Data packet forwarding method and apparatus, virtual gateway device, medium and system
By converting data packets into multiple TCP sub-message streams in the kernel space of the virtual gateway and performing multi-link aggregation forwarding through multiple TCP tunnels, the problem of the single data packet forwarding method in the existing technology is solved, and efficient and reliable data packet forwarding and network bandwidth improvement are achieved.
Patent Information
- Application Number
- CN202211282335.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-18
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2042-10-18
AI Technical Summary
In existing technologies, the WireGuard component can only convert data packets into UDP packets for kernel space forwarding, which limits its application scenarios and cannot meet the needs for personalized and convenient data packet forwarding.
In the kernel space of the virtual gateway, data packets are converted into multiple TCP sub-packet streams, and multi-link aggregation forwarding is performed through multiple TCP tunnels, leveraging the reliability of TCP tunnels to achieve multi-path aggregation forwarding.
It improves the efficiency and reliability of packet forwarding, enhances network bandwidth, and achieves load balancing.
Smart Images

Figure CN115633037B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a data packet forwarding method, apparatus, virtual gateway device, medium, and system. Background Technology
[0002] In order to avoid data packets being transmitted multiple times between the kernel space and user space of the virtual gateway during data transmission, the existing technology has proposed a WireGuard component. By embedding the WireGuard component in the Linux operating system of the virtual network card, it is possible to forward data packets only through the kernel space of the virtual gateway.
[0003] In the process of developing the invention, the inventors discovered the following shortcomings in the existing technology: The WireGuard component can convert data packets into UDP (User Datagram Protocol) messages for forwarding in kernel space, but the implementation method is singular and the application scenarios are limited, which cannot meet people's growing demand for personalized and convenient data packet forwarding. Summary of the Invention
[0004] This invention provides a data packet forwarding method, apparatus, virtual gateway device, medium, and system, which can convert data packets into multiple TCP (Transmission Control Protocol) sub-message streams in the kernel space of the virtual gateway for multi-link aggregation and forwarding.
[0005] According to one aspect of the present invention, a data packet forwarding method is provided, the method being performed by a virtual gateway device, comprising:
[0006] Receive raw data packets sent by internal network devices through the downlink port;
[0007] In kernel space, the raw data packet is converted into a target UDP packet, and the target UDP packet is sent to the Transmission Control Protocol TCP tunnel in kernel space;
[0008] Convert the target UDP packet within the TCP tunnel into a target TCP packet, where the peer address of the TCP tunnel is the set aggregation server;
[0009] The target TCP packet within the TCP tunnel is converted into multiple TCP sub-packet streams, and these multiple TCP sub-packet streams are forwarded to the aggregation server via multiple uplink ports through multiple sub-channels within the TCP tunnel.
[0010] According to another aspect of the present invention, a data packet forwarding apparatus is provided, executed by a virtual gateway device, comprising:
[0011] The raw data packet receiving module is used to receive raw data packets sent by intranet devices through the downlink port;
[0012] The first message conversion module is used to convert the raw data packets into target UDP packets in the kernel space and send the target UDP packets to the TCP tunnel in the kernel space.
[0013] The second message conversion module is used to convert target UDP packets within the TCP tunnel into target TCP packets, wherein the peer address of the TCP tunnel is the set aggregation server;
[0014] The packet forwarding module is used to convert the target TCP packet in the TCP tunnel into multiple TCP sub-packet streams, and forward the multiple TCP sub-packet streams to the aggregation server through multiple uplink ports via multiple sub-channels in the TCP tunnel.
[0015] According to another aspect of the present invention, a virtual gateway device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the data packet forwarding method described in any embodiment of the present invention.
[0016] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing a computer program configured to cause a processor to execute and implement the data packet forwarding method according to any embodiment of the present invention.
[0017] According to another aspect of the present invention, a data transmission system is provided, comprising: an intranet device, a virtual gateway device, a wide area network, an aggregation server gateway, and an aggregation server; the intranet device is connected to the virtual gateway device, the aggregation server gateway is connected to the aggregation server, and the virtual gateway device and the aggregation server are respectively connected to the wide area network.
[0018] The virtual gateway device is connected to the intranet device through a downlink port and accesses the wide area network through multiple uplink ports.
