Gateway negotiation method, device, and storage medium

By managing VPN gateway keys and certificates through cloud servers, the problem of poor scalability in VPN gateway negotiation operations is solved, thereby improving the security and scalability of the VPN gateway and meeting specific security standards.

CN115208555BActive Publication Date: 2026-01-23ALIBABA INNOVATION PRIVATE LIMITED
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110315713.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-03-24
Publication Date
2026-01-23
Estimated Expiration
2041-03-24

AI Technical Summary

Technical Problem

VPN gateways rely on hardware for negotiation, resulting in poor scalability and portability, making it difficult to meet specific security protection requirements under particular security standards.

Method used

The VPN gateway negotiates the required keys by managing the client through the cloud server, utilizes the virtual resources provided by the cloud server to achieve horizontal scaling of the VPN gateway, and has the encryption certificate and signing certificate and their corresponding keys hosted by the certificate management system to ensure the security and legitimate access of the keys.

Benefits of technology

It enables horizontal scaling and security assurance of VPN gateways, reduces dependence on hardware devices, and meets specified security requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115208555B_ABST
    Figure CN115208555B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a gateway negotiation method, device and storage medium. In the gateway negotiation method, the key required for gateway negotiation of the client is managed by a specified device. After the client requests the specified device to allocate a VPN gateway, the client can send a key ID of the key required for gateway negotiation to the VPN gateway. When the VPN gateway needs to use the key in the process of gateway negotiation, the VPN gateway can access the key managed by the specified device according to the key ID. In this implementation, the VPN gateway is allocated by the specified device, and the key required for VPN gateway negotiation is managed by the specified device. On the one hand, the horizontal expansion of the VPN gateway can be implemented based on the virtual resource provided by the specified device, and on the other hand, the security of the key can be ensured based on the management of the key by the specified device, the negotiation operation of the VPN gateway can meet the specified security requirements, and the dependence of the negotiation operation of the VPN gateway on the hardware device is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet, in particular to a gateway negotiation method, device and storage medium. BACKGROUND

[0002] In some scenarios, users of industry cloud or special cloud need to meet the security protection requirements of a specified level under a specific security standard. When the users of the industry cloud or the special cloud use a VPN (Virtual Private Network) gateway, the security protection requirements of the specified level need the VPN gateway to perform authentication according to a specified authentication mode in a negotiation phase.

[0003] At present, the negotiation operation of the VPN gateway is implemented based on a hardware device, and the expansibility is poor. Therefore, a new solution needs to be proposed. SUMMARY

[0004] Aspects of the present application provide a gateway negotiation method, device and storage medium to reduce the dependence of the negotiation operation of the VPN gateway on the hardware device.

[0005] The present application provides a gateway negotiation method, comprising: sending a gateway allocation request to a specified device to make the specified device allocate a VPN gateway for a client; and sending a key ID of a key required for gateway negotiation corresponding to the client to the VPN gateway to make the VPN gateway access the key required for the gateway negotiation according to the key ID when negotiating with a peer VPN gateway; wherein the key required for the gateway negotiation is managed by the cloud specified device.

[0006] The present application also provides a gateway negotiation method, comprising: allocating a VPN gateway for a client in response to a gateway allocation request sent by the client; receiving a message processing request sent by the VPN gateway according to a to-be-processed negotiation message and a key ID; processing the to-be-processed negotiation message according to a key corresponding to the key ID, and returning a negotiation message obtained by processing to the VPN gateway.

[0007] The present application also provides a gateway negotiation method applicable to a VPN gateway, comprising: receiving a key ID sent by a client; the key corresponding to the key ID is managed by a specified device; and in the process of negotiating with a peer VPN gateway, requesting the specified device to process a to-be-processed negotiation message according to a key corresponding to the key ID according to the to-be-processed negotiation message and the key ID.

[0008] This application also provides an electronic device, including: a memory and a processor; the memory is used to store one or more computer instructions; the processor is used to execute the one or more computer instructions to: perform the steps in the gateway negotiation method provided in this application.

[0009] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, can implement the steps in the gateway negotiation method provided in this application.

[0010] This application also provides a computer program product, including a computer program / instructions, wherein when the computer program is executed by a processor, it causes the processor to implement the steps in the gateway negotiation method provided in this application.

[0011] In the gateway negotiation method provided in this application embodiment, the key required by the client for gateway negotiation is managed by a designated device. After the client requests the allocation of a VPN gateway from the designated device, it can send the key ID of the key required for gateway negotiation to the VPN gateway. When the VPN gateway needs to use the key during the gateway negotiation process, it can access the key managed by the designated device based on the key ID. In this implementation, the VPN gateway is allocated by the designated device, and the key required for VPN gateway negotiation is managed by the designated device. On the one hand, horizontal scaling of the VPN gateway can be achieved based on the virtual resources provided by the designated device. On the other hand, the security of the key can be ensured based on the key management by the designated device, ensuring that the VPN gateway negotiation operation meets the specified security requirements, and reducing the dependence of the VPN gateway negotiation operation on hardware devices. Attached Figure Description

[0012] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0013] Figure 1 A schematic diagram of the gateway negotiation system provided in an exemplary embodiment of this application;

[0014] Figure 2a A schematic diagram of the gateway negotiation system provided as another exemplary embodiment of this application;

[0015] Figure 2b A schematic diagram of the gateway negotiation system provided as another exemplary embodiment of this application;

[0016] Figure 3a A schematic diagram illustrating the process of a gateway negotiation method provided in an exemplary embodiment of this application being executed on the terminal device side;

[0017] Figure 3b A schematic diagram illustrating the process of a gateway negotiation method performed on the terminal device side, as provided in another exemplary embodiment of this application;

[0018] Figure 4 A schematic diagram illustrating the process of a gateway negotiation method provided in an exemplary embodiment of this application being executed on the cloud server side;

[0019] Figure 5a A schematic diagram illustrating the process of the gateway negotiation method provided in an exemplary embodiment of this application being executed on the certificate management component side of a cloud server;

[0020] Figure 5b A schematic diagram illustrating the process of the gateway negotiation method provided in an exemplary embodiment of this application being executed on the identity authentication component side of a cloud server;

[0021] Figure 6 A schematic diagram illustrating the process of a gateway negotiation method provided in an exemplary embodiment of this application being executed on the VPN gateway side;

[0022] Figure 7 A schematic diagram of the structure of a terminal device provided in an exemplary embodiment of this application;

[0023] Figure 8 This is a schematic diagram of the structure of a server provided for an exemplary embodiment of this application. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0025] In some scenarios, users of industry clouds or private clouds need to meet specific security protection requirements under certain security standards. When using a VPN (Virtual Private Network) gateway, users of industry clouds or private clouds must meet specific security protection requirements under certain security standards. These specific security protection requirements necessitate authentication by the VPN gateway during the negotiation phase using a specified authentication mode.

[0026] Currently, VPN gateways perform negotiation and authentication operations based on hardware devices. The certificates and keys used for negotiation are stored in the hardware devices, resulting in poor scalability and portability.

[0027] In view of the above-mentioned technical problems, a solution is provided in some embodiments of this application, which will be described exemplarily below with reference to the accompanying drawings.

[0028] Figure 1 This is a schematic diagram of the structure and flow of a gateway negotiation system provided in an exemplary embodiment of this application, as shown below. Figure 1 As shown, the gateway negotiation system 100 may include: a client 10, a designated device (e.g., Figure 1 The cloud server 20 and the peer VPN gateway 30 are shown in the diagram.

[0029] The client application can be implemented on a user-side terminal device, including mobile phones, computers, tablets, smart wearable devices, etc., without limitation in this embodiment. The aforementioned terminal device may run applications or browsers that can access the specified device. The client can apply for or lease a user account on the specified device and access user-facing services provided by the specified device through that account.

[0030] The designated device can be any device capable of providing computing, networking, and storage capabilities to other devices based on hardware and software resources. In some embodiments, the designated device can be a server device, such as a conventional server, cloud host, cloud server, virtual center, or other similar server devices; this embodiment does not impose any limitations on this. The server device mainly comprises a processor, hard disk, memory, system bus, etc., and its architecture is similar to that of a general computer, so it will not be described in detail further.

[0031] In the following embodiments, the first terminal device will be used as the implementation. Figure 1 The cloud server 20 shown is used as an example for illustration. Here, a cloud server refers to a remote server that, supported by cloud computing technology, can provide on-demand, metered information technology services. In this context, client users can also be referred to as cloud users or cloud tenants.

[0032] In the gateway negotiation system 100, the client 10 is mainly used to send gateway allocation requests to the cloud server 20.

[0033] After receiving a gateway allocation request from client 10, cloud server 20 can allocate a VPN gateway to client 10 based on the virtual resources within cloud server 20. The VPN gateway can be provided by the cloud server. Based on the virtual resources and virtualized environment of cloud server 20, the VPN gateway can be quickly copied, expanded, and deleted without being limited by hardware devices.

[0034] In this embodiment, the cloud server 20 is also used to manage the key required for gateway negotiation corresponding to the client 10.

[0035] After client 10 determines the VPN gateway assigned to it by cloud server 20, it sends the key ID of the key required for gateway negotiation corresponding to client 10 to the VPN gateway. Then, when negotiating with peer VPN gateway 30, the VPN gateway can access the key required for gateway negotiation from cloud server 20 based on this key ID. The peer VPN gateway 30 can be any other VPN gateway on the cloud server, or it can be a VPN gateway for the user's offline network, depending on the specific application scenario; this embodiment does not impose any restrictions.

[0036] During gateway negotiation, cloud server 20 can receive message processing requests sent by VPN gateway based on the negotiation message to be processed and key ID; process the negotiation message to be processed according to the key corresponding to the key ID, and return the processed negotiation message to VPN gateway.

[0037] In some embodiments, the cloud server 20 may be deployed with a variety of components with different functions. These components may be implemented based on hardware, software, or a combination of hardware and software, and this embodiment does not impose any limitations. For example, in this embodiment, when the cloud server 20 is used for gateway negotiation, the cloud server 20 may include a certificate management component for managing client certificates, an authentication component for authenticating clients and assigning VPN gateways, a VPN gateway component for implementing VPN gateway functions, and so on.

[0038] The certificate management component, identity authentication component, and VPN gateway component can be implemented based on virtual servers, cloud hosts, or elastic computing instances on cloud servers, and this embodiment does not impose any restrictions. For example, in some embodiments, the certificate management component, identity authentication component, and VPN gateway component can be implemented by elastic computing instances (ElasticCompute Service, ECS) on cloud servers.

[0039] In the following embodiments, the certificate management component, identity authentication component, and VPN gateway component will be implemented as follows: Figure 1 The certificate management system 201, identity authentication system 202, and VPN gateway 203 shown are used as examples for illustrative purposes. Figure 1 In the diagram, VPN gateway 203 is used to illustrate the VPN gateway allocated by cloud server 20 to client 10.

[0040] In some optional embodiments, when a certificate management system 201 is deployed on the cloud server 20, the client 10 can obtain the certificate and key required for gateway negotiation before sending a gateway allocation request to the cloud server, and send the certificate and key to the certificate management system 201 on the cloud server 20 for management. The certificate required for gateway negotiation typically includes a public key, a certificate name, and a digital signature from a certificate authority. The key required for gateway negotiation typically includes a private key.

[0041] The certificate management system 201 is mainly used to: receive certificates and keys sent by client 10; determine the certificate ID (Identity Document) of the certificate and the key ID of the key, and return the certificate ID and the key ID to client 10.

[0042] Client 10 receives the certificate ID and key ID returned by the certificate management system 201, and can send a gateway allocation request to cloud server 20 based on the certificate ID.

[0043] In some optional embodiments, when an identity authentication system 202 is deployed on the cloud server 20, the client 10 can send a gateway allocation request to the identity authentication system 202 on the cloud server 20. On the cloud server 20, the identity authentication system 202 is primarily used for allocating VPN gateways. After receiving the gateway allocation request sent by the client 10, the identity authentication system 202 can determine the certificate ID of the client 10 carried in the gateway allocation request. Next, based on the client's certificate ID and the virtual resources and virtualization system on the cloud server 20, a VPN gateway is allocated to the client 10.

[0044] In this embodiment, the VPN gateway assigned to client 10 by the identity authentication system 202 is a VPN gateway provided by the cloud server, such as... Figure 1 The VPN gateway 203 is shown. Next, the authentication system 202 can return the identifier of the VPN gateway 203 to the client 10. Typically, the authentication system 202 can obtain the certificate corresponding to the certificate ID from the certificate management system 201 and authorize the VPN gateway 203 with the certificate.

[0045] Upon receiving the VPN gateway's identifier, client 10 can send the key ID issued by certificate management system 201 to VPN gateway 203. VPN gateway 203 receives the key ID sent by client 10. The key corresponding to this key ID is stored in certificate management system 201, so that VPN gateway 203 can request access to the key corresponding to the key ID from certificate management system 201 based on the key ID.

[0046] During the negotiation process between VPN gateway 203 and peer VPN gateway 30, VPN gateway 203 can request the certificate management system 201 to process the negotiation message to be processed according to the key corresponding to the key ID, based on the negotiation message to be processed and the key ID.

[0047] The VPN gateway can be a VPN gateway that complies with IPSec (Internet Protocol Security, abbreviated as Ipsec, Internet security protocol), i.e., an IPSecVPN gateway. This embodiment does not impose any restrictions.

[0048] In this embodiment, the VPN gateway is deployed on a cloud server. The key required for VPN gateway negotiation is managed by the certificate management system on the cloud server. On the one hand, the VPN gateway can be horizontally scaled based on the virtual resources provided by the cloud server. On the other hand, the certificate management system can ensure the security of the key and ensure that the VPN gateway negotiation operation meets the specified security requirements, thereby reducing the dependence of the VPN gateway negotiation operation on hardware devices.

