WO2013097067A1 - 一种虚拟机迁移后实现通信的方法、设备和系统 - Google Patents

一种虚拟机迁移后实现通信的方法、设备和系统 Download PDF

Info

Publication number
WO2013097067A1
WO2013097067A1 PCT/CN2011/084617 CN2011084617W WO2013097067A1 WO 2013097067 A1 WO2013097067 A1 WO 2013097067A1 CN 2011084617 W CN2011084617 W CN 2011084617W WO 2013097067 A1 WO2013097067 A1 WO 2013097067A1
Authority
WO
WIPO (PCT)
Prior art keywords
virtual machine
configuration protocol
host configuration
dynamic host
address information
Prior art date
Application number
PCT/CN2011/084617
Other languages
English (en)
French (fr)
Inventor
朱国军
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to EP11879109.4A priority Critical patent/EP2698957B1/en
Priority to PCT/CN2011/084617 priority patent/WO2013097067A1/zh
Priority to CN201180003061.8A priority patent/CN103534994B/zh
Publication of WO2013097067A1 publication Critical patent/WO2013097067A1/zh
Priority to US14/081,780 priority patent/US9479611B2/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/34Network arrangements or protocols for supporting network services or applications involving the movement of software or configuration parameters 
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L49/00Packet switching elements
    • H04L49/70Virtual switches
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/455Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
    • G06F9/45533Hypervisors; Virtual machine monitors
    • G06F9/45558Hypervisor-specific management and integration aspects
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/46Multiprogramming arrangements
    • G06F9/48Program initiating; Program switching, e.g. by interrupt
    • G06F9/4806Task transfer initiation or dispatching
    • G06F9/4843Task transfer initiation or dispatching by program, e.g. task dispatcher, supervisor, operating system
    • G06F9/485Task life-cycle, e.g. stopping, restarting, resuming execution
    • G06F9/4856Task life-cycle, e.g. stopping, restarting, resuming execution resumption being on a different machine, e.g. task migration, virtual machine migration
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/46Multiprogramming arrangements
    • G06F9/50Allocation of resources, e.g. of the central processing unit [CPU]
    • G06F9/5005Allocation of resources, e.g. of the central processing unit [CPU] to service a request
    • G06F9/5027Allocation of resources, e.g. of the central processing unit [CPU] to service a request the resource being a machine, e.g. CPUs, Servers, Terminals
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/46Multiprogramming arrangements
    • G06F9/50Allocation of resources, e.g. of the central processing unit [CPU]
    • G06F9/5061Partitioning or combining of resources
    • G06F9/5077Logical partitioning of resources; Management or configuration of virtualized resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5007Internet protocol [IP] addresses
    • H04L61/5014Internet protocol [IP] addresses using dynamic host configuration protocol [DHCP] or bootstrap protocol [BOOTP]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5076Update or notification mechanisms, e.g. DynDNS
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/50Address allocation
    • H04L61/5084Providing for device mobility
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/455Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
    • G06F9/45533Hypervisors; Virtual machine monitors
    • G06F9/45558Hypervisor-specific management and integration aspects
    • G06F2009/4557Distribution of virtual machine instances; Migration and load balancing
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F9/00Arrangements for program control, e.g. control units
    • G06F9/06Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
    • G06F9/44Arrangements for executing specific programs
    • G06F9/455Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
    • G06F9/45533Hypervisors; Virtual machine monitors
    • G06F9/45558Hypervisor-specific management and integration aspects
    • G06F2009/45595Network integration; Enabling network access in virtual machine instances

Definitions

  • the present invention relates to the field of computer communications, and more particularly to a method, device and system for implementing communication after virtual machine migration.
  • Cloud computing is an Internet-based computing method in which shared hardware and software resources and information can be provided to computers and other devices as needed.
  • virtualization technology virtualizes a physical computer into multiple virtual machines (Vir tua l Machine, called VM) and provides automatic deployment and rapid delivery of business capabilities through the management system. So that end users (tenants) can rent virtual machines quickly and easily.
  • IP Internet Protocol
  • Media Access Control Media Acces s Control, cartridge
  • the switch still stores the binding relationship between the IP address and the MAC address of the virtual machine before the migration, so that the switch considers that the virtual machine is migrated after the migration. Network, so there is no way to achieve communication after virtual machine migration.
  • An embodiment of the present invention provides a method for implementing communication after a virtual machine is migrated, including: After the virtual machine is migrated, a dynamic host configuration protocol request message carrying the address information of the virtual machine after migration is constructed;
  • the switch Sending the dynamic host configuration protocol request message to the switch, so that the switch establishes a binding relationship between the address information after the virtual machine is migrated and the port number accessed by the virtual machine; the address information includes IP address and MAC address.
  • a method for implementing communication after a virtual machine migration includes:
  • the switch After the virtual machine is migrated, the switch receives a dynamic host configuration protocol request message that carries the address information of the virtual machine after migration;
  • the switch establishes a binding relationship between the address information after the migration of the virtual machine and the port number accessed by the virtual machine;
  • the address information includes an IP address and a MAC address.
  • a device for implementing communication after a virtual machine migration includes:
  • a construction unit configured to: after the virtual machine is migrated, construct a dynamic host configuration protocol request carrying the address information of the virtual machine after migration;
  • a sending unit configured to send the dynamic host configuration protocol request message to the switch, so that the switch establishes a binding relationship between the address information after the virtual machine migration and the port number accessed by the virtual machine;
  • the address information includes an IP address and a MAC address.
  • a switch that implements communication after a virtual machine is migrated including:
  • the receiving unit after the virtual machine is migrated, is configured to receive a dynamic host configuration protocol request carrying the address information of the virtual machine after migration;
  • the binding processing unit is configured to establish a binding relationship between the address information after the migration of the virtual machine and the port number that the virtual machine accesses; the address information includes an IP address and a MAC address.
  • a system for implementing communication after a virtual machine migration includes:
  • the switch is configured to receive a dynamic host configuration protocol request message carrying the address information of the virtual machine after the migration, and establish a binding between the address information of the virtual machine after migration and the port number of the virtual machine accessing
  • the relationship information includes an IP address and a MAC address.
  • the method, device, and system for implementing communication after the virtual machine is migrated by the embodiment of the present invention by transmitting a dynamic host configuration protocol request message carrying the address information of the virtual machine after the migration, sending the dynamic host configuration protocol request to the switch
  • the packet so that the switch can establish the binding relationship between the address information of the virtual machine after migration and the port number accessed by the virtual machine, where the address information includes an IP address and a MAC address. Therefore, according to the binding relationship, the switch considers that the packet sent by the virtual machine is legal after the migration, and the packet sent by the virtual machine after the migration is processed, so that the virtual machine can be accessed after the virtual machine is migrated. Communication after virtual machine migration.
  • FIG. 1 is a scene diagram of an embodiment of the present invention
  • FIG. 2a is a schematic flow chart of a first embodiment of the present invention
  • 2b is a schematic flow chart of a second embodiment of the present invention
  • FIG. 3 is a schematic flow chart of a third embodiment of the present invention.
  • FIG. 4 is a schematic structural diagram of a virtualization platform according to a fourth embodiment of the present invention.
  • FIG. 5 is a schematic flowchart of a fourth embodiment of the present invention.
  • FIG. 6 is a schematic structural diagram of an apparatus for implementing communication after a virtual machine is migrated according to a fifth embodiment of the present invention
  • FIG. 7 is a schematic structural diagram of an apparatus for implementing communication after a virtual machine is migrated according to a sixth embodiment of the present invention
  • 8 is a schematic structural diagram of a switch for implementing communication after a virtual machine is migrated according to a seventh embodiment of the present invention
  • FIG. 9 is a schematic structural diagram of a system for implementing communication after a virtual machine is migrated according to an eighth embodiment of the present invention
  • FIG. 1 An application scenario of the embodiment of the present invention is shown in FIG. 1.
  • a typical application architecture is shown in FIG.
  • the technical features not related to the present invention are omitted in FIG. 1, and the information interaction process is also omitted, and only one application scenario architecture is given.
  • the present invention can be applied to the scene shown in Fig. 1, but is not limited to this scene.
  • the purpose of Figure 1 is to clarify the embodiments of the present invention and not to limit the scope of application of the present invention.
  • the address information corresponding to the virtual machine (the address information may include an IP address and a MAC address) and the port number of the accessed port are also required to be slave switches.
  • the Dynamic Host Configuration Protocol server receives the Dynamic Host Configuration Protocol Discovery message. After that, allocate resources to the virtual machine, and then issue a dynamic host configuration protocol OFFER message. After receiving the dynamic host configuration protocol OFFER packet, the virtual machine sends a dynamic host configuration protocol request packet to the dynamic host configuration protocol server, requests the server lease, and notifies other servers that the virtual machine has accepted the dynamic host configuration protocol server allocation. address.
  • the dynamic host configuration protocol server receives the dynamic host configuration protocol request message and verifies whether the resource can be allocated. If it can be allocated, the dynamic host configuration protocol server sends a dynamic host configuration protocol response to the virtual machine, and if it is not assignable, sends a dynamic host configuration protocol NAK message.
  • the virtual machine receives a dynamic host configuration protocol response and begins to use the resources allocated by the Dynamic Host Configuration Protocol server. If the dynamic host configuration protocol NAK packet is received, the virtual machine resends the dynamic host configuration protocol discovery text. All the above interactions can be called dynamic host configuration protocol packets.
  • the switch analyzes and processes dynamic host configuration protocol packets between the virtual machine and the dynamic host configuration protocol server.
  • the switch can filter untrusted dynamic host configuration protocol packets and establish and maintain binding relationships.
  • the binding relationship includes virtual machines.
  • the address information and the port number of the access, etc., and the address information may include the IP address and MAC address of the virtual machine.
  • the virtual machine migration is a copy process of the memory image.
  • the port number of the access switch connected to the virtual machine and the access switch changes, but The dynamic host configuration protocol process is not re-initiated. Therefore, if the address information of the virtual machine is not updated, the switch sends the packets sent by the VM to the switch. Therefore, normal communication cannot be achieved.
  • a dynamic host configuration protocol packet carrying the address information of the virtual machine after migration is configured, which is called a dynamic host configuration protocol request packet, and is migrated through the virtual machine.
  • the incoming switch is sent to the Dynamic Host Configuration Protocol server for verification.
  • the switch may allocate the port number of the access to the virtual machine, and record the access port number allocated to the virtual machine. If the dynamic host configuration protocol server verifies that the dynamic host configuration protocol request packet is a legal packet, it returns a dynamic host configuration protocol response packet.
  • the dynamic host configuration protocol response packet carries the virtual machine after migration. Address information.
  • the switch After receiving the dynamic host configuration protocol response packet carrying the address information of the migrated virtual machine, the switch obtains the address information of the virtual machine after the virtual machine is migrated, and combines the port number of the access allocated by the switch to the virtual machine. Generate a binding relationship, as shown in Table 1, and use the binding relationship table to exclude illegal packets.
  • Table 1 lists the binding information of the address information corresponding to the virtual machine and the port number of the access port. Table 1 is not a limitation on the binding relationship in the embodiment of the present invention, but is a binding relationship used to more clearly illustrate the embodiment of the present invention. The binding relationship between the address information and the port number of the access that can be implemented by those skilled in the art should also fall within the protection scope of the present invention.
  • the address information of the embodiment of the present invention may include an IP address and a MAC address, but is not limited thereto. Other address information that identifies the virtual machine is also available.
  • a first embodiment of the present invention provides a method for implementing communication after a virtual machine is migrated. As shown in FIG. 2a, the method includes:
  • Step 201a After the virtual machine is migrated, construct a dynamic host configuration protocol request message carrying the address information of the virtual machine after migration.
  • a dynamic host configuration protocol request message carrying the address information of the virtual machine after migration is constructed.
  • the dynamic host configuration protocol request message is a unicast renewal request message.
  • Step 202a Send the dynamic host configuration protocol request message to the switch, so that the switch establishes a binding relationship between the address information after the virtual machine is migrated and the port number accessed by the virtual machine.
  • the address information includes an IP address and a MAC address.
  • the method may further include: receiving, by the switch, a dynamic host configuration protocol response message carrying the address information of the virtual machine after migration; And updating, according to the dynamic host configuration protocol response packet, an expiration date of the migrated IP address of the virtual machine.
  • the embodiment of the present invention implements a dynamic host configuration protocol request message carrying the address information of the virtual machine after the virtual machine is migrated, and establishes the address information after the virtual machine is migrated and the port number accessed by the virtual machine in the switch.
  • the new binding relationship is enabled. Therefore, the switch can correctly identify the packets sent by the VM.
  • the packets sent after the VM is migrated are valid packets.
  • a second embodiment of the present invention provides a method for implementing communication after a virtual machine is migrated. As shown in FIG. 2b, the method includes:
  • Step 201b After the virtual machine is migrated, the switch receives a dynamic host configuration protocol request message carrying the address information of the virtual machine after migration.
  • the method further includes: sending the dynamic host configuration protocol request message to a dynamic host configuration protocol server, so that the dynamic host configuration protocol server is configured to The dynamic host configuration protocol request packet is legally verified; after the verification is passed, the dynamic host configuration protocol response message carrying the address information of the virtual machine after being returned by the dynamic host configuration protocol server is received;
  • Step 202b The switch establishes a binding relationship between the address information after the migration of the virtual machine and the port number accessed by the virtual machine; the address information includes an IP address and a MAC address.
  • the method further includes acquiring a port number of the virtual machine access
  • the establishing the binding relationship between the address information of the virtual machine and the port number of the virtual machine to be accessed includes: the virtual machine obtained according to the dynamic host configuration protocol response message. Deleting the binding relationship after the migrated address information and the acquired port number of the virtual machine; The method further includes: the switch assigning a port number of the virtual machine to the virtual machine, and recording a port accessed by the virtual machine, before the port number of the virtual machine is accessed. number;
  • the obtaining the port number of the virtual machine access includes: obtaining the port number of the virtual machine access from the record.
  • the dynamic host configuration protocol request message is sent to the dynamic host configuration protocol server by using the dynamic host configuration protocol relay.
  • the method further includes: the switch sending, to the virtual machine server or the virtual machine monitor, a dynamic host configuration protocol response message carrying the address information of the virtual machine after the migration, to update the virtual machine after the migration The validity period of the IP address.
  • the dynamic host configuration protocol request message is a unicast renewal request message.
  • the switch provided by the embodiment of the present invention receives a dynamic host configuration protocol request message carrying the address information of the virtual machine after the migration, and establishes a new binding relationship between the address information after the virtual machine is migrated and the port number accessed by the virtual machine. Therefore, the switch can correctly identify the packets sent by the VMs.
  • the packets sent by the VMs are valid packets and the normal communication after VM migration.
  • a third embodiment of the present invention provides a method for implementing communication after a virtual machine is migrated. As shown in FIG. 3, the method includes:
  • Step 301 The virtual machine is initially started.
  • the dynamic host configuration protocol request process is initiated.
  • the switch obtains the user's address information according to the dynamic host configuration protocol response packet returned by the dynamic host configuration protocol server, and generates a binding relationship, such as the port number assigned by the switch to the virtual machine. Table 1 shows.
  • the switch When the virtual machine is started, a complete IP address allocation process is initiated. After the switch receives the dynamic host configuration protocol response packet from the dynamic host configuration protocol server, the switch responds to the current address of the virtual machine carried in the dynamic host configuration protocol. Information, you can generate the address information of the virtual machine to The binding relationship between the port number of the virtual machine and the port number of the virtual machine. In addition to the packets of the centralized type, such as the dynamic host configuration protocol request packet, the binding relationship is not found in the binding relationship. When a packet is requested, the switch considers it to be an illegal request packet and discards the request packet. This ensures the security of the user VM and prevents unauthorized users from accessing it.
  • Step 302 Virtual machine migration.
  • the virtual machine is migrated from virtual machine server 1 to virtual machine server 2 to complete the virtual machine migration.
  • Step 303 The virtual machine server 2 detects that the virtual machine migration is completed.
  • Step 304 Construct a dynamic host configuration protocol request message.
  • the virtual machine server 2 After the virtual machine server 2 detects that the virtual machine is migrated, the virtual machine server 2 constructs a dynamic host configuration protocol request message, where the message carries the address information of the virtual machine after migration, and the address information includes an IP address and a MAC address.
  • the dynamic host configuration protocol request packet is a unicast packet.
  • the format of the message is as follows:
  • op The operation type of the dynamic host configuration protocol packet, which is divided into a request packet and a response packet, 1 is a request packet; 2 is a response packet.
  • xid The random number selected by the virtual machine when it initiates a request, which is used to identify an address request process.
  • the first bit is the broadcast response flag, which is used to identify whether the dynamic host configuration protocol server response message is sent by unicast or broadcast. The remaining bits are reserved.
  • IP address of the server from which the virtual machine obtains information such as the IP address.
  • chaddr The hardware address of the virtual machine.
  • sname The server name of the virtual machine to obtain information such as the IP address.
  • f i le The name of the startup configuration file specified by the dynamic host configuration protocol server for the virtual machine.
  • Optional variable length option field including the type of the packet, the effective lease duration, the IP address of the Doma in Name System (DNS) server, and the IP address of the wins server.
  • DNS Name System
  • Step 305 Send a dynamic host configuration protocol request message.
  • the dynamic host configuration protocol request packet is sent to the switch.
  • the switch allocates the port number of the access to the virtual machine, and records the connection allocated to the virtual machine. Enter the port number.
  • the switch 1 sends a dynamic host configuration protocol request message carrying the address information of the virtual machine to the dynamic host configuration protocol server. If there is a dynamic host configuration protocol relay, the switch 2 sends the dynamic host configuration protocol request message to the dynamic host first. Configure protocol relay.
  • Step 306 Send a dynamic host configuration protocol request message to the dynamic host configuration protocol server. After receiving the dynamic host configuration protocol request packet carrying the address information of the virtual machine, the switch sends the packet to the dynamic host configuration protocol server.
  • Step 307 Confirm that the dynamic host configuration protocol request packet is valid.
  • the dynamic host configuration protocol server After receiving the dynamic host configuration protocol request packet, the dynamic host configuration protocol server parses the packet content and confirms whether the packet is legal.
  • Step 308 Return to the dynamic host configuration protocol response.
  • the dynamic host configuration protocol server confirms that the dynamic host configuration protocol request message is valid.
  • the dynamic host configuration protocol server returns a dynamic host configuration protocol response message carrying the address information of the virtual machine after migration to the switch 2.
  • Step 309 The switch 2 obtains the address information of the migrated virtual machine according to the dynamic host configuration protocol response packet returned by the dynamic host configuration protocol server, and generates a binding relationship according to the port number assigned by the switch to the virtual machine in step 305. .
  • Step 310 Return to the dynamic host configuration protocol response.
  • the switch returns the dynamic host configuration protocol response packet to the virtual machine server 2.
  • Step 311 Update the validity period of the IP address after the virtual machine is migrated.
  • the dynamic host configuration protocol response packet can carry the dynamic host configuration protocol lease information in addition to the address information of the migrated virtual machine.
  • the lease information is carried in the EXPIRE field of the Dynamic Host Configuration Protocol response message.
  • the virtual machine server 2 can update the validity period of the virtual machine after the migration.
  • Step 312 The virtual machine acts as a legitimate user and communicates correctly with the external network.
  • the embodiment of the present invention provides a method for implementing communication after a virtual machine is migrated.
  • the virtual machine server 2 After the virtual machine server 2 completes the migration of the virtual machine, the virtual machine server 2 constructs a dynamic host configuration protocol request packet carrying the address information of the virtual machine after migration, thereby establishing the switch. Address information after virtual machine migration and virtual machine connection The port is in the new binding relationship. Therefore, the switch can correctly identify the packets sent from the VM.
  • the packets sent after the VM is migrated are valid packets.
  • a fourth embodiment of the present invention provides a method for implementing communication after a virtual machine is migrated, as shown in FIG. 4 and FIG. 5.
  • the virtual machine monitor after monitoring the virtual machine migration, obtains the address information of the virtual machine after migration, constructs and sends a dynamic host configuration protocol request message, and performs security verification through the dynamic host configuration protocol server. .
  • Step 501 The virtual machine is initially started.
  • the dynamic host configuration protocol request process is initiated, and the switch obtains the user's address information according to the dynamic host configuration protocol response information returned by the dynamic host configuration protocol server, and generates a binding relationship by using the access port number allocated by the switch for the virtual machine, as shown in Table 1. Shown.
  • the virtual machine When the virtual machine is started, the virtual machine initiates a complete IP address allocation process.
  • the switch After receiving the dynamic host configuration protocol response from the dynamic host configuration protocol server, the switch responds to the virtual machine currently carried in the response packet according to the dynamic host configuration protocol.
  • the address information of the virtual machine and the port number binding relationship of the virtual machine are generated. As shown in Table 1, except for a few centralized types of packets, such as dynamic host configuration protocol request packets,
  • the binding relationship table does not query the request packet of the corresponding binding relationship. The switch considers the device to be an invalid request packet and discards the request packet. This ensures the security of the user VM and prevents unauthorized users from accessing it.
  • Step 502 Virtual machine migration.
  • the virtual machine is migrated from virtual machine server 1 to virtual machine server 2.
  • Step 503 The virtual machine monitor monitors the virtual machine migration completion.
  • Step 504 Construct a dynamic host configuration protocol request message.
  • the virtual machine monitor monitors the completion of the virtual machine migration, and constructs a dynamic host configuration protocol request message carrying the address information of the virtual machine after migration.
  • the dynamic host configuration protocol request packet is a unicast packet.
  • the packet format is the same as that of the second embodiment of the present invention. For details, see the third embodiment. Description of the text format.
  • Step 505 Send a dynamic host configuration protocol request message to the switch.
  • the dynamic host configuration protocol request packet is sent to the switch.
  • the switch allocates the port number of the access to the virtual machine, and records the connection allocated to the virtual machine. Enter the port number.
  • the switch sends the packet carrying the address information of the migrated virtual machine to the dynamic host configuration protocol server. If there is a dynamic host configuration protocol relay, the switch sends the dynamic host configuration protocol request packet to the dynamic host configuration protocol relay.
  • Step 506 Send a dynamic host configuration protocol request message to the dynamic host configuration protocol server. After receiving the dynamic host configuration protocol request packet carrying the address information of the migrated virtual machine, the switch sends the packet to the dynamic host configuration protocol server.
  • Step 507 Confirm that the dynamic host configuration protocol request packet is valid.
  • the dynamic host configuration protocol server After receiving the dynamic host configuration protocol request packet, the dynamic host configuration protocol server parses the packet content and confirms whether the dynamic host configuration protocol request packet is legal.
  • Step 508 Return to the Dynamic Host Configuration Protocol response.
  • the dynamic host configuration protocol server confirms that the dynamic host configuration protocol request message is valid, and the dynamic host configuration protocol server returns a dynamic host configuration protocol response carrying the address information of the virtual machine after migration to the switch.
  • Step 509 The switch obtains the address information after the virtual machine is migrated according to the dynamic host configuration protocol returned by the dynamic host configuration protocol server, and generates a binding relationship according to the port number allocated by the switch for the virtual machine, as shown in Table 1. .
  • Step 51 0 Return to the Dynamic Host Configuration Protocol response.
  • the switch returns the Dynamic Host Configuration Protocol response to the virtual machine monitor.
  • Step 51 1 Update the validity period of the IP address after the virtual machine migration.
  • the dynamic host configuration protocol response packet carries the dynamic host configuration protocol lease information in addition to the address information of the migrated virtual machine.
  • the lease information is carried in the dynamic host configuration protocol response message.
  • EXPIRE field Update the validity period of the IP address after VM migration based on the dynamic host configuration protocol lease information.
  • Step 512 The virtual machine acts as a legitimate user and communicates correctly with the external network.
  • the embodiment of the present invention provides a method for implementing communication after a virtual machine is migrated.
  • the virtual machine monitor detects that the virtual machine is migrated, the virtual machine monitors a dynamic host configuration protocol request packet, and establishes the address information and the virtual machine after the virtual machine is migrated on the switch.
  • the port number of the access port is a new binding relationship. Therefore, the switch can correctly identify the packets sent by the VM.
  • the packets sent after the VM is migrated are valid packets.
  • a fifth embodiment of the present invention provides a device for implementing communication after a virtual machine is migrated. As shown in FIG. 6, the configuration unit 601 and the sending unit 602 are included.
  • the construction unit 601 is configured to: after the virtual machine is migrated, construct a dynamic host configuration protocol request message carrying the address information of the virtual machine after migration.
  • the sending unit 602 is configured to send the dynamic host configuration protocol request message to the switch, so that the switch establishes a binding relationship between the address information after the virtual machine is migrated and the port number accessed by the virtual machine, where the address information includes IP address and MAC address.
  • the apparatus for implementing communication after the migration of the virtual machine may further include a monitoring unit, configured to monitor the virtual machine migration. After the monitoring unit detects the migration of the virtual machine, the dynamic unit configuration protocol request message carrying the address information of the virtual machine after migration is constructed by the constructing unit.
  • the device for implementing the communication after the migration of the virtual machine provided by the embodiment of the present invention may be a virtual machine server or a virtual machine monitor.
  • a virtual machine server or a virtual machine monitor.
  • the device that implements the communication after the virtual machine is migrated can construct a dynamic host configuration protocol request message carrying the address information of the virtual machine after the virtual machine is migrated, and the address after the virtual machine is migrated is established on the switch.
  • a sixth embodiment of the present invention provides a device for implementing communication after migration of a virtual machine. As shown in FIG. 7, the configuration unit 701, the sending unit 702, the receiving unit 703, and the updating unit 704 are included.
  • the constructing unit 701 is configured to construct a dynamic host configuration protocol request message carrying the address information of the virtual machine after migration.
  • the sending unit 702 is configured to send the dynamic host configuration protocol request message to the switch, so that the switch establishes a binding relationship between the address information after the virtual machine is migrated and the port number accessed by the virtual machine, where the address information includes the IP address. Address and MAC address.
  • the receiving unit 703 is configured to receive a dynamic host configuration protocol response message sent by the switch and carrying the address information of the virtual machine after migration.
  • the updating unit 704 is configured to update an expiration date of the migrated IP address according to the dynamic host configuration protocol response message.
  • the apparatus for implementing communication after the migration of the virtual machine may further include a monitoring unit, configured to monitor the virtual machine migration. After the monitoring unit detects the migration of the virtual machine, the dynamic unit configuration protocol request message carrying the address information of the virtual machine after migration is constructed by the construction unit.
  • the device for implementing communication after the virtual machine is migrated in the embodiment of the present invention may be a virtual machine server or a virtual machine monitor.
  • the device that implements the communication provided by the embodiment can monitor the dynamic host configuration protocol request packet carrying the address information of the virtual machine after the virtual machine is migrated, where the address information includes the IP address and the MAC address. Update the validity period of the IP address after VM migration by setting the address information of the virtual machine after the VM is migrated and the port number of the VM accessing the switch, so that the switch can be in the validity period of the IP address after the VM migration.
  • the packets sent from the VM are correctly identified.
  • the packets sent after the VM is migrated are valid packets.
  • a seventh embodiment of the present invention provides a switch for implementing communication after a virtual machine is migrated. As shown in FIG. 8, the receiving unit 801 and the binding processing unit 802 are included.
  • the receiving unit 801 is configured to receive the virtual machine after the virtual machine is migrated. Dynamic Host Configuration Protocol request message for address information.
  • the binding processing unit 802 is configured to establish a binding relationship between the migrated address information of the virtual machine and a port number accessed by the virtual machine, where the address information includes an IP address and a MAC address.
  • Embodiments of the present invention may further include a sending unit and an obtaining unit.
  • the sending unit is configured to send the dynamic host configuration protocol request message to the dynamic host configuration protocol server, so that the dynamic host configuration protocol server validates the dynamic host configuration protocol request message.
  • the receiving unit 801 is further configured to receive a dynamic host configuration protocol response message that is returned by the dynamic host configuration protocol server and carries the address information of the virtual machine after migration.
  • the obtaining unit is configured to obtain the address information of the virtual machine after the migration from the dynamic host configuration protocol response message.
  • the switch that implements communication after the virtual machine is migrated may further include a port processing unit, configured to allocate an access port number to the virtual machine, and record an access port number allocated to the virtual machine.
  • the obtaining unit may also obtain the port number of the access of the virtual machine from the port processing unit.
  • the binding processing unit 802 the binding relationship between the address information of the virtual machine and the port number of the virtual machine is specifically configured to: according to the virtual machine migration obtained from the dynamic host configuration protocol response message The subsequent address information, and the recorded port number of the virtual machine access, establish the binding relationship, as shown in Table 1.
  • the sending unit is further configured to send, to the virtual machine server or the virtual machine monitor, a dynamic host configuration protocol response message carrying the migrated address information of the virtual machine, to update the migrated IP address of the virtual machine. Validity period.
  • the switch provided by the embodiment of the present invention receives, by the receiving unit, a dynamic host configuration protocol request message carrying the migrated address information of the virtual machine, and the binding processing unit establishes the address information of the virtual machine after migration and the access of the virtual machine.
  • the packets sent by the VMs are valid packets and the normal communication after VM migration.
  • An eighth embodiment of the present invention provides a system for implementing communication after a virtual machine is migrated, as shown in FIG.
  • the device includes a device 901 that implements communication after the virtual machine is migrated, and a switch 902 that implements communication after the virtual machine is migrated.
  • the device 901 for implementing communication after the virtual machine is migrated is configured to construct a dynamic host configuration protocol request message carrying the address information of the virtual machine after the virtual machine is migrated, and send the dynamic host configuration protocol to the switch 902. Request a message.
  • the switch 902 receives the dynamic host configuration protocol request message carrying the migrated address information of the virtual machine, and establishes a binding relationship between the address information after the virtual machine migration and the port number accessed by the virtual machine.
  • the address information includes an IP address and a MAC address.
  • the device 901 for realizing communication after migration of the virtual machine in the embodiment of the present invention may be a virtual machine server or a virtual machine monitor.
  • the system for implementing communication after the virtual machine is migrated in this embodiment, after the virtual machine is migrated, the device that implements the communication after the virtual machine is migrated, constructs a dynamic host configuration protocol request message carrying the address information of the virtual machine after the migration, and the switch passes the dynamic
  • the host configuration protocol response packet obtains the address information of the virtual machine after the migration, and establishes the binding information of the virtual machine after the migration and the port number of the virtual machine. Therefore, the switch can correctly identify the virtual machine to send out.
  • the packet is considered to be a valid packet after the VM is migrated.
  • the normal communication after the VM migration is implemented.
  • a ninth embodiment of the present invention provides a system for communication after virtual machine migration, as shown in FIG. 10, including a device 1001 for realizing communication after virtual machine migration, a switch 1002 for realizing communication after virtual machine migration, and a dynamic host configuration protocol.
  • Server 1003. The device 1001, which is configured to communicate after the virtual machine is migrated, is configured to: after the virtual machine is migrated, construct a dynamic host configuration protocol request message carrying the address information of the virtual machine after the migration, and send the dynamic host configuration protocol request to the switch 1002. Message.
  • the switch 1 002 is configured to receive a dynamic host configuration protocol request message that is configured and sent by the device 1001 that implements communication after the virtual machine is migrated, and configures the protocol server 1 QQ3 to the dynamic host.
  • the dynamic host configuration protocol request packet is sent for verification. After the verification is passed, the dynamic host configuration protocol response packet carrying the address information of the virtual machine after the virtual host configuration protocol server 1003 is received, and the virtual machine migration is established. Post address information and the virtual machine The binding relationship between the access port numbers is as shown in Table 1, where the address information includes an IP address and a MAC address.
  • the dynamic host configuration protocol server 1003 is configured to receive and verify the dynamic host configuration protocol request message, and if the verification succeeds, return to the switch 1002 a dynamic host configuration protocol response carrying the migrated address information of the virtual machine.
  • the apparatus 1001 for realizing communication after migration of a virtual machine in the embodiment of the present invention may be a virtual machine server or a virtual machine monitor.
  • the system in the seventh to eighth embodiments of the present invention can be specifically referred to the description of the devices of the fourth to sixth embodiments.
  • the device that implements the communication after the virtual machine is migrated the dynamic host configuration protocol request packet carrying the address information of the virtual machine after the migration is configured, and is sent to the dynamic host configuration protocol server for verification through the switch. Then, the dynamic host configuration protocol response packet is returned, and the switch obtains the address information of the virtual machine after the virtual machine is migrated from the dynamic host configuration protocol response packet, and establishes the address information of the virtual machine after migration and the port number of the virtual machine to be accessed. The relationship is determined so that the switch can correctly identify the packets sent by the virtual machine.
  • the packets sent after the virtual machine is migrated are valid packets, and the normal communication after the virtual machine migration is implemented.
  • the device embodiment and the system embodiment in the embodiment of the present invention are the same as the method embodiment of the present invention. For details, refer to the description of the method embodiment.
  • the disclosed systems, devices, and methods can be implemented in other ways.
  • the device embodiments described above are merely illustrative.
  • the division of the unit is only a logical function division.
  • there may be another division manner for example, multiple units or components may be combined or Can be integrated into another system, or some features can be ignored, or not executed.
  • the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be electrical, mechanical or otherwise.
  • each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
  • the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
  • the technical solution of the present invention may contribute to the prior art or all or part of the technical solution may be embodied in the form of a software product stored in a storage medium.
  • a computer device which may be a personal computer, a server, a storage medium including: a USB flash drive, a removable hard disk, a read-only memory (ROM), a random access memory (RAM, Random) Acces s Memory
  • a variety of media that can store program code, such as a disk or a disc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Small-Scale Networks (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

