WO2020186694A1 - 一种虚拟专用网络的通信方法及相关装置 - Google Patents
一种虚拟专用网络的通信方法及相关装置 Download PDFInfo
- Publication number
- WO2020186694A1 WO2020186694A1 PCT/CN2019/102738 CN2019102738W WO2020186694A1 WO 2020186694 A1 WO2020186694 A1 WO 2020186694A1 CN 2019102738 W CN2019102738 W CN 2019102738W WO 2020186694 A1 WO2020186694 A1 WO 2020186694A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- distributed
- distributed gateway
- client
- gateway
- communication connection
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L12/00—Data switching networks
- H04L12/28—Data switching networks characterised by path configuration, e.g. LAN [Local Area Networks] or WAN [Wide Area Networks]
- H04L12/46—Interconnection of networks
- H04L12/4641—Virtual LANs, VLANs, e.g. virtual private networks [VPN]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0485—Networking architectures for enhanced packet encryption processing, e.g. offloading of IPsec packet processing or efficient security association look-up
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/01—Protocols
- H04L67/10—Protocols in which an application is distributed across nodes in the network
- H04L67/1001—Protocols in which an application is distributed across nodes in the network for accessing one among a plurality of replicated servers
- H04L67/1034—Reaction to server failures by a load balancer
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/14—Session management
- H04L67/141—Setup of application sessions
Definitions
- This application relates to the field of cloud transmission, and in particular to a communication method and related devices of a virtual private network.
- the function of a virtual private network is to establish a private network on a public network, carry out encrypted communication, and realize remote access. It is widely used in corporate networks.
- the virtual private network solution used by cloud computing vendors is a master-backup method.
- the backup link does not participate when the master link transmits data. When the master link fails, the traffic is switched back to the backup link.
- a data communication tunnel is encapsulated on the public network using encryption technology, and secure communication is provided between the client and the distributed gateway through the IPSec protocol.
- the security alliance is the connection between the client and the distributed gateway.
- the agreement of communication elements for example, the protocol used, the encapsulation mode of the protocol, the cryptographic algorithm, the shared key to protect the data in a specific data stream, and the life cycle of the key, etc., are divided in a virtual private network that uses a master-backup method.
- the embodiments of the present application provide a virtual private network communication method and related devices, so as to realize efficient communication in the virtual private network.
- the first aspect of the present application provides a communication method for a virtual private network.
- the virtual private network includes N distributed gateways and centralized controllers, where N is a positive integer and includes:
- the first distributed gateway When the first distributed gateway establishes a communication connection with the client, acquiring the security alliance established by the first distributed gateway and the client, where the first distributed gateway belongs to the N distributed gateways;
- the gateway establishes a communication connection with the client through the security association.
- the second aspect of the application provides a virtual private network communication device, including:
- the obtaining module is configured to obtain the security alliance established between the first distributed gateway and the client when the first distributed gateway establishes a communication connection with the client, where the first distributed gateway belongs to the N Distributed gateways;
- the selection module is used to select a second distributed gateway that establishes a communication connection with the client among other distributed gateways when the first distributed gateway is down;
- a sending module configured to send a first communication connection establishment message to the second distributed gateway, wherein the first communication connection establishment message carries the security alliance, and the first communication connection establishment message is used to instruct all
- the second distributed gateway establishes a communication connection with the client through the security alliance.
- a third aspect of the present application provides an electronic device for a virtual private network.
- the electronic device includes a processor, a memory, a communication interface, and one or more programs, wherein the one or more programs are stored in the memory And is configured to be executed by the processor, and the program includes instructions for executing steps in any method of the first aspect of the present application.
- the fourth aspect of the present application provides a computer-readable storage medium, the computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement the part described in any method of the first aspect of the present application Or all steps.
- FIG. 1 is a flowchart of a virtual private network communication method provided by an embodiment of this application
- FIG. 2 is a flowchart of another virtual private network communication method provided by an embodiment of the application.
- FIG. 3 is a flowchart of another virtual private network communication method provided by an embodiment of the application.
- FIG. 4 is a schematic diagram of the first circular hash space provided by an embodiment of the application.
- FIG. 5 is a schematic diagram of a second circular hash space provided by an embodiment of this application.
- FIG. 6 is a schematic diagram of a virtual private network communication device provided by an embodiment of this application.
- FIG. 7 is a schematic structural diagram of an electronic device in a hardware operating environment involved in an embodiment of the application.
- the virtual private network communication method and related devices provided in the embodiments of the present application implement efficient communication in the virtual private network.
- the virtual private network includes N distributed gateways and centralized controllers, where N is a positive integer, and the centralized controller is used to control the operation of the virtual private network.
- FIG. 1 is a flowchart of a virtual private network communication method provided by an embodiment of the application.
- a virtual private network communication method provided by an embodiment of the present application may include:
- the first distributed gateway When the first distributed gateway establishes a communication connection with the client, acquire the security alliance established by the first distributed gateway and the client, where the first distributed gateway belongs to the N distributed Gateway.
- the first distributed gateway and the client establish a secure communication connection through the IPSec protocol.
- the IPSec protocol is a series of protocols formulated by the IETF (Internet Engineering Task Force), which provides high-quality security for IP datagrams and ensures that datagrams are The privacy and integrity of the transmission on the network.
- the security alliance is the agreement between the first distributed gateway and the client on the communication elements, including the use of authentication header protocol (AH, Authentication Header) or Encapsulated Security Payload Protocol (ESP) , Encapsulating Security Payload) or a combination of the two, whether the encapsulation mode of the protocol uses transmission mode or tunnel mode, whether the cryptographic algorithm uses DES or 3DES or other cryptographic algorithms, the shared key that protects the data in a specific data stream, and the life cycle of the key.
- AH authentication header protocol
- ESP Encapsulated Security Payload Protocol
- Encapsulating Security Payload Encapsulating Security Payload
- the centralized controller before obtaining the security alliance established by the first distributed gateway and the client, the centralized controller further includes:
- the centralized controller obtains the client ID of the client, processes the client ID through a hash algorithm to obtain the hash value of the client ID, and selects and establishes with the client from N distributed gateways according to the hash value of the client ID The first distributed gateway of the communication connection.
- the centralized controller selecting the first distributed gateway to establish a communication connection with the client among the N distributed gateways according to the hash value of the client identifier includes:
- the centralized controller obtains the N distributed gateway identities of the N distributed gateways, where the N distributed gateways correspond to the N distributed gateway identities one-to-one, and the N distributed gateway identities are processed through a hash algorithm to obtain N hash values, where N distributed gateway identifiers correspond to N hash values one-to-one, and the N hash values are mapped into the first circular hash space.
- the centralized controller maps the hash value identified by the client to the first circular hash space, and selects the first hash value from N hash values according to the position of the hash value identified by the client in the first circular hash space. Hence, it is determined that the distributed gateway corresponding to the first hash value is the first distributed gateway.
- the centralized controller selecting the first distributed gateway to establish a communication connection with the client among the N distributed gateways according to the hash value of the client identifier includes:
- the centralized controller obtains the N distributed gateway identities of the N distributed gateways.
- the N distributed gateways correspond to the N distributed gateway identities one-to-one, and the N distributed gateway identities are processed through a weighted hash algorithm.
- Process to obtain N weighted hash values where N distributed gateway identifiers correspond to N weighted hash values one-to-one, and the N weighted hash values are mapped to the second circular hash space
- M is a positive integer not less than N
- the distributed gateway corresponding to a hash value with a larger weight corresponds to more virtual nodes in the second circular hash space.
- the centralized controller maps the hash value of the client identification to the second circular hash space, and selects the first virtual node from M virtual nodes according to the position of the hash value of the client identification in the second circular hash space , Determining that the distributed gateway corresponding to the first virtual node is the first distributed gateway.
- the method before processing N distributed gateway identities through a hash algorithm with weights to obtain N hash values with weights, the method further includes:
- the N distributed gateways correspond to the N forwarding traffic capabilities one-to-one; the weight of the N distributed gateways is determined according to the N forwarding traffic capabilities, and the distribution of forwarding traffic capabilities is large The weight of the distributed gateway is greater than the weight of the distributed gateway with a small forwarding capacity; the weight of the N distributed gateway identifiers is set according to the weight of the N distributed gateways.
- the forwarding capacity of different distributed gateways is different. Some distributed gateways have stronger forwarding capacity, and some distributed gateways have weak forwarding capacity.
- the centralized controller obtains the N forwarding traffic capabilities of the N distributed gateways, and determines the weights of the N distributed gateways according to the N forwarding traffic capabilities. Among them, the distributed forwarding capacity is large. The weight of a gateway is greater than that of a distributed gateway with a small forwarding capacity, that is, a distributed gateway with a larger forwarding capacity has a larger weight, and a distributed gateway with a smaller forwarding capacity has a smaller weight.
- the distributed gateway Set the weight of the distributed gateway identifier.
- the centralized controller processes the N distributed gateway identifiers through the hash algorithm with weight to obtain N hash values with weight.
- the greater the weight of the distributed gateway identifier The weight of the hash value obtained through the hash algorithm processing is also greater, and N weighted hash values are mapped to the second circular hash space to obtain M virtual nodes, where M is not less than N
- the distributed gateway corresponding to the hash value with the larger weight corresponds to more virtual nodes in the second ring hash space, that is, the distributed gateway corresponding to the hash value with the larger weight is in the second ring hash space.
- the greater the possibility of a strong distributed gateway when a client establishes a connection with a distributed gateway with a strong ability to forward traffic, the data transmission speed of the client can be increased, and the high availability of a single distributed gateway can be realized.
- the centralized controller obtains the SA established between the first distributed gateway and the client
- the SA and the client identifier are associated and stored in the centralized controller, and the same distributed gateway can be associated with multiple
- the client establishes a connection
- multiple distributed gateways establish connections with multiple clients.
- the centralized controller obtains the security associations established by multiple other distributed gateways with other clients and stores the identification of the security association and the client through the storage security association.
- the association relationship can distinguish security associations based on client identification.
- the first distributed gateway When the first distributed gateway is down, select a second distributed gateway that establishes a communication connection with the client from other distributed gateways.
- the centralized controller selects the second distributed gateway to re-establish a communication connection with the client among other distributed gateways, including:
- the centralized controller deletes the first hash value from the first circular hash space, and selects the second hash value from other hash values according to the position of the hash value identified by the client in the first circular hash space, It is determined that the distributed gateway corresponding to the second hash value is the second distributed gateway.
- the client when the first distributed gateway is down, the client can no longer establish a communication connection with the first distributed gateway. At this time, the client needs to establish a communication connection with other distributed gateways to continue sending data, and the centralized controller determines the first A first hash value corresponding to a distributed gateway, delete the first hash value from the first ring hash space, so that other hash values in the first ring hash space correspond to distributions in working state And then select the second hash value from other hash values according to the position of the hash value of the client identifier in the first circular hash space.