[0049] In some optional embodiments, there may be multiple VPN gateways 203, which are not illustrated in this embodiment. When applying to use the VPN gateway of the cloud server, client 10 can specify the number of VPN gateways to be rented or purchased. When allocating VPN gateways to client 10, identity authentication system 202 can allocate corresponding VPN gateways to client 10 according to the number of gateways rented or purchased by client 10; this embodiment does not impose any restrictions. Therefore, the number of VPN gateways can be horizontally expanded without being limited by hardware devices.

[0050] In some alternative embodiments, communication between VPN gateways requires meeting a specified level of security protection under a particular security standard. This specified level of security protection necessitates the VPN gateways using "dual certificates" for authentication during the negotiation phase. These dual certificates include a signing certificate and an encryption certificate.

[0051] To meet the aforementioned security protection requirements, optionally, in this embodiment, the certificate sent by client 10 to certificate management system 201 for safekeeping may include: a signing certificate and an encryption certificate; the key sent by client 10 to certificate management system 201 for safekeeping may include: a signing key and an encryption key. The signing certificate contains a signing public key, and the encryption certificate contains an encryption public key; the signing key refers to the signing private key, and the encryption key refers to the encryption private key.

[0052] Accordingly, after receiving the signature certificate and the encryption certificate, the certificate management system 201 can generate the corresponding signature certificate ID and encryption certificate ID; after receiving the signature key and the encryption key, the certificate management system 201 can generate the corresponding signature key ID and encryption key ID.

[0053] Next, the certificate management system 201 can send the generated signature certificate ID, encryption certificate ID, signature key ID, and encryption key ID to the client 10, so that the client 10 and other devices associated with the client 10 can access the corresponding certificate or key based on the above IDs.

[0054] The signature key can be generated by client 10, or it can be generated by certificate management system 201 for client 10.

[0055] In some optional embodiments, client 10 may generate a signing public key and a signing private key. Next, optionally, client 10 may send a key management request to certificate management system 201, the key management request carrying the signing public key and signing private key generated by client 10. Upon receiving the signing public key and signing private key, certificate management system 201 may generate an ID for the signing private key and, based on the signing private key ID and the signing public key, generate a Certificate Signing Request (CSR). Certificate management system 201 may then return the Certificate Signing Request to client 10.

[0056] In some alternative embodiments, the signing key corresponding to client 10 can be generated by certificate management system 201. In this embodiment, client 10 can send a signing key generation request to certificate management system 201. Certificate management system 201 can generate a signing public key, a signing private key, and an ID of the signing private key for client 10 based on the client 10's key management request. Based on the signing public key and the signing private key ID, certificate management system 201 can generate a certificate request file and return the certificate request file to client 10.

[0057] The signature certificate, encryption certificate, and encryption key can be generated by a certificate authority. An example will be provided below.

[0058] The Certificate Authority (CA) can be a CA provided by the cloud computing platform where the cloud server 20 is located, or it can be a third-party CA. This embodiment does not impose any restrictions.

[0059] After receiving the certificate request file, client 10 can send a certificate request to certificate authority 40 based on the file, and receive the signing certificate, signing key, encryption certificate, and encryption key issued by the certificate authority. The encryption key can be encrypted using the signing public key to ensure its security.

[0060] Based on the above, when using the "dual certificate authentication" mode for gateway negotiation, the set of certificates requested by client 10 may include an encryption certificate and a signing certificate. A set of certificates can be assigned to multiple VPN gateways, each VPN gateway can load a set of certificates, and multiple virtual gateways can load the same set of certificates. Each VPN gateway can establish IPSec links with multiple peer VPN gateways that meet a specified security level. Different peer VPN gateways can use certificates issued by different certificate authorities, which will not be elaborated further.

[0061] In the foregoing embodiments, it is described that during the negotiation process between the VPN gateway 203 on the cloud server 20 and the peer VPN gateway 30, the VPN gateway 203 can request the certificate management system 201 to process the negotiation message to be processed according to the key corresponding to the key ID, based on the negotiation message to be processed and the key ID.

[0062] In some optional embodiments, the negotiation message to be processed includes a negotiation message to be signed by the VPN gateway 203. When the VPN gateway 203 determines that the message to be processed is a negotiation message to be signed, it can send a message signing request to the certificate management system based on the negotiation message to be signed and the ID of the signing key.

[0063] After receiving a message signing request, the certificate management system 201 can determine the signing key corresponding to the ID of the signing key from the managed keys, and use the signing key corresponding to the ID of the signing key to sign the negotiation message to be signed, thus obtaining a signed message. Next, the signed message is returned to the VPN gateway 203. The VPN gateway 203 can receive the signed message and send it to the peer VPN gateway 30 for negotiation.

[0064] In some alternative embodiments, the negotiation message to be processed includes a negotiation message to be decrypted received by VPN gateway 203.

[0065] When VPN gateway 203 receives a negotiation message to be decrypted from peer VPN gateway 30, it can send a message decryption request to certificate management system 201 based on the negotiation message to be decrypted and the ID of the encryption key.

[0066] After receiving a message decryption request, the certificate management system 201 can determine the encryption key corresponding to the encryption key ID from the managed keys, and use the encryption key corresponding to the encryption key ID to decrypt the negotiation message to be decrypted, obtaining a decrypted negotiation message. Next, the decrypted negotiation message is returned to the VPN gateway 203. The VPN gateway 203 can receive the decrypted negotiation message for use in gateway negotiations.

[0067] The following will provide a further illustrative description of the negotiation process between VPN gateway 203 and peer VPN gateway 30, with reference to the accompanying drawings.

[0068] To meet the specified security protection requirements of certain security standards, VPN gateway negotiation consists of two phases: the first phase in main mode and the second phase in fast mode. The first phase comprises six negotiation messages and requires dual authentication.

[0069] In the first phase, based on the first and second messages, the negotiation initiator can send one or more IKE (Internet Key Exchange Protocol) security proposals to the negotiation responder. The negotiation responder searches for a matching IKE security proposal and responds to the negotiation initiator with the found IKE security proposal. The principle for protocol matching is that both parties to the negotiation have the same encryption algorithm.

[0070] In the first phase, based on the third and fourth messages, the negotiation initiator and responder can exchange data. The exchanged data includes payload data such as the Nonce and ID. The Nonce is a parameter used to generate other session keys; the ID is the identifier of the negotiation initiator or responder. The payload data is encrypted using a temporary key Sk, which is further encrypted using the public key from the other party's encryption certificate. Both parties then digitally sign their respective data.

[0071] In the first phase, based on the 5th and 6th messages, the negotiation initiator and the negotiation responder can authenticate the data exchanged during the aforementioned message exchange process. The information transmitted in the 5th and 6th messages is encrypted using a symmetric cryptographic algorithm, which is determined by the IKE protocol negotiated in the 1st and 2nd messages.

