CN110971715A - Headquarter access request method, device and system - Google Patents

Headquarter access request method, device and system Download PDF

Info

Publication number
CN110971715A
CN110971715A CN201811140660.4A CN201811140660A CN110971715A CN 110971715 A CN110971715 A CN 110971715A CN 201811140660 A CN201811140660 A CN 201811140660A CN 110971715 A CN110971715 A CN 110971715A
Authority
CN
China
Prior art keywords
access request
network
headquarters
sending
module
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201811140660.4A
Other languages
Chinese (zh)
Inventor
曾东方
苗辉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Guizhou Baishancloud Technology Co Ltd
Original Assignee
Guizhou Baishancloud Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Guizhou Baishancloud Technology Co Ltd filed Critical Guizhou Baishancloud Technology Co Ltd
Priority to CN201811140660.4A priority Critical patent/CN110971715A/en
Publication of CN110971715A publication Critical patent/CN110971715A/en
Pending legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L61/00Network arrangements, protocols or services for addressing or naming
    • H04L61/45Network directories; Name-to-address mapping
    • H04L61/4505Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols
    • H04L61/4511Network directories; Name-to-address mapping using standardised directories; using standardised directory access protocols using domain name system [DNS]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L45/00Routing or path finding of packets in data switching networks
    • H04L45/12Shortest path evaluation
    • H04L45/121Shortest path evaluation by minimising delays
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

The invention discloses a headquarter access request method, a device and a system, wherein the method comprises the following steps: an exit router of the branch internal network receives an access request initiated by a client; judging whether the access request is an access request for accessing a headquarters; when the access request is an access request for accessing a headquarters, sending the access request to an acceleration network; the accelerating network sends the access request to client terminal equipment of a headquarter intranet, the client terminal equipment of the headquarter intranet determines a site server of the access request, source returning processing is carried out to obtain response data, the response data are sent to the accelerating network, and the accelerating network sends the response data to the branch intranet. The invention can ensure that the branch internal network can safely and quickly access the headquarter network, the deployment cost is greatly reduced compared with a special line, and the operation complexity is also greatly reduced.

