Secure Communication Method under the Network Architecture of Edge Servers and Cloud Servers
By introducing a communication channel establishment module into the network architecture of edge servers and cloud servers, and penetrating NAT to establish VPN tunnels, the problem of inability to communicate directly between edge servers is solved, and efficient and secure data interaction is achieved.
Patent Information
- Application Number
- CN202510310181.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-17
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-03-17
AI Technical Summary
Due to NAT restrictions between the LAN and the Internet of the edge server, communication channels cannot be directly established between the edge servers, which affects the secure communication between the edge server and the cloud server.
By introducing a communication channel establishment module into the edge server and cloud server network architecture, the NAT parameters of the target edge server are detected, the interactive channel establishment policy is generated, and the interactive channel establishment is established through the VPN program to penetrate the NAT and establish interactive channels and VPN tunnels, thereby realizing secure data interaction between edge servers.
It solves the problem that communication channels cannot be directly established due to NAT restrictions between edge servers, and realizes efficient and secure data interaction between edge servers, ensuring the security and stability of data transmission.
Smart Images

Figure CN119835093B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of communication security, and particularly relates to a secure communication method under the network architecture of an edge server and a cloud server. Background Art
[0002] In the era of rapid digital development, due to the explosive growth of Internet of Things devices and the increasing demand for low latency, high bandwidth, and real-time processing, the rapid development of cloud-edge integration technology has been spurred. The cloud-edge integration technology sinks the data with high latency requirements that need to be processed in real time to the edge server for data processing, uploads the key data or the data that can only be processed by the cloud server to the cloud for processing, and transmits the processing results of the edge server to the cloud server. On the one hand, it can greatly reduce the data transmission volume between the edge server and the cloud server, effectively saving bandwidth resources. On the other hand, by directly processing the data with high latency requirements that need to be processed in real time on the edge server, the exposure risk of this part of the data due to data transmission can be effectively reduced, and better protection of data security can be achieved. On the other hand, when a communication connection fails between the cloud server and the edge server, the edge server can process the peer data and maintain the continuity and stability of the local service.
[0003] Due to the organic cooperation between the edge server and the cloud server to achieve the fusion processing of various data, in order to achieve a secure communication connection between the edge server and the cloud server, a secure communication channel is established between the edge server and the cloud server through a VPN network to achieve a secure connection and data transmission between the edge server and the cloud server. Generally, in actual network deployment, there is no direct connection between edge servers. However, due to the different functions of each edge server and the different types of data processed by each edge server, in some cases, some edge servers may also need to communicate with each other. However, due to the NAT restriction between the local area network and the Internet of the edge server, a direct communication channel cannot be established between the edge servers.
[0004] Therefore, how to solve the technical problem that a direct communication channel cannot be established between edge servers due to the NAT restriction between the local area network and the Internet of the edge server on the basis of the network deployment of the edge server and the cloud server and ensuring the communication security between the edge server and the cloud server is a technical problem that urgently needs to be solved at present. Summary of the Invention
[0005] The object of the present invention is to provide a secure communication method under the network architecture of edge servers and cloud servers, so as to solve the technical problem that, on the basis of the network deployment of edge servers and cloud servers and ensuring the secure communication between edge servers and cloud servers, due to the NAT restriction between the local area network and the Internet of edge servers, direct communication channels cannot be established between edge servers.