[0072] Figure 2 illustrates the negotiation process between VPN gateway 203 and peer VPN gateway 30.

[0073] When VPN gateway 203 on cloud server 20 acts as the negotiation initiator, it can send a first message to peer VPN gateway 30, which contains multiple IKE security proposals. Peer VPN gateway 30 can then search for a matching IKE protocol from the multiple IKE security proposals based on supported encryption algorithms, and send a second message to VPN gateway 203 based on the found IKE security proposal.

[0074] Next, when VPN gateway 203 sends the third message to peer VPN gateway 30, it can encrypt the payload data to be sent using the public key in the encryption certificate of peer VPN gateway 30 to obtain the negotiation message to be signed. Then, VPN gateway 203 sends the signing key ID obtained from client 10 and the negotiation message to be signed to certificate management system 201.

[0075] The certificate management system 201 determines the signing key corresponding to the ID of the signing key from the managed signing keys, and uses the determined signing key to sign the negotiation message to be signed, thus obtaining a signed message. After the signed message is returned to the VPN gateway 203, the VPN gateway 203 can send a third message to the peer VPN gateway 30 based on the signed message.

[0076] After receiving the third message, the peer VPN gateway 30 can use the signing public key from the signing certificate of VPN gateway 203 to verify the signature of the third message. After successful signature verification, it decrypts the third message using its own encryption private key. Next, when the peer VPN gateway 30 sends the fourth message to VPN gateway 203, the payload data in this fourth message is encrypted using the encryption public key from the encryption certificate of VPN gateway 203 and signed using the signing private key of the peer VPN gateway 30.

[0077] When VPN gateway 203 receives the fourth message, it can first use the signing public key in the signing certificate of the peer VPN gateway 30 to verify the signature of the fourth message. After the signature verification is successful, the fourth message is determined to be a negotiation message to be decrypted. Next, VPN gateway 203 can send the ID of the encryption key obtained from client 10 and the decrypted negotiation message to certificate management system 201.

[0078] The certificate management system 201 determines the encryption key corresponding to the ID of the encryption key from the managed encryption keys, and uses the determined encryption key to decrypt the negotiation message to be decrypted, obtaining a decrypted negotiation message. After the decrypted negotiation message is returned to the VPN gateway 203, the VPN gateway 203 can perform subsequent negotiation steps based on the decrypted negotiation message. For example, the VPN gateway 203 can send the fifth message to the peer VPN gateway 30 based on the decrypted message, and receive the sixth message returned by the peer VPN gateway 30 to authenticate the data transmitted in the third and fourth messages, which will not be elaborated further.

[0079] In this embodiment, the virtualization system provided by the cloud server allows for easy horizontal scaling, enabling the creation of multiple VPN gateways. VPN gateways on the cloud server can be quickly copied, expanded, and deleted, no longer limited by hardware resources. The unified identity authentication system of the cloud server ensures that VPN gateways can only access authorized certificates. The certificate management system hosts encryption certificates, signing certificates, and their corresponding key pairs, guaranteeing legitimate and secure access to these certificates by the VPN gateways. During VPN gateway negotiation, the signing key of the VPN gateway's signing certificate and the encryption key of the encryption certificate are not stored on the VPN gateway's disk but are managed by the certificate management system on the cloud server, ensuring certificate security. Furthermore, the certificate management system can periodically check the validity of client certificates and control VPN gateway access based on certificate validity, denying access to VPN gateways after certificate expiration.

[0080] In addition to the gateway negotiation system described in the foregoing embodiments, this application also provides a gateway negotiation method, which will be described exemplarily below.

[0081] Figure 3a A flowchart illustrating a gateway negotiation method provided in an exemplary embodiment of this application is shown. When executed on the client side, the method mainly includes:

[0082] Step 301a: Send a gateway allocation request to the designated device so that the designated device can allocate a VPN gateway to the client.

[0083] Step 302a: Send the key ID of the key required for gateway negotiation corresponding to the client to the VPN gateway, so that the VPN gateway can access the key required for gateway negotiation based on the key ID when negotiating with the peer VPN gateway; wherein, the key required for gateway negotiation is managed by the designated device.

[0084] Further optionally, the designated device includes: a cloud server; before sending a gateway allocation request to the designated device, the method further includes: obtaining the certificate and key required for gateway negotiation; sending the certificate and key to a certificate management component on the cloud server for management; receiving the certificate ID of the certificate and the key ID of the key returned by the certificate management component; one method of sending the gateway allocation request to the designated device includes: sending a gateway allocation request to an identity authentication component on the cloud server according to the certificate ID, so that the identity authentication component allocates a VPN gateway adapted to the certificate ID for the client.

[0085] Further optionally, the certificate includes: a signing certificate and an encryption certificate; the certificate ID includes: the ID of the signing certificate and the ID of the encryption certificate; the key includes: a signing key and an encryption key; the key ID includes: the ID of the signing key and the ID of the encryption key.

[0086] Optionally, one method for obtaining the certificate and key required for gateway negotiation includes: sending a key management request to the certificate management component; receiving a certificate request file returned by the certificate management component based on the key management request; sending a certificate request to a certificate authority based on the certificate request file; and receiving a signature certificate, a signature key, an encryption certificate, and an encryption key encrypted using the signature public key issued by the certificate authority.

[0087] In this embodiment, the key required by the client for gateway negotiation is managed by a designated device. After requesting the allocation of a VPN gateway from the designated device, the client can send the key ID of the key required for gateway negotiation to the VPN gateway. When the VPN gateway needs to use the key during gateway negotiation, it can access the key managed by the designated device based on the key ID. In this implementation, the VPN gateway is allocated by the designated device, and the key required for VPN gateway negotiation is managed by the designated device. On the one hand, horizontal scaling of the VPN gateway can be achieved based on the virtual resources provided by the designated device. On the other hand, the security of the key can be ensured by the designated device's management of the key, ensuring that the VPN gateway negotiation operation meets the specified security requirements, and reducing the dependence of the VPN gateway negotiation operation on hardware devices.

[0088] Figure 3b This is a flowchart illustrating a gateway negotiation method provided in an exemplary embodiment of this application. In some embodiments, the designated device for allocating the VPN gateway is implemented as a cloud server, which includes a certificate management component and an identity authentication component. When executed on the client side, the method mainly includes:

[0089] Step 301b: Obtain the certificate and key required for gateway negotiation.

[0090] Step 302b: Send the certificate and key to the certificate management component on the cloud server for management.

[0091] Step 303b: Receive the certificate ID of the certificate and the key ID of the key returned by the certificate management component.

[0092] Step 304b: Send a gateway allocation request to the identity authentication component on the cloud server according to the certificate ID, so that the identity authentication component allocates a VPN gateway that matches the certificate ID to the client.

[0093] Step 305: Send the key ID to the VPN gateway so that the VPN gateway can access the key managed by the certificate management component based on the key ID when negotiating with the peer VPN gateway.