- the selection method can be clockwise to select the second hash value from the client identifier.
- the second hash value at the nearest location of the hash value determines the distributed gateway corresponding to the second hash value, that is, the second distributed gateway.
- the method includes:
- the centralized controller obtains the forwarding traffic size of the second distributed gateway, and if the forwarding traffic size of the second distributed gateway exceeds the preset forwarding traffic threshold, the second hash value is deleted from the first ring hash space.
- the centralized controller selects a third hash value from other hash values according to the position of the hash value identified by the client in the first circular hash space, and determines that the distributed gateway corresponding to the third hash value is the client The third distributed gateway that establishes a communication connection.
- the centralized controller sends the second communication connection establishment message to the third distributed gateway, where the second communication connection establishment message carries the security alliance, and the second communication connection establishment message is used to instruct the third distributed gateway to communicate with the client through the security alliance Establish a communication connection.
- the centralized controller selects the second distributed gateway to re-establish a communication connection with the client among other distributed gateways, including:
- the centralized controller determines the first distributed gateway identifier of the first distributed gateway, determines the weighted hash value corresponding to the first distributed gateway identifier, and determines the weighted hash value mapping corresponding to the first distributed gateway identifier
- the centralized controller deletes the at least one virtual node from the second circular hash space, and selects the first virtual node from other virtual nodes according to the position of the hash value identified by the client in the second circular hash space Two virtual nodes; the centralized controller determines that the distributed gateway corresponding to the second virtual node is the second distributed gateway.
- the client when the first distributed gateway is down, the client can no longer establish a communication connection with the first distributed gateway. At this time, the client needs to establish a communication connection with other distributed gateways to continue sending data, and the centralized controller determines the first
- the first distributed gateway identifier of a distributed gateway determines the weighted hash value corresponding to the first distributed gateway identifier, and further determines at least one virtual hash value mapped from the weighted hash value corresponding to the first distributed gateway identifier Nodes, where, if the weight of the first distributed gateway is greater, the corresponding virtual nodes are also more, and the at least one virtual node is deleted from the second ring hash space, so that other nodes in the second ring hash space
- the virtual nodes correspond to distributed gateways in working state, and then select the second virtual node from other virtual nodes according to the position of the hash value identified by the client in the second ring hash space.
- the selection method can be as follows The second virtual node closest to the hash value identified by
- the method includes:
- the centralized controller obtains the forwarding traffic size of the second distributed gateway, and if the forwarding traffic size of the second distributed gateway exceeds the preset forwarding traffic threshold, it determines the second distributed gateway identifier of the second distributed gateway and determines the second distribution
- the weighted hash value corresponding to the distributed gateway identifier is determined, and at least one virtual node obtained by mapping the weighted hash value corresponding to the second distributed gateway identifier is determined; the centralized controller obtains the at least one virtual node from the second ring hash value Remove from space.
- the centralized controller selects a third virtual node from other virtual nodes according to the location of the hash value of the client identifier in the second circular hash space, and determines that the distributed gateway corresponding to the third virtual node establishes a communication connection with the client The third distributed gateway.
- the centralized controller sends the second communication connection establishment message to the third distributed gateway, where the second communication connection establishment message carries the security alliance, and the second communication connection establishment message is used to instruct the third distributed gateway to communicate with the client through the security alliance Establish a communication connection.
- the distributed gateway establishes a communication connection with the client through the security alliance.
- the centralized controller Before sending the first communication connection establishment message to the second distributed gateway, the centralized controller searches for the security association stored in association with the client identifier of the client. The centralized controller sends the first communication connection establishment message to the second distributed gateway, where the first communication connection establishment message carries the security alliance. When receiving the first communication connection establishment message, the second distributed gateway establishes a communication connection with the client through the security association.
- the second distributed gateway when the second distributed gateway completes communication with the client, the second distributed gateway sends a communication end message to the centralized controller, the communication end message carries the client identifier of the client, and when the centralized controller receives the communication end message , According to the client identifier, search for the security association stored in association with the client identifier, and then the centralized controller deletes the security association from the security association database. In this way, it is possible to prevent invalid SAs from being stored in the centralized controller, resulting in waste of storage resources of the centralized controller.
- the centralized controller obtains the status of the first distributed gateway according to a preset period, and when the status of the first distributed gateway is working, the A hash value is added to the first annular space.
- the centralized controller sends a communication connection cutoff instruction to the second distributed gateway, where the communication connection cutoff instruction is used to instruct the second distributed gateway to cut off the communication connection with the client.
- the centralized controller sends a third communication connection establishment message to the first distributed gateway, where the third communication connection establishment message carries a security alliance, and the third communication connection establishment message is used to instruct the first distributed gateway to pass the security alliance Re-establish a communication connection with the client.
- FIG. 2 is a flowchart of another virtual private network communication method provided by another embodiment of the application.
- another virtual private network communication method provided by another embodiment of the present application may include:
- the centralized controller obtains the client identifier of the client, and processes the client identifier through a hash algorithm to obtain a hash value of the client identifier.
- the centralized controller selects the first distributed gateway that establishes a communication connection with the client among the N distributed gateways according to the hash value of the client identifier.
- the centralized controller selecting the first distributed gateway to establish a communication connection with the client among the N distributed gateways according to the hash value of the client identifier includes:
- the centralized controller obtains N distributed gateway identities of the N distributed gateways, where the N distributed gateways correspond to the N distributed gateway identities one-to-one, and the distributed gateway identities include the IP address or host name of the distributed gateway.
- the N distributed gateway identities are processed through a consistent hash algorithm to obtain N hash values.
- the N distributed gateway identities correspond to the N hash values one-to-one, and the N hash values are mapped to the first In a circular hash space, the first circular hash space is a virtual ring, organized in a clockwise direction.
- the centralized controller maps the hash value identified by the client to the first circular hash space, and selects the first hash value from N hash values according to the position of the hash value identified by the client in the first circular hash space.
- the hope value specifically, is the first hash value that is found clockwise along the ring according to the position of the client-identified hash value in the first circular hash space, that is, the first hash value, and the The distributed gateway corresponding to a hash value is the first distributed gateway.
- the first distributed gateway When the first distributed gateway establishes a communication connection with the client, acquire the security alliance established by the first distributed gateway and the client.
- the first distributed gateway and the client establish a secure communication connection through the IPSec protocol.
- the IPSec protocol is a series of protocols formulated by the IETF (Internet Engineering Task Force), which provides high-quality security for IP datagrams and ensures that datagrams are The privacy and integrity of the transmission on the network.
- the security alliance is the agreement between the first distributed gateway and the client on the communication elements, including the use of authentication header protocol (AH, Authentication Header) or Encapsulated Security Payload Protocol (ESP) , Encapsulating Security Payload) or a combination of the two, whether the encapsulation mode of the protocol uses transmission mode or tunnel mode, whether the cryptographic algorithm uses DES or 3DES or other cryptographic algorithms, the shared key that protects the data in a specific data stream, and the life cycle of the key.
- AH authentication header protocol
- ESP Encapsulated Security Payload Protocol
- Encapsulating Security Payload Encapsulating Security Payload
- the centralized controller stores the safety alliance.
- the centralized controller After the centralized controller obtains the SA established between the first distributed gateway and the client, the SA is associated with the client ID and stored in the centralized controller. In this way, when the centralized controller obtains multiple other distributed gateways When establishing security associations with other clients, the security associations can be distinguished based on the client ID, and the security association stored in association with the client ID can be obtained through the client ID.
- the centralized controller deletes the first hash value from the first ring hash space.
- the centralized controller obtains the first distributed gateway identifier of the first distributed gateway, processes the first distributed gateway identifier through a hash algorithm to obtain the first hash value, and converts the first hash value from the first ring hash Remove from space.
- the centralized controller selects a second distributed gateway that establishes a communication connection with the client from the (N-1) distributed gateways.
- the centralized controller selects the second hash value from (N-1) hash values according to the position of the hash value identified by the client in the first circular hash space, and determines the distributed value corresponding to the second hash value
- the gateway is the second distributed gateway.
- the client when the first distributed gateway is down, the client can no longer establish a communication connection with the first distributed gateway. At this time, the client needs to establish a communication connection with other distributed gateways to continue sending data, and the centralized controller determines the first A first hash value corresponding to a distributed gateway, delete the first hash value from the first ring hash space, so that other hash values in the first ring hash space correspond to distributions in working state And then select the second hash value from other hash values according to the position of the hash value of the client identifier in the first circular hash space.
- the selection method can be clockwise to select the second hash value from the client identifier.
- the second hash value at the nearest location of the hash value determines the distributed gateway corresponding to the second hash value, that is, the second distributed gateway.
- the centralized controller obtains the security alliance.
- the centralized controller searches whether there is a first client ID matching the client ID, and if so, the centralized controller obtains the association with the first client ID
- the stored SA is the original SA established between the first distributed gateway and the client. If there is no SA, the second distributed gateway needs to re-establish a SA with the client to perform secure communication.
- the centralized controller sends the first communication connection establishment message to the second distributed gateway, where the first communication connection establishment message carries the security alliance.
- the second distributed gateway establishes a communication connection with the client through the security alliance.
- the second distributed gateway when the second distributed gateway completes communication with the client, the second distributed gateway sends a communication end message to the centralized controller, the communication end message carries the client identifier of the client, and when the centralized controller receives the communication end message , According to the client identifier, search for the security association stored in association with the client identifier, and then the centralized controller deletes the security association from the security association database. In this way, it is possible to prevent invalid SAs from being stored in the centralized controller, resulting in waste of storage resources of the centralized controller.
- the centralized controller obtains the status of the first distributed gateway according to a preset period, and the preset period may be 10 minutes, 30 minutes, 60 minutes, etc. .
- the second distributed gateway maintains a communication connection with the client.
- the first hash value is added to the first ring space.
- the centralized controller sends a communication connection cutoff instruction to the second distributed gateway, where the communication connection cutoff instruction is used to instruct the second distributed gateway to cut off the communication connection with the client.
- the centralized controller sends a third communication connection establishment message to the first distributed gateway, where the third communication connection establishment message carries a security alliance, and the third communication connection establishment message is used to instruct the first distributed gateway to pass the security alliance Establish a communication connection with the client.
- FIG. 3 is a flowchart of another virtual private network communication method provided by another embodiment of the application.
- another virtual private network communication method provided by another embodiment of the present application may include:
- the centralized controller obtains the client identifier of the client, and processes the client identifier through a hash algorithm to obtain a hash value of the client identifier.