[0019] The intranet device is used to send raw data packets to the virtual gateway device;
[0020] The virtual gateway device is used to execute the data packet forwarding method described in any embodiment of the present invention;
[0021] The aggregation server gateway is used to receive multiple TCP sub-message streams corresponding to the original data packets sent by the virtual gateway device through the wide area network, and merge the multiple TCP sub-message streams into a single TCP packet and send it to the aggregation server;
[0022] The aggregation server is used to generate a response message that matches the TCP packet and send the response message back to the intranet device.
[0023] The technical solution of this invention converts the original data packet into a target UDP packet in the kernel space and sends it to the TCP tunnel in the kernel space. The target UDP packet in the TCP tunnel is then converted multiple times to generate multiple TCP sub-packet streams and forwarded to the aggregation server. This achieves multi-path aggregation and forwarding of data packets in the kernel space of the virtual gateway device, improving the forwarding efficiency and reliability of data packets. At the same time, it effectively increases network bandwidth and achieves load balancing.
[0024] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0026] Figure 1 This is a flowchart of a data packet forwarding method provided according to Embodiment 1 of the present invention;
[0027] Figure 2 This is a flowchart of another data packet forwarding method provided according to Embodiment 2 of the present invention;
[0028] Figure 3 This is a schematic diagram of the structure of a data packet forwarding device according to Embodiment 3 of the present invention;
[0029] Figure 4 This is a schematic diagram of a data transmission system according to Embodiment 4 of the present invention;
[0030] Figure 5 This is a schematic diagram of the structure of an electronic device that implements the data packet forwarding method of this invention. Detailed Implementation
[0031] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0032] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0033] Example 1
[0034] Figure 1 This is a flowchart of a data packet forwarding method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where data packets are transformed multiple times to generate multiple TCP sub-message streams in the kernel space of a virtual gateway device, and the multiple TCP sub-message streams are forwarded to an aggregation server via multiple uplink ports. This method can be executed by a data packet forwarding device, which can be implemented in hardware and / or software. The data packet forwarding device can be configured in a virtual gateway device with data processing capabilities.
[0035] Understandably, a virtual gateway can be used to forward raw data packets sent by internal network devices to external network servers. To address the problem that existing gateway devices cannot perform multi-path aggregation and forwarding of data packets in kernel space, this invention proposes a method that transforms raw data packets multiple times in kernel space to generate multiple TCP sub-message streams, and then forwards these TCP sub-message streams to an aggregation server via multiple uplink ports, thereby achieving multi-path aggregation and forwarding of data packets in kernel space.
[0036] like Figure 1 As shown, the method includes:
[0037] S110: Receive raw data packets sent by intranet devices through the downlink port.
[0038] The virtual gateway device may include at least one downlink port. The virtual gateway device can connect to the internal network device through the downlink port, and the internal network device can send raw data packets to the virtual gateway device through the downlink port.
[0039] S120. In kernel space, the original data packet is converted into a target UDP packet, and the target UDP packet is sent to the TCP tunnel in kernel space.
[0040] To improve packet forwarding efficiency and avoid multiple transmissions of packets between kernel space and user space, a WireGuard component is provided in the prior art. The WireGuard component can convert raw packets into UDP packets and forward them through a UDP tunnel.
[0041] However, this invention also considers that if multi-path aggregation is used for forwarding during the forwarding process, it can effectively improve the network bandwidth of data transmission and achieve load balancing, thereby further improving the performance and efficiency of data transmission. Therefore, based on the existing technology, this invention proposes a method for multi-path aggregation and forwarding of data packets through kernel space.
[0042] If multi-path aggregation is used for forwarding, packets need to be forwarded to the same aggregation server through multiple ports, where they are further merged. Since UDP is a datagram-oriented protocol with no packet overhead, UDP packets cannot be converted into multiple sub-packet streams for multi-link aggregation and forwarding by the aggregation server. However, TCP provides reliable byte stream services; for ease of transmission, it divides large blocks of data into segments for management. Therefore, TCP packets can be converted into multiple TCP sub-packet streams, which are then merged and forwarded by the aggregation server. This invention creatively proposes replacing the standard UDP tunnel in the instantiated WireGuard component with a TCP tunnel and adding a component in the kernel space capable of converting UDP packets into TCP packets. This allows UDP packets generated by the WireGuard component to be transmitted through a TCP tunnel and further converted into TCP packets.
[0043] Preferably, a WireGuard component management module can be built into the user space. The WireGuard component management module can be used to instantiate the WireGuard component in the kernel space and replace the standard UDP tunnel in the instantiated WireGuard component with a TCP tunnel.
[0044] Furthermore, after converting the raw data packets into target UDP packets, the WireGuard component can send the UDP packets to the TCP tunnel.
[0045] S130. Convert the target UDP packet within the TCP tunnel into a target TCP packet.
[0046] The peer address of the TCP tunnel is the configured aggregation server.
[0047] Preferably, an RDS (Reliable Datagram Socket) management component can be built into the user space, and a matching RDS component can be built into the kernel space. The RDS management component can create TCP tunnels for the RDS component in the kernel space.
[0048] Furthermore, the RDS component can convert UDP packets generated by the WireGuard component into target TCP packets based on the RDS protocol within the TCP tunnel.
[0049] S140. Convert the target TCP packet in the TCP tunnel into multiple TCP sub-packet streams, and forward the multiple TCP sub-packet streams to the aggregation server through multiple uplink ports via multiple sub-channels in the TCP tunnel.
[0050] Preferably, a multi-channel TCP aggregation component can be built into the kernel space, and this component can be associated with multiple uplink ports in the virtual gateway device. After the target UDP packet in the TCP tunnel is converted into a target TCP packet, it can be converted into multiple TCP sub-packet streams through the multi-channel TCP aggregation component, and these sub-packet streams can be forwarded to the aggregation server via multiple uplink ports through multiple sub-channels in the TCP tunnel.
[0051] Preferably, an aggregation server gateway connected to the aggregation server can also be configured. The TCP sub-message stream can be forwarded to the aggregation server gateway via multiple uplink ports. The aggregation server gateway can merge multiple TCP sub-message streams into a single TCP packet and send it to the aggregation server.
[0052] Furthermore, the multiple uplink ports configured in the virtual gateway device can be used to forward multiple TCP sub-message streams converted by the multi-TCP aggregation component to the aggregation server gateway.
[0053] Furthermore, after the aggregation server gateway merges multiple TCP sub-message streams into a single TCP packet and sends it to the aggregation server, the aggregation server can generate a response packet that matches the merged single TCP packet. The response packet can serve as feedback information to the internal network devices, and the aggregation server will send the response packet back to the internal network devices.
[0054] The technical solution of this invention converts the original data packet into a target UDP packet in the kernel space and sends it to the TCP tunnel in the kernel space. The target UDP packet in the TCP tunnel is then converted multiple times to generate multiple TCP sub-packet streams and forwarded to the aggregation server. This achieves multi-path aggregation and forwarding of data packets in the kernel space of the virtual gateway device, improving the forwarding efficiency and reliability of data packets. At the same time, it effectively increases network bandwidth and achieves load balancing.
[0055] Example 2
[0056] Figure 2 This is a flowchart of a data packet forwarding method provided in Embodiment 2 of the present invention. Based on the above embodiments, this embodiment further illustrates the data packet forwarding method proposed by the present invention. Figure 2 As shown, the method includes:
[0057] S210. Creates a TCP tunnel for the RDS component built into the kernel space through the RDS management component built into the user space.
[0058] S220. Instantiate the WireGuard component through the WireGuard component management module built into the user space, and replace the standard UDP tunnel in the instantiated WireGuard component with a TCP tunnel.
[0059] S230 receives raw data packets sent by internal network devices through the downlink port.
[0060] S240: Using the WireGuard component built into the kernel space, the raw data packet is converted into a target UDP packet in the kernel space, and the target UDP packet is sent to the TCP tunnel in the kernel space.
[0061] In this component, the standard UDP tunnel in the WireGuard component is pre-replaced with the TCP tunnel.
[0062] S250. Using the RDS component, the target UDP packets within the TCP tunnel are converted into target TCP packets based on the RDS protocol.
[0063] The purpose of this setup is to achieve multi-path aggregation and forwarding. Since the aggregation server can only merge sub-message streams under the TCP protocol, it is necessary to first convert the target UDP message into a TCP message, and then further convert the TCP message into a TCP sub-message stream and send it to the aggregation server.
[0064] S260. Convert the target TCP packet in the TCP tunnel into multiple TCP sub-packet streams, and forward the multiple TCP sub-packet streams to the aggregation server through multiple uplink ports via multiple sub-channels in the TCP tunnel.
[0065] Specifically, converting the target TCP packet within the TCP tunnel into multiple TCP sub-packet streams, and forwarding these multiple TCP sub-packet streams to the aggregation server via multiple uplink ports through multiple sub-channels within the TCP tunnel, may include:
[0066] By using a multi-path TCP aggregation component built into the kernel space, the target TCP packet in the TCP tunnel is converted into multiple TCP sub-packet streams, and the multiple TCP sub-packet streams are forwarded to multiple uplink ports through multiple sub-channels in the TCP tunnel.