[0006] To solve the above technical problems, the technical solution adopted by the present invention is as follows:
[0007] A secure communication method under the network architecture of edge servers and cloud servers, comprising the following steps:
[0008] S1: The terminal device transmits the generated data to the nearest edge server. The edge server identifies the received data, transmits the data that needs to be processed by the cloud server to the cloud server, and determines whether the remaining data needs to be processed by other edge servers. If not, the nearest edge server directly processes the data and transmits the processed result to the cloud server. If so, step S2 is executed;
[0009] S2: The nearest edge server matches the data that needs to be processed by other edge servers with the corresponding edge servers based on the identification result, and informs the communication channel establishment module of the communication requirements between the nearest edge server and the target edge server;
[0010] S3: The communication channel establishment module detects the NAT parameters of the target edge server, obtains the NAT type of the target edge server, establishes an interactive channel establishment policy, generates a pairing key and a detection packet, and transmits the interactive channel establishment policy, the pairing key and the detection packet to the target edge server;
[0011] S4: The communication channel establishment module penetrates the NAT through the VPN program between the nearest edge server and the target edge server to establish an interactive channel. The communication channel establishment module establishes a VPN tunnel on the interactive channel established by penetrating the NAT, and at the same time sets a data forwarding policy;
[0012] S5: The nearest edge server initiates a communication request to the target edge server, and the target edge server returns a response. The nearest edge server sends the terminal data to be processed to the target edge server through the established VPN tunnel and the data forwarding policy;
[0013] S6: The target server receives the terminal data to be processed and performs corresponding data processing, and transmits the processed data result to the cloud server based on the network architecture of the original edge server and the cloud server.
[0014] Preferably, the specific process of the edge server identifying the received data in step S1 is as follows:
[0015] S11: Extract preset key features from the received data and extract the mapping relationship table between the preset data types and the key features;
[0016] S12: Match the extracted key features through the mapping relationship table and obtain the corresponding data type based on the matching relationship between the key features and the data types.
[0017] Preferably, the specific process of obtaining the NAT type of the target edge server by detecting the NAT parameters of the target edge server in step S3 is as follows:
[0018] S311: The communication channel establishment module sends an ECHO request to the target server. If the target server returns information, then determine whether the public IP address is the same as the NAT internal address of the nearest edge server. If they are the same, it is confirmed that the nearest edge server is not behind the NAT but a public address;
[0019] S312: Determine whether the public address of the nearest edge server is a complete public address. Send preset information to the first IP address and port. The target server receives the preset information and replies with a message using the second IP address and port;
[0020] S313: If a reply message is received, it is determined to be a complete public address. If no reply message is received, it is behind a symmetric firewall;
[0021] S314: If the received public IP address is different from the IP address of the nearest edge server, it is confirmed that the nearest edge server is behind the NAT;
[0022] S315: Send a request to the first address and port of the target server again. The target server replies with a message using the second IP address and port. Establish a mapping table between the internal network address and the external network address on the nearest edge server. If a public reply message can be received, it is determined to be a full cone NAT;
[0023] S316: If a public reply message cannot be received, send information to the second IP address and port of the target server. The target server replies with information using the second IP address and port and brings back the public IP address. If the public IP address is different from the public IP address received in step S34, it is determined to be a symmetric NAT. If they are the same, it is determined to be a restricted NAT;
[0024] S317: Send information to the first IP address and port of the target server again. If the target server replies with information using the same IP address but different port numbers in step S36, it is determined to be an IP restricted NAT. If they are the same port numbers, it is determined to be a port restricted NAT.
[0025] Preferably, the pairing key generated in step S3 is a temporary key for encrypting data packets during the process of establishing an interaction channel between the nearest edge server and the target edge server, and for encrypting heartbeat packets during channel persistence. The pairing key automatically expires when both the establishment of the interaction channel and persistence are completed.
[0026] Preferably, the interaction channel establishment policy includes the type of interaction channel establishment, the master-slave relationship, and policy parameters.
[0027] Preferably, the specific process of step S3 is as follows:
[0028] S321: The communication channel establishment module detects the NAT parameters of the nearest edge server and the NAT parameters of the target edge server;
[0029] S322: The communication channel establishment module generates an interaction channel establishment policy based on the NAT parameters of the nearest edge server and the NAT parameters of the target edge server, creates a temporary pairing key and a probe packet in the interaction channel establishment stage, and sends them to the target edge server;
[0030] S323: The target edge server returns a response for establishing the interaction channel to the communication channel establishment module. The communication channel establishment module sends the interaction channel establishment policy, the pairing key, and the probe packet to the nearest edge server, and the nearest edge server returns a response for establishing the interaction channel to the communication channel establishment module.
[0031] Preferably, the specific process of the communication channel establishment module establishing a VPN tunnel on the interactive channel established through NAT penetration in step S4 is as follows:
[0032] S41: The communication channel establishment module sends a request configured as a VPN server to the target edge server, and the target edge server responds to the request configured as a VPN server;
[0033] S42: The communication channel establishment module sends a request configured as a VPN server to the nearest edge server, and the nearest edge server responds to the request configured as a VPN server;
[0034] S43: The communication channel establishment module creates a VPN tunnel on the established interaction channel.
[0035] Preferably, it further includes an account management process between the nearest edge server and the target edge server, which provides authentication support for the establishment of the interaction channel between the nearest edge server and the target edge server and for data interaction after the establishment of the VPN tunnel, and prevents unauthorized devices from accessing the VPN network.
[0036] Preferably, during the account management process, all data interactions between the nearest edge server and the target edge server are transmitted through the established VPN tunnel.
[0037] The beneficial effects of the present invention include:
[0038] The secure communication method under the edge server and cloud server network architecture provided by the present invention is as follows: The terminal device transmits the generated data to the nearest edge server. When there is data that needs to be processed by other edge servers, the corresponding edge server is matched; the communication channel establishment module detects the NAT type of the target edge server, generates an interactive channel establishment policy, a pairing key, and a detection packet, and transmits them to the target edge server; the VPN program penetrates the NAT to establish an interactive channel, and the communication channel establishment module establishes a VPN tunnel on the interactive channel established by penetrating the NAT, and at the same time sets a data forwarding policy; the nearest edge server initiates a communication request to the target edge server, the target edge server returns a response, and the nearest edge server sends the terminal data to be processed to the target edge server; the target server receives the terminal data to be processed and performs corresponding data processing. It realizes the direct establishment of a communication channel between edge servers for data interaction, and on the basis of the network deployment of edge servers and cloud servers and ensuring the communication security between edge servers and cloud servers, solves the technical problem that direct communication channels cannot be established between edge servers due to the NAT restriction between the local area network and the Internet of edge servers.
[0039] First, by extracting preset key features from the received data and extracting the mapping relationship table between the preset data types and the key features, and matching the extracted key features through the mapping relationship table, the corresponding data type is obtained based on the matching relationship between the key features and the data types, realizing the analysis of the data types. Since a certain edge server cannot process all types of data, it is necessary to send the data that cannot be processed to other edge servers for processing, so that specific data is processed by specific servers to ensure that the data processing results meet the corresponding requirements.
[0040] Second, through the detailed judgment process of the NAT type of the target server in steps S311~S317, it can accurately judge that the NAT type of the target server is a full cone NAT or a symmetric NAT or a port-restricted NAT or an IP-restricted NAT. For different NAT types, the corresponding interactive channel establishment processes are completely different. Therefore, the accurate judgment of the NAT type can effectively improve the success rate of establishing a point-to-point interactive channel between the edge server and the target server.
[0041] Again, by detecting the NAT parameters of the nearest edge server and the target edge server and generating an interactive channel establishment policy, a temporary pairing key and a probe packet in the interactive channel establishment phase are established and sent to the target edge server; the target edge server returns a response for establishing the interactive channel to the communication channel establishment module, and the communication channel establishment module sends the interactive channel establishment policy, the pairing key, and the probe packet to the nearest edge server. The nearest edge server returns a response for establishing the interactive channel to the communication channel establishment module, thereby penetrating the NAT to establish an interactive channel. A VPN tunnel is established on the interactive channel established by penetrating the NAT to achieve efficient and secure data interaction between the nearest edge server and the target edge server.
[0042] Finally, a request to configure as a VPN server is sent to the target edge server through the communication channel establishment module, and the target edge server responds to the request to configure as a VPN server; a request to configure as a VPN server is sent to the nearest edge server through the communication channel establishment module, and the nearest edge server responds to the request to configure as a VPN server; in the process of creating a VPN tunnel on the established interactive channel by the communication channel establishment module, a secure data transmission channel between the target edge server and the nearest edge server is established, solving the technical problem that direct communication channels cannot be established between edge servers due to NAT restrictions between the local area network and the Internet of edge servers, and ensuring the security of data transmission between the two. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] Figure 1 It is a schematic flowchart of a secure communication method under the network architecture of the edge server and the cloud server of the present invention.
[0044] Figure 2 It is a schematic diagram of the network architecture of the edge server and the cloud server of the present invention.
[0045] Figure 3 It is a schematic flowchart of establishing a VPN tunnel on the interactive channel established by penetrating the NAT of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0046] The following is a further detailed description of the present invention in conjunction with the attached Figures 1 to 3 :
[0047] Embodiment 1
[0048] Referring to the attached Figure 1 and Figure 2 shown, a secure communication method under the network architecture of the edge server and the cloud server includes the following steps:
[0049] S1: The terminal device transmits the generated data to the nearest edge server. The edge server identifies the received data, transmits the data that needs to be processed by the cloud server to the cloud server, and determines whether the remaining data needs to be processed by other edge servers. If not, the nearest edge server directly processes the data and transmits the processed result to the cloud server. If so, step S2 is executed;
[0050] S2: Based on the recognition result, the nearest edge server matches the data that needs to be processed by other edge servers with the corresponding edge servers, and informs the communication channel establishment module of the communication requirements between the target edge server;
[0051] S3: The communication channel establishment module detects the NAT parameters of the target edge server, obtains the NAT type of the target edge server, establishes an interactive channel establishment policy, generates a pairing key and a detection packet, and transmits the interactive channel establishment policy, the pairing key and the detection packet to the target edge server;
[0052] S4: The communication channel establishment module penetrates the NAT through the VPN program between the nearest edge server and the target edge server to establish an interactive channel. The communication channel establishment module establishes a VPN tunnel on the interactive channel established by penetrating the NAT, and sets a data forwarding policy at the same time;
[0053] S5: The nearest edge server initiates a communication request to the target edge server. The target edge server returns a response. The nearest edge server sends the terminal data to be processed to the target edge server through the established VPN tunnel and the data forwarding policy;
[0054] S6: The target server receives the terminal data to be processed and performs corresponding data processing, and transmits the processed data result to the cloud server based on the network architecture of the original edge server and the cloud server.
[0055] In this embodiment, since in the existing network architecture of the edge server and the cloud server, there is no direct communication channel established for data interaction between the edge servers. Therefore, when the terminal generates data to be processed, it is transmitted to the nearest edge server for data processing. However, the nearest edge server cannot process all data types generated by the terminal. The solution in the prior art is to directly transmit the data that it cannot process to the cloud server for processing. This processing method will, on the one hand, cause the existing cloud-edge fusion processing technology to fall into a technical bottleneck and cannot achieve the actual sinking processing of data with high latency requirements.
[0056] Therefore, in the present invention, the data generated by the terminal device is transmitted to the nearest edge server. When there is data that needs to be processed by other edge servers, the corresponding edge server is matched. The communication channel establishment module detects the NAT type of the target edge server, generates an interactive channel establishment policy, a pairing key, and a detection packet, and transmits them to the target edge server. The VPN program penetrates the NAT to establish an interactive channel, and the communication channel establishment module establishes a VPN tunnel on the interactive channel established by penetrating the NAT, and at the same time sets a data forwarding policy. The nearest edge server initiates a communication request to the target edge server, the target edge server returns a response, and the nearest edge server sends the terminal data to be processed to the target edge server. The target server receives the terminal data to be processed and performs corresponding data processing. It realizes directly establishing a communication channel between edge servers for data interaction, solves the technical problem that edge servers cannot directly establish a communication channel due to the NAT restriction between the local area network and the Internet of edge servers, on the basis of the network deployment between edge servers and cloud servers and ensuring the communication security between edge servers and cloud servers. Furthermore, when there is a data interaction requirement between an edge server and another edge server, a VPN security tunnel is created to realize the data interaction between the two, realize true edge collaboration data processing, reduce the latency of terminal data processing, and improve the security of data interaction.