- the centralized controller selects the first distributed gateway that establishes a communication connection with the client among the N distributed gateways according to the hash value of the client identifier.
- the centralized controller selecting the first distributed gateway to establish a communication connection with the client among the N distributed gateways according to the hash value of the client identifier includes:
- the centralized controller obtains N distributed gateway identities of the N distributed gateways, where the N distributed gateways correspond to the N distributed gateway identities one-to-one, and the distributed gateway identities include the IP address or host name of the distributed gateway.
- the N distributed gateway identities are processed through a consistent hash algorithm to obtain N hash values.
- the N distributed gateway identities correspond to the N hash values one-to-one, and the N hash values are mapped to the first In a circular hash space, the first circular hash space is a virtual ring, organized in a clockwise direction.
- the centralized controller maps the hash value identified by the client to the first circular hash space, and selects the first hash value from N hash values according to the position of the hash value identified by the client in the first circular hash space.
- the hope value is the first hash value that is found clockwise along the ring according to the position of the client-identified hash value in the first circular hash space, that is, the first hash value, and the The distributed gateway corresponding to a hash value is the first distributed gateway.
- the centralized controller selecting the first distributed gateway to establish a communication connection with the client among the N distributed gateways according to the hash value of the client identifier includes:
- the centralized controller obtains N distributed gateway identities of the N distributed gateways, where the N distributed gateways correspond to the N distributed gateway identities one-to-one, and the distributed gateway identities include the IP address or host name of the distributed gateway.
- N distributed gateway identities are processed through a weighted hash algorithm to obtain N weighted hash values.
- N distributed gateway identities correspond to N weighted hash values one-to-one
- N A weighted hash value is mapped to the second circular hash space to obtain M virtual nodes, where M is a positive integer not less than N, and the second circular hash space is a virtual ring, clockwise Directional organization, a distributed gateway with a stronger forwarding capability has a greater weight.
- client mapping The greater the probability of reaching the distributed gateway corresponding to the hash value with the greater the weight, that is, the greater the probability of the client establishing a communication connection with the distributed gateway with stronger forwarding capability.
- the centralized controller maps the hash value of the client identification to the second circular hash space, and selects the first virtual node from M virtual nodes according to the position of the hash value of the client identification in the second circular hash space , Determining that the distributed gateway corresponding to the first virtual node is the first distributed gateway.
- the first distributed gateway When the first distributed gateway establishes a communication connection with the client, acquire the security association established by the first distributed gateway and the client.
- the first distributed gateway and the client establish a secure communication connection through the IPSec protocol.
- the IPSec protocol is a series of protocols formulated by the IETF (Internet Engineering Task Force), which provides high-quality security for IP datagrams and ensures that datagrams are The privacy and integrity of the transmission on the network.
- the security alliance is the agreement between the first distributed gateway and the client on the communication elements, including the use of authentication header protocol (AH, Authentication Header) or Encapsulated Security Payload Protocol (ESP) , Encapsulating Security Payload) or a combination of the two, whether the encapsulation mode of the protocol uses transmission mode or tunnel mode, whether the cryptographic algorithm uses DES or 3DES or other cryptographic algorithms, the shared key that protects the data in a specific data stream, and the life cycle of the key.
- AH authentication header protocol
- ESP Encapsulated Security Payload Protocol
- Encapsulating Security Payload Encapsulating Security Payload
- the centralized controller stores the safety alliance.
- the centralized controller After the centralized controller obtains the SA established between the first distributed gateway and the client, the SA is associated with the client ID and stored in the centralized controller. In this way, when the centralized controller obtains multiple other distributed gateways When establishing security associations with other clients, the security associations can be distinguished based on the client ID, and the security association stored in association with the client ID can be obtained through the client ID.
- the centralized controller selects a second distributed gateway that establishes a communication connection with the client from (N-1) distributed gateways.
- the centralized controller when the first distributed gateway is down, the centralized controller obtains the first distributed gateway identifier of the first distributed gateway, and processes the first distributed gateway identifier through a hash algorithm to obtain the first distributed gateway identifier.
- a hash value the first hash value is deleted from the first circular hash space.
- the centralized controller selects the second hash value from (N-1) hash values according to the position of the hash value identified by the client in the first circular hash space, and determines the distributed value corresponding to the second hash value
- the gateway is the second distributed gateway.
- the centralized controller selects the second distributed gateway to re-establish a communication connection with the client among other distributed gateways, including:
- the centralized controller determines the first distributed gateway identifier of the first distributed gateway, determines the weighted hash value corresponding to the first distributed gateway identifier, and determines the weighted hash value mapping corresponding to the first distributed gateway identifier
- the centralized controller deletes the at least one virtual node from the second circular hash space, and selects the first virtual node from other virtual nodes according to the position of the hash value identified by the client in the second circular hash space Two virtual nodes; the centralized controller determines that the distributed gateway corresponding to the second virtual node is the second distributed gateway.
- the centralized controller obtains the forwarding traffic size of the second distributed gateway.
- the centralized controller selects a third distributed gateway that establishes a communication connection with the client from (N-2) distributed gateways.
- the forwarding traffic size of the second distributed gateway exceeds the preset forwarding traffic threshold, if the second distributed gateway establishes a communication connection with the client, it will cause network congestion, affect the traffic forwarding efficiency of the second distributed gateway, and also cause The client's traffic cannot be forwarded in time, and the network delay is too large, so the centralized controller needs to select the third distributed gateway that establishes a communication connection with the client from (N-2) distributed gateways.
- the method for the centralized controller to select a third distributed gateway to establish a communication connection with the client from (N-2) distributed gateways may be:
- the centralized controller selects the third hash value from (N-2) hash values according to the position of the hash value identified by the client in the first circular hash space, and determines the distribution corresponding to the third hash value
- the distributed gateway is the third distributed gateway that establishes a communication connection with the client.
- the centralized controller obtains the security alliance.
- the centralized controller sends the second communication connection establishment message to the third distributed gateway, where the second communication connection establishment message carries the security alliance.
- the third distributed gateway establishes a communication connection with the client through the security alliance.
- the third distributed gateway when the third distributed gateway completes communication with the client, the third distributed gateway sends a communication end message to the centralized controller, the communication end message carries the client identifier of the client, and when the centralized controller receives the communication end message , According to the client identifier, search for the security association stored in association with the client identifier, and then the centralized controller deletes the security association from the security association database. In this way, it is possible to prevent invalid SAs from being stored in the centralized controller, resulting in waste of storage resources of the centralized controller.
- the centralized controller obtains the state of the first distributed gateway according to a preset period, and the preset period may be 10 minutes, 30 minutes, 60 minutes, etc. .
- the third distributed gateway maintains a communication connection with the client.
- the first hash value is added to the first ring space.
- the centralized controller sends a communication connection disconnection instruction to the third distributed gateway, where the communication connection disconnection instruction is used to instruct the third distributed gateway to disconnect the communication connection with the client.
- the centralized controller sends a third communication connection establishment message to the first distributed gateway, where the third communication connection establishment message carries a security alliance, and the third communication connection establishment message is used to instruct the first distributed gateway to pass the security alliance Establish a communication connection with the client.
- FIG. 4 is a schematic diagram of a first circular hash space provided by an embodiment of this application.
- N distributed gateways and clients are mapped to the first ring hash space, and the N distributed gateways are distributed gateway 1, distributed gateway 2, distributed gateway N, etc.
- the distributed gateway closest to the client is the first distributed gateway, and it can be determined that the client establishes a communication connection with the first distributed gateway.
- FIG. 5 is a schematic diagram of a second circular hash space provided by an embodiment of this application.
- N distributed gateways and clients are mapped to the second circular hash space, and the positions of M virtual nodes and clients in the second circular hash space are obtained.
- M virtual nodes They are virtual node 1, virtual node 2, virtual node 3, virtual node 4, virtual node M, etc.
- the closest location to the client is the first virtual node, and the client and the first virtual node can be determined
- the corresponding distributed gateway establishes a communication connection.
- FIG. 6 is a schematic diagram of a virtual private network communication device provided by another embodiment of this application.
- a virtual private network communication device provided by another embodiment of the present application may include:
- the obtaining module 601 is configured to obtain the security alliance established between the first distributed gateway and the client when the first distributed gateway establishes a communication connection with the client, where the first distributed gateway belongs to the N distributed gateways.
- the selection module 602 is configured to select a second distributed gateway that establishes a communication connection with the client from other distributed gateways when the first distributed gateway is down.
- the sending module 603 is configured to send a first communication connection establishment message to the second distributed gateway, wherein the first communication connection establishment message carries the security alliance, and the first communication connection establishment message is used to indicate The second distributed gateway establishes a communication connection with the client through the security alliance.
- FIG. 7 is a schematic structural diagram of an electronic device in a hardware operating environment involved in an embodiment of the application.
- the electronic device of the hardware operating environment involved in the embodiment of the present application may include:
- the processor 701 is, for example, a CPU.
- the memory 702 may be a high-speed RAM memory, or a stable memory, such as a disk memory.
- the communication interface 703 is used to implement connection and communication between the processor 701 and the memory 702.
- the structure of the communication electronic device of the virtual private network shown in FIG. 7 does not constitute a limitation on the communication electronic device of the virtual private network, and may include more or less components than shown in the figure, or Combining certain components, or different component arrangements.
- the memory 702 may include an operating system, a network communication module, and a communication program of a virtual private network.
- the operating system is a program that manages and controls the hardware and software resources of the communication electronic equipment of the virtual private network, and supports the operation of the communication program of the virtual private network and other software or programs.
- the network communication module is used to implement communication between various components in the memory 702 and communication with other hardware and software in the communication electronic device of the virtual private network.
- the processor 701 is configured to execute the communication program of the virtual private network stored in the memory 702, and implement the following steps:
- the first distributed gateway When the first distributed gateway establishes a communication connection with the client, acquiring the security alliance established by the first distributed gateway and the client, where the first distributed gateway belongs to the N distributed gateways.
- a second distributed gateway that establishes a communication connection with the client is selected among other distributed gateways.
- the gateway establishes a communication connection with the client through the security association.
- Another embodiment of the present application provides a computer-readable storage medium, the computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement the following steps:
- the first distributed gateway When the first distributed gateway establishes a communication connection with the client, acquiring the security alliance established by the first distributed gateway and the client, where the first distributed gateway belongs to the N distributed gateways.
- a second distributed gateway that establishes a communication connection with the client is selected among other distributed gateways.