本发明提供了一种虚拟机迁移后实现通信的方法、设备及系统。该方法包括:当虚拟机迁移后,构造携带所述虚拟机迁移后的地址信息的动态主机配置协议请求报文;向交换机发送所述动态主机配置协议请求报文,以使所述交换机建立所述虚拟机迁移后的地址信息以及所述虚拟机接入的端口号之间的绑定关系。构造携带所述虚拟机迁移后的地址信息的动态主机配置协议请求报文,向交换机发送动态主机配置协议请求报文,交换机建立虚拟机迁移后的地址信息以及虚拟机接入的端口号之间的绑定关系,其中,地址信息包括IP地址和MAC地址,交换机会认为迁移后虚拟机发送的报文是合法的,从而实现虚拟机迁移后访问网络,实现通信。

Description

说 明 书
一种虚拟机迁移后实现通信的方法、 设备和系统 技术领域
本发明涉及计算机通信领域, 特别是一种虚拟机迁移后实现通信的方 法、 设备和系统。
背景技术
云计算, 是一种基于互联网的计算方式, 通过这种方式, 共享的软硬件资 源和信息可以按需提供给计算机和其他设备。虚拟化技术作为云计算的基石之 一, 通过将一台物理的计算机虚拟化成多个虚拟机 (Vi r tua l Machine , 筒称 为 VM) , 并通过管理系统提供自动部署和快速发放的业务能力, 从而使得最终 用户 (租户)可以快速, 便捷的租用虚拟机。
云计算在提供便捷、快速的虚拟机业务的同时, 由于用户拥有对自己使用 的虚拟机的控制权限, 因此也面临一些安全问题, 例如, 用户私自修改网际协 议(Internet Protocol , 筒称为 IP)地址或介质访问控制 ( Media Acces s Control , 筒称为 MAC )地址, 造成沖突甚至网络瘫痪等。 由于虚拟机是通过 交换机接入网络,为了解决上述问题,可以在交换机中保存包含虚拟机的 IP 地 址和 MAC 地址的绑定关系, 保证只有合法用户才能够访问网络。
发明人发现现有技术中,虚拟机迁移后, 交换机中保存的仍然是包含迁移 前的虚拟机的 IP地址和 MAC地址的绑定关系, 从而交换机会认为迁移后虚拟机 实现虚拟机迁移后访问网络, 从而没有办法实现虚拟机迁移后的通信。
发明内容
在下文中给出了关于本发明的筒要概述,以便提供关于本发明的某些方面 的基本理解。 应当理解, 这个概述并不是关于本发明的穷举性概述。 它并不是 意图确定本发明的关键或重要部分,也不是意图限定本发明的范围。其目的仅 仅是以筒化的形式给出某些概念, 以此作为稍后论述的更详细描述的前序。
本发明实施例提供了一种虚拟机迁移后实现通信的方法, 包括: 当虚拟机迁移后,构造携带所述虚拟机迁移后的地址信息的动态主机配置 协议请求报文;
向交换机发送所述动态主机配置协议请求报文,以使所述交换机建立所述 虚拟机迁移后的地址信息以及所述虚拟机接入的端口号之间的绑定关系; 所述地址信息包括 IP地址和 MAC地址。
一种虚拟机迁移后实现通信的方法, 包括:
当虚拟机迁移后,交换机接收携带所述虚拟机迁移后的地址信息的动态主 机配置协议请求报文;
所述交换机建立所述虚拟机迁移后的地址信息以及所述虚拟机接入的端 口号之间的绑定关系;
所述地址信息包括 IP地址和 MAC地址。
一种虚拟机迁移后实现通信的装置, 包括:
构造单元, 用于当虚拟机迁移后,构造携带所述虚拟机迁移后的地址信息 的动态主机配置协议请求 4艮文;
发送单元, 用于向交换机发送所述动态主机配置协议请求报文, 以使所述 交换机建立所述虚拟机迁移后的地址信息以及所述虚拟机接入的端口号之间 的绑定关系;
所述地址信息包括 IP地址和 MAC地址。
一种虚拟机迁移后实现通信的交换机, 包括:
接收单元, 当虚拟机迁移后, 用于接收携带所述虚拟机迁移后的地址信息 的动态主机配置协议请求 4艮文;
绑定处理单元,用于建立所述虚拟机迁移后的地址信息以及所述虚拟机接 入的端口号之间的绑定关系; 所述地址信息包括 IP地址和 MAC地址。
一种虚拟机迁移后实现通信的系统, 包括:
虚拟机迁移后实现通信的装置, 当虚拟机迁移后, 用于构造携带所述虚拟 机迁移后的地址信息的动态主机配置协议请求报文,向交换机发送所述动态主 机配置协议请求报文;
所述交换机,用于接收携带所述虚拟机迁移后的地址信息的动态主机配置 协议请求报文,建立所述虚拟机迁移后的地址信息以及所述虚拟机接入的端口 号之间的绑定关系; 所述地址信息包括 IP地址和 MAC地址。
本发明实施例提供的虚拟机迁移后实现通信的方法、设备及系统, 通过构 造携带所述虚拟机迁移后的地址信息的动态主机配置协议请求报文,向交换机 发送所述动态主机配置协议请求报文,从而交换机可以建立所述虚拟机迁移后 的地址信息以及所述虚拟机接入的端口号之间的绑定关系,其中地址信息包括 IP地址和 MAC地址。 因此, 根据所述绑定关系, 这时交换机会认为迁移后虚拟 机发送的报文是合法的,将对迁移后虚拟机发送的报文予以处理, 可以实现虚 拟机迁移后访问网络, 从而实现虚拟机迁移后的通信。
附图说明
为了更清楚地说明本发明实施例中的技术方案,下面将对实施例描述中所 使用的附图作一筒地介绍,显而易见地, 下面描述中的附图是本发明的一些实 施例, 对于本领域普通技术人员来讲, 在不付出创造性劳动的前提下, 还可以 根据这些附图获得其他的附图。
图 1为本发明实施例的一种场景图;
图 2a为本发明第一实施例的流程示意图;
图 2b为本发明第二实施例的流程示意图
图 3为本发明第三实施例的流程示意图;
图 4为本发明第四实施例的虚拟化平台结构示意图;
图 5为本发明第四实施例的流程示意图;
图 6为本发明第五实施例的虚拟机迁移后实现通信的装置结构示意图; 图 7为本发明第六实施例的虚拟机迁移后实现通信的装置结构示意图; 图 8为本发明第七实施例的虚拟机迁移后实现通信的交换机结构示意图; 图 9为本发明第八实施例的虚拟机迁移后实现通信的系统结构示意图; 图 10为本发明第九实施例的虚拟机迁移后实现通信的系统结构示意图。 具体实施例
在下文中将结合附图对本发明的示范性实施例进行描述。为了清楚和筒明 起见, 在说明书中并未描述实际实施方式的所有特征。 然而, 应该了解, 在开 发任何这种实际实施例的过程中必须做出很多特定于实施方式的决定,以便实 现开发人员的具体目标, 并且这些决定可能会随着实施方式的不同而有所改 变。
本发明实施例一种应用场景, 如图 1所示, 为了说明本发明实施例的实施 场景, 图 1中给出了一个典型应用架构。 图 1中省略了与本发明不相关的技术特 征, 同时也省略了信息交互流程, 只给出了一个应用场景架构。 本发明可以应 用于图 1所示的场景,但是并不局限于该场景。 图 1的目的只是为了更加清楚地 说明本发明有关实施例, 不是对本发明应用范围的限制。 当虚拟机从虚拟机服 务器 1迁移到虚拟机 务器 2时, 该虚拟机对应的地址信息(该地址信息可以包 括 IP地址和 MAC地址 )和接入的端口号的绑定关系,也需要从交换机 1更新到交 换机 2。 虚拟机接入的交换机、 虚拟机接入交换机时对应的接入端口也会发生 改变, 但是虚拟机迁移并不会重新发起动态主机配置协议(Dynamic Hos t Conf igurat ion Protocol , 筒称为 DHCP)流程, 因此在没有更新虚拟机的地址 信息(包括 IP地址和 MAC地址)和接入的端口号的绑定关系的情况下, 迁移后 一个动态主机配置协议流程通常是虚拟机发出动态主机配置协议发现广 播报文给动态主机配置协议服务器,若虚拟机在一定时间内没有收到动态主机 配置协议服务器的响应,则虚拟机重发动态主机配置协议发现报文给动态主机 配置协议服务器。 动态主机配置协议服务器收到动态主机配置协议发现报文 后, 给虚拟机分配资源, 然后发出动态主机配置协议 OFFER报文。 虚拟机收到 动态主机配置协议 OFFER报文后,发出动态主机配置协议请求报文给动态主机 配置协议服务器,请求获取服务器租约, 并通告其他服务器该虚拟机已经接受 此动态主机配置协议服务器分配的地址。动态主机配置协议服务器收到动态主 机配置协议请求报文, 验证资源是否可以分配。 如果可以分配, 则动态主机配 置协议服务器发送动态主机配置协议响应给虚拟机,如果不可分配, 则发送动 态主机配置协议 NAK报文。虚拟机收到动态主机配置协议响应, 开始使用动态 主机配置协议服务器分配的资源。 如果收到动态主机配置协议 NAK报文,则虚 拟机重新发送动态主机配置协议发现 文。以上交互的所有 文都可以称为动 态主机配置协议报文。
交换机通过截获虚拟机与动态主机配置协议服务器之间的动态主机配置 协议报文进行分析处理,可以过滤不信任的动态主机配置协议报文并建立和维 护绑定关系, 该绑定关系包括虚拟机的地址信息和接入的端口号等, 该地址信 息可以包括虚拟机的 IP地址和 MAC地址。
但是在云环境中虚拟机迁移的场景下, 虚拟机迁移是内存镜像的拷贝过 程,虚拟机迁移之后,虚拟机接入的交换机和接入交换机时对应的接入的端口 号发生改变,但是并不会重新发起动态主机配置协议流程, 因此在没有更新虚 拟机对应的地址信息和接入的端口号的绑定关系的情况下,虚拟机对外发送的 报文会被交换机认为是非法报文, 从而无法实现正常通信。 为解决这一问题, 本发明实施例在虚拟机迁移后,构造一个携带虚拟机迁移后的地址信息的动态 主机配置协议报文,称为动态主机配置协议请求报文,通过虚拟机迁移后接入 的交换机发送到动态主机配置协议服务器进行验证。此时, 交换机可以为所述 虚拟机分配接入的端口号, 并记录为所述虚拟机分配的接入端口号。如果动态 主机配置协议服务器验证动态主机配置协议请求报文为合法报文,则返回动态 主机配置协议响应报文。该动态主机配置协议响应报文中携带虚拟机迁移后的 地址信息。交换机接收到该携带虚拟机迁移后的地址信息的动态主机配置协议 响应报文后,从该响应报文中获取虚拟机迁移后的地址信息, 并结合交换机给 虚拟机分配的接入的端口号生成绑定关系, 如表 1所示, 利用该绑定关系表来 排除非法报文。
Figure imgf000008_0002
Figure imgf000008_0001
在虚拟机接入的交换机建立虚拟机对应的地址信息以及接入的端口号的 绑定关系如表 1所示。表 1并不是对本发明实施例中绑定关系的限定, 只是为了 更加清楚地说明本发明实施例, 而采用的一种绑定关系。本领域技术人员能够 实现的地址信息以及接入的端口号的绑定关系也应属于本发明保护范围。本发 明实施例地址信息可以包括 IP地址和 MAC地址, 但是并不限于此。 能够识别虚 拟机的其他地址信息也可以。本发明第一实施例提供了一种虚拟机迁移后实现 通信的方法, 如图 2a所示, 包括:
步骤 201a: 当虚拟机迁移后, 构造携带所述虚拟机迁移后的地址信息的 动态主机配置协议请求报文。
可选地, 由虚拟机服务器或虚拟机监视器监测所述虚拟机迁移后,构造携 带所述虚拟机迁移后的地址信息的动态主机配置协议请求报文。
可选地, 所述动态主机配置协议请求报文为单播的续租请求报文。
步骤 202a: 向交换机发送所述动态主机配置协议请求报文, 以使所述交 换机建立所述虚拟机迁移后的地址信息以及所述虚拟机接入的端口号之间的 绑定关系; 所述地址信息包括 IP地址和 MAC地址。
可选地, 所述方法还可以包括: 接收所述交换机发送的携带有所述虚拟机 迁移后的地址信息的动态主机配置协议响应 ^艮文; 根据所述动态主机配置协议响应报文, 更新所述虚拟机迁移后的 IP地址 的有效期。
本发明实施例实现在虚拟机迁移之后,构造携带虚拟机迁移后的地址信息 的动态主机配置协议请求报文,在交换机中建立虚拟机迁移后的地址信息以及 虚拟机接入的端口号之间新的绑定关系,因此交换机能够正确识别虚拟机向外 发送的报文,认为虚拟机迁移后发送的报文是合法的报文, 实现虚拟机迁移后 的正常通信。