[0057] Embodiment 2
[0058] On the basis of Embodiment 1, the specific process of the edge server identifying the received data in step S1 is as follows:
[0059] S11: Extract preset key features from the received data, and extract the mapping relationship table between the preset data types and the key features;
[0060] S12: Match the extracted key features through the mapping relationship table, and obtain the corresponding data type based on the matching relationship between the key features and the data type.
[0061] In this embodiment, since a certain edge server cannot process all types of data, it is necessary to send the data that cannot be processed to other edge servers for processing. The present invention extracts preset key features from the received data, extracts the mapping relationship table between the preset data types and the key features, matches the extracted key features through the mapping relationship table, and obtains the corresponding data type based on the matching relationship between the key features and the data type, realizing accurate identification and analysis of the data type. Furthermore, subsequently, on the basis of establishing a secure VPN tunnel, specific data is transmitted through the secure VPN tunnel to a specific server for processing, improving the accuracy and efficiency of the data processing result, and ensuring that the data processing result meets the corresponding requirements.
[0062] Example 3
[0063] Based on the technology of Example 1 or Example 2, the specific process of detecting the NAT parameters of the target edge server and obtaining the NAT type of the target edge server in step S3 is as follows:
[0064] S311: The communication channel establishment module sends an ECHO request to the target server. If the target server returns information, it is determined whether the public IP address is the same as the NAT internal address of the nearest edge server. If they are the same, it is confirmed that the nearest edge server is not behind the NAT but a public address;
[0065] S312: Determine whether the public address of the nearest edge server is a complete public address. Send a preset message to the first IP address and port. The target server receives the preset message and replies with a message using the second IP address and port;
[0066] S313: If a reply message is received, it is determined to be a complete public address. If no reply message is received, it is behind a symmetric firewall;
[0067] S314: If the received public IP address is different from the IP address of the nearest edge server, it is confirmed that the nearest edge server is behind the NAT;
[0068] S315: Send a request to the first address and port of the target server again. The target server replies with a message using the second IP address and port. An internal network address and external network address mapping table is established on the nearest edge server. If a public network reply message can be received, it is determined to be a full cone NAT;
[0069] S316: If a public network reply message cannot be received, send information to the second IP address and port of the target server. The target server replies with information using the second IP address and port and brings back the public IP address. If the public IP address is different from the public IP address received in step S34, it is determined to be a symmetric NAT. If they are the same, it is determined to be a restricted NAT;
[0070] S317: Send information to the first IP address and port of the target server again. If the target server replies with the same IP address but a different port number as in step S36, it is determined to be an IP restricted NAT. If it is the same port number, it is determined to be a port restricted NAT.
[0071] Due to the different NAT types of the target servers, different interaction establishment methods are required. If the NAT type of the target server cannot be accurately detected, it is almost impossible to establish the subsequent interaction channel and the VPN tunnel. Therefore, in this embodiment, through the above detailed process of judging the NAT type of the target server, it is possible to accurately judge that the NAT type of the target server is a full cone NAT, or a symmetric NAT, or a port-restricted NAT, or an IP-restricted NAT. For different NAT types, the corresponding interaction channel establishment processes are completely different. Therefore, the accurate judgment of the NAT type can effectively improve the success rate of establishing a point-to-point interaction channel between the edge server and the target server.
[0072] In this embodiment, the pairing key generated in step S3 is a temporary key for encrypting data packets during the process of establishing an interaction channel between the nearest edge server and the target edge server, and for encrypting heartbeat packets during channel persistence. The pairing key automatically expires when both the establishment of the interaction channel and persistence are completed. The interaction channel establishment policy includes the interaction channel establishment type, the master-slave relationship, and policy parameters.