[0094] In this embodiment, the certificate and key required for gateway negotiation obtained by the client are managed by the certificate management component of the cloud server, and the certificate management component can return a certificate ID and a key ID to the client. The client can request the allocation of a VPN gateway from the identity authentication component on the cloud server based on the certificate ID, and send the key ID to the VPN gateway. When the VPN gateway needs to use the key during gateway negotiation, it can access the key managed by the certificate management component based on the key ID. In this implementation, the VPN gateway is deployed on a cloud server, and the key required for VPN gateway negotiation is managed by the certificate management component on the cloud server. On the one hand, horizontal scaling of the VPN gateway can be achieved based on the virtual resources provided by the cloud server; on the other hand, the certificate management component ensures the security of the key, ensuring that the VPN gateway negotiation operation meets the specified security requirements, and reducing the dependence of the VPN gateway negotiation operation on hardware devices.

[0095] Figure 4 A flowchart illustrating a gateway negotiation method provided in another exemplary embodiment of this application, which, when executed on a designated device side for allocating a VPN gateway, mainly includes:

[0096] Step 401: Respond to the gateway allocation request sent by the client and allocate a VPN gateway to the client.

[0097] Step 402: Receive the message processing request sent by the VPN gateway based on the negotiation message to be processed and the key ID.

[0098] Step 403: Process the negotiation message to be processed according to the key corresponding to the key ID, and return the processed negotiation message to the VPN gateway.

[0099] Further optionally, before allocating a VPN gateway to the client, the method further includes: receiving a certificate and key required for gateway negotiation sent by the client; determining the certificate ID of the certificate and the key ID of the key; and returning the certificate ID and the key ID to the client so that the client sends the key ID to the VPN gateway that is compatible with the certificate ID.

[0100] Further optionally, one method for allocating a VPN gateway to the client may include: obtaining the client's certificate ID carried in the gateway allocation request; and allocating a VPN gateway to the client based on the client's certificate ID.

[0101] Further optionally, the method further includes: receiving a key management request sent by a client; generating a certificate request file corresponding to the client based on the key management request; and returning the certificate request file to the client so that the client can request an encryption certificate and encryption key from a certificate authority based on the certificate request file.

[0102] Further optionally, the certificate includes: a signing certificate and an encryption certificate; the certificate ID includes: the ID of the signing certificate and the ID of the encryption certificate.

[0103] Further optionally, the message processing request is a message signing request, and the key ID includes: the ID of the signing key; a method of processing the negotiation message to be processed according to the key corresponding to the key ID and returning the processed negotiation message to the VPN gateway includes: signing the negotiation message to be processed using the signing key corresponding to the signing key ID to obtain a signed message; returning the signed message to the VPN gateway so that the VPN gateway sends the signed message to the peer VPN gateway for negotiation.

[0104] Further optionally, the message processing request is a message decryption request, and the key ID of the key includes: the ID of the encryption key; a method of processing the negotiation message to be processed according to the key corresponding to the key ID and returning the processed negotiation message to the VPN gateway includes: decrypting the negotiation message to be processed according to the encryption key corresponding to the encryption key ID to obtain a decrypted message; and returning the decrypted message to the VPN gateway for negotiation.

[0105] In this embodiment, the key required by the client for gateway negotiation is managed by a designated device. After requesting the allocation of a VPN gateway from the designated device, the client can send the key ID of the key required for gateway negotiation to the VPN gateway. When the VPN gateway needs to use the key during gateway negotiation, it can access the key managed by the designated device based on the key ID. In this implementation, the VPN gateway is allocated by the designated device, and the key required for VPN gateway negotiation is managed by the designated device. On the one hand, horizontal scaling of the VPN gateway can be achieved based on the virtual resources provided by the designated device. On the other hand, the security of the key can be ensured by the designated device's management of the key, ensuring that the VPN gateway negotiation operation meets the specified security requirements, and reducing the dependence of the VPN gateway negotiation operation on hardware devices.

[0106] Figure 5a The flowchart illustrating a gateway negotiation method provided for another exemplary embodiment of this application illustrates that, when the designated device for allocating the VPN gateway is implemented as a cloud server, the cloud server may include a certificate management component. When this method is executed on the certificate management component side of the cloud server, it mainly includes:

[0107] Step 501a: Receive the certificate and key required for gateway negotiation sent by the client.

[0108] Step 502a: Determine the certificate ID of the certificate and the key ID of the key.

[0109] Step 503a: Return the certificate ID and the key ID to the client so that the client sends the key ID to the VPN gateway that is compatible with the certificate ID.

[0110] Step 504a: Receive the message processing request sent by the VPN gateway based on the negotiation message to be processed and the key ID.

[0111] Step 505a: Process the negotiation message to be processed according to the key corresponding to the key ID, and return the processed negotiation message to the VPN gateway.

[0112] In this embodiment, the certificate and key required for gateway negotiation are managed by the certificate management system of the cloud server, and the certificate management system can return the certificate ID and key ID to the client. The client can request the allocation of a VPN gateway from the identity authentication system on the cloud server based on the certificate ID, and send the key ID to the VPN gateway. When the VPN gateway needs to use a key during gateway negotiation, it can access the key managed by the certificate management system based on the key ID. In this implementation, the VPN gateway is deployed on the cloud server, and the key required for VPN gateway negotiation is managed by the certificate management system on the cloud server. On the one hand, horizontal scaling of the VPN gateway can be achieved based on the virtual resources provided by the cloud server; on the other hand, the certificate management system ensures the security of the key, ensuring that the VPN gateway negotiation operation meets the specified security requirements, and reducing the dependence of the VPN gateway negotiation operation on hardware devices.

[0113] Figure 5b This is a flowchart illustrating a gateway negotiation method provided as another exemplary embodiment of this application. When the designated device for allocating the VPN gateway is implemented as a cloud server, the cloud server may include an identity authentication component. When this method is executed on the identity authentication component side of the cloud server, it mainly includes:

[0114] Step 501b: Receive a gateway allocation request sent by the client, the gateway allocation request carrying the client's certificate ID.

[0115] Step 502b: Assign a VPN gateway to the client based on the client's certificate ID.

[0116] Step 503b: Return the identifier of the VPN gateway to the client.

[0117] Optionally, when using the "dual certificate authentication" mode for gateway negotiation, the client's certificate set may include an encryption certificate and a signing certificate. A certificate set can be assigned to multiple VPN gateways, each VPN gateway can load a set of certificates, and multiple virtual gateways can load the same set of certificates. Each VPN gateway can establish IPSec links with multiple peer VPN gateways that meet a specified security level. Different peer VPN gateways can use certificates issued by different certificate authorities, which will not be elaborated further.

[0118] In this embodiment, the VPN gateway is deployed on a cloud server. The identity authentication system can assign a VPN gateway to a client based on the client's certificate ID. Furthermore, the VPN gateway can be horizontally scaled based on the virtual resources provided by the cloud server, reducing the dependence on hardware devices.

[0119] Figure 6A flowchart illustrating a gateway negotiation method provided as another exemplary embodiment of this application, which, when executed on the VPN gateway side, mainly includes:

[0120] Step 601: Receive the key ID sent by the client; the key corresponding to the key ID is managed by the designated device.

[0121] Step 602: During the negotiation process with the peer VPN gateway, based on the negotiation message to be processed and the key ID, request the designated device to process the negotiation message to be processed according to the key corresponding to the key ID.

[0122] Further optionally, the key ID includes: the ID of the signing key; the designated device includes: a cloud server; correspondingly, a method of requesting the designated device to process the negotiation message to be processed according to the key ID based on the negotiation message to be processed and the key ID may include: when a negotiation message to be signed is determined, sending a message signing request to a certificate management component in the cloud server based on the negotiation message to be signed and the ID of the signing key; obtaining a signed message obtained by the certificate management component signing the negotiation message to be signed according to the signing key; and sending the signed message to the peer VPN gateway.

[0123] Further optionally, the key ID includes: the ID of the encryption key; the designated device includes: a cloud server; correspondingly, a method of requesting the designated device to process the negotiation message to be processed according to the key corresponding to the key ID, based on the negotiation message to be processed and the key ID of the key, may include: upon receiving the negotiation message to be decrypted sent by the peer VPN gateway, sending a message decryption request to the certificate management component in the cloud server according to the negotiation message to be decrypted and the ID of the encryption key; and receiving the negotiation message obtained by the certificate management system decrypting the negotiation message to be decrypted according to the encryption key.

[0124] In this embodiment, the certificate and key required for gateway negotiation are managed by the certificate management component of the designated device. When the VPN gateway needs to use the key during gateway negotiation, it can access the key managed by the certificate management component based on the key ID. In this implementation, the VPN gateway is deployed on the designated device, and the key required for VPN gateway negotiation is managed by the certificate management component on the designated device. On the one hand, horizontal scaling of the VPN gateway can be achieved based on the virtual resources provided by the designated device. On the other hand, the security of the key can be ensured by the certificate management component of the designated device, ensuring that the VPN gateway negotiation operation meets the specified security requirements, thus reducing the dependence of the VPN gateway negotiation operation on hardware devices.

[0125] It should be noted that the execution subject of each step of the method provided in the above embodiments can be the same device, or the method can be executed by different devices. For example, the execution subject of steps 401 to 404 can be device A; or the execution subject of steps 401 and 402 can be device A, and the execution subject of step 403 can be device B; and so on.

[0126] Furthermore, in some of the processes described in the above embodiments and accompanying drawings, multiple operations appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order they appear herein, or they may be executed in parallel. The operation numbers, such as 401, 402, etc., are merely used to distinguish different operations and do not represent any execution order. Additionally, these processes may include more or fewer operations, and these operations may be executed sequentially or in parallel. It should be noted that the descriptions such as "first" and "second" in this document are used to distinguish different messages, devices, modules, etc., and do not represent a sequential order, nor do they limit "first" and "second" to different types.

[0127] Figure 7 This illustration shows a structural diagram of a terminal device provided in an exemplary embodiment of this application. For example... Figure 7 As shown, the server includes: a memory 701, a processor 702, and a communication component 703.

[0128] Memory 701 is used to store computer programs and can be configured to store various other data to support operations on the server. Examples of this data include instructions for any application or method operating on the server, contact data, phone book data, messages, pictures, videos, etc.

[0129] The memory 701 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.

[0130] Processor 702, coupled to memory 701, is configured to execute a computer program in memory 701 for: sending a gateway allocation request to a designated device via communication component 703, so that the designated device allocates a VPN gateway to the client; sending a key ID of a key required for gateway negotiation corresponding to the client to the VPN gateway, so that the VPN gateway accesses the key required for gateway negotiation based on the key ID when negotiating with the peer VPN gateway; wherein the key required for gateway negotiation is managed by the designated device.

[0131] Further optionally, the designated device includes: a cloud server; before sending a gateway allocation request to the designated device through the communication component 703, the processor 702 is further configured to: obtain the certificate and key required for gateway negotiation; send the certificate and key to a certificate management component on the cloud server for management; receive the certificate ID of the certificate and the key ID of the key returned by the certificate management component; correspondingly, when sending the gateway allocation request to the designated device through the communication component 703, the processor 702 is specifically configured to: send a gateway allocation request to the identity authentication component on the cloud server according to the certificate ID, so that the identity authentication component allocates a VPN gateway adapted to the certificate ID for the client.

[0132] Further optionally, the certificate includes: a signing certificate and an encryption certificate; the certificate ID includes: the ID of the signing certificate and the ID of the encryption certificate; the key includes: a signing key and an encryption key; the key ID includes: the ID of the signing key and the ID of the encryption key.

[0133] Further optionally, when the processor 702 obtains the certificate and key required for gateway negotiation, it is specifically configured to: send a key management request to the certificate management component; receive a certificate request file returned by the certificate management component according to the key management request; send a certificate request to the certificate authority according to the certificate request file; and receive a signature certificate, a signature key, an encryption certificate, and an encryption key encrypted using the signature public key issued by the certificate authority.

[0134] Furthermore, such as Figure 7 As shown, the client also includes other components such as display component 704, audio component 705, and power component 706. Figure 7 The diagram only shows some components and does not mean that the server only includes... Figure 7 The components shown.

[0135] The display component 704 includes a screen, which may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touchscreen to receive input signals from a user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can sense not only the boundaries of the touch or swipe action but also the duration and pressure associated with the touch or swipe operation.

[0136] The audio component 705 can be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC) configured to receive external audio signals when the device containing the audio component is in an operating mode, such as call mode, recording mode, and voice recognition mode. The received audio signals can be further stored in memory or transmitted via a communication component. In some embodiments, the audio component also includes a speaker for outputting audio signals.

[0137] In this embodiment, the certificate and key required for gateway negotiation obtained by the client are managed by the certificate management system of the designated device, and the certificate management system can return the certificate ID and key ID to the client. The client can request the allocation of a VPN gateway from the identity authentication system on the designated device based on the certificate ID, and send the key ID to the VPN gateway. When the VPN gateway needs to use the key during gateway negotiation, it can access the key managed by the certificate management system based on the key ID. In this implementation, the VPN gateway is deployed on the designated device, and the key required for VPN gateway negotiation is managed by the certificate management system of the designated device. On the one hand, horizontal scaling of the VPN gateway can be achieved based on the virtual resources provided by the designated device; on the other hand, the security of the key can be ensured by the certificate management system of the designated device, ensuring that the VPN gateway negotiation operation meets the specified security requirements, and reducing the dependence of the VPN gateway negotiation operation on hardware devices.

[0138] Accordingly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed, can perform the steps that can be executed by a terminal device in the above method embodiments.

[0139] Accordingly, embodiments of this application also provide a computer program product, including a computer program / instructions, wherein when the computer program is executed by a processor, it causes the processor to implement the steps of a method that can be executed by a terminal device.

[0140] Figure 8 This illustration shows a structural diagram of a server provided in an exemplary embodiment of this application. For example... Figure 8 As shown, the server includes: a memory 801, a processor 802, and a communication component 803.

[0141] In some embodiments, the server may be implemented as a virtual server, cloud host, or cloud server (such as an Elastic Compute Service (ECS) instance on a cloud platform, etc., and this embodiment does not impose any restrictions.

[0142] Memory 801 is used to store computer programs and can be configured to store various other data to support operations on the server. Examples of this data include instructions for any application or method operating on the server, contact data, phone book data, messages, pictures, videos, etc.

[0143] The memory 801 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk or optical disk.

[0144] The processor 802, coupled to the memory 801, is configured to execute a computer program in the memory 801 for: responding to a gateway allocation request sent by a client, allocating a VPN gateway to the client; receiving, via the communication component 803, a message processing request sent by the VPN gateway based on a negotiation message to be processed and a key ID; processing the negotiation message to be processed according to the key corresponding to the key ID, and returning the processed negotiation message to the VPN gateway.

[0145] Further optionally, before allocating a VPN gateway to the client, the processor 802 is further configured to: receive, via the communication component 803, a certificate and key required for gateway negotiation sent by the client; determine the certificate ID of the certificate and the key ID of the key; and return the certificate ID and the key ID to the client so that the client sends the key ID to the VPN gateway adapted to the certificate ID.

[0146] Further optionally, when allocating a VPN gateway to the client, the processor 802 is specifically configured to: obtain the client's certificate ID carried in the gateway allocation request through the communication component 803; and allocate a VPN gateway to the client based on the client's certificate ID.

[0147] Further optionally, the processor 802 is also configured to: receive a key management request sent by a client; generate a certificate request file corresponding to the client based on the key management request; and return the certificate request file to the client so that the client can request an encryption certificate and encryption key from a certificate authority based on the certificate request file.

[0148] Further optionally, the certificate includes: a signing certificate and an encryption certificate; the certificate ID includes: the ID of the signing certificate and the ID of the encryption certificate.

[0149] Further optionally, the message processing request is a message signing request, and the key ID includes: the ID of the signing key; when the processor 802 processes the negotiation message to be processed according to the key corresponding to the key ID and returns the processed negotiation message to the VPN gateway, it is specifically used to: sign the negotiation message to be processed using the signing key corresponding to the ID of the signing key to obtain a signed message; and return the signed message to the VPN gateway so that the VPN gateway sends the signed message to the peer VPN gateway for negotiation.

[0150] Further optionally, the message processing request is a message decryption request, and the key ID of the key includes: the ID of the encryption key; when the processor 802 processes the negotiation message to be processed according to the key corresponding to the key ID and returns the processed negotiation message to the VPN gateway, it is specifically used to: decrypt the negotiation message to be processed according to the encryption key corresponding to the encryption key ID to obtain a decrypted message; and return the decrypted message to the VPN gateway for negotiation.

[0151] In some embodiments, Figure 8 The illustrated server is also used to implement a VPN gateway. When used to implement a VPN gateway, the processor 802 is configured with instructions or code to: receive a key ID sent by a client via the communication component 803; the key corresponding to the key ID is managed by the server; and during negotiation with the peer VPN gateway, request the server to process the negotiation message to be processed according to the key ID based on the negotiation message to be processed and the key ID.

[0152] Further optionally, the key ID includes: the ID of the signing key; when the processor 802 requests the server to process the negotiation message to be processed according to the key ID based on the negotiation message to be processed and the key ID, it is specifically configured to: when determining the negotiation message to be signed, send a message signing request to the certificate management component in the server based on the negotiation message to be signed and the ID of the signing key; obtain the signed message obtained by the certificate management component signing the negotiation message to be signed according to the signing key; and send the signed message to the peer VPN gateway.

[0153] Further optionally, the key ID includes: the ID of the encryption key; when the processor 802 requests the server to process the negotiation message to be processed according to the key ID based on the negotiation message to be processed and the key ID of the key, it is specifically configured to: upon receiving the negotiation message to be decrypted sent by the peer VPN gateway, send a message decryption request to the certificate management component in the server according to the negotiation message to be decrypted and the ID of the encryption key; and receive the negotiation message obtained by the certificate management component decrypting the negotiation message to be decrypted according to the encryption key.

[0154] Furthermore, such as Figure 8 As shown, the server also includes other components such as the power supply component 804. Figure 8 The diagram only shows some components and does not mean that the server only includes... Figure 8 The components shown.

[0155] In this embodiment, the certificate and key required for gateway negotiation are managed by the server's certificate management system. When the VPN gateway needs to use a key during gateway negotiation, it can access the key managed by the certificate management system based on the key ID. In this implementation, the VPN gateway is deployed on a server, and the key required for VPN gateway negotiation is managed by the certificate management system on the server. On the one hand, horizontal scaling of the VPN gateway can be achieved based on the virtual resources provided by the server. On the other hand, the server's certificate management system ensures the security of the key, ensuring that the VPN gateway negotiation operation meets the specified security requirements, thus reducing the dependence of the VPN gateway negotiation operation on hardware devices.

[0156] Accordingly, embodiments of this application also provide a computer-readable storage medium storing a computer program, which, when executed, can implement the steps that can be executed by the server in the above method embodiments.

[0157] Accordingly, embodiments of this application also provide a computer program product, including a computer program / instructions, wherein when the computer program is executed by a processor, it causes the processor to implement the steps in a method that can be executed by a server.

[0158] exist Figure 7 as well as Figure 8In this embodiment, the communication component is configured to facilitate wired or wireless communication between the device containing the communication component and other devices. The device containing the communication component can access wireless networks based on communication standards, such as WiFi, 2G, 3G, 4G, or 5G, or combinations thereof. In one exemplary embodiment, the communication component receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In one exemplary embodiment, the communication component may be implemented based on Near Field Communication (NFC), Radio Frequency Identification (RFID), Infrared Data Association (IrDA), Ultra Wideband (UWB), Bluetooth (BT), and other technologies.

[0159] exist Figure 7 as well as Figure 8 In this context, a power supply component provides power to various components within the device in which it resides. A power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the device in which it resides.

[0160] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0161] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0162] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0163] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0164] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0165] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0166] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0167] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0168] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A gateway negotiation method, characterized in that, include: A gateway allocation request is sent to the designated device based on the certificate ID required for gateway negotiation, so that the designated device can allocate a VPN gateway to the client. The gateway allocation request is used to: enable the designated device to allocate a VPN gateway to the client based on the client's certificate ID and the virtual resources and virtualization system on the designated device; The key ID of the key required for gateway negotiation corresponding to the client is sent to the VPN gateway, so that the VPN gateway can access the key required for gateway negotiation based on the key ID when negotiating with the peer VPN gateway; the certificate ID and the key ID are issued by the certificate management component on the designated device based on the certificate and key sent by the client; The key required for gateway negotiation is managed by the designated device. The virtual resources and virtualization system are used to enable the designated device to create VPN gateways and horizontally scale the number of VPN gateways, and to allocate corresponding VPN gateways to the client based on the number of VPN gateways rented or purchased by the client.

2. The method according to claim 1, characterized in that, The designated device includes: a cloud server; before sending the gateway allocation request to the designated device, it also includes: Obtain the certificate and key required for gateway negotiation; The certificate and key are sent to the certificate management component on the cloud server for management; Receive the certificate ID of the certificate and the key ID of the key returned by the certificate management component; Send a gateway allocation request to the specified device, including: Based on the certificate ID, a gateway allocation request is sent to the identity authentication component on the cloud server, so that the identity authentication component allocates a VPN gateway that matches the certificate ID to the client.

3. The method according to claim 2, characterized in that, The certificate includes: a signing certificate and an encryption certificate; the certificate ID includes: the ID of the signing certificate and the ID of the encryption certificate; The key includes a signature key and an encryption key; the key ID includes the ID of the signature key and the ID of the encryption key.

4. The method according to claim 2, characterized in that, Obtain the certificates and keys required for gateway negotiation, including: Send a key management request to the certificate management component; Receive the certificate request file returned by the certificate management component based on the key management request; According to the certificate request file, a certificate request is sent to the Certificate Authority. Receive the signature certificate, signature key, encryption certificate, and encryption key encrypted using the signature public key issued by the certificate authority.

5. A gateway negotiation method, characterized in that, include: In response to a gateway allocation request sent by a client based on the certificate ID required for gateway negotiation, a VPN gateway is allocated to the client, including: allocating a VPN gateway to the client based on the client's certificate and local virtual resources and virtualization system; the virtual resources and virtualization system is used to create VPN gateways and perform horizontal scaling of the number of VPN gateways, and allocates a corresponding VPN gateway to the client based on the number of VPN gateways rented or purchased by the client. Receives a message processing request sent by the VPN gateway based on the negotiation message to be processed and the key ID; the certificate ID and the key ID are issued by the local certificate management component based on the certificate and key sent by the client; The negotiation message to be processed is processed according to the key corresponding to the key ID managed locally, and the processed negotiation message is returned to the VPN gateway.

6. The method according to claim 5, characterized in that, Before assigning a VPN gateway to the client, the following steps are also included: Receive the certificate and key required for gateway negotiation sent by the client; Determine the certificate ID of the certificate and the key ID of the key; The certificate ID and the key ID are returned to the client so that the client can send the key ID to the VPN gateway that is compatible with the certificate ID.

7. The method according to claim 6, characterized in that, Assigning a VPN gateway to the client includes: Obtain the client's certificate ID carried in the gateway allocation request; Assign a VPN gateway to the client based on the client's certificate ID.

8. The method according to claim 6, characterized in that, Also includes: Receive key management requests sent by clients; Based on the key management request, generate the certificate request file corresponding to the client; The certificate request file is returned to the client, so that the client can request an encryption certificate and encryption key from the Certificate Authority based on the certificate request file.

9. The method according to claim 6, characterized in that, The certificate includes a signing certificate and an encryption certificate; the certificate ID includes the ID of the signing certificate and the ID of the encryption certificate.

10. The method according to claim 5, characterized in that, The message processing request is a message signing request, and the key ID includes: the ID of the signing key; The negotiation message to be processed is processed according to the key corresponding to the key ID, and the processed negotiation message is returned to the VPN gateway, including: The negotiation message to be processed is signed using the signature key corresponding to the ID of the signature key to obtain a signed message; The signed message is returned to the VPN gateway, so that the VPN gateway sends the signed message to the peer VPN gateway for negotiation.

11. The method according to claim 5, characterized in that, The message processing request is a message decryption request, and the key ID of the key includes: the ID of the encryption key; The negotiation message to be processed is processed according to the key corresponding to the key ID, and the processed negotiation message is returned to the VPN gateway, including: The negotiation message to be processed is decrypted according to the encryption key corresponding to the ID of the encryption key to obtain the decrypted message; The decrypted message is returned to the VPN gateway for negotiation.

12. A gateway negotiation method, applicable to VPN gateways, characterized in that, include: Receive the key ID sent by the client; The key corresponding to the key ID is managed by a designated device; the designated device is used to: allocate the VPN gateway to the client based on the client's certificate ID and the virtual resources and virtualization system on the designated device; the virtual resources and virtualization system is used to enable the designated device to create VPN gateways and horizontally expand the number of VPN gateways, and allocate corresponding VPN gateways to the client based on the number of VPN gateways rented or purchased by the client. During the negotiation process with the peer VPN gateway, based on the negotiation message to be processed and the key ID, a request is sent to the designated device to process the negotiation message to be processed according to the key corresponding to the key ID; The certificate ID and the key ID are issued by the certificate management component on the designated device based on the certificate and key sent by the client.

13. The method according to claim 12, characterized in that, The key ID includes: the ID of the signing key; the designated device includes: a cloud server; Based on the negotiation message to be processed and the key ID, request the designated device to process the negotiation message to be processed according to the key corresponding to the key ID, including: When a negotiation message to be signed is determined, a message signing request is sent to the certificate management component in the cloud server based on the negotiation message to be signed and the ID of the signing key. Obtain the signed message obtained by the certificate management component signing the negotiation message to be signed according to the signing key; The signed message is sent to the peer VPN gateway.

14. The method according to claim 12, characterized in that, The key ID includes: the ID of the encryption key; the designated device includes: a cloud server; Based on the negotiation message to be processed and the key ID of the key, request the designated device to process the negotiation message to be processed according to the key corresponding to the key ID, including: Upon receiving a negotiation message to be decrypted from the peer VPN gateway, a message decryption request is sent to the certificate management component in the cloud server based on the negotiation message to be decrypted and the ID of the encryption key. The certificate management component receives the negotiation message obtained by decrypting the negotiation message to be decrypted using the encryption key.

15. A terminal device, characterized in that, include: Memory, processor, and communication components; The memory is used to store one or more computer instructions; The processor is configured to execute one or more computer instructions for: performing the steps of the method according to any one of claims 1-4 via the communication component.

16. A server, characterized in that, include: Memory, processor, and communication components; The memory is used to store one or more computer instructions; The processor is configured to execute one or more computer instructions for: performing the steps of the method according to any one of claims 5-14 via the communication component.

17. A computer-readable storage medium storing a computer program, characterized in that, When a computer program is executed by a processor, it is able to perform the steps of the method described in any one of claims 1-4 or 5-14.

18. A computer program product comprising a computer program / instructions, characterized in that, When a computer program is executed by a processor, it causes the processor to perform the steps of the method described in any one of claims 1-4 or 5-14.

Citation Information

Patent Citations

  • Access method of Virtual Private Network and Virtual Private Network client

    CN102984045A

  • Method and system for extended use of quantum keys in IPSec VPN (internet protocol security-virtual private network)

    CN104660603A