本发明第二实施例提供了一种虚拟机迁移后实现通信的方法, 如图 2b所 示, 包括:
步骤 201b: 当虚拟机迁移后, 交换机接收携带所述虚拟机迁移后的地址 信息的动态主机配置协议请求报文。
可选地, 接收所述动态主机配置协议请求 文后, 所述方法还包括: 向动态主机配置协议服务器发送所述动态主机配置协议请求报文,以使所 述动态主机配置协议服务器对所述动态主机配置协议请求报文进行合法验证; 验证通过后,接收所述动态主机配置协议服务器返回的携带有所述虚拟机 迁移后的地址信息的动态主机配置协议响应 ^艮文;
从所述动态主机配置协议响应报文中获取所述虚拟机迁移后的地址信息。 步骤 202b: 所述交换机建立所述虚拟机迁移后的所述地址信息与所述虚 拟机接入的端口号之间的绑定关系; 所述地址信息包括 IP地址和 MAC地址。
可选地,接收所述动态主机配置协议请求报文后, 所述方法还包括获取所 述虚拟机接入的端口号;
则建立所述虚拟机迁移后的所述地址信息以及所述虚拟机接入的端口号 之间的绑定关系具体包括: 根据从所述动态主机配置协议响应报文中获取的 所述虚拟机迁移后的所述地址信息以及获取的所述虚拟机接入的端口号建立 所述绑定关系; 进一步地, 获取所述虚拟机接入的端口号之前, 所述方法还包括: 所述交 换机为所述虚拟机分配所述虚拟机接入的端口号,并记录所述虚拟机接入的端 口号;
则获取所述虚拟机接入的端口号具体包括:从所述记录中获取所述虚拟机 接入的端口号。
可选地, 当存在动态主机配置协议中继的情况下,通过所述动态主机配置 协议中继向所述动态主机配置协议服务器发送所述动态主机配置协议请求报 文。
可选地,所述方法还包括所述交换机向虚拟机服务器或虚拟机监视器发送 携带有所述虚拟机迁移后的地址信息的动态主机配置协议响应报文,以更新所 述虚拟机迁移后的 IP地址的有效期。
可选地, 所述动态主机配置协议请求报文为单播的续租请求报文。
本发明实施例提供的交换机,接收携带虚拟机迁移后的地址信息的动态主 机配置协议请求报文,建立虚拟机迁移后的地址信息以及虚拟机接入的端口号 之间新的绑定关系, 因此交换机能够正确识别虚拟机向外发送的报文,认为虚 拟机迁移后发送的报文是合法的报文, 实现虚拟机迁移后的正常通信。
本发明第三实施例提供了一种虚拟机迁移后实现通信的方法, 如图 3所 示, 包括:
步骤 301: 虚拟机初始启动。
发起动态主机配置协议请求流程,交换机根据动态主机配置协议服务器返 回的动态主机配置协议响应报文, 获取用户的地址信息, 结合交换机为虚拟机 分配的接入的端口号, 生成绑定关系, 如表 1所示。
虚拟机启动时, 会发起完整的 IP地址分配流程, 交换机从动态主机配置 协议服务器接收到返回的动态主机配置协议响应报文后,根据动态主机配置协 议响应报文中携带的虚拟机当前的地址信息,即可生成该虚拟机的地址信息以 及虚拟机的接入的端口号之间的绑定关系,除动态主机配置协议请求报文等少 数集中类型的报文之外,在交换机中的绑定关系中没有查询到相应绑定关系的 请求报文, 交换机一律认为是非法请求报文并丢弃该请求报文,从而保证用户 虚拟机的安全, 杜绝非法用户的接入。
步骤 302: 虚拟机迁移。
虚拟机从虚拟机服务器 1迁移到虚拟机服务器 2 , 完成虚拟机迁移。
步骤 303: 虚拟机服务器 2监测到虚拟机迁移完成。
步骤 304: 构造一个动态主机配置协议请求报文。
虚拟机服务器 2监测到虚拟机迁移完成后,虚拟机服务器 2构造一个动态 主机配置协议请求报文,该报文中携带虚拟机迁移后的地址信息, 所述地址信 息包括 IP地址和 MAC地址。 该动态主机配置协议请求报文为单播报文。 该报 文格式如下:
OP Htype hlen hops
( 1字节) ( 1字节) ( 1字节) ( 1字节)
xid (4字节)
sees (2字节) flags (2字节)
ciaddr (4 - 节)
yiaddr (4 - 节)
siaddr (4 - 节)
giaddr (4 ^ 节)
chaddr ( 16字节)
sname (64字节)
file ( 128 - 节)
options (64字节) 其中每个单元的解释如下:
1、 op: 动态主机配置协议报文的操作类型, 分为请求报文和响应报文, 1 为请求报文; 2为响应报文。
1、 htype, hlen: 虚拟机的硬件地址类型及长度。 3、 hops : 动态主机配置协议 文经过的动态主机配置协议中继的数目。 动态主机配置协议请求报文每经过一个动态主机配置协议中继,该字段就会增 加 1。
4、 xid: 虚拟机发起一次请求时选择的随机数, 用来标识一次地址请求过 程。
5、 sees : 动虚拟机开始动态主机配置协议请求后的时间。
6、 f lags : 第一个比特为广播响应标识位, 用来标识动态主机配置协议服 务器响应报文是采用单播还是广播发送。 其余比特保留不用。
7、 c iaddr: 虚拟机的 IP地址。
8、 yiaddr: 动态主机配置协议良务器分配给虚拟机的 IP地址。
9、 s iaddr: 虚拟机获取 IP地址等信息的服务器 IP地址。
10、 g iaddr: 虚拟机发出请求报文后经过的第一个动态主机配置协议中继 的 IP地址。
11、 chaddr: 虚拟机的硬件地址。
12、 sname: 虚拟机获取 IP地址等信息的服务器名称。
13、 f i le: 动态主机配置协议服务器为虚拟机指定的启动配置文件名称。
14、 opt ion: 可选变长选项字段, 包含报文的类型、 有效租期、 域名系统 ( Doma in Name Sys tem, 筒称 DNS )服务器的 IP地址、 wins服务器的 IP地址 等配置信息。
步骤 305: 发送动态主机配置协议请求报文。
构造完该动态主机配置协议请求报文后,向交换机发送该动态主机配置协 议请求报文, 此时, 交换机为所述虚拟机分配接入的端口号, 并记录为所述虚 拟机分配的接入端口号。经交换机 1发送携带该虚拟机迁移后的地址信息的动 态主机配置协议请求报文至动态主机配置协议服务器。如果存在动态主机配置 协议中继,则交换机 2接收到该动态主机配置协议请求报文后先发给动态主机 配置协议中继。
步骤 306: 发送动态主机配置协议请求报文至动态主机配置协议服务器。 交换机接收到携带该虚拟机迁移后的地址信息的动态主机配置协议请求 报文后, 向动态主机配置协议服务器发送该报文。
步骤 307: 确认动态主机配置协议请求报文合法。
动态主机配置协议服务器接收到该动态主机配置协议请求报文之后,解析 报文内容, 确认该报文是否合法。
步骤 308: 返回动态主机配置协议响应 ^艮文。
动态主机配置协议服务器确认动态主机配置协议请求报文合法,动态主机 配置协议服务器返回携带虚拟机迁移后的地址信息的动态主机配置协议响应 报文至交换机 2。
步骤 309: 交换机 2根据动态主机配置协议服务器返回的动态主机配置协 议响应报文, 获取虚拟机迁移后的地址信息, 并根据步骤 305中交换机为虚拟 机分配的接入的端口号生成绑定关系。
步骤 310: 返回动态主机配置协议响应 ^艮文。
交换机将该动态主机配置协议响应报文返回至虚拟机服务器 2。
步骤 311 : 更新虚拟机迁移后 IP地址的有效期。
动态主机配置协议响应报文中除携带迁移后虚拟机的地址信息外,还可以 携带动态主机配置协议租期信息。该租期信息携带在动态主机配置协议响应报 文的 EXPIRE字段中。 根据该动态主机配置协议租期信息, 虚拟机服务器 2可 以更新虚拟机迁移后 IP地址的有效期。
步骤 312: 虚拟机作为合法用户, 与外部网络正确通信。
本发明实施例提供虚拟机迁移后实现通信的方法,虚拟机服务器 2监测到 虚拟机迁移完成后,通过构造一个携带虚拟机迁移后的地址信息的动态主机配 置协议请求报文,从而在交换机建立虚拟机迁移后的地址信息以及虚拟机的接 入端口号新的绑定关系, 因此交换机能够正确识别虚拟机向外发送的报文,认 为虚拟机迁移后发送的报文是合法的报文, 实现虚拟机迁移后的正常通信。
本发明第四实施例提供了一种虚拟机迁移后实现通信的方法, 如图 4、 图 5所示。
图 4所示架构中,虚拟机监视器,在监测到虚拟机迁移完成后, 获取虚拟机 迁移后的地址信息,构造并发送动态主机配置协议请求报文,通过动态主机配 置协议服务器进行安全验证。
步骤 501: 虚拟机初始启动。
发起动态主机配置协议请求流程,交换机根据动态主机配置协议服务器返 回的动态主机配置协议响应信息, 获取用户的地址信息, 结合交换机为虚拟机 分配的接入端口号, 生成绑定关系, 如表 1所示。
虚拟机在虚拟机服务器启动时, 会发起完整的 IP地址分配流程, 交换机 从动态主机配置协议服务器接收到返回的动态主机配置协议响应后,根据动态 主机配置协议响应报文中携带的虚拟机当前的地址信息,即可生成该虚拟机的 地址信息以及虚拟机的接入的端口号绑定关系,如表 1所示, 除动态主机配置 协议请求报文等少数集中类型的报文之外,在交换机上绑定关系表没有查询到 相应绑定关系的请求报文, 交换机一律认为是非法请求报文并丢弃该请求报 文, 从而保证用户虚拟机的安全, 杜绝非法用户的接入。
步骤 502 : 虚拟机迁移。
虚拟机从虚拟机服务器 1迁移到虚拟机服务器 2。
步骤 503: 虚拟机监视器监测虚拟机迁移完成。
步骤 504 : 构造一个动态主机配置协议请求报文。
虚拟机监视器监测到虚拟机迁移完成,则构造携带虚拟机迁移后的地址信 息的动态主机配置协议请求报文。动态主机配置协议请求报文为单播报文。该 报文格式与本发明第二实施例相同报文格式相同,具体见第三实施例中关于报 文格式的说明。
步骤 505 : 发送动态主机配置协议请求报文至交换机。
构造完该动态主机配置协议请求报文后,向交换机发送该动态主机配置协 议请求报文, 此时, 交换机为所述虚拟机分配接入的端口号, 并记录为所述虚 拟机分配的接入端口号。交换机发送该携带虚拟机迁移后的地址信息的报文至 动态主机配置协议服务器。如果存在动态主机配置协议中继, 则交换机接收到 该动态主机配置协议请求报文后, 先发给动态主机配置协议中继。
步骤 506 : 发送动态主机配置协议请求报文至动态主机配置协议服务器。 交换机接收到该携带虚拟机迁移后的地址信息的动态主机配置协议请求 报文之后, 向动态主机配置协议服务器发送该报文。
步骤 507 : 确认动态主机配置协议请求报文合法。
动态主机配置协议服务器接收到该动态主机配置协议请求报文之后,解析 报文内容, 确认该动态主机配置协议请求报文是否合法。
步骤 508 : 返回动态主机配置协议响应。
动态主机配置协议服务器确认该动态主机配置协议请求报文合法,则动态 主机配置协议服务器返回携带虚拟机迁移后的地址信息的动态主机配置协议 响应至交换机。
步骤 509 : 交换机根据动态主机配置协议服务器返回的动态主机配置协议 响应, 获取虚拟机迁移后的地址信息, 并根据交换机为虚拟机分配的接入的端 口号生成绑定关系, 如表 1所示。
步骤 51 0: 返回动态主机配置协议响应。 交换机将该动态主机配置协议响 应返回至虚拟机监视器。
步骤 51 1 : 更新虚拟机迁移后 IP地址的有效期。
动态主机配置协议响应报文中除携带迁移后虚拟机的地址信息外,还携带 动态主机配置协议租期信息。该租期信息携带在动态主机配置协议响应报文的 EXPIRE字段中。 根据该动态主机配置协议租期信息, 更新虚拟机迁移后 IP地 址的有效期。
步骤 512: 虚拟机作为合法用户, 与外部网络正确通信。