[0073] The pairing key types are different in different security levels. The pairing key of the pre-set key is the key index, the pairing key of the negotiated key is the symmetric key, and the pairing key for plaintext communication is empty. Different security levels are set for different data interactions because different data interactions require different security requirements. When the NAT types of two edge servers are the same and the master-slave relationship cannot be determined, the initiator acts as the master server.
[0074] The specific process of step S3 is as follows:
[0075] S321: The communication channel establishment module detects the NAT parameters of the nearest edge server and the NAT parameters of the target edge server;
[0076] S322: The communication channel establishment module generates an interaction channel establishment policy based on the NAT parameters of the nearest edge server and the NAT parameters of the target edge server, generates a temporary pairing key and a probe packet in the interaction channel establishment stage, and sends them to the target edge server;
[0077] S323: The target edge server returns a response for establishing the interaction channel to the communication channel establishment module. The communication channel establishment module sends the interaction channel establishment policy, the pairing key, and the probe packet to the nearest edge server, and the nearest edge server returns a response for establishing the interaction channel to the communication channel establishment module.
[0078] In this embodiment, by detecting the NAT parameters of the nearest edge server and the target edge server and generating an interactive channel establishment policy, a temporary pairing key and a probe packet in the interactive channel establishment phase are established and sent to the target edge server; the target edge server returns a response for establishing the interactive channel to the communication channel establishment module, and the communication channel establishment module sends the interactive channel establishment policy, the pairing key, and the probe packet to the nearest edge server. The nearest edge server returns a response for establishing the interactive channel to the communication channel establishment module, thereby penetrating the NAT to establish an interactive channel, and establishing a VPN tunnel on the interactive channel penetrated by the NAT, so as to achieve efficient and secure data interaction between the nearest edge server and the target edge server.
[0079] Embodiment 4
[0080] Based on the technology of Embodiment 1 or Embodiment 2 or Embodiment 3, refer to Figure 3 , the specific process of the communication channel establishment module establishing a VPN tunnel on the interactive channel penetrated by the NAT in step S4 is as follows:
[0081] S41: The communication channel establishment module sends a request configured as a VPN server to the target edge server, and the target edge server responds to the request configured as a VPN server;
[0082] S42: The communication channel establishment module sends a request configured as a VPN server to the nearest edge server, and the nearest edge server responds to the request configured as a VPN server;
[0083] S43: The communication channel establishment module creates a VPN tunnel on the established interactive channel.
[0084] In the above process, the communication channel establishment module sends a request configured as a VPN server to the target edge server, and the target edge server responds to the request configured as a VPN server; the communication channel establishment module sends a request configured as a VPN server to the nearest edge server, and the nearest edge server responds to the request configured as a VPN server; the communication channel establishment module creates a VPN tunnel on the established interactive channel. By this process, a secure data transmission channel between the target edge server and the nearest edge server is established, solving the technical problem that the edge servers cannot directly establish a communication channel due to the NAT restriction between the local area network and the Internet of the edge servers, and ensuring the security of data transmission between the two.
[0085] In this embodiment, it further includes an account management process between the nearest edge server and the target edge server, which provides authentication support for the establishment of the interaction channel between the nearest edge server and the target edge server and the data interaction after the establishment of the VPN tunnel, and prevents unlicensed devices from accessing the VPN network. In the account management process, all data interactions between the nearest edge server and the target edge server are transmitted through the established VPN tunnel.
