according to a source network address of the data packet, the virtual network element corresponding to the computing instance. 7. A data packet processing method, wherein the data packet processing method is applied to a cloud computing system comprising a cloud management platform and at least one host, and wherein the data packet processing method comprises: sending, by the cloud management platform, virtual private cloud (VPC) network information of a computing instance running on the at least one host to a network processing device according to a correspondence between a management network Internet Protocol (IP) address of the at least one host and a management network IP address of the network processing device, wherein the at least one host comprises a virtual switch and the network processing device, wherein a plurality of computing instances runs on the at least one host, wherein virtual local area network (VLAN) identifiers are configured for virtual ports of the plurality of computing instances, wherein the VLAN identifiers of the virtual ports of the plurality of computing instances are different from each other, and wherein the at least one host communicates with another device in the cloud computing system using the network processing device; receiving, by the virtual switch, a data packet from the computing instance using a virtual port of the computing instance, wherein the data packet carries a network address of the computing instance and a VLAN identifier of the virtual port sending the data packet; sending, by the virtual switch, the data packet according to the VLAN identifier; routing, by the virtual switch, the data packet to the network processing device; receiving, by the network processing device, the data packet; determining, by the network processing device, the VPC network information of the computing instance according to the network address of the computing instance, performing, by the network processing device, network function processing on the data packet; and sending, by the network processing device, the data packet. 8. The method according to claim 7 , wherein before receiving the data packet, the method further comprises receiving, by the network processing device, online information from the cloud management platform, and wherein the online information comprises a service network IP address of another network processing device and a network address of a computing instance running on a host coupled to the other network processing device. 9. The method according to claim 8 , wherein sending the data packet comprises: determining, by the network processing device according to a destination network address of the data packet, a service network IP address of a network processing device corresponding to a destination computing instance of the data packet; establishing, by the network processing device, a tunnel between the network processing device and the network processing device corresponding to the destination computing instance of the data packet; and sending, by the network processing device, the data packet using the established tunnel. 10. The method according to claim 8 , wherein before sending the VPC network information, the method further comprises: allocatin
for supporting virtual local area networks [VLAN] · CPC title
Virtual switches · CPC title
Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines · CPC title
Details on frame tagging (routing of packets H04L45/00; support for virtual LAN H04L49/354) · CPC title
Hypervisor-specific management and integration aspects · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.