- the gateway establishes a communication connection with the client through the security association.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computing Systems (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
本申请涉及云传输领域,提供一种虚拟专用网络的通信方法及相关装置。一种虚拟专用网络的通信方法包括:当第一分布式网关与客户端建立通信连接时,获取第一分布式网关与客户端建立的安全联盟;当第一分布式网关宕机时,在其他分布式网关中选择与客户端建立通信连接的第二分布式网关;将第一建立通信连接消息发给第二分布式网关,其中,第一建立通信连接消息携带安全联盟,第一建立通信连接消息用于指示第二分布式网关通过安全联盟与客户端建立通信连接。本申请实施例的技术方案,实现了在虚拟专用网络中高效的通信。
Description
本申请要求于2019年3月15日提交中国专利局、申请号为2019101961475、申请名称为“一种虚拟专用网络的通信方法及相关装置”的中国专利申请的优先权,其部分内容通过引用结合在本申请中。
本申请涉及云传输领域,尤其涉及一种虚拟专用网络的通信方法及相关装置。
虚拟专用网络的功能是在公用网络上建立专用网络,进行加密通讯,实现远程访问,在企业网络中有广泛应用。目前,云计算厂商使用的虚拟专用网络方案是主备的方式,主链路传输数据的时候备链路不参与,当主链路发生故障时,流量切回到备链路。
目前在虚拟专用网络中,利用加密技术在公网上封装出一个数据通讯隧道,通过IPSec协议在客户端与分布式网关之间提供安全通信,其中,安全联盟是客户端与分布式网关之间对通信要素的约定,例如,使用的协议、协议的封装模式、密码算法、特定数据流中保护数据的共享密钥以及密钥的生存周期等,在采用主备的方式的虚拟专用网络中,分为两种方式,一种是主链路和备链路不同步安全联盟,那么当主链路的分布式网关宕机时,已经建立的安全联盟会丢失,客户端与其他分布式网关需要重新建立安全联盟才能进行安全通信,另一种是主链路和备链路同步安全联盟,那么需要在所有的分布式网关之间定时的同步数据,这两种方式都不能实现在虚拟专用网络中高效的通信。
发明内容
本申请实施例提供一种虚拟专用网络的通信方法及相关装置,以实现在虚拟专用网络中高效的通信。
本申请第一方面提供一种虚拟专用网络的通信方法,所述虚拟专用网络包括N个分布式网关和集中控制器,其中,N为正整数,包括:
当第一分布式网关与客户端建立通信连接时,获取所述第一分布式网关与所述客户端建立的安全联盟,其中,所述第一分布式网关属于所述N个分布式网关;
当所述第一分布式网关宕机时,在其他分布式网关中选择与所述客户端建立通信连接的第二分布式网关;
将第一建立通信连接消息发给所述第二分布式网关,其中,所述第一建立通信连接消息携带所述安全联盟,所述第一建立通信连接消息用于指示所述第二分布式网关通过所述安全联盟与所述客户端建立通信连接。
本申请第二方面提供了一种虚拟专用网络的通信装置,包括:
获取模块,用于当第一分布式网关与客户端建立通信连接时,获取所述第一分布式网关与所述客户端建立的安全联盟,其中,所述第一分布式网关属于所述N个分布式网关;
选择模块,用于当所述第一分布式网关宕机时,在其他分布式网关中选择与所述客户端建立通信连接的第二分布式网关;
发送模块,用于将第一建立通信连接消息发给所述第二分布式网关,其中,所述第一建立通信连接消息携带所述安全联盟,所述第一建立通信连接消息用于指示所述第二分布式网关通过所述安全联盟与所述客户端建立通信连接。
本申请第三方面提供了一种虚拟专用网络的电子设备,所述电子设备包括处理器、存储器、通信接口以及一个或多个程序,其中,所述一个或多个程序被存储在所述存储器中,并且被配置由所述处理器执行,所述程序包括用于执行本申请第一方面任一方法中的步骤的指令。
本申请第四方面提供了一种计算机可读存储介质,所述计算机可读存储介质存储有计算机程序,所述计算机程序被处理器执行以实现本申请第一方面任一方法中所描述的部分或全部步骤。
可以看到,上述技术方案中,不需要在第一分布式网关与第二分布式网关之间同步安全联盟,造成资源浪费,也不需要第二分布式网关与客户端重新建立安全联盟,实现了在虚拟专用网络中高效的通信。
为了更清楚地说明本申请实施例中的技术方案,下面将对实施例中所需使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本申请实施例提供的一种虚拟专用网络的通信方法的流程图;
图2为本申请实施例提供的另一种虚拟专用网络的通信方法的流程图;
图3为本申请实施例提供的另一种虚拟专用网络的通信方法的流程图;
图4为本申请实施例提供的第一环形哈希空间的示意图;
图5为本申请实施例提供的第二环形哈希空间的示意图;
图6为本申请实施例提供的一种虚拟专用网络的通信装置的示意图;
图7为本申请实施例涉及的硬件运行环境的电子设备结构示意图。
本申请实施例提供的虚拟专用网络的通信方法及相关装置,以实现在虚拟专用网络中高效的通信。
为了使本技术领域的人员更好地理解本申请方案,下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所 描述的实施例仅仅是本申请一部分的实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都应当属于本申请保护的范围。
以下分别进行详细说明。
本申请的实施例中,虚拟专用网络包括N个分布式网关和集中控制器,其中,N为正整数,集中控制器用于控制虚拟专用网络的运行。
首先参见图1,图1为本申请的一个实施例提供的一种虚拟专用网络的通信方法的流程图。其中,如图1所示,本申请的一个实施例提供的一种虚拟专用网络的通信方法可以包括:
101、当第一分布式网关与客户端建立通信连接时,获取所述第一分布式网关与所述客户端建立的安全联盟,其中,所述第一分布式网关属于所述N个分布式网关。
第一分布式网关与客户端通过IPSec协议建立安全的通信连接,IPSec协议是IETF(Internet Engineering Task Force)制定的一系列协议,为IP数据报提供了高质量的安全性,保证了数据报在网络上传输时的私有性和完整性,其中,安全联盟是第一分布式网关与客户端之间对通信要素的约定,包括使用认证头协议(AH,Authentication Header)还是封装安全载荷协议(ESP,Encapsulating Security Payload)还是两者结合,协议的封装模式使用传输模式还是隧道模式,密码算法使用DES还是3DES还是其他密码算法,特定数据流中保护数据的共享密钥以及密钥的生存周期等。
可选的,集中控制器在获取第一分布式网关与客户端建立的安全联盟之前,还包括:
集中控制器获取客户端的客户端标识,对客户端标识通过哈希算法进行处理以得到客户端标识的哈希值,根据客户端标识的哈希值在N个分布式网关中选择与客户端建立通信连接的第一分布式网关。
可选的,集中控制器根据客户端标识的哈希值在N个分布式网关中选择与客户端建立通信连接的第一分布式网关包括:
集中控制器获取N个分布式网关的N个分布式网关标识,其中,N个分布式网关与N个分布式网关标识一一对应,对N个分布式网关标识通过哈希算法进行处理以得到N个哈希值,其中,N个分布式网关标识与N个哈希值一一对应,将N个哈希值映射到第一环形哈希空间中。
集中控制器将客户端标识的哈希值映射到第一环形哈希空间中,根据客户端标识的哈希值在第一环形哈希空间中的位置从N个哈希值中选择第一哈希值,确定与第一哈希值对应的分布式网关为第一分布式网关。
可选的,集中控制器根据客户端标识的哈希值在N个分布式网关中选择与客户端建立通信连接的第一分布式网关包括:
集中控制器获取N个分布式网关的N个分布式网关标识,其中,N个分 布式网关与N个分布式网关标识一一对应,对N个分布式网关标识通过带权重的哈希算法进行处理以得到N个带权重的哈希值,其中,N个分布式网关标识与N个带权重的哈希值一一对应,将N个带权重的哈希值映射到第二环形哈希空间中以得到M个虚拟节点,其中,M为不小于N的正整数,带权重越大的哈希值对应的分布式网关在第二环形哈希空间中对应的虚拟节点越多。
集中控制器将客户端标识的哈希值映射到第二环形哈希空间中,根据客户端标识的哈希值在第二环形哈希空间中的位置从M个虚拟节点中选择第一虚拟节点,确定与第一虚拟节点对应的分布式网关为第一分布式网关。
基于上述示例,在一个可能的示例中,对N个分布式网关标识通过带权重的哈希算法进行处理以得到N个带权重的哈希值之前,还包括:
分别获取N个分布式网关的N个转发流量能力,N个分布式网关与N个转发流量能力一一对应;根据N个转发流量能力确定N个分布式网关的权重,转发流量能力大的分布式网关的权重大于转发流量能力小的分布式网关的权重;根据N个分布式网关的权重设置N个分布式网关标识的权重。
具体的,不同分布式网关的转发流量能力不同,有些分布式网关的转发流量能力较强,有些分布式网关的转发流量能力较弱,客户端与转发流量能力较强的分布式网关建立连接时,可以提高客户端的数据传输速度,集中控制器分别获取N个分布式网关的N个转发流量能力,根据N个转发流量能力确定N个分布式网关的权重,其中,转发流量能力大的分布式网关的权重大于转发流量能力小的分布式网关的权重,即,转发流量能力越大的分布式网关的权重越大,转发流量能力越小的分布式网关的权重越小,然后根据分布式网关的权重设置分布式网关标识的权重,这样,集中控制器对N个分布式网关标识通过带权重的哈希算法进行处理以得到N个带权重的哈希值,分布式网关标识的权重越大,则通过哈希算法处理得到的哈希值的权重也越大,将N个带权重的哈希值映射到第二环形哈希空间中以得到M个虚拟节点,其中,M为不小于N的正整数,带权重越大的哈希值对应的分布式网关在第二环形哈希空间中对应的虚拟节点越多,即,带权重越大的哈希值对应的分布式网关在第二环形哈希空间中的范围越大,因此将客户端映射到第二环形哈希空间后,选择带权重越大的哈希值对应的分布式网关的可能性更大,即选择转发流量能力较强的分布式网关的可能性越大,客户端与转发流量能力较强的分布式网关建立连接时,可以提高客户端的数据传输速度,实现单个分布式网关的高可用性。
进一步可选的,集中控制器获取了第一分布式网关与客户端建立的安全联盟后,将该安全联盟与该客户端标识关联存储在集中控制器中,同一个分布式网关可以与多个客户端建立连接,多个分布式网关与多个客户端建立连接,这样,集中控制器获取了多个其他分布式网关与其他客户端建立的安全联盟并存储通过存储安全联盟与客户端标识的关联关系,可以根据客户端标识对安全联盟做出区分。
102、当所述第一分布式网关宕机时,在其他分布式网关中选择与所述客户端建立通信连接的第二分布式网关。
在一个可能的示例中,当第一分布式网关宕机时,集中控制器在其他分布式网关中选择与客户端重新建立通信连接的第二分布式网关,包括:
集中控制器将第一哈希值从第一环形哈希空间中删除,根据客户端标识的哈希值在第一环形哈希空间中的位置从其他哈希值中选择第二哈希值,确定与第二哈希值对应的分布式网关为第二分布式网关。
具体的,第一分布式网关宕机时,客户端无法再与第一分布式网关建立通信连接,此时客户端需要与其他分布式网关建立通信连接,从而继续发送数据,集中控制器确定第一分布式网关对应的第一哈希值,将第一哈希值从第一环形哈希空间中删除,这样第一环形哈希空间中的其他哈希值对应的都是处于工作状态的分布式网关,然后根据客户端标识的哈希值在第一环形哈希空间中的位置从其他哈希值中选择第二哈希值,选择的方式可以是按照顺时针方向选择离客户端标识的哈希值最近位置的第二哈希值,确定第二哈希值对应的分布式网关,即为第二分布式网关。
基于上述示例,集中控制器在其他分布式网关中选择与客户端重新建立通信连接的第二分布式网关之后,包括:
集中控制器获取第二分布式网关的转发流量大小,若第二分布式网关的转发流量大小超过预设转发流量阈值,则将第二哈希值从第一环形哈希空间中删除。集中控制器根据客户端标识的哈希值在第一环形哈希空间中的位置从其他哈希值中选择第三哈希值,确定与第三哈希值对应的分布式网关为与客户端建立通信连接的第三分布式网关。集中控制器将第二建立通信连接消息发给第三分布式网关,其中,第二建立通信连接消息携带安全联盟,第二建立通信连接消息用于指示第三分布式网关通过安全联盟与客户端建立通信连接。
在一个可能的示例中,当第一分布式网关宕机时,集中控制器在其他分布式网关中选择与客户端重新建立通信连接的第二分布式网关,包括:
集中控制器确定第一分布式网关的第一分布式网关标识,确定第一分布式网关标识对应的带权重的哈希值,确定第一分布式网关标识对应的带权重的哈希值映射得到的至少一个虚拟节点;集中控制器将该至少一个虚拟节点从第二环形哈希空间中删除,根据客户端标识的哈希值在第二环形哈希空间中的位置从其他虚拟节点中选择第二虚拟节点;集中控制器确定与第二虚拟节点对应的分布式网关为第二分布式网关。
具体的,第一分布式网关宕机时,客户端无法再与第一分布式网关建立通信连接,此时客户端需要与其他分布式网关建立通信连接,从而继续发送数据,集中控制器确定第一分布式网关的第一分布式网关标识,确定第一分布式网关标识对应的带权重的哈希值,进一步确定第一分布式网关标识对应的带权重的哈希值映射得到的至少一个虚拟节点,其中,如果第一分布式网关的权重越大, 那么对应的虚拟节点也越多,将该至少一个虚拟节点从第二环形哈希空间中删除,这样第二环形哈希空间中的其他虚拟节点对应的都是处于工作状态的分布式网关,然后根据客户端标识的哈希值在第二环形哈希空间中的位置从其他虚拟节点中选择第二虚拟节点,选择的方式可以是按照顺时针方向选择离客户端标识的哈希值最近位置的第二虚拟节点,确定第二虚拟节点后,确定与第二虚拟节点对应的分布式网关,即为第二分布式网关。
基于上述示例,集中控制器在其他分布式网关中选择与客户端重新建立通信连接的第二分布式网关之后,包括:
集中控制器获取第二分布式网关的转发流量大小,若第二分布式网关的转发流量大小超过预设转发流量阈值,则确定第二分布式网关的第二分布式网关标识,确定第二分布式网关标识对应的带权重的哈希值,确定第二分布式网关标识对应的带权重的哈希值映射得到的至少一个虚拟节点;集中控制器将该至少一个虚拟节点从第二环形哈希空间中删除。集中控制器根据客户端标识的哈希值在第二环形哈希空间中的位置从其他虚拟节点中选择第三虚拟节点,确定与第三虚拟节点对应的分布式网关为与客户端建立通信连接的第三分布式网关。集中控制器将第二建立通信连接消息发给第三分布式网关,其中,第二建立通信连接消息携带安全联盟,第二建立通信连接消息用于指示第三分布式网关通过安全联盟与客户端建立通信连接。
103、将第一建立通信连接消息发给所述第二分布式网关,其中,所述第一建立通信连接消息携带所述安全联盟,所述第一建立通信连接消息用于指示所述第二分布式网关通过所述安全联盟与所述客户端建立通信连接。
集中控制器在将第一建立通信连接消息发给第二分布式网关之前,查找与客户端的客户端标识关联存储的安全联盟。集中控制器将第一建立通信连接消息发给第二分布式网关,其中,该第一建立通信连接消息携带该安全联盟。第二分布式网关接收该第一建立通信连接消息时,通过该安全联盟与客户端建立通信连接。
可选的,当第二分布式网关与客户端完成通信时,第二分布式网关向集中控制器发送通信结束消息,通信结束消息携带客户端的客户端标识,集中控制器接收到通信结束消息时,根据客户端标识查找与客户端标识关联存储的安全联盟,然后集中控制器将该安全联盟从安全联盟数据库中删除。这样,可以避免无效的安全联盟存储在集中控制器中,造成集中控制器的存储资源浪费。
进一步可选的,在第二分布式网关与客户端进行通信的过程中,集中控制器按照预设周期获取第一分布式网关的状态,当第一分布式网关的状态为工作时,将第一哈希值添加到所述第一环形空间中。集中控制器将切断通信连接指令发给第二分布式网关,其中,该切断通信连接指令用于指示第二分布式网关与所述客户端切断通信连接。集中控制器将第三建立通信连接消息发给第一分布式网关,其中,该第三建立通信连接消息携带安全联盟,该第三建立通信连 接消息用于指示第一分布式网关通过该安全联盟与客户端重新建立通信连接。
参见图2,图2为本申请的另一个实施例提供的另一种虚拟专用网络的通信方法的流程图。其中,如图2所示,本申请的另一个实施例提供的另一种虚拟专用网络的通信方法可以包括:
201、集中控制器获取客户端的客户端标识,对客户端标识通过哈希算法进行处理以得到客户端标识的哈希值。
202、集中控制器根据客户端标识的哈希值在N个分布式网关中选择与客户端建立通信连接的第一分布式网关。
可选的,集中控制器根据客户端标识的哈希值在N个分布式网关中选择与客户端建立通信连接的第一分布式网关包括:
集中控制器获取N个分布式网关的N个分布式网关标识,其中,N个分布式网关与N个分布式网关标识一一对应,分布式网关标识包括分布式网关的IP地址或者主机名。
对N个分布式网关标识通过一致性哈希算法进行处理以得到N个哈希值,其中,N个分布式网关标识与N个哈希值一一对应,将N个哈希值映射到第一环形哈希空间中,第一环形哈希空间是一个虚拟的圆环,按顺时针方向组织。
集中控制器将客户端标识的哈希值映射到第一环形哈希空间中,根据客户端标识的哈希值在第一环形哈希空间中的位置从N个哈希值中选择第一哈希值,具体为,根据客户端标识的哈希值在第一环形哈希空间中的位置沿环顺时针方向寻找到的第一个哈希值,即为第一哈希值,确定与第一哈希值对应的分布式网关为第一分布式网关。
203、当第一分布式网关与客户端建立通信连接时,获取第一分布式网关与所述客户端建立的安全联盟。
第一分布式网关与客户端通过IPSec协议建立安全的通信连接,IPSec协议是IETF(Internet Engineering Task Force)制定的一系列协议,为IP数据报提供了高质量的安全性,保证了数据报在网络上传输时的私有性和完整性,其中,安全联盟是第一分布式网关与客户端之间对通信要素的约定,包括使用认证头协议(AH,Authentication Header)还是封装安全载荷协议(ESP,Encapsulating Security Payload)还是两者结合,协议的封装模式使用传输模式还是隧道模式,密码算法使用DES还是3DES还是其他密码算法,特定数据流中保护数据的共享密钥以及密钥的生存周期等。
204、集中控制器存储该安全联盟。
集中控制器获取了第一分布式网关与客户端建立的安全联盟后,将该安全联盟与该客户端标识关联存储在集中控制器中,这样,当集中控制器获取了多个其他分布式网关与其他客户端建立的安全联盟时,可以根据客户端标识对安全联盟做出区分,通过客户端标识可以获得与客户端标识关联存储的安全联盟。
205、当第一分布式网关宕机时,集中控制器将第一哈希值从第一环形哈 希空间中删除。
集中控制器获取第一分布式网关的第一分布式网关标识,对第一分布式网关标识通过哈希算法进行处理以得到第一哈希值,将第一哈希值从第一环形哈希空间中删除。
206、集中控制器从(N-1)个分布式网关中选择与客户端建立通信连接的第二分布式网关。
集中控制器根据客户端标识的哈希值在第一环形哈希空间中的位置从(N-1)个哈希值中选择第二哈希值,确定与第二哈希值对应的分布式网关为第二分布式网关。
具体的,第一分布式网关宕机时,客户端无法再与第一分布式网关建立通信连接,此时客户端需要与其他分布式网关建立通信连接,从而继续发送数据,集中控制器确定第一分布式网关对应的第一哈希值,将第一哈希值从第一环形哈希空间中删除,这样第一环形哈希空间中的其他哈希值对应的都是处于工作状态的分布式网关,然后根据客户端标识的哈希值在第一环形哈希空间中的位置从其他哈希值中选择第二哈希值,选择的方式可以是按照顺时针方向选择离客户端标识的哈希值最近位置的第二哈希值,确定第二哈希值对应的分布式网关,即为第二分布式网关。
207、集中控制器获取该安全联盟。
可选的,由于集中控制器中存储有多个安全联盟,所以集中控制器查找是否存在与客户端标识匹配的第一客户端标识,若有,则集中控制器获取与第一客户端标识关联存储的安全联盟,即为原先第一分布式网关与客户端建立的安全联盟,若没有,则第二分布式网关需要重新与客户端建立安全联盟,才能进行安全通信。
208、集中控制器将第一建立通信连接消息发给第二分布式网关,其中,第一建立通信连接消息携带该安全联盟。
209、第二分布式网关通过安全联盟与客户端建立通信连接。
可选的,当第二分布式网关与客户端完成通信时,第二分布式网关向集中控制器发送通信结束消息,通信结束消息携带客户端的客户端标识,集中控制器接收到通信结束消息时,根据客户端标识查找与客户端标识关联存储的安全联盟,然后集中控制器将该安全联盟从安全联盟数据库中删除。这样,可以避免无效的安全联盟存储在集中控制器中,造成集中控制器的存储资源浪费。
可选的,在第二分布式网关与客户端进行通信的过程中,集中控制器按照预设周期获取第一分布式网关的状态,该预设周期可以是10分钟、30分钟、60分钟等。
当第一分布式网关的状态仍然为宕机时,第二分布式网关保持与客户端的通信连接。当第一分布式网关的状态为工作时,将第一哈希值添加到所述第一环形空间中。
集中控制器将切断通信连接指令发给第二分布式网关,其中,该切断通信连接指令用于指示第二分布式网关与所述客户端切断通信连接。
集中控制器将第三建立通信连接消息发给第一分布式网关,其中,该第三建立通信连接消息携带安全联盟,该第三建立通信连接消息用于指示第一分布式网关通过该安全联盟与客户端建立通信连接。
参见图3,图3为本申请的另一个实施例提供的另一种虚拟专用网络的通信方法的流程图。其中,如图3所示,本申请的另一个实施例提供的另一种虚拟专用网络的通信方法可以包括:
301、集中控制器获取客户端的客户端标识,对客户端标识通过哈希算法进行处理以得到客户端标识的哈希值。
302、集中控制器根据客户端标识的哈希值在N个分布式网关中选择与客户端建立通信连接的第一分布式网关。
可选的,集中控制器根据客户端标识的哈希值在N个分布式网关中选择与客户端建立通信连接的第一分布式网关包括:
集中控制器获取N个分布式网关的N个分布式网关标识,其中,N个分布式网关与N个分布式网关标识一一对应,分布式网关标识包括分布式网关的IP地址或者主机名。对N个分布式网关标识通过一致性哈希算法进行处理以得到N个哈希值,其中,N个分布式网关标识与N个哈希值一一对应,将N个哈希值映射到第一环形哈希空间中,第一环形哈希空间是一个虚拟的圆环,按顺时针方向组织。集中控制器将客户端标识的哈希值映射到第一环形哈希空间中,根据客户端标识的哈希值在第一环形哈希空间中的位置从N个哈希值中选择第一哈希值,具体为,根据客户端标识的哈希值在第一环形哈希空间中的位置沿环顺时针方向寻找到的第一个哈希值,即为第一哈希值,确定与第一哈希值对应的分布式网关为第一分布式网关。
可选的,集中控制器根据客户端标识的哈希值在N个分布式网关中选择与客户端建立通信连接的第一分布式网关包括:
集中控制器获取N个分布式网关的N个分布式网关标识,其中,N个分布式网关与N个分布式网关标识一一对应,分布式网关标识包括分布式网关的IP地址或者主机名。对N个分布式网关标识通过带权重的哈希算法进行处理以得到N个带权重的哈希值,其中,N个分布式网关标识与N个带权重的哈希值一一对应,将N个带权重的哈希值映射到第二环形哈希空间中以得到M个虚拟节点,其中,M为不小于N的正整数,第二环形哈希空间是一个虚拟的圆环,按顺时针方向组织,转发能力越强的分布式网关带的权重越大,由于带权重越大的哈希值对应的分布式网关在第二环形哈希空间中对应的虚拟节点越多,所以客户端映射到带权重越大的哈希值对应的分布式网关的几率越大,即客户端与转发能力较强的分布式网关建立通信连接的几率较大。集中控制器将客户端标识的哈希值映射到第二环形哈希空间中,根据客户端标识的哈 希值在第二环形哈希空间中的位置从M个虚拟节点中选择第一虚拟节点,确定与第一虚拟节点对应的分布式网关为第一分布式网关。
303、当第一分布式网关与客户端建立通信连接时,获取第一分布式网关与所述客户端建立的安全联盟。
第一分布式网关与客户端通过IPSec协议建立安全的通信连接,IPSec协议是IETF(Internet Engineering Task Force)制定的一系列协议,为IP数据报提供了高质量的安全性,保证了数据报在网络上传输时的私有性和完整性,其中,安全联盟是第一分布式网关与客户端之间对通信要素的约定,包括使用认证头协议(AH,Authentication Header)还是封装安全载荷协议(ESP,Encapsulating Security Payload)还是两者结合,协议的封装模式使用传输模式还是隧道模式,密码算法使用DES还是3DES还是其他密码算法,特定数据流中保护数据的共享密钥以及密钥的生存周期等。
304、集中控制器存储该安全联盟。
集中控制器获取了第一分布式网关与客户端建立的安全联盟后,将该安全联盟与该客户端标识关联存储在集中控制器中,这样,当集中控制器获取了多个其他分布式网关与其他客户端建立的安全联盟时,可以根据客户端标识对安全联盟做出区分,通过客户端标识可以获得与客户端标识关联存储的安全联盟。
305、当第一分布式网关宕机时,集中控制器从(N-1)个分布式网关中选择与客户端建立通信连接的第二分布式网关。
在一个可能的示例中,当第一分布式网关宕机时,集中控制器获取第一分布式网关的第一分布式网关标识,对第一分布式网关标识通过哈希算法进行处理以得到第一哈希值,将第一哈希值从第一环形哈希空间中删除。
集中控制器根据客户端标识的哈希值在第一环形哈希空间中的位置从(N-1)个哈希值中选择第二哈希值,确定与第二哈希值对应的分布式网关为第二分布式网关。
在一个可能的示例中,当第一分布式网关宕机时,集中控制器在其他分布式网关中选择与客户端重新建立通信连接的第二分布式网关,包括:
集中控制器确定第一分布式网关的第一分布式网关标识,确定第一分布式网关标识对应的带权重的哈希值,确定第一分布式网关标识对应的带权重的哈希值映射得到的至少一个虚拟节点;集中控制器将该至少一个虚拟节点从第二环形哈希空间中删除,根据客户端标识的哈希值在第二环形哈希空间中的位置从其他虚拟节点中选择第二虚拟节点;集中控制器确定与第二虚拟节点对应的分布式网关为第二分布式网关。
306、集中控制器获取第二分布式网关的转发流量大小。
307、若第二分布式网关的转发流量大小超过预设转发流量阈值,则集中控制器从(N-2)个分布式网关中选择与客户端建立通信连接的第三分布式网关。
若第二分布式网关的转发流量大小超过预设转发流量阈值,如果第二分布式网关与客户端建立通信连接,会造成网络拥塞,影响第二分布式网关的流量转发效率,并且也会造成该客户端的流量不能及时转发出去,网络延时太大,所以集中控制器需要从(N-2)个分布式网关中选择与客户端建立通信连接的第三分布式网关。
在一个可能的示例中,集中控制器从(N-2)个分布式网关中选择与客户端建立通信连接的第三分布式网关的方法可以是:
获取第二分布式网关的第二分布式网关标识,对第二分布式网关标识通过哈希算法进行处理以得到第二哈希值,将第二哈希值从第一环形哈希空间中删除,集中控制器根据客户端标识的哈希值在第一环形哈希空间中的位置从(N-2)个哈希值中选择第三哈希值,确定与第三哈希值对应的分布式网关为与客户端建立通信连接的第三分布式网关。
308、集中控制器获取该安全联盟。
309、集中控制器将第二建立通信连接消息发给第三分布式网关,其中,第二建立通信连接消息携带安全联盟。
310、第三分布式网关通过安全联盟与客户端建立通信连接。
可选的,当第三分布式网关与客户端完成通信时,第三分布式网关向集中控制器发送通信结束消息,通信结束消息携带客户端的客户端标识,集中控制器接收到通信结束消息时,根据客户端标识查找与客户端标识关联存储的安全联盟,然后集中控制器将该安全联盟从安全联盟数据库中删除。这样,可以避免无效的安全联盟存储在集中控制器中,造成集中控制器的存储资源浪费。
可选的,在第三分布式网关与客户端进行通信的过程中,集中控制器按照预设周期获取第一分布式网关的状态,该预设周期可以是10分钟、30分钟、60分钟等。
当第一分布式网关的状态仍然为宕机时,第三分布式网关保持与客户端的通信连接。当第一分布式网关的状态为工作时,将第一哈希值添加到所述第一环形空间中。
集中控制器将切断通信连接指令发给第三分布式网关,其中,该切断通信连接指令用于指示第三分布式网关与所述客户端切断通信连接。集中控制器将第三建立通信连接消息发给第一分布式网关,其中,该第三建立通信连接消息携带安全联盟,该第三建立通信连接消息用于指示第一分布式网关通过该安全联盟与客户端建立通信连接。
参见图4,图4为本申请的一个实施例提供的一种第一环形哈希空间的示意图。其中,如图4所示,将N个分布式网关和客户端映射到第一环形哈希空间中,N个分布式网关分别为分布式网关1、分布式网关2、分布式网关N等,按照顺时针方向,距离客户端最近位置的分布式网关为第一分布式网关,即可以确定客户端与第一分布式网关建立通信连接。
参见图5,图5为本申请的一个实施例提供的一种第二环形哈希空间的示意图。其中,如图5所示,将N个分布式网关和客户端映射到第二环形哈希空间中,得到M个虚拟节点和客户端在第二环形哈希空间中的位置,M个虚拟节点分别为虚拟节点1、虚拟节点2、虚拟节点3、虚拟节点4、虚拟节点M等,按照顺时针方向,距离客户端最近位置的为第一虚拟节点,即可以确定客户端与第一虚拟节点对应的分布式网关建立通信连接。
参见图6,图6为本申请的另一个实施例提供的一种虚拟专用网络的通信装置的示意图。其中,如图6所示,本申请的另一个实施例提供的一种虚拟专用网络的通信装置可以包括:
获取模块601,用于当第一分布式网关与客户端建立通信连接时,获取所述第一分布式网关与所述客户端建立的安全联盟,其中,所述第一分布式网关属于所述N个分布式网关。
选择模块602,用于当所述第一分布式网关宕机时,在其他分布式网关中选择与所述客户端建立通信连接的第二分布式网关。
发送模块603,用于将第一建立通信连接消息发给所述第二分布式网关,其中,所述第一建立通信连接消息携带所述安全联盟,所述第一建立通信连接消息用于指示所述第二分布式网关通过所述安全联盟与所述客户端建立通信连接。
本申请虚拟专用网络的通信装置的具体实施可参见上述虚拟专用网络的通信方法的各实施例,在此不做赘述。
参见图7,图7为本申请的实施例涉及的硬件运行环境的电子设备结构示意图。其中,如图7所示,本申请的实施例涉及的硬件运行环境的电子设备可以包括:
处理器701,例如CPU。
存储器702,可选的,存储器可以为高速RAM存储器,也可以是稳定的存储器,例如磁盘存储器。
通信接口703,用于实现处理器701和存储器702之间的连接通信。
本领域技术人员可以理解,图7中示出的虚拟专用网络的通信电子设备的结构并不构成对虚拟专用网络的通信电子设备的限定,可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置。
如图7所示,存储器702中可以包括操作系统、网络通信模块以及虚拟专用网络的通信程序。操作系统是管理和控制虚拟专用网络的通信电子设备硬件和软件资源的程序,支持虚拟专用网络的通信程序以及其他软件或程序的运行。网络通信模块用于实现存储器702内部各组件之间的通信,以及与虚拟专用网络的通信电子设备中其他硬件和软件之间通信。
在图7所示的虚拟专用网络的通信电子设备中,处理器701用于执行存储器702中存储的虚拟专用网络的通信程序,实现以下步骤:
当第一分布式网关与客户端建立通信连接时,获取所述第一分布式网关与所述客户端建立的安全联盟,其中,所述第一分布式网关属于所述N个分布式网关。
当所述第一分布式网关宕机时,在其他分布式网关中选择与所述客户端建立通信连接的第二分布式网关。
将第一建立通信连接消息发给所述第二分布式网关,其中,所述第一建立通信连接消息携带所述安全联盟,所述第一建立通信连接消息用于指示所述第二分布式网关通过所述安全联盟与所述客户端建立通信连接。
本申请虚拟专用网络的通信电子设备的具体实施可参见上述虚拟专用网络的通信方法的各实施例,在此不做赘述。
本申请的另一个实施例提供了一种计算机可读存储介质,计算机可读存储介质存储有计算机程序,计算机程序被处理器执行以实现以下步骤:
当第一分布式网关与客户端建立通信连接时,获取所述第一分布式网关与所述客户端建立的安全联盟,其中,所述第一分布式网关属于所述N个分布式网关。
当所述第一分布式网关宕机时,在其他分布式网关中选择与所述客户端建立通信连接的第二分布式网关。
将第一建立通信连接消息发给所述第二分布式网关,其中,所述第一建立通信连接消息携带所述安全联盟,所述第一建立通信连接消息用于指示所述第二分布式网关通过所述安全联盟与所述客户端建立通信连接。
本申请计算机可读存储介质的具体实施可参见上述虚拟专用网络的通信方法的各实施例,在此不做赘述。
还需要说明的是,对于前述的各方法实施例,为了简单描述,故将其都表述为一系列的动作组合,但是本领域技术人员应该知悉,本申请并不受所描述的动作顺序的限制,因为依据本申请,某些步骤可以采用其他顺序或者同时进行。其次,本领域技术人员也应该知悉,说明书中所描述的实施例均属于优选实施例,所涉及的动作和模块并不一定是本申请所必须的。在上述实施例中,对各个实施例的描述都各有侧重,某个实施例中没有详述的部分,可以参见其他实施例的相关描述。
以上所述,以上实施例仅用以说明本申请的技术方案,而非对其限制;尽管参照前述实施例对本申请进行了详细的说明,本领域的普通技术人员应当理解:其依然可以对前述各实施例所记载的技术方案进行修改,或者对其中部分技术特征进行等同替换;而这些修改或者替换,并不使相应技术方案的本质脱离本申请各实施例技术方案的范围。
Claims (20)
- 一种虚拟专用网络的通信方法,其特征在于,所述虚拟专用网络包括N个分布式网关和集中控制器,其中,N为正整数,包括:当第一分布式网关与客户端建立通信连接时,获取所述第一分布式网关与所述客户端建立的安全联盟,其中,所述第一分布式网关属于所述N个分布式网关;当所述第一分布式网关宕机时,在其他分布式网关中选择与所述客户端建立通信连接的第二分布式网关;将第一建立通信连接消息发给所述第二分布式网关,其中,所述第一建立通信连接消息携带所述安全联盟,所述第一建立通信连接消息用于指示所述第二分布式网关通过所述安全联盟与所述客户端建立通信连接。
- 根据权利要求1所述的方法,其特征在于,所述获取所述第一分布式网关与所述客户端建立的安全联盟之前,所述方法还包括:获取所述客户端的客户端标识;对所述客户端标识通过哈希算法进行处理以得到所述客户端标识的哈希值;根据所述客户端标识的哈希值在所述N个分布式网关中选择与所述客户端建立通信连接的所述第一分布式网关。
- 根据权利要求2所述的方法,其特征在于,所述根据所述客户端标识的哈希值在所述N个分布式网关中选择与所述客户端建立通信连接的所述第一分布式网关,包括:获取所述N个分布式网关的N个分布式网关标识,其中,所述N个分布式网关与所述N个分布式网关标识一一对应;对所述N个分布式网关标识通过哈希算法进行处理以得到N个哈希值,其中,所述N个分布式网关标识与所述N个哈希值一一对应;将所述N个哈希值映射到第一环形哈希空间中;将所述客户端标识的哈希值映射到所述第一环形哈希空间中;根据所述客户端标识的哈希值在所述第一环形哈希空间中的位置从所述N个哈希值中选择第一哈希值;确定与所述第一哈希值对应的分布式网关为所述第一分布式网关。
- 根据权利要求2所述的方法,其特征在于,所述根据所述客户端标识的哈希值在所述N个分布式网关中选择与所述客户端建立通信连接的所述第一分布式网关,包括:获取所述N个分布式网关的N个分布式网关标识,其中,所述N个分布式网关与所述N个分布式网关标识一一对应;对所述N个分布式网关标识通过带权重的哈希算法进行处理以得到N个带权重的哈希值,其中,所述N个分布式网关标识与所述N个带权重的哈希 值一一对应;将所述N个带权重的哈希值映射到第二环形哈希空间中以得到M个虚拟节点,其中,M为不小于N的正整数;将所述客户端标识的哈希值映射到所述第二环形哈希空间中;根据所述客户端标识的哈希值在所述第二环形哈希空间中的位置从所述M个虚拟节点中选择第一虚拟节点;确定与所述第一虚拟节点对应的分布式网关为所述第一分布式网关。
- 根据权利要求4所述的方法,其特征在于,所述对所述N个分布式网关标识通过带权重的哈希算法进行处理以得到N个带权重的哈希值之前,所述方法还包括:分别获取所述N个分布式网关的N个转发流量能力,所述N个分布式网关与所述N个转发流量能力一一对应;根据所述N个转发流量能力确定所述N个分布式网关的权重,转发流量能力大的分布式网关的权重大于转发流量能力小的分布式网关的权重;根据所述N个分布式网关的权重设置所述N个分布式网关标识的权重。
- 根据权利要求3所述的方法,其特征在于,所述在其他分布式网关中选择与所述客户端建立通信连接的第二分布式网关包括:将所述第一哈希值从所述第一环形哈希空间中删除;根据所述客户端标识的哈希值在所述第一环形哈希空间中的位置从其他哈希值中选择第二哈希值;确定与所述第二哈希值对应的分布式网关为所述第二分布式网关。
- 根据权利要求4所述的方法,其特征在于,所述在其他分布式网关中选择与所述客户端建立通信连接的第二分布式网关包括:确定所述第一分布式网关的第一分布式网关标识;确定所述第一分布式网关标识对应的带权重的哈希值;确定所述第一分布式网关标识对应的带权重的哈希值映射得到的至少一个虚拟节点;将所述至少一个虚拟节点从所述第二环形哈希空间中删除;根据所述客户端标识的哈希值在所述第二环形哈希空间中的位置从其他虚拟节点中选择第二虚拟节点;确定与所述第二虚拟节点对应的分布式网关为所述第二分布式网关。
- 根据权利要求6所述的方法,其特征在于,所述在其他分布式网关中选择与所述客户端建立通信连接的第二分布式网关之后,所述方法还包括:获取所述第二分布式网关的转发流量大小;若所述第二分布式网关的转发流量大小超过预设转发流量阈值,则将所述第二哈希值从所述第一环形哈希空间中删除;根据所述客户端标识的哈希值在所述第一环形哈希空间中的位置从其他 哈希值中选择第三哈希值;确定与所述第三哈希值对应的分布式网关为与所述客户端建立通信连接的第三分布式网关;将第二建立通信连接消息发给所述第三分布式网关,其中,所述第二建立通信连接消息携带所述安全联盟,所述第二建立通信连接消息用于指示所述第三分布式网关通过所述安全联盟与所述客户端建立通信连接。
- 根据权利要求6所述的方法,其特征在于,所述方法还包括:按照预设周期获取所述第一分布式网关的状态;当所述第一分布式网关的状态为工作时,将所述第一哈希值添加到所述第一环形空间中;将切断通信连接指令发给所述第二分布式网关,其中,所述切断通信连接指令用于指示所述第二分布式网关与所述客户端切断通信连接;将第三建立通信连接消息发给所述第一分布式网关,其中,所述第三建立通信连接消息携带所述安全联盟,所述第三建立通信连接消息用于指示所述第一分布式网关通过所述安全联盟与所述客户端建立通信连接。
- 一种虚拟专用网络的通信装置,其特征在于,所述装置包括:获取模块,用于当第一分布式网关与客户端建立通信连接时,获取所述第一分布式网关与所述客户端建立的安全联盟,其中,所述第一分布式网关属于所述N个分布式网关;第一选择模块,用于当所述第一分布式网关宕机时,在其他分布式网关中选择与所述客户端建立通信连接的第二分布式网关;发送模块,用于将第一建立通信连接消息发给所述第二分布式网关,其中,所述第一建立通信连接消息携带所述安全联盟,所述第一建立通信连接消息用于指示所述第二分布式网关通过所述安全联盟与所述客户端建立通信连接。
- 根据权利要求10所述的装置,其特征在于,所述装置还包括第二选择模块,所述第二选择模块用于:获取所述客户端的客户端标识;对所述客户端标识通过哈希算法进行处理以得到所述客户端标识的哈希值;根据所述客户端标识的哈希值在所述N个分布式网关中选择与所述客户端建立通信连接的所述第一分布式网关。
- 根据权利要求11所述的装置,其特征在于,在所述根据所述客户端标识的哈希值在所述N个分布式网关中选择与所述客户端建立通信连接的所述第一分布式网关方面,所述第二选择模块具体用于:获取所述N个分布式网关的N个分布式网关标识,其中,所述N个分布式网关与所述N个分布式网关标识一一对应;对所述N个分布式网关标识通过哈希算法进行处理以得到N个哈希值, 其中,所述N个分布式网关标识与所述N个哈希值一一对应;将所述N个哈希值映射到第一环形哈希空间中;将所述客户端标识的哈希值映射到所述第一环形哈希空间中;根据所述客户端标识的哈希值在所述第一环形哈希空间中的位置从所述N个哈希值中选择第一哈希值;确定与所述第一哈希值对应的分布式网关为所述第一分布式网关。
- 根据权利要求11所述的装置,其特征在于,在所述根据所述客户端标识的哈希值在所述N个分布式网关中选择与所述客户端建立通信连接的所述第一分布式网关方面,所述第二选择模块具体用于:获取所述N个分布式网关的N个分布式网关标识,其中,所述N个分布式网关与所述N个分布式网关标识一一对应;对所述N个分布式网关标识通过带权重的哈希算法进行处理以得到N个带权重的哈希值,其中,所述N个分布式网关标识与所述N个带权重的哈希值一一对应;将所述N个带权重的哈希值映射到第二环形哈希空间中以得到M个虚拟节点,其中,M为不小于N的正整数;将所述客户端标识的哈希值映射到所述第二环形哈希空间中;根据所述客户端标识的哈希值在所述第二环形哈希空间中的位置从所述M个虚拟节点中选择第一虚拟节点;确定与所述第一虚拟节点对应的分布式网关为所述第一分布式网关。
- 根据权利要求13所述的装置,其特征在于,所述装置还包括设置模块,所述设置模块用于:分别获取所述N个分布式网关的N个转发流量能力,所述N个分布式网关与所述N个转发流量能力一一对应;根据所述N个转发流量能力确定所述N个分布式网关的权重,转发流量能力大的分布式网关的权重大于转发流量能力小的分布式网关的权重;根据所述N个分布式网关的权重设置所述N个分布式网关标识的权重。
- 根据权利要求12所述的装置,其特征在于,所述第一选择模块具体用于:将所述第一哈希值从所述第一环形哈希空间中删除;根据所述客户端标识的哈希值在所述第一环形哈希空间中的位置从其他哈希值中选择第二哈希值;确定与所述第二哈希值对应的分布式网关为所述第二分布式网关。
- 根据权利要求13所述的装置,其特征在于,所述第一选择模块具体用于:确定所述第一分布式网关的第一分布式网关标识;确定所述第一分布式网关标识对应的带权重的哈希值;确定所述第一分布式网关标识对应的带权重的哈希值映射得到的至少一个虚拟节点;将所述至少一个虚拟节点从所述第二环形哈希空间中删除;根据所述客户端标识的哈希值在所述第二环形哈希空间中的位置从其他虚拟节点中选择第二虚拟节点;确定与所述第二虚拟节点对应的分布式网关为所述第二分布式网关。
- 根据权利要求15所述的装置,其特征在于,所述装置还包括第一处理模块,所述第一处理模块用于:获取所述第二分布式网关的转发流量大小;若所述第二分布式网关的转发流量大小超过预设转发流量阈值,则将所述第二哈希值从所述第一环形哈希空间中删除;根据所述客户端标识的哈希值在所述第一环形哈希空间中的位置从其他哈希值中选择第三哈希值;确定与所述第三哈希值对应的分布式网关为与所述客户端建立通信连接的第三分布式网关;将第二建立通信连接消息发给所述第三分布式网关,其中,所述第二建立通信连接消息携带所述安全联盟,所述第二建立通信连接消息用于指示所述第三分布式网关通过所述安全联盟与所述客户端建立通信连接。
- 根据权利要求15所述的装置,其特征在于,所述装置还包括第二处理模块,所述第二处理模块用于:按照预设周期获取所述第一分布式网关的状态;当所述第一分布式网关的状态为工作时,将所述第一哈希值添加到所述第一环形空间中;将切断通信连接指令发给所述第二分布式网关,其中,所述切断通信连接指令用于指示所述第二分布式网关与所述客户端切断通信连接;将第三建立通信连接消息发给所述第一分布式网关,其中,所述第三建立通信连接消息携带所述安全联盟,所述第三建立通信连接消息用于指示所述第一分布式网关通过所述安全联盟与所述客户端建立通信连接。
- 一种虚拟专用网络的通信电子设备,其特征在于,所述电子设备包括处理器、存储器、通信接口以及一个或多个程序,其中,所述一个或多个程序被存储在所述存储器中,并且被配置由所述处理器执行,所述程序包括用于执行权利要求1至9任一项方法中的步骤的指令。
- 一种计算机可读存储介质,其特征在于,所述计算机可读存储介质存储有计算机程序,所述计算机程序被处理器执行以实现权利要求1至7任意一项所述的方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201910196147.5 | 2019-03-15 | ||
| CN201910196147.5A CN110011892B (zh) | 2019-03-15 | 2019-03-15 | 一种虚拟专用网络的通信方法及相关装置 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2020186694A1 true WO2020186694A1 (zh) | 2020-09-24 |
Family
ID=67167133
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2019/102738 Ceased WO2020186694A1 (zh) | 2019-03-15 | 2019-08-27 | 一种虚拟专用网络的通信方法及相关装置 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN110011892B (zh) |
| WO (1) | WO2020186694A1 (zh) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN118487769A (zh) * | 2024-05-17 | 2024-08-13 | 北京电子科技学院 | 基于puf的轻量级多网关的身份认证与密钥协商方法 |
Families Citing this family (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110011892B (zh) * | 2019-03-15 | 2022-04-05 | 平安科技(深圳)有限公司 | 一种虚拟专用网络的通信方法及相关装置 |
| CN110267290A (zh) * | 2019-07-29 | 2019-09-20 | 苏州泰铭玥智能科技有限公司 | 智能控制系统的数据处理方法和装置 |
| CN112788060B (zh) * | 2021-01-29 | 2023-07-04 | 北京字跳网络技术有限公司 | 数据包传输方法和装置、存储介质和电子设备 |
| CN114445998B (zh) * | 2022-04-11 | 2022-06-07 | 广州联客信息科技有限公司 | 一种基于ai的火灾报警监测方法及系统 |
| CN115296939A (zh) * | 2022-10-09 | 2022-11-04 | 中国电子科技集团公司第三十研究所 | 解决虚拟机迁移与IPsec机制冲突的方法、设备及介质 |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103023741A (zh) * | 2012-12-04 | 2013-04-03 | 汉柏科技有限公司 | Vpn设备故障处理方法 |
| US20130182712A1 (en) * | 2012-01-13 | 2013-07-18 | Dan Aguayo | System and method for managing site-to-site vpns of a cloud managed network |
| CN103491088A (zh) * | 2013-09-22 | 2014-01-01 | 成都卫士通信息产业股份有限公司 | 一种IPSec VPN网关数据处理方法 |
| CN106559349A (zh) * | 2015-09-24 | 2017-04-05 | 阿里巴巴集团控股有限公司 | 业务传输速率的控制方法及装置、系统 |
| CN110011892A (zh) * | 2019-03-15 | 2019-07-12 | 平安科技(深圳)有限公司 | 一种虚拟专用网络的通信方法及相关装置 |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7028183B2 (en) * | 2001-11-13 | 2006-04-11 | Symantec Corporation | Enabling secure communication in a clustered or distributed architecture |
| CN103200094A (zh) * | 2013-03-14 | 2013-07-10 | 成都卫士通信息产业股份有限公司 | 一种实现网关动态负载分配的方法 |
| CN106873919A (zh) * | 2017-03-20 | 2017-06-20 | 郑州云海信息技术有限公司 | 一种基于云存储系统的数据存储方法和装置 |
| CN108989194B (zh) * | 2017-05-31 | 2021-07-09 | 微软技术许可有限责任公司 | 分布式IPSec网关 |
-
2019
- 2019-03-15 CN CN201910196147.5A patent/CN110011892B/zh active Active
- 2019-08-27 WO PCT/CN2019/102738 patent/WO2020186694A1/zh not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20130182712A1 (en) * | 2012-01-13 | 2013-07-18 | Dan Aguayo | System and method for managing site-to-site vpns of a cloud managed network |
| CN103023741A (zh) * | 2012-12-04 | 2013-04-03 | 汉柏科技有限公司 | Vpn设备故障处理方法 |
| CN103491088A (zh) * | 2013-09-22 | 2014-01-01 | 成都卫士通信息产业股份有限公司 | 一种IPSec VPN网关数据处理方法 |
| CN106559349A (zh) * | 2015-09-24 | 2017-04-05 | 阿里巴巴集团控股有限公司 | 业务传输速率的控制方法及装置、系统 |
| CN110011892A (zh) * | 2019-03-15 | 2019-07-12 | 平安科技(深圳)有限公司 | 一种虚拟专用网络的通信方法及相关装置 |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN118487769A (zh) * | 2024-05-17 | 2024-08-13 | 北京电子科技学院 | 基于puf的轻量级多网关的身份认证与密钥协商方法 |
Also Published As
| Publication number | Publication date |
|---|---|
| CN110011892B (zh) | 2022-04-05 |
| CN110011892A (zh) | 2019-07-12 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2020186694A1 (zh) | 一种虚拟专用网络的通信方法及相关装置 | |
| CN107210929B (zh) | 互联网协议安全隧道的负载均衡 | |
| US10630784B2 (en) | Facilitating a secure 3 party network session by a network device | |
| CN112468518B (zh) | 访问数据处理方法、装置、存储介质及计算机设备 | |
| CN102882789B (zh) | 一种数据报文处理方法、系统及设备 | |
| CN109150688B (zh) | IPSec VPN数据传输方法及装置 | |
| CN108601043B (zh) | 用于控制无线接入点的方法和设备 | |
| JP6395867B2 (ja) | OpenFlow通信方法及びシステム、制御部、並びにサービスゲートウェイ | |
| CN105991562B (zh) | IPSec加速方法、装置及系统 | |
| CN110719248A (zh) | 用户数据报协议报文的转发方法及装置 | |
| US12052223B2 (en) | Maintaining internet protocol security tunnels | |
| CN107819685A (zh) | 一种数据处理的方法以及网络设备 | |
| JP2025027025A5 (ja) | 通信方法、通信装置および通信プログラム | |
| WO2023284623A1 (zh) | 一种数据同步方法、装置及系统 | |
| CN113949730B (zh) | 一种设备的通信方法和装置 | |
| CN112019418B (zh) | 基于野蛮模式的IPSec隧道建立方法及其装置 | |
| CN118316658A (zh) | 报文封装方法、装置、设备及存储介质 | |
| WO2020133603A1 (zh) | 一种dr模式下的防护方法和装置 | |
| WO2025059850A1 (zh) | 一种网络设备会话管理的通信方法、设备和介质 | |
| CN105610599B (zh) | 用户数据管理方法及装置 | |
| CN114070606A (zh) | 一种基于国产操作系统的网络安全终端装置及工作方法 | |
| KR20230070662A (ko) | 데이터 이름 기반의 정보 중심 인-네트워크 컴퓨팅을 위한 데이터 보호 방법 및 이를 이용한 시스템 | |
| JP2017208718A (ja) | 通信装置および通信方法 | |
| CN111556084B (zh) | Vpn设备间的通信方法、装置、系统、介质和电子设备 | |
| CN116405346A (zh) | 一种vpn通道建立方法、装置、设备及介质 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 19920608 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 19920608 Country of ref document: EP Kind code of ref document: A1 |