本发明实施例提供虚拟机迁移后实现通信的方法,虚拟机监视器监测到虚 拟机迁移完成后,构造一个动态主机配置协议请求报文,通过在交换机建立虚 拟机迁移后的地址信息以及虚拟机的接入的端口号新的绑定关系,因此交换机 能够正确识别虚拟机向外发送的报文,认为虚拟机迁移后发送的报文是合法的 报文, 实现虚拟机迁移后的正常通信。
本发明第五实施例提供了一种虚拟机迁移后实现通信的装置, 如图 6所 示, 包括构造单元 601、 发送单元 602。
其中, 构造单元 601 , 用于当虚拟机迁移后, 构造携带该虚拟机迁移后的 地址信息的动态主机配置协议请求报文。 发送单元 602 , 用于向交换机发送该 动态主机配置协议请求 文,以使该交换机建立该虚拟机迁移后的地址信息以 及虚拟机接入的端口号之间的绑定关系, 所述地址信息包括 IP地址和 MAC地 址。
本发明实施例提供的虚拟机迁移后实现通信的装置, 还可以包括监测单 元, 用于监测所述虚拟机迁移。 当监测单元监测到该虚拟机迁移后, 由构造单 元构造携带该虚拟机迁移后的地址信息的动态主机配置协议请求报文。
本发明实施例提供的虚拟机迁移后实现通信的装置可以是虚拟机服务器 或者虚拟机监视器, 具体可以参照方法实施例的描述。
本发明实施例提供的虚拟机迁移后实现通信的装置, 可以在虚拟机迁移 后,构造携带虚拟机迁移后的地址信息的动态主机配置协议请求报文, 通过在 交换机建立虚拟机迁移后的地址信息以及虚拟机的接入的端口号新的绑定关 系, 其中, 地址信息包括 IP地址和 MAC地址。 因此交换机能够正确识别虚拟 机向外发送的报文,认为虚拟机迁移后发送的报文是合法的报文, 实现虚拟机 迁移后的正常通信。
本发明第六实施例提供了一种虚拟机迁移后实现通信的装置, 如图 7所 示, 包括构造单元 701、 发送单元 702、 接收单元 703和更新单元 704
其中, 构造单元 701 , 用于构造携带该虚拟机迁移后的地址信息的动态主 机配置协议请求报文。 发送单元 702 , 用于向交换机发送该动态主机配置协议 请求报文,以使该交换机建立该虚拟机迁移后的地址信息以及虚拟机接入的端 口号之间的绑定关系, 地址信息包括 IP地址和 MAC地址。 接收单元 703 , 用 于接收该交换机发送的携带有该虚拟机迁移后的地址信息的动态主机配置协 议响应报文。 更新单元 704 , 用于根据该动态主机配置协议响应报文, 更新该 虚拟机迁移后的 IP地址的有效期。
本发明实施例提供的虚拟机迁移后实现通信的装置, 还可以包括监测单 元, 用于监测该虚拟机迁移。 当监测单元监测到该虚拟机迁移后, 由构造单元 构造携带该虚拟机迁移后的地址信息的动态主机配置协议请求报文。
本发明实施例中提供的虚拟机迁移后实现通信的装置,可以是虚拟机服务 器或者虚拟机监视器。
本实施例提供的虚拟机迁移后实现通信的装置,可以监测到虚拟机迁移完 成后,构造携带虚拟机迁移后的地址信息的动态主机配置协议请求报文, 其中 地址信息包括 IP地址和 MAC地址, 通过在交换机建立虚拟机迁移后的地址信 息以及虚拟机的接入的端口号新的绑定关系, 更新虚拟机迁移后 IP地址的有 效期, 使交换机在虚拟机迁移后 IP地址的有效期内能够正确识别虚拟机向外 发送的报文,认为虚拟机迁移后发送的报文是合法的报文, 实现虚拟机迁移后 的正常通信。
本发明第七实施例提供了一种虚拟机迁移后实现通信的交换机, 如图 8 所示, 包括接收单元 801和绑定处理单元 802。
其中, 接收单元 801 , 当虚拟机迁移后, 用于接收携带该虚拟机迁移后的 地址信息的动态主机配置协议请求报文。 绑定处理单元 802 , 用于建立所述虚 拟机迁移后的地址信息以及所述虚拟机接入的端口号之间的绑定关系,其中地 址信息包括 IP地址和 MAC地址。
本发明实施例还可以包括发送单元和获取单元。发送单元用于向动态主机 配置协议服务器发送该动态主机配置协议请求报文,以使该动态主机配置协议 服务器对该动态主机配置协议请求报文进行合法验证。若验证通过后,接收单 元 801还用于接收该动态主机配置协议服务器返回的携带该虚拟机迁移后的 地址信息的动态主机配置协议响应报文。获取单元用于从该动态主机配置协议 响应报文中获取该虚拟机迁移后的地址信息。
该虚拟机迁移后实现通信的交换机还可以包括端口处理单元, 用于为所 述虚拟机分配接入的端口号, 并记录为所述虚拟机分配的接入端口号。
获取单元还可以从所述端口处理单元中获取虚拟机的接入的端口号。绑定 处理单元 802 , 建立该虚拟机迁移后的地址信息以及该虚拟机接入的端口号之 间的绑定关系具体包括: 根据从该动态主机配置协议响应报文中获取的该虚 拟机迁移后的地址信息, 以及记录的该虚拟机接入的端口号建立该绑定关系, 如表 1所示。
本发明实施例中发送单元,还用于向虚拟机服务器或虚拟机监视器发送携 带有该虚拟机迁移后的地址信息的动态主机配置协议响应报文,以更新该虚拟 机迁移后的 IP地址的有效期。
本发明实施例提供的交换机,通过接收单元接收携带所述虚拟机迁移后的 地址信息的动态主机配置协议请求 文,绑定处理单元建立虚拟机迁移后的地 址信息以及该虚拟机的接入的端口号的绑定关系, 其中, 地址信息包括 IP地 址和 MAC地址。 因此交换机能够正确识别虚拟机向外发送的报文,认为虚拟机 迁移后发送的报文是合法的报文, 实现虚拟机迁移后的正常通信。
本发明第八实施例提供了一种虚拟机迁移后实现通信的系统, 如图 9所 示,包括一种虚拟机迁移后实现通信的装置 901和虚拟机迁移后实现通信的交 换机 902。 其中, 虚拟机迁移后实现通信的装置 901 , 当虚拟机迁移后, 用于 构造携带所述虚拟机迁移后的地址信息的动态主机配置协议请求报文,向交换 机 902发送所述动态主机配置协议请求报文。交换机 902接收携带所述虚拟机 迁移后的地址信息的动态主机配置协议请求^艮文,建立所述虚拟机迁移后的地 址信息以及所述虚拟机接入的端口号之间的绑定关系, 如表 1所示, 其中, 地 址信息包括 IP地址和 MAC地址。
本发明实施例中的虚拟机迁移后实现通信的装置 901可以是虚拟机服务 器或者虚拟机监视器。
本实施例提供的虚拟机迁移后实现通信的系统,虚拟机迁移后实现通信的 装置在虚拟机迁移后,构造携带虚拟机迁移后的地址信息的动态主机配置协议 请求报文,交换机通过从动态主机配置协议响应报文中获取虚拟机迁移后的地 址信息, 建立虚拟机迁移后的地址信息以及该虚拟机的接入的端口号的绑定 表, 因此交换机能够正确识别虚拟机向外发送的报文,认为虚拟机迁移后发送 的报文是合法的报文, 实现虚拟机迁移后的正常通信。
本发明第九实施例提供了一种虚拟机迁移后通信的系统, 如图 10所示, 包括虚拟机迁移后实现通信的装置 1001、 虚拟机迁移后实现通信的交换机 1 002和动态主机配置协议服务器 1003。 其中, 虚拟机迁移后实现通信的装置 1 001 , 用于当虚拟机迁移后,构造携带该虚拟机迁移后的地址信息的动态主机 配置协议请求报文, 向交换机 1002发送该动态主机配置协议请求报文。 交换 机 1 002 , 用于接收该虚拟机迁移后实现通信的装置 1001构造并发送的携带该 虚拟机迁移后的地址信息的动态主机配置协议请求 ^艮文,并向该动态主机配置 协议服务器 1 QQ3发送该动态主机配置协议请求报文进行验证,若验证通过后, 接收该动态主机配置协议服务器 1003返回的携带该虚拟机迁移后的地址信息 的动态主机配置协议响应报文,建立该虚拟机迁移后的地址信息以及该虚拟机 接入的端口号之间的绑定关系, 如表 1所示, 其中, 地址信息包括 IP地址和 MAC地址。
动态主机配置协议服务器 1003 , 用于接收并且验证该动态主机配置协议 请求报文, 若验证通过, 向交换机 1002返回携带该虚拟机迁移后的地址信息 的动态主机配置协议响应 4艮文。
本发明实施例中的虚拟机迁移后实现通信的装置 1001可以是虚拟机服务 器或者虚拟机监视器。
本发明第七至八实施例中的系统具体可以参照实施例第四至六装置的描 述。
本实施例提供的系统,虚拟机迁移后实现通信的装置在虚拟机迁移后, 构 造携带虚拟机迁移后的地址信息的动态主机配置协议请求报文,通过交换机发 送到动态主机配置协议服务器验证通过后, 返回动态主机配置协议响应报文, 交换机从动态主机配置协议响应报文中获取虚拟机迁移后的地址信息,建立虚 拟机迁移后的地址信息以及该虚拟机的接入的端口号的绑定关系,从而交换机 能够正确识别虚拟机向外发送的报文,认为虚拟机迁移后发送的报文是合法的 报文, 实现虚拟机迁移后的正常通信。
本发明实施例中的装置实施例和系统实施例与本发明方法实施例属于同 一构思, 具体可以参照方法实施例的描述。
本领域普通技术人员可以意识到,结合本文中所公开的实施例描述的各示 例的单元及算法步骤, 能够以电子硬件、 计算机软件或者二者的结合来实现, 为了清楚地说明硬件和软件的可互换性,在上述说明中已经按照功能一般性地 描述了各示例的组成及步骤。这些功能究竟以硬件还是软件方式来执行,取决 于技术方案的特定应用和设计约束条件。专业技术人员可以对每个特定的应用 来使用不同方法来实现所描述的功能,但是这种实现不应认为超出本发明的范 围。 所属领域的技术人员可以清楚地了解到, 为描述的方便和筒洁, 上述描述 的系统、装置和单元的具体工作过程,可以参考前述方法实施例中的对应过程, 在此不再赘述。
在本申请所提供的几个实施例中, 应该理解到, 所披露的系统、 装置和方 法, 可以通过其它的方式实现。 例如, 以上所描述的装置实施例仅仅是示意性 的, 例如, 所述单元的划分, 仅仅为一种逻辑功能划分, 实际实现时可以有另 外的划分方式, 例如多个单元或组件可以结合或者可以集成到另一个系统, 或 一些特征可以忽略, 或不执行。 另一点, 所显示或讨论的相互之间的耦合或直 接耦合或通信连接可以是通过一些接口, 装置或单元的间接耦合或通信连接, 可以是电性, 机械或其它的形式。
另外, 在本发明各个实施例中的各功能单元可以集成在一个处理单元中, 也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元 中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的 形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售 或使用时, 可以存储在一个计算机可读取存储介质中。基于这样的理解, 本发 明的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全 部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储 介质中, 包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器, 的存储介质包括: U盘、 移动硬盘、 只读存储器(ROM, Read-Only Memory ), 随机存取存储器(RAM, Random Acces s Memory ), 磁碟或者光盘等各种可以存 储程序代码的介质。
以上所述,仅为本发明的具体实施方式,但本发明的保护范围并不局限于 此,任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可轻易想到 变化或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明的保护范围应 以所述权利要求的保护范围为准。