[0067] Specifically, each sub-channel in the multi-channel TCP aggregation component is pre-associated with each uplink port in the virtual gateway device, and a gateway address corresponding to each uplink port is configured.
[0068] The technical solution of this invention replaces the standard UDP tunnel in the instantiated WireGuard component with a TCP tunnel and creates a TCP tunnel for the RDS component in the kernel space. This allows the UDP packets generated by the WireGuard component to be transformed multiple times in the TCP tunnel to generate multiple TCP sub-packet streams, thereby further realizing the aggregation and forwarding of TCP sub-packet streams. This achieves an efficient and fully kernel-based multi-path aggregation and forwarding method.
[0069] Example 3
[0070] Figure 3 This is a schematic diagram of a data packet forwarding device provided in Embodiment 3 of the present invention. Figure 3 As shown, the device includes: a raw data packet receiving module 310, a first message conversion module 320, a second message conversion module 330, and a message forwarding module 340.
[0071] The raw data packet receiving module 310 is used to receive raw data packets sent by intranet devices through the downlink port.
[0072] The first message conversion module 320 is used to convert the raw data packet into a target UDP message in the kernel space and send the target UDP message to the TCP tunnel in the kernel space.
[0073] The second message conversion module 330 is used to convert target UDP messages within the TCP tunnel into target TCP messages, wherein the peer address of the TCP tunnel is the set aggregation server.
[0074] The packet forwarding module 340 is used to convert the target TCP packet in the TCP tunnel into multiple TCP sub-packet streams, and forward the multiple TCP sub-packet streams to the aggregation server through multiple uplink ports via multiple sub-channels in the TCP tunnel.
[0075] The technical solution of this invention converts the original data packet into a target UDP packet in the kernel space and sends it to the TCP tunnel in the kernel space. The target UDP packet in the TCP tunnel is then converted multiple times to generate multiple TCP sub-packet streams and forwarded to the aggregation server. This achieves multi-path aggregation and forwarding of data packets in the kernel space of the virtual gateway device, improving the forwarding efficiency and reliability of data packets. At the same time, it effectively increases network bandwidth and achieves load balancing.
[0076] Based on the above embodiments, the first message conversion module 320 can be specifically used for:
[0077] The WireGuard component, built into the kernel space, converts the raw data packets into target UDP packets in the kernel space and sends the target UDP packets to the TCP tunnel in the kernel space.
[0078] In this component, the standard UDP tunnel in the WireGuard component is pre-replaced with the TCP tunnel.
[0079] Based on the above embodiments, it may further include: a TCP tunnel creation module, used to create the TCP tunnel for the RDS component built into the kernel space through the RDS management component built into the user space.
[0080] Based on the above embodiments, the second message conversion module 330 can be specifically used for:
[0081] The RDS component converts target UDP packets within the TCP tunnel into target TCP packets based on the RDS protocol.
[0082] Based on the above embodiments, it may further include: a UDP tunnel replacement module, used to instantiate a WireGuard component through a WireGuard component management module built into the user space, and replace the standard UDP tunnel in the instantiated WireGuard component with the TCP tunnel.
[0083] Based on the above embodiments, the message forwarding module 340 can be specifically used for:
[0084] The multi-path TCP aggregation component built into the kernel space converts the target TCP packet in the TCP tunnel into multiple TCP sub-packet streams, and forwards the multiple TCP sub-packet streams to multiple uplink ports through multiple sub-channels in the TCP tunnel;
[0085] Specifically, each sub-channel in the multi-channel TCP aggregation component is pre-associated with each uplink port in the virtual gateway device, and a gateway address corresponding to each uplink port is configured.
[0086] The data packet forwarding device provided in the embodiments of the present invention can execute the data packet forwarding method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0087] Example 4
[0088] Figure 4 This is a schematic diagram of a data transmission system provided in Embodiment 4 of the present invention, as shown below. Figure 4 As shown, the data transmission system includes: intranet device 410, virtual gateway device 420, wide area network 430, aggregation server gateway 440, and aggregation server 450.
[0089] Among them, the intranet device 410 is connected to the virtual gateway device 420, the aggregation server gateway 440 is connected to the aggregation server 450, and the virtual gateway device 430 and the aggregation server gateway 440 are respectively connected to the wide area network 430.
[0090] The virtual gateway device 420 is connected to the intranet device 410 through a downlink port and accesses the wide area network 430 through multiple uplink ports.
[0091] Optionally, the intranet device 410 can be used to send raw data packets to the virtual gateway device 420.
[0092] Optionally, the virtual gateway device 420 can be used to perform the packet forwarding method described in any embodiment of the present invention.
[0093] The virtual gateway device 420 may include a user space and a kernel space. The user space can be configured with the WireGuard component management module and the RDS management component; the kernel space can be configured with the WireGuard component, the RDS component, and the multi-TCP aggregation component.
[0094] Specifically, the WireGuard component management module can be used to instantiate the WireGuard component in the kernel space and replace the standard UDP tunnel in the instantiated WireGuard component with the TCP tunnel; the RDS management component can be used to create a TCP tunnel for the RDS component in the kernel space.
[0095] Furthermore, the WireGuard component can be used to convert raw data packets into target UDP packets and send the target UDP packets to the TCP tunnel; the RDS component can be used to convert target UDP packets within the TCP tunnel into target TCP packets based on the RDS protocol; and the multi-channel TCP aggregation component can be used to convert target TCP packets within the TCP tunnel into multiple TCP sub-packet streams and forward the multiple TCP sub-packet streams to multiple uplink ports through multiple sub-channels in the TCP tunnel.
[0096] Optionally, the aggregation server gateway 440 can be used to receive multiple TCP sub-message streams corresponding to the original data packets sent by the virtual gateway device 420 via the wide area network 430, and merge the multiple TCP sub-message streams into a single TCP packet and send it to the aggregation server 450.
[0097] Optionally, the aggregation server 450 can be used to generate a response message that matches the said TCP message and send the response message back to the intranet device 410.
[0098] The technical solution of this invention, by configuring intranet devices, virtual gateway devices, wide area networks, aggregation server gateways, and aggregation servers in the data transmission system, can send data packets from intranet devices to the aggregation server through multiple transmissions, which can effectively improve network bandwidth and ensure the reliability of data packet transmission.
[0099] Example 5
[0100] Figure 5 A schematic diagram of an electronic device 50 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0101] like Figure 5As shown, the electronic device 50 includes at least one processor 51 and a memory, such as a read-only memory (ROM) 52 and a random access memory (RAM) 53, communicatively connected to the at least one processor 51. The memory stores computer programs executable by the at least one processor. The processor 51 can perform various appropriate actions and processes based on the computer program stored in the ROM 52 or loaded into the RAM 53 from storage unit 58. The RAM 53 can also store various programs and data required for the operation of the electronic device 50. The processor 51, ROM 52, and RAM 53 are interconnected via a bus 54. An input / output (I / O) interface 55 is also connected to the bus 54.
[0102] Multiple components in electronic device 50 are connected to I / O interface 55, including: input unit 56, such as keyboard, mouse, etc.; output unit 57, such as various types of monitors, speakers, etc.; storage unit 58, such as disk, optical disk, etc.; and communication unit 59, such as gateway, modem, wireless transceiver, etc. Communication unit 59 allows electronic device 50 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0103] Processor 51 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 51 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 51 performs the various methods and processes described above, such as the packet forwarding method as described in the embodiments of the present invention. That is:
[0104] Receive raw data packets sent by internal network devices through the downlink port;
[0105] In kernel space, the raw data packet is converted into a target user datagram UDP packet, and the target UDP packet is sent to the Transmission Control Protocol TCP tunnel in kernel space;
[0106] Convert the target UDP packet within the TCP tunnel into a target TCP packet, where the peer address of the TCP tunnel is the set aggregation server;
[0107] The target TCP packet within the TCP tunnel is converted into multiple TCP sub-packet streams, and these multiple TCP sub-packet streams are forwarded to the aggregation server via multiple uplink ports through multiple sub-channels within the TCP tunnel.
[0108] In some embodiments, the packet forwarding method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 58. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 50 via ROM 52 and / or communication unit 59. When the computer program is loaded into RAM 53 and executed by processor 51, one or more steps of the packet forwarding method described above may be performed. Alternatively, in other embodiments, processor 51 may be configured to perform the packet forwarding method by any other suitable means (e.g., by means of firmware).
[0109] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0110] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0111] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0112] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0113] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0114] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0115] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0116] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A data packet forwarding method, executed by a virtual gateway device, characterized in that, include: Receive raw data packets sent by internal network devices through the downlink port; In kernel space, the raw data packet is converted into a target user datagram UDP packet, and the target UDP packet is sent to the Transmission Control Protocol TCP tunnel in kernel space; Convert the target UDP packet within the TCP tunnel into a target TCP packet, where the peer address of the TCP tunnel is the set aggregation server; The target TCP packet within the TCP tunnel is converted into multiple TCP sub-packet streams, and these multiple TCP sub-packet streams are forwarded to the aggregation server via multiple uplink ports through multiple sub-channels within the TCP tunnel. Before receiving raw data packets sent by intranet devices through the downlink port, the process also includes: The TCP tunnel is created for the RDS component built into the kernel space using the reliable datagram socket RDS management component built into user space; The target TCP packet within the TCP tunnel is converted into multiple TCP sub-packet streams, and these multiple TCP sub-packet streams are forwarded to the aggregation server via multiple uplink ports through multiple sub-channels within the TCP tunnel, including: The multi-path TCP aggregation component built into the kernel space converts the target TCP packet in the TCP tunnel into multiple TCP sub-packet streams, and forwards the multiple TCP sub-packet streams to multiple uplink ports through multiple sub-channels in the TCP tunnel; Specifically, each sub-channel in the multi-channel TCP aggregation component is pre-associated with each uplink port in the virtual gateway device, and a gateway address corresponding to each uplink port is configured.
2. The method according to claim 1, characterized in that, In kernel space, the raw data packets are converted into target UDP packets, and the target UDP packets are sent to the TCP tunnel in kernel space, including: The WireGuard security network component, built into the kernel space, converts the raw data packets into target UDP packets in the kernel space and sends the target UDP packets to the TCP tunnel in the kernel space. In this component, the standard UDP tunnel in the WireGuard component is pre-replaced with the TCP tunnel.
3. The method according to claim 1, characterized in that, Converting target UDP packets within the TCP tunnel into target TCP packets includes: The RDS component converts target UDP packets within the TCP tunnel into target TCP packets based on the RDS protocol.
4. The method according to claim 1, characterized in that, Before receiving raw data packets sent by the downlink device through the downlink port, the following is also included: The WireGuard component is instantiated using the WireGuard component management module built into user space, and the standard UDP tunnel in the instantiated WireGuard component is replaced with the TCP tunnel.
5. A data packet forwarding device, executed by a virtual gateway device, characterized in that, include: The raw data packet receiving module is used to receive raw data packets sent by intranet devices through the downlink port; The first message conversion module is used to convert the raw data packet into a target user datagram UDP message in the kernel space, and send the target UDP message to the Transmission Control Protocol TCP tunnel in the kernel space. The second message conversion module is used to convert target UDP packets within the TCP tunnel into target TCP packets, wherein the peer address of the TCP tunnel is the set aggregation server; The packet forwarding module is used to convert the target TCP packet in the TCP tunnel into multiple TCP sub-packet streams, and forward the multiple TCP sub-packet streams to the aggregation server through multiple uplink ports via multiple sub-channels in the TCP tunnel; The TCP tunnel creation module is used to create the TCP tunnel for the RDS component built into the kernel space through the RDS management component built into the user space; The message forwarding module is specifically used for: The multi-path TCP aggregation component built into the kernel space converts the target TCP packet in the TCP tunnel into multiple TCP sub-packet streams, and forwards the multiple TCP sub-packet streams to multiple uplink ports through multiple sub-channels in the TCP tunnel; Specifically, each sub-channel in the multi-channel TCP aggregation component is pre-associated with each uplink port in the virtual gateway device, and a gateway address corresponding to each uplink port is configured.
6. A virtual gateway device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the data packet forwarding method as described in any one of claims 1-4.
7. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the packet forwarding method as described in any one of claims 1-4.
8. A data transmission system, characterized in that, include: Intranet devices, virtual gateway devices, wide area networks, aggregation server gateways, and aggregation servers; The intranet device is connected to the virtual gateway device, the aggregation server gateway is connected to the aggregation server, and the virtual gateway device and the aggregation server gateway are respectively connected to the wide area network. The virtual gateway device is connected to the intranet device through a downlink port and accesses the wide area network through multiple uplink ports. The intranet device is used to send raw data packets to the virtual gateway device; The virtual gateway device is configured to perform the method as described in any one of claims 1-4; The aggregation server gateway is used to receive multiple TCP sub-message streams corresponding to the original data packets sent by the virtual gateway device through the wide area network, and merge the multiple TCP sub-message streams into a single TCP packet and send it to the aggregation server; The aggregation server is used to generate a response message that matches the TCP packet and send the response message back to the intranet device.