[0086] In summary, the secure communication method under the edge server and cloud server network architecture provided by the present invention extracts preset key features from the received data, extracts the mapping relationship table between the preset data types and the key features, matches the extracted key features through the mapping relationship table, and obtains the corresponding data types based on the matching relationship between the key features and the data types, realizing the analysis of the data types. Since a certain edge server cannot process all types of data, it is necessary to send the data that cannot be processed to other edge servers for processing, so that specific data is processed by specific servers to ensure that the data processing results meet the corresponding requirements. Through the detailed judgment process of the NAT type of the target server, it can accurately judge that the NAT type of the target server is a full cone NAT or a symmetric NAT or a port restricted NAT or an IP restricted NAT. For different NAT types, the corresponding interaction channel establishment processes are completely different. Therefore, the accurate judgment of the NAT type can effectively improve the success rate of establishing a point-to-point interaction channel between the edge server and the target server.
[0087] By detecting the NAT parameters of the nearest edge server and the target edge server and generating an interactive channel establishment policy, a temporary pairing key and a probe packet in the interactive channel establishment phase are established and sent to the target edge server; the target edge server returns a response for establishing the interactive channel to the communication channel establishment module, the communication channel establishment module sends the interactive channel establishment policy, the pairing key and the probe packet to the nearest edge server, and the nearest edge server returns a response for establishing the interactive channel to the communication channel establishment module, thereby penetrating the NAT to establish an interactive channel, and establishing a VPN tunnel on the interactive channel established by penetrating the NAT to achieve efficient and secure data interaction between the nearest edge server and the target edge server. By the communication channel establishment module sending a request to configure the target edge server as a VPN server, the target edge server responds to the request to configure it as a VPN server; the communication channel establishment module sends a request to configure the nearest edge server as a VPN server, and the nearest edge server responds to the request to configure it as a VPN server; in the process of the communication channel establishment module creating a VPN tunnel on the established interactive channel, a secure data transmission channel between the target edge server and the nearest edge server is established, solving the technical problem that the edge servers cannot directly establish a communication channel due to the NAT restriction between the local area network and the Internet of the edge servers, and ensuring the security of data transmission between the two.
Claims
1. A secure communication method under an edge server and cloud server network architecture, characterized in that: The following steps are involved: S1: The terminal device transmits the generated data to the nearest edge server. The edge server identifies the received data, transmits the data that needs to be processed by the cloud server to the cloud server, and determines whether the remaining data needs to be processed by other edge servers. If not, the nearest edge server directly processes the data and transmits the processed results to the cloud server. If so, execute step S2; S2: The nearest edge server matches the data that needs to be processed by other edge servers with the corresponding edge server based on the identification result, and informs the communication channel establishment module of the communication requirements between it and the target edge server; S3: The communication channel establishment module detects the NAT parameters of the target edge server, obtains the NAT type of the target edge server, establishes an interactive channel establishment strategy, generates a pairing key and a detection packet, and transmits the interactive channel establishment strategy, pairing key and detection packet to the target edge server; S4: the communication channel establishment module establishes an interactive channel between the nearest edge server and the target edge server by penetrating NAT through a VPN program, and the communication channel establishment module establishes a VPN tunnel on the interactive channel established by penetrating NAT, and sets a data forwarding strategy at the same time; S5: The nearest edge server initiates a communication request to the target edge server, the target edge server returns a response, and the nearest edge server sends the terminal data to be processed to the target edge server through the established VPN tunnel and the data forwarding strategy; S6: The target server receives the terminal data to be processed, performs corresponding data processing, and transmits the processed data results to the cloud server based on the network architecture of the original edge server and the cloud server; The specific process of detecting the NAT parameters of the target edge server and obtaining the NAT type of the target edge server in step S3 is as follows: S311: The communication channel establishment module sends an ECHO request to the target server. If the target server returns information, it is determined whether the public network IP address is consistent with the NAT internal address of the nearest edge server. If they are consistent, it is confirmed that the nearest edge server is not behind NAT but is a public network address. S312: Determine whether the public network address of the nearest edge server is a complete public network address, send preset information to the first IP address and port, the target server receives the preset information, and uses the second IP address and port to reply the message; S313: If a reply message is received, it is determined to be a complete public network address; if no reply message is received, it is behind a symmetrical firewall; S314: If the received public network IP address is inconsistent with the IP address of the nearest edge server, confirm that the nearest edge server is behind NAT; S315: Send a request to the first address and port of the target server again. The target server replies with the second IP address and port. A mapping table between the intranet address and the external network address is established on the nearest edge server. If a public network reply message can be received, it is determined to be a full cone NAT. S316: If the public network reply message cannot be received, information is sent to the second IP address and port of the target server. The target server uses the second IP address and port to reply information and brings back the public network IP address. If the public network IP address is inconsistent with the public network IP address received in step S34, it is determined to be symmetric NAT. If they are consistent, it is determined to be restrictive NAT. S317: Send information to the first IP address and port of the target server again. If the target server replies with the same IP address but different port number as in step S36, it is determined to be IP-restricted NAT. If the port number is the same, it is determined to be port-restricted NAT. The pairing key generated in step S3 is a temporary key used to encrypt data packets during the process of establishing an interactive channel between the nearest edge server and the target edge server, and to encrypt heartbeat packets when the channel is persistent. When both the establishment of the interactive channel and persistence are completed, the pairing key automatically becomes invalid; The specific process of step S3 is as follows: S321: The communication channel establishment module detects NAT parameters of the nearest edge server and NAT parameters of the target edge server; S322: The communication channel establishment module generates an interactive channel establishment strategy based on the NAT parameters of the nearest edge server and the NAT parameters of the target edge server, establishes a temporary pairing key and a detection packet in the interactive channel establishment phase, and sends them to the target edge server; S323: The target edge server returns a response for establishing an interactive channel to the communication channel establishment module, and the communication channel establishment module sends the interactive channel establishment strategy, the pairing key, and the detection packet to the nearest edge server, and the nearest edge server returns a response for establishing an interactive channel to the communication channel establishment module; The specific process of the communication channel establishment module in step S4 establishing a VPN tunnel on the interactive channel established by penetrating NAT is as follows: S41: the communication channel establishing module initiates a request to configure as a VPN server to the target edge server, and the target edge server responds to the request to configure as a VPN server; S42: the communication channel establishing module initiates a request to the nearest edge server to be configured as a VPN server, and the nearest edge server responds to the request to be configured as a VPN server; S43: the communication channel establishing module creates a VPN tunnel on the established interactive channel; The pairing key types are different at different security levels. The pairing key for the preset key is the key index, the pairing key for the negotiated key is the symmetric key, and the pairing key for plaintext communication is empty. Different security levels are set to match different data interactions because different data interactions require different security requirements. When the NAT types of two edge servers are the same and the master-slave relationship cannot be determined, the initiator serves as the master server.
2. The secure communication method under the edge server and cloud server network architecture according to claim 1, characterized in that: The specific process of the edge server identifying the received data in step S1 is as follows: S11: extracting preset key features from the received data, and extracting a mapping relationship table between preset data types and key features; S12: Matching the extracted key features through the mapping relationship table, and acquiring corresponding data types based on the matching relationship between the key features and the data types.
3. The secure communication method under the edge server and cloud server network architecture according to claim 1, characterized in that: The interactive channel establishment strategy includes an interactive channel establishment type, a master-slave relationship and strategy parameters.
4. The secure communication method under the edge server and cloud server network architecture according to claim 1, characterized in that: It also includes an account management process between the nearest edge server and the target edge server, through which the account management process provides identity authentication support for the establishment of an interaction channel between the nearest edge server and the target edge server and data interaction after the VPN tunnel is established, and prevents unauthorized devices from accessing the VPN network.
5. The secure communication method under the edge server and cloud server network architecture according to claim 3 is characterized in that: During the account management process, all data interactions between the nearest edge server and the target edge server are transmitted through the established VPN tunnel.
Citation Information
Patent Citations
Method for accessing intranet resources by client and readable storage medium
CN116233071A
Cloud edge container network communication and optimization system based on network performance perception
CN119342050A