Claims

权 利 要 求 书
1、 一种虚拟机迁移后实现通信的方法, 其特征在于, 包括:
当虚拟机迁移后,构造携带所述虚拟机迁移后的地址信息的动态主机配置 协议请求报文;
向交换机发送所述动态主机配置协议请求报文,以使所述交换机建立所述 虚拟机迁移后的地址信息和所述虚拟机接入的端口号之间的绑定关系;所述地 址信息包括 IP地址和 MAC地址。
2、 如权利要求 1所述的方法, 其特征在于, 由虚拟机服务器或虚拟机监 视器监测所述虚拟机迁移后,构造携带所述虚拟机迁移后的地址信息的动态主 机配置协议请求报文。
3、 如权利要求 1或 2所述的方法, 其特征在于, 所述方法还包括: 接收所述交换机发送的携带有所述虚拟机迁移后的地址信息的动态主机 配置协议响应 4艮文;
根据所述动态主机配置协议响应报文, 更新所述虚拟机迁移后的 IP地址 的有效期。
4、 如权利要求 1至 3所述的方法, 其特征在于, 所述动态主机配置协议 请求报文为单播的续租请求报文。
5、 一种虚拟机迁移后实现通信的方法, 其特征在于, 包括:
当虚拟机迁移后,交换机接收携带所述虚拟机迁移后的地址信息的动态主 机配置协议请求报文;
所述交换机建立所述虚拟机迁移后的所述地址信息与所述虚拟机接入的 端口号之间的绑定关系; 所述地址信息包括 IP地址和 MAC地址。
6、 如权利要求 5所述的方法, 其特征在于, 接收所述动态主机配置协议 请求报文后, 所述方法还包括:
向动态主机配置协议服务器发送所述动态主机配置协议请求报文,以使所 述动态主机配置协议服务器对所述动态主机配置协议请求报文进行合法验证; 验证通过后,接收所述动态主机配置协议服务器返回的携带有所述虚拟机 迁移后的地址信息的动态主机配置协议响应 ^艮文;
从所述动态主机配置协议响应报文中获取所述虚拟机迁移后的地址信息。
7、 如权利要求 6所述的方法, 其特征在于, 接收所述动态主机配置协议 请求报文后, 所述方法还包括获取所述虚拟机接入的端口号;
则建立所述虚拟机迁移后的所述地址信息以及所述虚拟机接入的端口号 之间的绑定关系具体包括: 根据从所述动态主机配置协议响应报文中获取的 所述虚拟机迁移后的地址信息以及获取的所述虚拟机接入的端口号建立所述 绑定关系。
8、 如权利要求 7所述的方法, 其特征在于,
获取所述虚拟机接入的端口号之前, 所述方法还包括: 所述交换机为所述 虚拟机分配所述虚拟机接入的端口号, 并记录所述虚拟机接入的端口号; 则获取所述虚拟机接入的端口号具体包括:从所述记录中获取所述虚拟机 接入的端口号。
8、 如权利要求 6或 7所述的方法, 其特征在于, 当存在动态主机配置协 议中继的情况下,通过所述动态主机配置协议中继向所述动态主机配置协议服 务器发送所述动态主机配置协议请求报文。
9、 如权利要求 6至 8任一所述的方法, 其特征在于, 所述方法还包括所 述交换机向虚拟机服务器或虚拟机监视器发送携带有所述虚拟机迁移后的地 址信息的动态主机配置协议响应 文, 以更新所述虚拟机迁移后的 IP地址的 有效期。
10、 如权利要求 5至 9任一所述的方法, 其特征在于, 所述动态主机配置 协议请求报文为单播的续租请求报文。
11、 一种虚拟机迁移后实现通信的装置, 其特征在于, 包括:
构造单元, 用于当虚拟机迁移后,构造携带所述虚拟机迁移后的地址信息 的动态主机配置协议请求 4艮文;
发送单元, 用于向交换机发送所述动态主机配置协议请求报文, 以使所述 交换机建立所述虚拟机迁移后的地址信息以及所述虚拟机接入的端口号之间 的绑定关系;
所述地址信息包括 IP地址和 MAC地址。
12、 如权利要求 11所述的装置, 其特征在于,
还包括监测单元, 用于监测所述虚拟机迁移;
当监测单元监测到所述虚拟机迁移后,由构造单元构造携带所述虚拟机迁 移后的地址信息的动态主机配置协议请求报文。
13、 如权利要求 11或 12所述的装置, 其特征在于, 还包括:
接收单元,用于接收所述交换机发送的携带有所述虚拟机迁移后的地址信 息的动态主机配置协议响应 4艮文;
更新单元, 用于根据所述动态主机配置协议响应报文, 更新所述虚拟机迁 移后的 IP地址的有效期。
14、 如权利要求 11至 13任一所述的装置, 其特征在于, 所述装置包括虚 拟机服务器或虚拟机监视器。
15、 一种虚拟机迁移后实现通信的交换机, 其特征在于, 包括: 接收单元, 当虚拟机迁移后, 用于接收携带所述虚拟机迁移后的地址信息 的动态主机配置协议请求 4艮文;
绑定处理单元,用于建立所述虚拟机迁移后的地址信息以及所述虚拟机接 入的端口号之间的绑定关系;
所述地址信息包括 IP地址和 MAC地址。
16、 如权利要求 15所述的交换机, 其特征在于, 还包括:
发送单元, 用于当接收单元接收所述动态主机配置协议请求报文后, 向动 态主机配置协议服务器发送所述动态主机配置协议请求报文,以使所述动态主 机配置协议服务器对所述动态主机配置协议请求报文进行合法验证; 若验证通过后,接收单元,还用于接收所述动态主机配置协议服务器返回 的携带所述虚拟机迁移后的地址信息的动态主机配置协议响应报文;
获取单元,用于从所述动态主机配置协议响应报文中获取所述虚拟机迁移 后的地址信息。
17、 如权利要求 16所述的交换机, 其特征在于,
获取单元,还用于当接收单元接收所述动态主机配置协议请求报文后, 获 取所述虚拟机接入的端口号;
则绑定处理单元,建立所述虚拟机迁移后的所述地址信息以及所述虚拟机 接入的端口号之间的绑定关系具体包括: 根据从所述动态主机配置协议响应 报文中获取的所述虚拟机迁移后的所述地址信息以及记录的所述虚拟机接入 的端口号建立所述绑定关系。
18、 如权利要求 17所述的交换机, 其特征在于, 还包括:
分配单元, 用于当接收单元接收所述动态主机配置协议请求报文后, 为所 述虚拟机分配接入的端口号, 并记录为所述虚拟机分配的接入的端口号。
19、 如权利 16至 18所述的交换机, 其特征在于, 所述发送单元, 还用于 向虚拟机服务器或虚拟机监视器发送携带有所述虚拟机迁移后的地址信息动 态主机配置协议响应报文, 以更新所述虚拟机迁移后的 IP地址的有效期。
20、 一种虚拟机迁移后实现通信的系统, 其特征在于, 包括:
虚拟机迁移后实现通信的装置, 当虚拟机迁移后, 用于构造携带所述虚拟 机迁移后的地址信息的动态主机配置协议请求报文,向交换机发送所述动态主 机配置协议请求报文;
交换机,接收携带所述虚拟机迁移后的地址信息的动态主机配置协议请求 报文,建立所述虚拟机迁移后的所述地址信息以及所述虚拟机接入的端口号之 间的绑定关系; 所述地址信息包括 IP地址和 MAC地址。
21、 如权利要求 20所述的系统, 其特征在于, 还包括动态主机配置协议 服务器, 其中,
交换机,接收所述虚拟机迁移后实现通信的装置构造并发送的携带所述虚 拟机迁移后的地址信息的动态主机配置协议请求 >¾文 ,并向所述动态主机配置 协议服务器发送所述动态主机配置协议请求报文进行验证, 若验证通过后,接 收所述动态主机配置协议服务器返回的携带所述虚拟机迁移后的地址信息的 动态主机配置协议响应报文,建立所述虚拟机迁移后的所述地址信息以及所述 虚拟机接入的端口号之间的绑定关系;
所述动态主机配置协议服务器接收并且验证所述动态主机配置协议请求 报文, 若验证通过, 向交换机返回携带所述虚拟机迁移后的地址信息的动态主 机配置协议响应艮文。
22、 如权利要求 20或 21所述的系统, 其特征在于, 所述虚拟机迁移后实 现通信的装置, 具体包括虚拟机服务器或者虚拟机监视器。
PCT/CN2011/084617 2011-12-26 2011-12-26 一种虚拟机迁移后实现通信的方法、设备和系统 WO2013097067A1 (zh)

Priority Applications (4)

Application Number Priority Date Filing Date Title
EP11879109.4A EP2698957B1 (en) 2011-12-26 2011-12-26 Method, device and system for realizing communication after virtual machine migration
PCT/CN2011/084617 WO2013097067A1 (zh) 2011-12-26 2011-12-26 一种虚拟机迁移后实现通信的方法、设备和系统
CN201180003061.8A CN103534994B (zh) 2011-12-26 2011-12-26 一种虚拟机迁移后实现通信的方法、设备和系统
US14/081,780 US9479611B2 (en) 2011-12-26 2013-11-15 Method, device, and system for implementing communication after virtual machine migration

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2011/084617 WO2013097067A1 (zh) 2011-12-26 2011-12-26 一种虚拟机迁移后实现通信的方法、设备和系统

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US14/081,780 Continuation US9479611B2 (en) 2011-12-26 2013-11-15 Method, device, and system for implementing communication after virtual machine migration

Publications (1)

Publication Number Publication Date
WO2013097067A1 true WO2013097067A1 (zh) 2013-07-04

Family

ID=48696164

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/084617 WO2013097067A1 (zh) 2011-12-26 2011-12-26 一种虚拟机迁移后实现通信的方法、设备和系统

Country Status (4)

Country Link
US (1) US9479611B2 (zh)
EP (1) EP2698957B1 (zh)
CN (1) CN103534994B (zh)
WO (1) WO2013097067A1 (zh)

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105262685A (zh) * 2014-07-14 2016-01-20 杭州华三通信技术有限公司 一种报文处理方法和装置
CN106549800A (zh) * 2016-10-31 2017-03-29 北京奇鱼时代科技有限公司 用于在网络系统中批量校验数据接口的方法和装置
CN108199962A (zh) * 2017-12-22 2018-06-22 新华三技术有限公司 地址迁移方法、装置、网络设备及可读存储介质
CN113220413A (zh) * 2021-04-21 2021-08-06 新浪网技术(中国)有限公司 虚拟机迁移后清除交换机旧端口arp表项的方法及系统
CN115499298A (zh) * 2022-11-15 2022-12-20 济南浪潮数据技术有限公司 一种虚拟机热迁移方法、装置、设备及介质

Families Citing this family (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2014236330A (ja) * 2013-05-31 2014-12-15 富士通株式会社 使用態様情報生成プログラム、使用態様情報生成装置、通信システム、及び使用態様情報生成方法
US20150071091A1 (en) * 2013-09-12 2015-03-12 Alcatel-Lucent Usa Inc. Apparatus And Method For Monitoring Network Performance
CN106254574B (zh) * 2016-09-09 2019-09-17 新华三技术有限公司 一种地址分配方法和装置
US10977064B2 (en) 2017-08-23 2021-04-13 Red Hat, Inc. Live virtual machine migration
US10838752B2 (en) 2017-08-28 2020-11-17 Red Hat Israel, Ltd. Network notification loss detection for virtual machine migration
US11070629B2 (en) 2017-08-30 2021-07-20 Red Hat Israel, Ltd Migration notification and response messages for virtual machines
US10628198B2 (en) 2017-08-30 2020-04-21 Red Hat Israel Ltd. Hypervisor management of migration notification and response messages for virtual machines
US10965641B2 (en) 2017-12-07 2021-03-30 Red Hat, Inc. Live virtual machine migration utilizing network address pools
US10693801B2 (en) 2018-02-20 2020-06-23 Red Hat, Inc. Packet drop reduction in virtual machine migration
US10802813B2 (en) * 2018-12-19 2020-10-13 Atlassian Pty Ltd. Systems and methods for updating virtual machines
CN111988223B (zh) * 2020-08-19 2022-04-08 杭州迪普科技股份有限公司 虚拟机迁移方法与网络系统

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101876921A (zh) * 2009-04-29 2010-11-03 华为技术有限公司 一种虚拟机迁移决策方法、装置及系统
CN101951345A (zh) * 2010-10-15 2011-01-19 杭州华三通信技术有限公司 一种报文的发送方法和设备
US20110255533A1 (en) * 2010-04-14 2011-10-20 Brocade Communications Systems, Inc. Remote F_Ports

Family Cites Families (27)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6768743B1 (en) * 1999-10-26 2004-07-27 3Com Corporation Method and system for address server redirection for multiple address networks
US7139818B1 (en) * 2001-10-04 2006-11-21 Cisco Technology, Inc. Techniques for dynamic host configuration without direct communications between client and server
US7313606B2 (en) * 2001-11-27 2007-12-25 The Directv Group, Inc. System and method for automatic configuration of a bi-directional IP communication device
US6973086B2 (en) * 2002-01-28 2005-12-06 Nokia Corporation Method and system for securing mobile IPv6 home address option using ingress filtering
CN100391180C (zh) * 2003-10-30 2008-05-28 华为技术有限公司 一种以太网二层交换设备绑定硬件地址和端口的方法
GB2418326B (en) 2004-09-17 2007-04-11 Hewlett Packard Development Co Network vitrualization
CN100574334C (zh) * 2005-09-09 2009-12-23 华为技术有限公司 Ppp接入终端实现自动业务发放的方法
US8838756B2 (en) * 2009-07-27 2014-09-16 Vmware, Inc. Management and implementation of enclosed local networks in a virtual lab
US8381209B2 (en) * 2007-01-03 2013-02-19 International Business Machines Corporation Moveable access control list (ACL) mechanisms for hypervisors and virtual machines and virtual port firewalls
US7653063B2 (en) * 2007-01-05 2010-01-26 Cisco Technology, Inc. Source address binding check
US8467355B2 (en) 2009-01-22 2013-06-18 Belair Networks Inc. System and method for providing wireless local area networks as a service
US8213336B2 (en) 2009-02-23 2012-07-03 Cisco Technology, Inc. Distributed data center access switch
US7984125B2 (en) * 2009-11-17 2011-07-19 Iron Mountain Incorporated Techniques for deploying virtual machines using a DHCP server to assign reserved IP addresses
CN101876883B (zh) * 2009-11-30 2012-02-01 英业达股份有限公司 保持虚拟机器的远程操作不中断的方法
CN102081552A (zh) * 2009-12-01 2011-06-01 华为技术有限公司 一种物理机到虚拟机的在线迁移方法、装置和系统
US8694654B1 (en) * 2010-03-23 2014-04-08 Juniper Networks, Inc. Host side protocols for use with distributed control plane of a switch
CN101827106A (zh) 2010-04-29 2010-09-08 华为技术有限公司 一种dhcp安全通信方法、装置和系统
CN101888387B (zh) 2010-07-14 2014-09-10 福建星网锐捷网络有限公司 重新建立绑定表项的方法、装置及侦听设备
CN102136931B (zh) * 2010-09-20 2013-12-04 华为技术有限公司 虚端口网络策略配置方法、一种网络管理中心和相关设备
CN102457583B (zh) * 2010-10-19 2014-09-10 中兴通讯股份有限公司 一种虚拟机移动性的实现方法及系统
US8458700B1 (en) * 2010-12-07 2013-06-04 Netapp, Inc. Provisioning virtual machines
CN102594652B (zh) * 2011-01-13 2015-04-08 华为技术有限公司 一种虚拟机迁移方法、交换机、虚拟机系统
CN102694720B (zh) * 2011-03-24 2015-07-29 日电(中国)有限公司 编址方法、编址装置、架构管理器、交换机和数据路由方法
CN102185774A (zh) * 2011-05-10 2011-09-14 中兴通讯股份有限公司 虚拟机无缝迁移的方法、管理器及系统
US20130024553A1 (en) * 2011-07-18 2013-01-24 Cisco Technology, Inc. Location independent dynamic IP address assignment
US9231846B2 (en) * 2011-11-22 2016-01-05 Microsoft Technology Licensing, Llc Providing network capability over a converged interconnect fabric
US9001696B2 (en) * 2011-12-01 2015-04-07 International Business Machines Corporation Distributed dynamic virtual machine configuration service

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101876921A (zh) * 2009-04-29 2010-11-03 华为技术有限公司 一种虚拟机迁移决策方法、装置及系统
US20110255533A1 (en) * 2010-04-14 2011-10-20 Brocade Communications Systems, Inc. Remote F_Ports
CN101951345A (zh) * 2010-10-15 2011-01-19 杭州华三通信技术有限公司 一种报文的发送方法和设备

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP2698957A4 *

Cited By (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105262685A (zh) * 2014-07-14 2016-01-20 杭州华三通信技术有限公司 一种报文处理方法和装置
WO2016008394A1 (en) * 2014-07-14 2016-01-21 Hangzhou H3C Technologies Co., Ltd. Packets processing
CN105262685B (zh) * 2014-07-14 2018-10-09 新华三技术有限公司 一种报文处理方法和装置
US10686733B2 (en) 2014-07-14 2020-06-16 Hewlett Packard Enterprise Development Lp System and method for virtual machine address association
CN106549800A (zh) * 2016-10-31 2017-03-29 北京奇鱼时代科技有限公司 用于在网络系统中批量校验数据接口的方法和装置
CN108199962A (zh) * 2017-12-22 2018-06-22 新华三技术有限公司 地址迁移方法、装置、网络设备及可读存储介质
CN108199962B (zh) * 2017-12-22 2021-09-07 新华三技术有限公司 地址迁移方法、装置、网络设备及可读存储介质
CN113220413A (zh) * 2021-04-21 2021-08-06 新浪网技术(中国)有限公司 虚拟机迁移后清除交换机旧端口arp表项的方法及系统
CN113220413B (zh) * 2021-04-21 2023-11-21 新浪技术(中国)有限公司 虚拟机迁移后清除交换机旧端口arp表项的方法及系统
CN115499298A (zh) * 2022-11-15 2022-12-20 济南浪潮数据技术有限公司 一种虚拟机热迁移方法、装置、设备及介质
CN115499298B (zh) * 2022-11-15 2023-02-28 济南浪潮数据技术有限公司 一种虚拟机热迁移方法、装置、设备及介质

Also Published As

Publication number Publication date
EP2698957A1 (en) 2014-02-19
EP2698957A4 (en) 2014-10-15
US20140074997A1 (en) 2014-03-13
CN103534994A (zh) 2014-01-22
EP2698957B1 (en) 2016-07-27
CN103534994B (zh) 2017-08-25
US9479611B2 (en) 2016-10-25

Similar Documents

Publication Publication Date Title
WO2013097067A1 (zh) 一种虚拟机迁移后实现通信的方法、设备和系统
EP3675418B1 (en) Issuance of service configuration file
US8125993B2 (en) Network element having a DHCP lease timer
US9143479B2 (en) DHCP proxy in a subscriber environment
EP2608491B1 (en) Method, apparatus and system for allocating public IP address
EP1766860B1 (en) Method and system for dynamic device address management
US20100223655A1 (en) Method, System, and Apparatus for DHCP Authentication
CN110417929B (zh) 通过在区块链网络上运行dhcp服务器提供的高可用性dhcp服务
WO2013163944A1 (zh) 一种共享IaaS业务云账号的方法、及共享平台和网络装置
US9432474B2 (en) Control method, control device, and processor in software defined network
JP2018525907A (ja) 端末に関連付けられているソースアドレスの検証
CN114070723B (zh) 裸金属服务器的虚拟网络配置方法、系统及智能网卡
US8887237B2 (en) Multimode authentication
KR20120132206A (ko) 디바이스의 서버 연결 방법, 정보 제공 방법 및 이를 적용한 디바이스 및, 클라우딩 컴퓨팅 네트워크 시스템 및 그 동작 방법
CN111585887A (zh) 基于多个网络的通信方法、装置、电子设备及存储介质
WO2014110984A1 (zh) 用户终端接入网络的认证方法及装置
US20050188063A1 (en) Modifying a DHCP configuration for one system according to a request from another system
WO2011095079A1 (zh) 一种ip地址分配方法、装置及系统
CN114124812A (zh) 维护表项一致性的方法、装置及电子设备
JP2013183243A (ja) 仮想マシンにアドレスを割り当てるプログラム、方法及び物理サーバ
WO2023134557A1 (zh) 一种基于工业互联网标识的处理方法及装置
WO2014090022A1 (zh) 动态主机配置协议服务器的识别方法和装置
WO2020048177A1 (zh) 机顶盒管理方法、装置、设备及存储介质
EP4216510A1 (en) Method for acquiring address, apparatus and system
CN110933199B (zh) 一种地址分配方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11879109

Country of ref document: EP

Kind code of ref document: A1

REEP Request for entry into the european phase

Ref document number: 2011879109

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 2011879109

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE