VPN Rule Matching Method, Device, Equipment and Storage Medium

By normalizing and configuring VPN rule entries, combining the matching method of interval tree and linked list structure, the problem of low efficiency in configuration and management of VPN rules is solved, and efficient VPN rule matching and management is achieved.

CN113839848BActive Publication Date: 2025-07-18SANECHIPS TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202010514410.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-06-08
Publication Date
2025-07-18
Estimated Expiration
2040-06-08

AI Technical Summary

Technical Problem

In the prior art, VPN rules are configured and managed inefficiently, especially in the case of a large number of VPN rules, the linked list model cannot meet the needs and affects work efficiency.

Method used

The VPN rule entries sent by the receiving management platform are normalized, configured as an interval tree or linked list structure, and extract key information in the user access request for matching, and allocate VPN channels.

Benefits of technology

It improves the configuration efficiency and matching efficiency of VPN rules, reduces the amount of information interaction, and improves the processing capabilities of large-scale VPN rules.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113839848B_ABST
    Figure CN113839848B_ABST
Patent Text Reader

Abstract

An embodiment of the present application discloses a method, device, equipment, and storage medium for matching VPN rules. The method includes: receiving a VPN rule entry sent by a management platform and performing normalization processing on the VPN rule entry; configuring the VPN rule entry after the normalization processing; extracting key information in an access request sent by a user terminal; matching the key information with the configured VPN rule entry, and if the key information belongs to the VPV rule entry, the matching is successful, so as to allocate a VPN channel to the user terminal, enabling user data to be transmitted through the VPN channel. The method for matching VPN rules provided by the embodiment of the present application can reduce the amount of information interaction and thus improve the configuration efficiency by performing normalization processing on the VPN rule entry before configuration. In addition, matching the key information in the user access request according to the VPN rule entry can improve the matching efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network communication technologies, and in particular, to a method, apparatus, device, and storage medium for matching VPN rules. Background Art

[0002] With the development of communication technologies, the development of the Internet has promoted the development of virtual private networks (VPNs) based on public networks, making it possible for different departments of enterprises across regions to interconnect through public networks, eliminating the need for enterprises to rebuild networks and saving a large amount of communication costs and funds. These new business requirements pose higher performance requirements for the configuration and management of VPNs.

[0003] In the prior art, a management platform sends VPN rules to different service modules through an interface layer, and each service module configures and manages the VPN rules according to specific policies, resulting in a large amount of information interaction between the interface layer and the service modules, seriously affecting the efficiency of VPN rule configuration. In addition, existing VPN matching rules all adopt a linked list model. When the VPN requirements are small and the number of matching entries is small, the linked list model basically meets the business requirements. However, with the increase in business requirements, in the case of more than 10K VPN rules, the Hash or linked list model cannot meet the requirements, seriously affecting work efficiency. Summary of the Invention

[0004] Embodiments of the present application provide a method, apparatus, device, and storage medium for matching VPN rules, which can improve the efficiency of VPN rule matching.

[0005] To achieve the above object, an embodiment of the present application provides a method for matching VPN rules, including:

[0006] Receiving VPN rule entries sent by a management platform and performing normalization processing on the VPN rule entries;

[0007] Configuring the VPN rule entries after normalization processing;

[0008] Extracting key information in an access request sent by a user terminal;

[0009] Matching the key information with the configured VPN rule entries. If the key information belongs to the VPV rule entries, the matching is successful, and a VPN channel is allocated to the user terminal so that user data is transmitted through the VPN channel.

[0010] To achieve the above object, an embodiment of the present application provides a device for matching VPN rules, including:

[0011] A VPN rule normalization processing module, which is used to receive the VPN rule entries sent by the management platform and perform normalization processing on the VPN rule entries;

[0012] A VPN rule configuration module, which is used to configure the VPN rule entries after normalization processing;

[0013] A key information extraction module, which is used to extract the key information in the access request sent by the user terminal;

[0014] A matching module, which is used to match the key information with the configured VPN rule entries. If the key information belongs to the VPV rule entries, the matching is successful, so as to allocate a VPN channel to the user terminal and enable the user data to be transmitted through the VPN channel.

[0015] To achieve the above object, an embodiment of the present application provides a communication device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the VPN rule matching method as described in the embodiment of the present application.

[0016] To achieve the above object, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the VPN rule matching method as described in the embodiment of the present application.

[0017] The VPN rule matching method, device, equipment and storage medium proposed in the embodiment of the present application first receive the VPN rule entries sent by the management platform, perform normalization processing on the VPN rule entries, then configure the VPN rule entries after normalization processing, then extract the key information in the access request sent by the user, and finally match the key information with the configured VPN rule entries. If the key information belongs to the VPV rule entries, the matching is successful, so as to allocate a VPN channel to the user terminal and enable the user data to be transmitted through the VPN channel. The VPN rule matching method provided by the embodiment of the present application performs normalization processing on the VPN rule entries and then configures them, which can reduce the amount of information interaction and thus improve the configuration efficiency. In addition, matching the key information in the user access request with the VPN rule entries can improve the matching efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 is a flowchart of a VPN rule matching method in an embodiment of the present application;

[0019] Figure 2 is a schematic structural diagram of a VPN rule matching device in an embodiment of the present application;

[0020] Figure 3It is the working principle diagram of a VPN rule matching device in an embodiment of the present application;

[0021] Figure 4 It is the structural schematic diagram of a device in an embodiment of the present application. Detailed implementation manners

[0022] To make the objectives, technical solutions and advantages of the present application clearer and more understandable, the embodiments of the present application will be described in detail below with reference to the accompanying drawings. It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined arbitrarily with each other.

[0023] It should be understood that the specific embodiments described herein are only used to explain the present invention, rather than to limit the present invention.

[0024] In subsequent descriptions, suffixes such as "module", "component" or "unit" used to represent elements are only for the convenience of describing the present invention, and they have no specific meaning in themselves. Therefore, "module", "component" or "unit" can be used interchangeably.

[0025] In one embodiment, Figure 1 It is the flowchart of a VPN rule matching method provided by an embodiment of the present application. This method is applicable to the situation of configuring and matching VPN rules, and this method can be executed by a VPN rule matching device. As Figure 1 shown, this method includes the following steps:

[0026] S110, receive the VPN rule entry sent by the management platform, and perform normalization processing on the VPN rule entry.

[0027] Among them, the management platform can be understood as a third-party platform that needs to create a VPN. Different management platforms can adopt different communication protocols and data structures. For example: the management platform can be a TR069 platform. The VPN rule entry can include the destination IP address range, the destination Uniform Resource Locator (URL), and the source Media Access Control Address (MAC) address.

[0028] In this embodiment, the way to perform normalization processing on the VPN rule entry can be: perform normalization processing on the communication protocol and / or data structure of the VPN rule entry. Normalize the different communication protocols of each management platform into the same communication protocol, and normalize the different data structures of each management platform into the same data structure. The normalization processing of the VPN rule entry is executed by the configuration manager in the system.

[0029] In this embodiment, a large number of VPN rule entries are dynamically issued by different management platforms. After the system receives the VPN rule entries, it normalizes the communication protocols and / or data structures of the multiple VPN rule entries. This avoids using different service modules to process the VPN rule entries separately due to the differences in the communication protocols and data structures of each management platform. In the embodiment of the present application, the VPN rule entries from different management platforms can be uniformly processed. After the normalization processing of the VPN rule entries, the differences between the management platforms are masked, which can reduce the amount of interaction data and the number of messages, thereby improving the processing efficiency of VPN rule configuration.

[0030] S120, configure the normalized VPN rule entries.

[0031] Among them, the process of configuring the VPN rule entries can be understood as the process of adding the VPN rule entries to a preset database. The preset database is responsible for the configuration and management of the VPN rule entries, including the addition, deletion, and query of the VPN rule entries.

[0032] In this embodiment, the method of configuring the normalized VPN rule entries can be: determine whether the VPN rule entry exists in the preset database; if it is determined that the VPN rule entry exists in the preset database, return a configuration success message to the management platform; if it is determined that the VPN rule entry does not exist in the preset database, add the VPN rule entry to the preset database.

[0033] Specifically, the preset database queries the VPN rule entry. If a rule entry identical to the received VPN rule entry can be found, a configuration success message is returned to the management platform. If not, the VPN rule entry is added to the preset database.

[0034] In this embodiment, when the VPN rule entry is a destination IP address range or a destination URL, the method of adding the VPN rule entry to the preset database can be: convert the VPN rule entry into an IntervalTree structure; add the IntervalTree structure to the preset database.

[0035] Among them, if it is a destination URL, the destination URL is first converted into a destination IP address range. The IntervalTree structure can be understood as a tree structure composed of destination IP address ranges. This interval tree structure includes multiple nodes, including a root node, child nodes, and leaf nodes. Each node represents a destination IP address range, and the destination IP address range represented by the child node is a subset of the IP address range represented by its parent node. In this embodiment, the destination IP address is stored in the preset database in the form of an interval tree structure.

[0036] In this embodiment, the method of converting the VPN rule entry into an interval tree structure may be as follows: divide the destination IP address range corresponding to the VPN rule entry into multiple sub-ranges; determine the node positions of each sub-range according to the IP address ranges corresponding to each sub-range; construct an interval tree structure according to the node positions.

[0037] Among them, the relationship between any two of the multiple sub-ranges includes at least one of the following: inclusion relationship or empty intersection. Exemplarily, assuming that the destination IP address range is 1-100, then the divided sub-ranges include 1-100, 1-50, 51-100, 1-30, 31-50, 51-80, 81-100. Then the root node of the determined interval tree structure is 1-100, and the child nodes included in the root node are 1-50 and 51-100. The child nodes included in 1-50 are 1-30 and 31-50, and the child nodes included in 51-100 are 51-80 and 81-100. After determining the node positions corresponding to each sub-range, an interval tree structure can be established according to the node positions.

[0038] Specifically, after converting the destination IP address range into an interval tree structure, if the interval tree structure is a branch of an existing interval tree structure, add the interval tree structure to the existing interval tree structure; if the interval tree structure is not a branch of an existing interval tree structure, add the interval tree structure as an independent tree structure to a preset database; if the interval tree structure has an intersection with the existing interval tree structure, adjust the existing interval tree structure according to the interval tree structure to obtain an adjusted interval tree structure.

[0039] In this embodiment, if the VPN rule entry is the source MAC address, the method of adding the VPN rule entry to the preset database may be: convert the VPN rule entry into a linked list structure; add the linked list structure to the preset database.

[0040] Among them, the linked list structure may be a hash list. That is, if the VPN rule entry is the source MAC address, store the MAC address in the form of a linked list structure.

[0041] S130, extract the key information in the access request sent by the user terminal.

[0042] The user may be a user in the management platform, and the user may send an access request to the system through the LAN port or the WLAN port. Among them, the key information may be the destination IP address or the MAC address.

[0043] S140, match the key information with the configured VPN rule entry. If the key information belongs to the VPV rule entry, the match is successful, and a VPN channel is allocated to the user terminal so that the user data is transmitted through the VPN channel.

[0044] In this embodiment, if the key information is the MAC address, the process of matching the key information according to the VPN rule entries may be to query the MAC address from the linked list structure. If a MAC address identical to the MAC address in the key information can be found, the matching is successful; otherwise, the matching is unsuccessful. This embodiment uses an interval tree structure to match the user's access request, without having to traverse all the destination IP address intervals, which can improve the matching efficiency.

[0045] In this embodiment, if the key information is the destination IP address, the method of matching the key information according to the VPN rule entries may be as follows: convert the destination IP address into a destination IP address interval; match the destination IP address interval with the interval tree structure. If the destination IP address interval belongs to the IP address interval corresponding to the interval tree structure, the matching is successful.

[0046] Among them, the converted destination IP address interval of the destination IP address is the destination IP address - the destination IP address. For example, assuming the destination IP address is 5, then the destination IP address interval is 5 - 5. Specifically, first determine the corresponding interval tree structure according to the destination IP address interval, and then start searching downward from the root node of the interval tree structure. If a node matching the destination IP address interval is found, the matching is successful; if no node matching the destination IP address interval is found, the matching is unsuccessful.

[0047] In this embodiment, if the key information in the user access request is successfully matched, it indicates that the user is a legitimate user, and then a VPN channel is allocated to the user so that the user data is transmitted through the VPN channel.

[0048] In this embodiment, the techniques of interval overlap, red - black tree, and interval tree (IntervalTree) are applied to solve the matching problem of VPN rule entries with a quantity above the 10K level of the ONU gateway, improving the matching efficiency of the rule entries.

[0049] The technical solution of this embodiment is as follows: first, receive the VPN rule entries sent by the management platform and perform normalization processing on the VPN rule entries, then configure the normalized VPN rule entries, then extract the key information in the access request sent by the user, and finally match the key information with the configured VPN rule entries. If the key information belongs to the VPV rule entries, the matching is successful, so as to allocate a VPN channel to the user terminal and make the user data transmitted through the VPN channel. The matching method of the VPN rules provided in the embodiments of this application can reduce the amount of information interaction and thus improve the configuration efficiency by performing normalization processing on the VPN rule entries before configuration. In addition, matching the key information in the user access request according to the VPN rule entries can improve the matching efficiency.

[0050] In this embodiment, after allocating a VPN channel to a user, the following steps are further included: collecting the user's behavior data; statistically analyzing the user's behavior data to obtain an analysis result; and performing at least one of the following operations according to the analysis result: adjusting the user priority, the VPN channel priority, and the network bandwidth.

[0051] In this embodiment, the manner of matching the key information with the configured VPN rule entries may also be: when there are multiple pieces of key information, the key information is sequentially matched with the configured VPN rule entries according to the priority of the user terminals corresponding to the key information. That is, first match the key information of the user terminal with a higher priority, and then match the key information of the user terminal with a lower priority.

[0052] In this embodiment, the manner of allocating a VPN channel to a user terminal may be: allocating a VPN channel to the user terminal according to the priority of the VPN channel, and allocating the adjusted network bandwidth to the VPN channel. That is, the VPN channel with a higher priority is preferentially allocated to the user terminal, and the network bandwidth is allocated to the VPV channel according to the adjusted network bandwidth.

[0053] In one embodiment Figure 2 is a schematic structural diagram of a matching device for VPN rules provided by an embodiment of the present application. As Figure 2 shown, the device includes: a VPN rule normalization processing module 210, a VPN rule configuration module 220, a key information extraction module 230, and a matching module 240.

[0054] The VPN rule normalization processing module 210 is configured to receive the VPN rule entries sent by the management platform and perform normalization processing on the VPN rule entries;

[0055] The VPN rule configuration module 220 is configured to configure the VPN rule entries after the normalization processing;

[0056] The key information extraction module 230 is configured to extract the key information in the access request sent by the user terminal;

[0057] The matching module 240 is configured to match the key information with the configured VPN rule entries. If the key information belongs to the VPV rule entries, the matching is successful, so as to allocate a VPN channel to the user terminal, so that the user data is transmitted through the VPN channel.

[0058] In one embodiment, the VPN rule normalization processing module 210 is further configured to:

[0059] perform normalization processing on the communication protocol and / or data structure of the VPN rule entries.

[0060] Optionally, the VPN rule configuration module 220 is further configured to:

[0061] Determine whether a VPN rule entry exists in a preset database;

[0062] If it is determined that the VPN rule entry exists in the preset database, return a message indicating successful configuration to the management platform;

[0063] If it is determined that the VPN rule entry does not exist in the preset database, add the VPN rule entry to the preset database.

[0064] In one embodiment, if the VPN rule entry is a destination IP address range or a destination URL, the VPN rule configuration module 220 is further configured to:

[0065] Convert the VPN rule entry into an interval tree structure;

[0066] Add the interval tree structure to the preset database.

[0067] In one embodiment, the VPN rule configuration module 220 is further configured to:

[0068] Divide the destination IP address range corresponding to the VPN rule entry into multiple sub-ranges; the relationship between any two of the multiple sub-ranges includes at least one of the following: inclusion relationship or empty intersection;

[0069] Determine the node positions of the sub-ranges according to the IP address ranges corresponding to the sub-ranges;

[0070] Construct an interval tree structure according to the node positions.

[0071] In one embodiment, if the VPN rule entry is a source MAC address, the VPN rule configuration module 220 is further configured to:

[0072] Convert the VPN rule entry into a linked list structure;

[0073] Add the linked list structure to the preset database.

[0074] In one embodiment, the key information includes a destination IP address, and the matching module 240 is further configured to:

[0075] Convert the destination IP address into a destination IP address range;

[0076] Match the destination IP address range with the interval tree structure, and if the destination IP address range belongs to the IP address range corresponding to the interval tree structure, the matching is successful.

[0077] In one embodiment, it further includes: a behavior data analysis module, configured to:

[0078] Collect the behavior data of the user terminal;

[0079] Statistically analyze the behavior data of the user terminal to obtain the analysis result;

[0080] Perform at least one of the following operations according to the analysis result: adjust the priority of the user terminal, the priority of the VPN channel, and the network bandwidth.

[0081] In one embodiment, the matching module 240 is further configured to:

[0082] When there are multiple pieces of key information, match the key information with the configured VPN rule entries in sequence according to the priority of the user terminal corresponding to the key information.

[0083] In one embodiment, the matching module 240 is further configured to:

[0084] Allocate a VPN channel to the user terminal according to the priority of the VPN channel, and allocate the adjusted network bandwidth to the VPN channel.

[0085] In one embodiment Figure 3 is the working principle diagram of a VPN rule matching device provided by an embodiment of the present application. As Figure 3 shown, multiple management platforms send VPN rule entries to the system through the communication module, receive the VPN rule entries sent by the management platform, perform normalization processing on the VPN rule entries, and configure the normalized VPN rule entries. The user sends an access request to the system, and the system extracts the key information in the access request sent by the user; match the key information according to the VPN rule entries. If the match is successful, allocate a VPN channel to the user so that the user data is transmitted through the VPN channel.

[0086] In one embodiment Figure 4 is the structural schematic diagram of a device provided by an embodiment of the present application. As Figure 4 shown, the device provided by the present application includes: a processor 310 and a memory 320. The number of processors 310 in the device may be one or more, Figure 4 taking one processor 310 as an example. The number of memories 320 in the device may be one or more, Figure 4 taking one memory 320 as an example. The processor 310 and the memory 320 of the device may be connected through a bus or other means, Figure 4 taking the connection through a bus as an example. In the embodiment, the device is a communication device.

[0087] The memory 320, being a computer-readable storage medium, can be configured to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the device in any embodiment of the present application (for example, the encoding module and the first sending module in the data transmission device). The memory 320 can include a program storage area and a data storage area. Among them, the program storage area can store an operating system and application programs required for at least one function; the data storage area can store data created according to the use of the device, etc. In addition, the memory 320 can include high-speed random access memory and can also include non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some instances, the memory 320 can further include a memory remotely set relative to the processor 310, and these remote memories can be connected to the device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0088] The device provided above can be configured to execute the matching method for VPN rules provided in any of the above embodiments, and has corresponding functions and effects.

[0089] The program stored in the corresponding memory 320 can be the program instructions / modules corresponding to the signal processing method provided in the embodiments of the present application. The processor 310 executes one or more functional applications and data processing of the computer device by running the software programs, instructions, and modules stored in the memory 320, that is, implements the signal processing method in the above method embodiments. It can be understood that when the above device is a receiving end, it can execute the signal processing method provided in any embodiment of the present application and has corresponding functions and effects. Among them, the device can be one of a base station or a UE.

[0090] The embodiments of the present application also provide a storage medium containing computer-executable instructions. The computer-executable instructions are used to execute a method for matching VPN rules when executed by a computer processor. The method includes: receiving VPN rule entries sent by a management platform and performing normalization processing on the VPN rule entries; configuring the normalized VPN rule entries; extracting key information in an access request sent by a user; matching the key information according to the VPN rule entries. If the match is successful, a VPN channel is allocated to the user so that user data is transmitted through the VPN channel.

[0091] Those skilled in the art should understand that the term user equipment covers any suitable type of wireless user equipment, such as a mobile phone, a portable data processing device, a portable network browser, or an in-vehicle mobile station.

[0092] In general, the various embodiments of the present application can be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. For example, some aspects can be implemented in hardware, while other aspects can be implemented in firmware or software that can be executed by a controller, a microprocessor, or other computing devices, although the present application is not limited thereto.

[0093] The embodiments of the present application can be implemented by a data processor of a mobile device executing computer program instructions, for example, in a processor entity, or by hardware, or by a combination of software and hardware. The computer program instructions can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages.

[0094] Any block diagram of a logical process in the accompanying drawings of the present application can represent program steps, or can represent interconnected logical circuits, modules, and functions, or can represent a combination of program steps and logical circuits, modules, and functions. The computer program can be stored in a memory. The memory can have any type suitable for the local technical environment and can be implemented using any suitable data storage technology, such as but not limited to read-only memory (ROM), random access memory (RAM), optical memory devices and systems (digital video disc (DVD) or compact disk (CD)), etc. The computer-readable medium can include non-transitory storage media. The data processor can be any type suitable for the local technical environment, such as but not limited to a general-purpose computer, a dedicated computer, a microprocessor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FGPA), and a processor based on a multi-core processor architecture.

[0095] As described above, the above are only exemplary embodiments of the present application and are not used to limit the protection scope of the present application.

[0096] Embodiments of the present application can be implemented by a data processor of a mobile device executing computer program instructions, for example, in a processor entity, or by hardware, or by a combination of software and hardware. The computer program instructions can be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages.

[0097] By way of example and not limitation, a detailed description of exemplary embodiments of the present application has been provided above. However, various modifications and adaptations of the above embodiments will be apparent to those skilled in the art when considered in conjunction with the accompanying drawings and the claims, without departing from the scope of the invention. Accordingly, the proper scope of the invention will be determined in accordance with the claims.

Claims

1. A method for matching VPN rules, characterized in that, including: receiving the VPN rule entries sent by the management platform and normalizing the VPN rule entries; configuring the normalized VPN rule entries; extracting key information in the access request sent by the user terminal; matching the key information with the configured VPN rule entries, if the key information belongs to the VPN rule entries, the matching is successful, and a VPN channel is allocated to the user terminal so that user data is transmitted through the VPN channel; the normalizing the VPN rule entries includes: normalizing the communication protocol and / or data structure of the VPN rule entries; normalizing different communication protocols of each management platform into the same communication protocol, and normalizing different data structures of each management platform into the same data structure.

2. The method according to claim 1, characterized in that, configuring the normalized VPN rule entries includes: judging whether the VPN rule entries exist in a preset database; if it is judged that the VPN rule entries exist in the preset database, returning information indicating successful configuration to the management platform; if it is judged that the VPN rule entries do not exist in the preset database, adding the VPN rule entries to the preset database.

3. The method according to claim 2, wherein if the VPN rule entries are destination IP address ranges or destination URLs, adding the VPN rule entries to the preset database includes: converting the VPN rule entries into an interval tree structure; adding the interval tree structure to the preset database.

4. The method according to claim 3, characterized in that converting the VPN rule entries into an interval tree structure includes: dividing the destination IP address range corresponding to the VPN rule entries into multiple sub-ranges; the relationship between any two of the multiple sub-ranges includes at least one of the following: inclusion relationship or empty intersection; determining the node positions where each sub-range is located according to the IP address range corresponding to each sub-range; constructing an interval tree structure according to the node positions.

5. The method according to claim 2, characterized in that, if the VPN rule entry is a source MAC address, adding the VPN rule entry to the preset database includes: converting the VPN rule entry into a linked list structure; adding the linked list structure to the preset database.

6. The method according to claim 3, wherein the key information includes a destination IP address, matching the key information with the configured VPN rule entries, if the key information belongs to the VPN rule entries, the matching is successful, including: converting the destination IP address into a destination IP address range; matching the destination IP address range with the interval tree structure, if the destination IP address range belongs to the IP address range corresponding to the interval tree structure, the matching is successful.

7. The method according to claim 1, characterized in that after allocating the VPN channel to the user, it further includes collecting user terminal behavior data; statistically analyzing the user terminal behavior data to obtain an analysis result; performing at least one of the following operations according to the analysis result: adjusting the priority of the user terminal, the priority of the VPN channel, and the network bandwidth.

8. The method according to claim 7, wherein Match the key information with the configured VPN rule entries, including, when there are multiple key information, match the key information with the configured VPN rule entries in sequence according to the priorities of the user terminals corresponding to the key information; Allocate a VPN channel to the user terminal, including allocating a VPN channel to the user terminal according to the priority of the VPN channel, and allocating an adjusted network bandwidth to the VPN channel.

9. A matching device for VPN rules, characterized in that, including: A VPN rule normalization processing module, configured to receive VPN rule entries sent by a management platform and perform normalization processing on the VPN rule entries; A VPN rule configuration module, configured to configure the VPN rule entries after normalization processing; A key information extraction module, configured to extract key information in an access request sent by a user terminal; A matching module, configured to match the key information with the configured VPN rule entries. If the key information belongs to the VPN rule entries, the matching is successful, so as to allocate a VPN channel to the user terminal, and enable user data to be transmitted through the VPN channel; The VPN rule normalization processing module is further configured to: Perform normalization processing on the communication protocol and / or data structure of the VPN rule entries; normalize different communication protocols of each management platform into the same communication protocol, and normalize different data structures of each management platform into the same data structure.

10. A communication device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the VPN rule matching method according to any one of claims 1-8.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the VPN rule matching method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Heterogeneous API conversion system for cloud management platforms

    CN104486444A

  • Message transmission method and device

    CN111010329A

  • Data structure for range-specified algorithms

    EP1515501A1