IP Library Granted Patent US 12,495,000
Granted Patent B2
US 12,495,000 · App. 18/685,218 · Granted Dec 9, 2025

Method and apparatus for controlling flow entry

Inventors: Shunmin Zhu (Hangzhou, CN); Yisong Qiao (Hangzhou, CN); Nianbing Yu (Hangzhou, CN); Zikang Chen (Hangzhou, CN)
Assignee: Hangzhou AliCloud Feitian Information Technology Co., Ltd.
H04L45/76H04L45/02H04L45/745
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,495,000
App. No.
18/685,218
Granted
Dec 9, 2025
Kind
B2
Abstract

This specification provides a method and an apparatus for controlling a flow entry. The method includes: receiving a data message sent by a user, and determining a target flow entry matched with the data message, where the target flow entry is one of at least one flow entry corresponding to a target virtual machine in a local position; in a case that a first version number of the target virtual machine included in the target flow entry is inconsistent with a second version number of the target virtual machine recorded in the local position, deleting a flow entry including the first version number in the local position; and sending the data message to a centrex, so that the centrex forwards the data message to a target host machine, where the second version number is generated in a case that the target virtual machine is migrated to the target host machine.

Claims (101)

1 . A method for controlling a flow entry applied to a source host machine in which a target virtual machine is located before the target virtual machine is migrated to a target host machine, comprising:

receiving a data message sent by a user;

determining a target flow entry that is matched with the data message,

wherein the target flow entry is one of at least one flow entry corresponding to the target virtual machine in the source host machine,

wherein a first version number of the target virtual machine is in the target flow entry, and

wherein, in response to the target virtual machine being migrated to the target host machine, a second version number of the target virtual machine is generated; and

in response to the first version number of the target virtual machine in the target flow entry being inconsistent with the second version number of the target virtual machine recorded in the source host machine:

deleting a flow entry comprising the first version number in the source host machine, and

sending the data message to the target host machine through a virtual switch on the source host machine.

2 . The method according to claim 1 , further comprising:

before receiving the data message sent by the user, generating the first version number of the target virtual machine and adding the first version number to the at least one flow entry;

determining that the target virtual machine is migrated from the source host machine to the target host machine; and

in response to determining that the target virtual machine is migrated from the source host machine to the target host machine, recording the second version number of the target virtual machine after migration.

3 . The method for according to claim 1 , further comprising:

in response to the target flow entry that is matched with the data message not being found:

generating a first flow entry according to the data message through the virtual switch, and

adding the first version number to the first flow entry.

4 . The method according to claim 3 , wherein the generating the first flow entry according to the data message through the virtual switch comprises:

establishing a long connection data channel with a client of the user according to a client identifier of the user comprised in the data message through the virtual switch, and

constructing the first flow entry according to a result of establishment of the long connection data channel through the virtual switch, wherein the first flow entry comprises interface configuration information of the long connection data channel.

5 . The method according to claim 1 , further comprising:

in response to the first version number of the target virtual machine in the target flow entry being inconsistent with the second version number of the target virtual machine recorded in the source host machine:

generating a second flow entry corresponding to the data message through the virtual switch,

adding the second version number to the second flow entry through the virtual switch,

performing forwarding processing on the data message according to the second flow entry through the virtual switch, and

delivering the second flow entry to the target host machine through the virtual switch.

6 . The method according to claim 5 , wherein the generating the second flow entry corresponding to the data message through the virtual switch comprises:

establishing a long connection data channel between the target host machine and a client of the user according to a client identifier of the user comprised in the data message through the virtual switch, and

constructing the second flow entry according to a result of establishment of the long connection data channel through the virtual switch, wherein the second flow entry comprises interface configuration information of the long connection data channel.

7 . The method according to claim 1 , further comprising:

in response to the first version number of the target virtual machine in the target flow entry being consistent with the second version number of the target virtual machine recorded in the source host machine:

determining an attribute identifier of the data message,

determining, in the target flow entry, a set of actions corresponding to the attribute identifier, and

forwarding the data message according to the set of actions.

8 . The method according to claim 1 , wherein the determining the target flow entry that is matched with the data message comprises:

determining, according to a user identifier of the user, the target virtual machine associated with the user in the source host machine,

determining the at least one flow entry corresponding to the target virtual machine, and

determining the target flow entry that is matched with the data message according to tuple data comprised in a header field of each flow entry.

9 . The method according to claim 1 , wherein, in response to the first version number of the target virtual machine comprised in the target flow entry being consistent with the second version number of the target virtual machine recorded in the source host machine, determining that the target flow entry is a hit; and

in response to the target flow entry being a hit, the method further comprises:

counting a number of hits of the target flow entry within a target time interval, and

in response to the number of hits being less than a preset number threshold, deleting the flow entry comprising the first version number in the source host machine.

10 . A non-transitory computer-readable storage medium, having computer-executable instructions stored thereon, wherein in response to the computer-executable instructions being executed by a processor, the steps of the method according to claim 1 are implemented.

11 . A network interface card in a source host machine in which a target virtual machine is located before the target virtual machine is migrated to a target host machine, comprising:

a memory and a processor,

wherein the memory is configured to store computer-executable instructions,

wherein the processor is configured to execute the computer-executable instructions, and

wherein, in response to the computer-executable instructions being executed by the processor, the processor is configured to:

receive a data message sent by a user, and

determine a target flow entry that is matched with the data message,

wherein the target flow entry is one of at least one flow entry corresponding to the target virtual machine in the source host machine,

wherein a first version number of the target virtual machine is in the target flow entry,

wherein, in response to the target virtual machine being migrated to the target host machine, a second version number of the target virtual machine is generated, and

wherein, in response to the first version number of the target virtual machine in the target flow entry being inconsistent with the second version number of the target virtual machine recorded in the source host machine, the processor is further configured to:

 delete a flow entry comprising the first version number in the source host machine, and

 send the data message to the target host machine through a virtual switch on the source host machine.

12 . The network interface card according to claim 11 , wherein the processor is further configured to:

before receiving the data message sent by the user, generate the first version number of the target virtual machine and add the first version number to the at least one flow entry; and

in response to determining that the target virtual machine is migrated from the source host machine to the target host machine, record the second version number of the target virtual machine after migration.

13 . The network interface card according to claim 11 , wherein the processor is further configured to:

in response to the target flow entry that is matched with the data message not being found,

generate a first flow entry according to the data message through the virtual switch, and

add the first version number to the first flow entry.

14 . The network interface card according to claim 13 , wherein the processor is configured to:

establish a long connection data channel with a client of the user according to a client identifier of the user comprised in the data message through the virtual switch, and

construct the first flow entry according to a result of establishment of the long connection data channel through the virtual switch, wherein the first flow entry comprises interface configuration information of the long connection data channel.

15 . The network interface card according to claim 11 , wherein the processor is further configured to:

in response to the first version number of the target virtual machine comprised in the target flow entry being inconsistent with the second version number of the target virtual machine recorded in the source host machine:

generate a second flow entry corresponding to the data message through the virtual switch,

add the second version number to the second flow entry through the virtual switch,

perform forwarding processing on the data message according to the second flow entry through the virtual switch, and

deliver the second flow entry to the target host machine through the virtual switch.

16 . The network interface card according to claim 15 , wherein the processor is configured to:

establish a long connection data channel between the target host machine and a client of the user according to a client identifier of the user comprised in the data message through the virtual switch, and

construct the second flow entry according to a result of establishment of the long connection data channel through the virtual switch, wherein the second flow entry comprises interface configuration information of the long connection data channel.

17 . The network interface card according to claim 11 , wherein the processor is further configured to:

in response to the first version number of the target virtual machine comprised in the target flow entry being consistent with the second version number of the target virtual machine recorded in the source host machine:

determine an attribute identifier of the data message,

determine, in the target flow entry, a set of actions corresponding to the attribute identifier, and

forward the data message according to the set of actions.

18 . The network interface card according to claim 11 , wherein the processor is configured to:

determine, according to a user identifier of the user, the target virtual machine associated with the user in the source host machine,

determine the at least one flow entry corresponding to the target virtual machine, and

determine the target flow entry that is matched with the data message according to tuple data comprised in a header field of each flow entry.

19 . The network interface card according to claim 11 , wherein in response to the first version number of the target virtual machine in the target flow entry being consistent with the second version number of the target virtual machine recorded in the source host machine, determining that the target flow entry is a hit;

in response to the target flow entry being a hit, the processor is further configured to:

count a number of hits of the target flow entry within a target time interval; and

in response to the number of hits being less than a preset number threshold, delete the flow entry comprising the first version number in the source host machine.

20 . A computing device in a source host machine in which a target virtual machine is located before the target virtual machine is migrated to a target host machine, comprising:

a memory and a processor,

wherein the memory is configured to store computer-executable instructions,

wherein the processor is configured to execute the computer-executable instructions, and

wherein, in response to the computer-executable instructions being executed by the processor, the processor is configured to:

receive a data message sent by a user, and

determine a target flow entry that is matched with the data message,

wherein the target flow entry is one of at least one flow entry corresponding to the target virtual machine in the source host machine,

wherein a first version number of the target virtual machine is in the target flow entry,

wherein, in response to the target virtual machine being migrated to the target host machine, a second version number of the target virtual machine is generated, and

wherein, in response to the first version number of the target virtual machine in the target flow entry being inconsistent with the second version number of the target virtual machine recorded in the source host machine, the processor is further configured to:

 delete a flow entry comprising the first version number in the source host machine, and

 send the data message to the target host machine through a virtual switch run on the source host machine.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2026
From: HANGZHOU ALICLOUD FEITIAN INFORMATION TECHNOLOGY CO., LTD.
To: CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PRIVATE LIMITED
Reel/Frame 075437/0941 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2025
From: ZHU, SHUNMIN; QIAO, YISONG; YU, NIANBING; CHEN, ZIKANG
To: HANGZHOU ALICLOUD FEITIAN INFORMATION TECHNOLOGY CO., LTD.
Reel/Frame 070390/0950 →
Priority Claims (1)
CN 202210114494.0 · Jan 30, 2022 · national
Continuity (1)
Related Publication 20250227066A1 · Jul 10, 2025
References Cited (26)
US 20140130044A1 · Zhang · 2014 [cited by examiner]
US 20140280547A1 · DeCusatis · 2014 [cited by examiner]
US 20150309818A1 · Lee · 2015 [cited by examiner]
US 20160188378A1 · Chao · 2016 [cited by examiner]
US 20210349767A1 · Asayag · 2021 [cited by examiner]
CN 101321088A · 2008 [cited by applicant]
CN 105589744A · 2016 [cited by applicant]
CN 106909439A · 2017 [cited by applicant]
CN 109412925A · 2019 [cited by applicant]
CN 110324245A · 2019 [cited by applicant]
CN 111698167A · 2020 [cited by applicant]
CN 111740909A · 2020 [cited by applicant]
CN 111740910A · 2020 [cited by applicant]
CN 113220413A · 2021 [cited by applicant]
CN 113254148A · 2021 [cited by examiner]
CN 113672354A · 2021 [cited by applicant]
CN 113703921A · 2021 [cited by applicant]
CN 114598645A · 2022 [cited by applicant]
WO WO2014067055A1 · 2014 [cited by examiner]
WO 2021169514A1 · 2021 [cited by applicant]
WO WO2022088743A1 · 2022 [cited by examiner]
Translation of WO-2014067055-A1. (Year: 2014). [cited by examiner]
Chinese Office Action, as issued in connection with Chinese Application No. 2024062802183170, dated Jun. 28, 2024, 17 pgs. [cited by applicant]
Notice of Allowance as received in Chinese Application No. 202210114494.0, dated Sep. 27, 2024. [cited by applicant]
Yanzhi et al., Software defining network virtualization scheme based on OpenFlow, Application Research of Computers, Nov. 2018, vol. 35, No. 11, China. [cited by applicant]
China National Intellectual Property Administration; International Search Report and Written Opinion issued in PCT App. No. PCT/CN2023/073725 dated Apr. 27, 2023; 14 pages. [cited by applicant]