Description

Headquarter access request method, device and system
Technical Field
The invention relates to the technical field of internet, in particular to a headquarters access request method, device and system.
Background
Retail establishments typically have a large number of chain stores, which refers to numerous small, distributed branch stores that operate like goods and services. Under the leadership of the headquarter, common business policy and consistent marketing action are adopted, the organic combination of centralized purchasing and decentralized selling is realized, and the combination of scale economic benefit is realized through standardized operation. Such businesses include branded apparel businesses, agencies, logistics businesses, etc., again hereinafter exemplified by retail stores.
The store has two modes of direct operation and franchise, the scale is not too large, the number of staff in the store is not more than 20, even only 1, the network environment is managed and operated by a headquarter I T department, and core services such as a trading system and a warehouse management system required by store operation are deployed in the headquarter or a central machine room. The store has a need to access a headquarters, but the headquarters typically does not need to access services or systems within the store.
Because the retail enterprises are very frequently expanded and changed in the internet cloud era, the addresses of the stores are frequently changed, the network capabilities of the store owners and the staff are relatively weak, and the network deployment capability is basically unavailable, the network operation deployment brings great workload. In addition, general stores are distributed in various regions throughout the country, cities of different scales and the like, and the existing access mode influences the network quality of a branch store access headquarters, real-time store transaction and normal business of the stores.
There are generally two types of network schemes that retail enterprises currently branch on:
when a special line of an operator, such as an MPLS special line, is purchased, a headquarters and each branch shop are interconnected through a special line intranet, and the problems of service safety and unsmooth network in remote areas can be effectively solved. However, the price is high, the deployment and operation are very complex, each branch network segment needs to be managed and allocated, the conflict is prevented, the implementation period is long, and the implementation period is recorded in months. And the retail business requires frequent changes of stores, such as rapid expansion and market preemption.
The operator broadband is directly used, and each branch store dials into the headquarters by using the SSL VPN to access the intranet service of the headquarters. The scheme can effectively solve the problem of rapid deployment, facilitates service expansion, and ensures the safety of service data. But the service experience is unstable, the networks of stores in various places throughout the country are different, the computer using environment of each store manager is different, and a large number of daily operation problems need to be maintained and processed.
Because the transaction, the warehouse and the like belong to the core data of the enterprise, in order to prevent the safety problem and the leakage risk, the enterprise usually can not directly make the store directly access the core service of the data center through the public network. It is therefore necessary to use an access method capable of preventing data leakage.
In conclusion, in the internet cloud era, retail enterprises face the problems that a large number of branches are complex to manage and maintain, the service availability of branch stores is not guaranteed well, and the security of enterprise core data needs to be guaranteed.
Disclosure of Invention
In order to solve the technical problem, the invention provides a headquarters access request processing method, device and system.
The headquarters access request processing method provided by the invention comprises the following steps:
an exit router of the branch internal network receives an access request initiated by a client;
judging whether the access request is an access request for accessing a headquarters;
when the access request is an access request for accessing a headquarters, sending the access request to an acceleration network;
the accelerating network sends the access request to client terminal equipment of a headquarter intranet, the client terminal equipment of the headquarter intranet determines a site server of the access request, source returning processing is carried out to obtain response data, the response data are sent to the accelerating network, and the accelerating network sends the response data to the branch intranet.
The headquarters access request processing method also has the following characteristics:
the method further comprises the following steps: and when the access request is not used for accessing the headquarters, sending the access request to an external network.
The headquarters access request processing method also has the following characteristics:
the sending the access request to an acceleration network comprises: and determining a network access point which is closest to the home location of the branch intranet in the acceleration network, and sending the access request to the network access point which is closest to the home location of the branch intranet in the acceleration network.
The headquarters access request processing method also has the following characteristics:
the sending the access request to an acceleration network comprises: the exit router encrypts the access request by using a preset encryption rule and then sends the access request to the acceleration network;
the method further comprises the following steps: and the client terminal equipment of the headquarter intranet decrypts the received access request by using the preset encryption rule.
The invention provides a headquarters access request processing device, comprising:
the system comprises an exit router positioned in an internal network of a branch store and client terminal equipment positioned in an internal network of a headquarter;
the exit router comprises a first receiving module, a judging module and a first sending module;
the first receiving module is used for receiving an access request initiated by a client;
the judging module is used for judging whether the access request is an access request for accessing a headquarters;
a first sending module, configured to send the access request to an acceleration network when the access request is an access request for accessing a headquarters;
the client terminal equipment comprises a second receiving module, a site server determining module, an obtaining module and a second sending module;
the second receiving module is configured to receive the access request for accessing the headquarters, which is forwarded by the acceleration network;
the site server determining module is used for determining the site server of the access request;
the acquisition module is used for carrying out source returning processing to acquire response data;
and the second sending module is used for sending the response data to the acceleration network.
The headquarters access request processing apparatus further has the following features:
the first sending module is used for sending the access request to an external network when the access request is not used for accessing the headquarters.
The headquarters access request processing apparatus further has the following features:
the first sending module further comprises an access point determining unit and a sending unit;
the access point determining unit is used for determining a network access point which is closest to the attribution place of the branch intranet in the acceleration network;
and the sending unit is used for sending the access request to a network access point which is closest to the attribution place of the branch internal network in the acceleration network.
The headquarters access request processing apparatus further has the following features:
the exit router also comprises an encryption module used for encrypting the access request by using a preset encryption rule;
the client terminal equipment further comprises a decryption module used for decrypting the access request according to the preset encryption rule when the access request is the access request encrypted by using the preset encryption rule.
The headquarters access request processing system provided by the invention comprises the headquarters access request processing device and an acceleration network.
The invention can ensure that the branch internal network can safely and quickly access the headquarter network, the deployment cost is greatly reduced compared with a special line, and the operation complexity is also greatly reduced.
Drawings
The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate an embodiment of the invention and, together with the description, serve to explain the invention and not to limit the invention. In the drawings:
FIG. 1 is a schematic diagram of an application scenario of a headquarters access request processing method in an embodiment;
FIG. 2 is a flowchart of a headquarters access request processing method in an embodiment;
fig. 3 is a configuration diagram of a headquarters access request processing apparatus in the embodiment.
Detailed Description
In order to make the objects, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention, and it is obvious that the described embodiments are some, but not all, embodiments of the present invention. All other embodiments, which can be derived by a person skilled in the art from the embodiments given herein without making any creative effort, shall fall within the protection scope of the present invention. It should be noted that the embodiments and features of the embodiments in the present application may be arbitrarily combined with each other without conflict.
Fig. 1 is a schematic diagram of an application scenario to which the headquarters access request processing method is applied in the embodiment.
As shown in fig. 2, a headquarters access request processing method in a first embodiment includes:
step 201, an exit router of an intranet of an branch store receives an access request initiated by a client;
step 202, judging whether the access request is an access request for accessing a headquarters;
step 203, when the access request is an access request for accessing the headquarters, sending the access request to the acceleration network;
and step 204, the accelerating network sends the access request to the client terminal equipment of the headquarter intranet, the client terminal equipment determines a site server of the access request, returns the source to process to obtain response data, sends the response data to the accelerating network, and sends the response data to the branch intranet.
Wherein the content of the first and second substances,
step 202 further comprises: when the access request is not an access request for accessing the headquarters, the access request is transmitted to the external network. Specifically, the access request is sent to the external Network by way of Network Address translation (NAT i.e. NAT).
The exit router in the method can provide dial-up networking function, can be a common intelligent router, and loads an access program capable of executing the steps 201, 202 and 203; or it may be a router that has been loaded with an access program that can perform steps 201, 202 and 203. The client terminal device may be a normal host or a virtual machine on which the software program for executing step 204 is loaded, or may be a device that has been loaded with the software program for executing step 204.
The access request includes information such as request content, site server, port information, and the like.
Sending the access request to the acceleration network in step 203 comprises: and determining a network access point closest to the home location of the branch intranet in the acceleration network, and sending the access request to the network access point closest to the home location of the branch intranet in the acceleration network.
In order to make the access process more secure and prevent data leakage, encryption and decryption processing needs to be performed on the access request. Specifically, when the access request is encrypted by using a preset encryption rule, the exit router encrypts the access request by using the preset encryption rule and then sends the encrypted access request to the acceleration network;
when the access request is decrypted by using the preset encryption rule, the client terminal equipment of the headquarters intranet decrypts the received access request by using the preset encryption rule.
After the client terminal device of the headquarters intranet determines the site server of the access request in step 204, performing back-to-source processing to obtain response data includes: the client terminal device of the headquarters intranet transmits an access request to the specified site server, and receives response data from this site server.
The step 204 of sending the response data to the branch intranet by the acceleration network includes: the client terminal equipment of the headquarter intranet determines a network access point which is closest to the home location of the headquarter intranet in the acceleration network, transmits the response data to the network access point which is closest to the home location of the headquarter intranet in the acceleration network, and transmits the response data to the branch intranet through the acceleration network.
In order to make the access process safer and prevent data leakage, encryption and decryption processing needs to be carried out on response data. Specifically, when the response data is encrypted, the client terminal device of the headquarters intranet encrypts the response data by using a preset encryption rule and then sends the encrypted response data to the network access point closest to the home location of the headquarters intranet;
when the response data is decrypted by using the preset encryption rule, the outlet router of the branch shop intranet receives the encrypted response data from the acceleration network and then performs decryption processing by using the preset encryption rule.
The acceleration Network is a Software-defined wide Area Network (SD-WAN), the Network comprises a plurality of Network access points, namely point-of-Presence (PoP), the SD-WAN is a private Network which is formed by mass resources and extends all over the world, and the SD-WAN is accessed through POP and selects an optimal back source path through internal dynamic routing. In a typical application scenario, an access PoP point with a nearest address (e.g., same city) in an intranet of a branch store can be found through the SD-WAN, and a return PoP point with a nearest address (e.g., same city) to a site server can be found, so that extranet data required by a user can be acquired very quickly.
As shown in fig. 2, the headquarters access request processing apparatus includes an egress router located in an intranet of an branch office and a client terminal device located in the intranet of the headquarters.
The exit router comprises a first receiving module, a judging module and a first sending module;
the first receiving module is used for receiving an access request initiated by a client;
the judging module is used for judging whether the access request is an access request for accessing the headquarters;
the first sending module is used for sending the access request to the acceleration network when the access request is the access request for accessing the headquarters.
The client terminal equipment comprises a second receiving module, a site server determining module, an obtaining module and a second sending module;
the second receiving module is used for receiving an access request which is forwarded by the acceleration network and is used for accessing the headquarters;
the site server determining module is used for determining a site server of the access request;
the acquisition module is used for carrying out source returning processing to acquire response data;
and the second sending module is used for sending the response data to the acceleration network.
Wherein the content of the first and second substances,
and the first sending module is used for sending the access request to the external network when the access request is not used for accessing the headquarters. The first transmission module further includes an access point determination unit and a transmission unit.
The access point determining unit is used for determining a network access point which is closest to the home of the branch internal network in the acceleration network.
The sending unit is used for sending the access request to a network access point which is closest to the home of the branch internal network in the acceleration network.
In order to make the access process safer and prevent data leakage, the access request sent from the branch intranet is an encrypted access request by using a preset encryption rule. The egress router further comprises an encryption module for encrypting the access request using a preset encryption rule. The client terminal equipment also comprises a decryption module which is used for decrypting the access request according to the preset encryption rule when the access request is the access request after being encrypted by using the preset encryption rule.
The headquarters access request processing system provided in the embodiment of the present invention comprises the above headquarters access request processing apparatus and an acceleration network, wherein the acceleration network comprises a plurality of network access points, and the acceleration network may be an SD-WAN.
The invention can ensure that the branch internal network can safely and quickly access the headquarter network, the deployment cost is greatly reduced compared with a special line, and the operation complexity is also greatly reduced.
The above-described aspects may be implemented individually or in various combinations, and such variations are within the scope of the present invention.
It will be understood by those skilled in the art that all or part of the steps of the above methods may be implemented by instructing the relevant hardware through a program, and the program may be stored in a computer-readable storage medium, such as a read-only memory, a magnetic or optical disk, and the like. Alternatively, all or part of the steps of the foregoing embodiments may also be implemented by using one or more integrated circuits, and accordingly, each module/unit in the foregoing embodiments may be implemented in the form of hardware, and may also be implemented in the form of a software functional module. The present invention is not limited to any specific form of combination of hardware and software.
It is to be noted that, in this document, the terms "comprises", "comprising" or any other variation thereof are intended to cover a non-exclusive inclusion, so that an article or apparatus including a series of elements includes not only those elements but also other elements not explicitly listed or inherent to such article or apparatus. Without further limitation, an element defined by the phrase "comprising … …" does not exclude the presence of additional like elements in the article or device comprising the element.
The above embodiments are merely to illustrate the technical solutions of the present invention and not to limit the present invention, and the present invention has been described in detail with reference to the preferred embodiments. It will be understood by those skilled in the art that various modifications and equivalent arrangements may be made without departing from the spirit and scope of the present invention and it should be understood that the present invention is to be covered by the appended claims.

Claims (9)

1. A headquarters access request processing method, comprising:
an exit router of the branch internal network receives an access request initiated by a client;
judging whether the access request is an access request for accessing a headquarters;
when the access request is an access request for accessing a headquarters, sending the access request to an acceleration network;
the accelerating network sends the access request to client terminal equipment of a headquarter intranet, the client terminal equipment of the headquarter intranet determines a site server of the access request, source returning processing is carried out to obtain response data, the response data are sent to the accelerating network, and the accelerating network sends the response data to the branch intranet.
2. The headquarters access request processing method as claimed in claim 1,
the method further comprises the following steps: and when the access request is not used for accessing the headquarters, sending the access request to an external network.
3. The headquarters access request processing method as claimed in claim 1,
the sending the access request to an acceleration network comprises: and determining a network access point which is closest to the home location of the branch intranet in the acceleration network, and sending the access request to the network access point which is closest to the home location of the branch intranet in the acceleration network.
4. The headquarters access request processing method as claimed in claim 1,
the sending the access request to an acceleration network comprises: the exit router encrypts the access request by using a preset encryption rule and then sends the access request to the acceleration network;
the method further comprises the following steps: and the client terminal equipment of the headquarter intranet decrypts the received access request by using the preset encryption rule.
5. A headquarters access request processing apparatus, comprising:
the system comprises an exit router positioned in an internal network of a branch store and client terminal equipment positioned in an internal network of a headquarter;
the exit router comprises a first receiving module, a judging module and a first sending module;
the first receiving module is used for receiving an access request initiated by a client;
the judging module is used for judging whether the access request is an access request for accessing a headquarters;
a first sending module, configured to send the access request to an acceleration network when the access request is an access request for accessing a headquarters;
the client terminal equipment comprises a second receiving module, a site server determining module, an obtaining module and a second sending module;
the second receiving module is configured to receive the access request for accessing the headquarters, which is forwarded by the acceleration network;
the site server determining module is used for determining the site server of the access request;
the acquisition module is used for carrying out source returning processing to acquire response data;
and the second sending module is used for sending the response data to the acceleration network.
6. The headquarters access request processing device as claimed in claim 5,
the first sending module is used for sending the access request to an external network when the access request is not used for accessing the headquarters.
7. The headquarters access request processing device as claimed in claim 5,
the first sending module further comprises an access point determining unit and a sending unit;
the access point determining unit is used for determining a network access point which is closest to the attribution place of the branch intranet in the acceleration network;
and the sending unit is used for sending the access request to a network access point which is closest to the attribution place of the branch internal network in the acceleration network.
8. The headquarters access request processing device as claimed in claim 5,
the exit router also comprises an encryption module used for encrypting the access request by using a preset encryption rule;
the client terminal equipment further comprises a decryption module used for decrypting the access request according to the preset encryption rule when the access request is the access request encrypted by using the preset encryption rule.
9. A headquarters access request processing system, comprising headquarters access request processing means as claimed in any one of the preceding claims 5 to 8, and an acceleration network.
CN201811140660.4A 2018-09-28 2018-09-28 Headquarter access request method, device and system Pending CN110971715A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201811140660.4A CN110971715A (en) 2018-09-28 2018-09-28 Headquarter access request method, device and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201811140660.4A CN110971715A (en) 2018-09-28 2018-09-28 Headquarter access request method, device and system

Publications (1)

Publication Number Publication Date
CN110971715A true CN110971715A (en) 2020-04-07

Family

ID=70026893

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201811140660.4A Pending CN110971715A (en) 2018-09-28 2018-09-28 Headquarter access request method, device and system

Country Status (1)

Country Link
CN (1) CN110971715A (en)

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104967609A (en) * 2015-04-28 2015-10-07 腾讯科技(深圳)有限公司 Intranet development server access method, intranet development server access device and intranet development server access system
CN106714176A (en) * 2017-01-04 2017-05-24 北京百度网讯科技有限公司 Access control method and device for intranet service
CN107426302A (en) * 2017-06-26 2017-12-01 腾讯科技(深圳)有限公司 Access scheduling method, apparatus, system, terminal, server and storage medium
CN108551464A (en) * 2018-03-08 2018-09-18 网宿科技股份有限公司 A kind of connection foundation of mixed cloud, data transmission method, device and system

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104967609A (en) * 2015-04-28 2015-10-07 腾讯科技(深圳)有限公司 Intranet development server access method, intranet development server access device and intranet development server access system
CN106714176A (en) * 2017-01-04 2017-05-24 北京百度网讯科技有限公司 Access control method and device for intranet service
CN107426302A (en) * 2017-06-26 2017-12-01 腾讯科技(深圳)有限公司 Access scheduling method, apparatus, system, terminal, server and storage medium
CN108551464A (en) * 2018-03-08 2018-09-18 网宿科技股份有限公司 A kind of connection foundation of mixed cloud, data transmission method, device and system

Non-Patent Citations (3)

* Cited by examiner, † Cited by third party
Title
王德清: ""大地云网通用SD-WAN整体解决方案"", pages 4 - 6, Retrieved from the Internet <URL:http://www.cww.net.cn/article?id=424983> *
王晔: ""电信SD-WAN解决方案的关键技术"", 《电信科学》, no. 12, pages 177 - 182 *
王熙: ""零售业更青睐SD-WAN市场潜力大引发收购热潮"", 《通信世界》 *

Similar Documents

Publication Publication Date Title
US11962571B2 (en) Ecosystem per distributed element security through virtual isolation networks
AU2020200073B2 (en) Method and apparatus for multi-tenancy secrets management
CN110971626B (en) Enterprise branch office access request processing method, device and system
JP5998248B2 (en) How to provide local secure network access to remote services
US8230050B1 (en) Providing access to configurable private computer networks
CN102203764B (en) Selective data forwarding storage
US11799960B2 (en) Distributed network security system providing isolation of customer data
CN107005582A (en) Public point is accessed using the voucher being stored in different directories
CN105210327A (en) Providing devices as a service
US20100242101A1 (en) Method and system for securely managing access and encryption credentials in a shared virtualization environment
CN110971714A (en) Enterprise export access request processing method, device and system
CN108093015A (en) Document transmission system
CN113067824A (en) Data scheduling method, system, virtual host and computer readable storage medium
CN208656807U (en) A kind of system for branch access general headquarters
CN110971715A (en) Headquarter access request method, device and system
CN116366689A (en) Distributed industrial private cloud system
US11102231B2 (en) Distributed scanning
CN110972093A (en) Mobile office implementation method and system
CN106559271B (en) A kind of resource access method and system
Mosch User-controlled data sovereignty in the Cloud
CN113300867B (en) CDN system, information processing method and device, and CDN node
CN112835537A (en) Distributed data access method and device and computer equipment
CN114422459A (en) Instant message transmission method and device and computer equipment
FR3057126A1 (en) METHOD FOR CONTROLLING THE DISTRIBUTION OF RECORDING DEVICES DEPLOYED IN VIRTUALIZED INFRASTRUCTURES OF TWO ENTITIES
KR20170128972A (en) Method and system for providing managed service

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination