Message Processing Method, Device, Storage Medium, and Program Product

By pre-encrypting packets on the virtual switch of the cloud computing node and filling the packet information with the IPSec VPN gateway, the performance bottleneck problem of the IPSec VPN gateway in the cloud computing node is solved, and efficient message transmission is achieved.

CN115664773BActive Publication Date: 2025-07-18BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211289296.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-20
Publication Date
2025-07-18
Estimated Expiration
2042-10-20

AI Technical Summary

Technical Problem

In cloud computing nodes, due to the large number of virtual machines and large traffic, the IPSec VPN gateway is under too much pressure to process a large number of encrypted packets, resulting in performance bottlenecks.

Method used

The virtual switches through cloud computing nodes encrypt the packets according to the IPSec VPN gateway by sending IPSec SA information in advance, and the IPSec VPN gateway fills the encrypted packets with message information, encapsulating them into complete target packets, reducing the encryption processing burden of the IPSec VPN gateway.

Benefits of technology

It fully utilizes the computing power resources of each computing node, solves the performance bottleneck problem of IPSec VPN gateway in the case of too many virtual switches, and ensures the transmission of packets.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115664773B_ABST
    Figure CN115664773B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide a message processing method, device, storage medium, and program product. The virtual switch of the cloud computing node encrypts the data packet according to the security association information pre-sent by the virtual private network gateway and sends it to the virtual private network gateway. The virtual private network gateway fills the message information for the encrypted data packet, encapsulates it into a complete target message, and sends the target message to the target customer gateway. This fully utilizes the computing power resources of each computing node, enabling the virtual private network gateway to not need to perform encryption processing, solving the performance bottleneck problem of the virtual private network gateway in scenarios with too many virtual switches, and ensuring the transmission of messages.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the technical fields of computer and network communication technologies and cloud computing technologies, and in particular, to a method, device, storage medium, and program product for message processing. Background Art

[0002] A Virtual Private Network (VPN) is a private network established on a public network for encrypted communication. Encryption of data packets and conversion of the target addresses of data packets are performed using a VPN gateway, or tunneling technology is used to achieve remote access. VPNs can be implemented in various ways, such as through servers, hardware, and software. An IPsec VPN is a VPN technology that uses IPsec (Internet Protocol Security) to achieve remote access.

[0003] When implementing an IPsec VPN in the cloud, a computing node is connected to an IPsec VPN gateway through a virtual switch. Data packets transmitted externally by each virtual machine (VM) in the computing node are sent by the virtual switch to the IPsec VPN gateway, which encrypts the data packets to generate messages and then sends them to the target gateway.

[0004] In the prior art, in a cloud scenario, the number of virtual machines in a computing node is large, the traffic is high, and the distribution is scattered, which increases the pressure on the IPsec VPN gateway when processing a large number of encrypted messages and requires high performance. Summary of the Invention

[0005] Embodiments of the present disclosure provide a method, device, storage medium, and program product for message processing to reduce the pressure on the IPsec VPN gateway and avoid performance bottleneck problems of the IPsec VPN gateway.

[0006] In a first aspect, embodiments of the present disclosure provide a method for message processing, the method including:

[0007] Receiving an encrypted data packet sent by a virtual switch of a cloud computing node, where the encrypted data packet is encrypted by the virtual switch according to security association information of the Internet Security Protocol; the security association information is pre-sent to the virtual switch;

[0008] Filling message information into the encrypted data packet and encapsulating it into a complete target message;

[0009] Sending the target message to a target customer gateway.

[0010] In a second aspect, embodiments of the present disclosure provide a method for message processing, the method including:

[0011] Receive the data packet to be sent sent by the virtual machine of the cloud computing node;

[0012] According to the encryption policy in the security association information of the Internet security protocol, determine whether the data packet to be sent needs to be encrypted. If it is determined that encryption is required, encrypt the data packet to be sent according to the key in the security association information to obtain an encrypted data packet; wherein, the security association information is pre-sent by the cloud based on the virtual private network gateway of the Internet security protocol;

[0013] Send the encrypted data packet to the virtual private network gateway, so that the virtual private network gateway fills the message information for the encrypted data packet, encapsulates it into a complete target message, and sends it to the target customer gateway.

[0014] In a third aspect, an embodiment of the present disclosure provides a message processing device, including:

[0015] A receiving unit, configured to receive an encrypted data packet sent by a virtual switch of a cloud computing node, where the encrypted data packet is encrypted by the virtual switch according to security association information of an Internet security protocol; the security association information is pre-sent to the virtual switch;

[0016] A processing unit, configured to fill message information for the encrypted data packet and encapsulate it into a complete target message;

[0017] A sending unit, configured to send the target message to a target customer gateway.

[0018] In a fourth aspect, an embodiment of the present disclosure provides a message processing device, including:

[0019] A receiving unit, configured to receive the data packet to be sent sent by the virtual machine of the cloud computing node;

[0020] A processing unit, configured to determine whether the data packet to be sent needs to be encrypted according to the encryption policy in the security association information of the Internet security protocol. If it is determined that encryption is required, encrypt the data packet to be sent according to the key in the security association information to obtain an encrypted data packet; wherein, the security association information is pre-sent by the cloud based on the virtual private network gateway of the Internet security protocol;

[0021] A sending unit, configured to send the encrypted data packet to the virtual private network gateway, so that the virtual private network gateway fills the message information for the encrypted data packet, encapsulates it into a complete target message, and sends it to the target customer gateway.

[0022] In a fifth aspect, an embodiment of the present disclosure provides an electronic device, including: at least one processor and a memory;

[0023] The memory stores computer-executable instructions;

[0024] The at least one processor executes the computer-executable instructions stored in the memory, so that the at least one processor executes the message processing method described in the first aspect above and various possible designs of the first aspect, or the message processing method described in the second aspect and various possible designs of the second aspect.

[0025] In a sixth aspect, an embodiment of the present disclosure provides a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the message processing method described in the first aspect above and various possible designs of the first aspect, or the message processing method described in the second aspect and various possible designs of the second aspect are implemented.

[0026] In a seventh aspect, an embodiment of the present disclosure provides a computer program product, including computer-executable instructions. When a processor executes the computer-executable instructions, the message processing method described in the first aspect above and various possible designs of the first aspect, or the message processing method described in the second aspect and various possible designs of the second aspect are implemented.

[0027] The message processing method, device, storage medium and program product provided by the embodiments of the present disclosure encrypt a data packet by a virtual switch of a cloud computing node according to security association information pre-sent by a virtual private network gateway, and send it to the virtual private network gateway. The virtual private network gateway fills message information in the encrypted data packet, encapsulates it into a complete target message, and sends the target message to a target customer gateway. The computing power resources of each computing node are fully utilized, so that the virtual private network gateway does not need to perform encryption processing, solving the performance bottleneck problem of the virtual private network gateway in the scenario of too many virtual switches and ensuring the transmission of messages. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present disclosure. For those of ordinary skill in the art, other drawings can be obtained according to these drawings without creative efforts.

[0029] Figure 1a It is a schematic diagram of an architecture for implementing IPsec VPN in the cloud in the prior art;

[0030] Figure 1b It is a schematic diagram of data encryption and encapsulation by an IPsec VPN gateway in the prior art;

[0031] Figure 2 Schematic diagram of the message processing method provided by an embodiment of the present disclosure;

[0032] Figure 3 Schematic diagram of the message processing method provided by another embodiment of the present disclosure;

[0033] Figure 4 Schematic diagram of the message processing method provided by another embodiment of the present disclosure;

[0034] Figure 5 Signaling diagram of the message processing method provided by an embodiment of the present disclosure;

[0035] Figure 6 Block diagram of the structure of the message processing device provided by an embodiment of the present disclosure;

[0036] Figure 7 Block diagram of the structure of the message processing device provided by another embodiment of the present disclosure;

[0037] Figure 8 Schematic diagram of the hardware structure of the electronic device provided by an embodiment of the present disclosure. Detailed implementation manners

[0038] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Apparently, the described embodiments are some but not all of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts shall fall within the scope of protection of the present disclosure.

[0039] A Virtual Private Network (VPN) is a private network established on a public network for encrypted communication. Encryption of data packets and conversion of the target addresses of data packets are performed using a VPN gateway, or remote access is achieved using tunneling technology. A VPN can be implemented in various ways such as through servers, hardware, and software. An IPSec VPN is a VPN technology for remote access using IPSec (Internet Protocol Security). IPSec is a protocol packet that protects the network transport protocol family (a set of interrelated protocols) of the IP protocol by encrypting and authenticating IP protocol packets.

[0040] IPSec mainly consists of the following protocols:

[0041] 1. Authentication Header (AH) provides connectionless data integrity, message authentication, and protection against replay attacks for IP datagrams;

[0042] 2. Encapsulating Security Payload (ESP) provides confidentiality, data source authentication, connectionless integrity, anti-replay, and limited traffic-flow confidentiality;

[0043] 3. Internet Key Exchange (abbreviated as IKE or IKEv2) provides algorithms, packets, and key parameters for the Security Association (SA) required for AH and ESP operations.

[0044] When implementing an IPsec VPN in the cloud, the architecture is as Figure 1a shown. Each computing node (such as computing node 1, computing node 2) may include a virtual switch and virtual machines (VMs) of multiple Virtual Private Clouds (VPCs). Each VPC (such as VPC1, VPC2) can be isolated from each other. The virtual machines of each VPC are connected to the virtual switch, and the virtual switch is connected to the IPsec VPN gateway on the cloud.

[0045] Packets transmitted by any virtual machine (VM) in the computing node to the outside are sent by the virtual switch to the IPsec VPN gateway. The IPsec VPN gateway encrypts and encapsulates the packets into messages according to the IPsec SA information negotiated with the target customer gateway, and then sends them to the target customer gateway (which is also an IPsec VPN gateway).

[0046] IPsec VPN on the cloud usually uses the ESP protocol and the tunnel mode. The IPsec VPN gateway encrypts and encapsulates the packets as Figure 1b shown. The unencrypted message is on the left side, and the ESP-encrypted message is on the right side. That is, the IPsec VPN gateway encrypts the packets (the gray part), and adds ESP header information (especially the ESP Sequence Number) and tail information.

[0047] In the existing technology in the cloud scenario, due to the large number of virtual machines, high traffic, and scattered distribution within the VPC in the computing node, the pressure on the IPsec VPN gateway to process a large number of encrypted messages increases, and higher performance requirements are imposed.

[0048] To solve the above technical problems, the present disclosure provides a message processing method. The virtual switch of the cloud computing node encrypts the data packet according to the IPSec SA information pre-sent by the IPSec VPN gateway and sends it to the IPSec VPN gateway. The IPSec VPN gateway fills the message information into the encrypted data packet, encapsulates it into a complete target message, and sends the target message to the target customer gateway. The computing power resources of each computing node are fully utilized, so that the IPSec VPN gateway does not need to perform encryption processing, solving the performance bottleneck problem of the IPSec VPN gateway in the scenario of too many virtual switches and ensuring the transmission of messages.

[0049] The message processing method of the present disclosure will be introduced in detail below in combination with specific embodiments.

[0050] Reference Figure 2 , Figure 2 is a schematic flowchart of the message processing method provided by an embodiment of the present disclosure. The method of this embodiment can be applied to an Internet Protocol Security (IPSec) Virtual Private Network (VPN) gateway based on the cloud. The message processing method includes:

[0051] S201. Receive the encrypted data packet sent by the virtual switch of the cloud computing node, where the encrypted data packet is encrypted by the virtual switch according to the IPSec SA information; the IPSec SA information is pre-sent by the IPSec VPN gateway to the virtual switch.

[0052] In this embodiment, the IPSec VPN gateway negotiates with the target customer gateway (also a VPN gateway) in advance to determine the IPSec SA information. Specifically, the IPSec SA information can be determined through the Internet Key Exchange (IKE or IKEv2) of IPSec, including encryption policies, keys, etc. The encryption policy is used to determine which data needs to be encrypted according to the IPSec SA information. For example, the data of 192.168.1.0 / 24 → 172.16.1.0 / 24 needs to be encrypted with the key K1. Further, the IPSec VPN gateway can send the IPSec SA information to the virtual switch of the cloud computing node connected to the IPSec VPN gateway. Optionally, to ensure information security, an encrypted connection can be established with the virtual switch first, such as an SSH (Secure Shell) connection, and the IPSec SA information is sent to the virtual switch through the encrypted connection.

[0053] When the virtual switch needs to send a data packet to the target customer gateway, it can check according to the encryption policy in the IPSec SA information to determine whether the data packet to be sent needs to be encrypted. If it is determined that encryption is required, the data packet to be sent is encrypted according to the key in the IPSec SA information to obtain an encrypted data packet. Specifically, ESP encryption is performed on the data packet to be sent according to the key in the IPSec SA information. Further, the virtual switch sends the encrypted data packet to the IPSec VPN gateway. In this way, after receiving the encrypted data packet that has been encrypted according to the IPSec SA information, the IPSec VPN gateway does not need to execute the encryption process according to the IPSec SA information, that is, it can skip the encryption process.

[0054] Among them, optionally, not all data packets conform to the encryption policy in the IPSec SA information. Therefore, the data packet received by the IPSec VPN gateway may be an encrypted data packet that has been encrypted according to the IPSec SA information, or it may be an unencrypted data packet. For the convenience of distinction, the virtual switch can add an identifier to the encrypted data packet that has been encrypted according to the IPSec SA information to indicate that the data packet has been encrypted according to the IPSec SA information. After receiving the data packet, if the IPSec VPN gateway recognizes that the data packet carries an identifier, it can determine that the data packet has been encrypted according to the IPSec SA information and can skip the encryption process.

[0055] S202. Fill the encrypted data packet with message information and encapsulate it into a complete target message.

[0056] In this embodiment, the IPSec VPN gateway can fill in the remaining message information on the basis of the encrypted data packet that has been encrypted according to the IPSec SA information, including but not limited to message header information and tail information, and encapsulate the encrypted data packet into a complete target message.

[0057] Optionally, ESP header information (especially ESP sequence number) and tail information can be filled in the encrypted data packet, and tunnel encapsulation is performed using the VPN public network IP.

[0058] S203. Send the target message to the target customer gateway.

[0059] In this embodiment, after encapsulating the complete target message, the IPSec VPN gateway sends the target message to the target customer gateway, which completes the data transmission from the cloud computing node to the target customer gateway.

[0060] The packet processing method of this embodiment encrypts the data packet according to the IPSec SA information pre - sent by the IPSec VPN gateway through the virtual switch of the cloud computing node, and sends it to the IPSec VPN gateway. The IPSec VPN gateway fills the packet information for the encrypted data packet, encapsulates it into a complete target packet, and sends the target packet to the target customer gateway. It makes full use of the computing power resources of each computing node, so that the IPSec VPN gateway does not need to perform encryption processing, solves the performance bottleneck problem of the IPSec VPN gateway in the scenario of too many virtual switches, and ensures the transmission of packets.

[0061] Based on the above - mentioned embodiment, when an encrypted connection is established between the IPSec VPN gateway and the virtual switch, and the IPSec SA information is sent to the virtual switch through the encrypted connection, since there may be multiple cloud computing nodes connected to the IPSec VPN gateway, there may be multiple virtual switches of the cloud computing nodes connected to the IPSec VPN gateway. In this embodiment, the IPSec VPN gateway can send the IPSec SA information to all the virtual switches of the cloud computing nodes connected to the IPSec VPN gateway; or, it can also be sent only to the virtual switches of the cloud computing nodes that have the need to transmit data packets to the target customer gateway. Specifically, as Figure 3 shown, establishing an encrypted connection with the virtual switch and sending the IPSec SA information to the virtual switch through the encrypted connection may include:

[0062] S301. Receive the data packet to be encrypted sent by the virtual switch, encrypt the data packet to be encrypted according to the IPSec SA information and encapsulate it into a complete target packet, and send it to the target customer gateway.

[0063] In this embodiment, after the IPSec VPN gateway obtains the IPSec SA information, it can send the IPSec SA information to the virtual switch according to the transmission requirements. Therefore, the IPSec VPN gateway needs to first determine which virtual switches have the need to transmit data packets to the target customer gateway. In this embodiment, after the IPSec VPN gateway receives the data packet to be encrypted that needs to be sent to the target customer gateway sent by any virtual switch, it can first judge whether the data packet to be sent needs to be encrypted according to the encryption policy in the IPSec SA information. If it is determined that encryption is required, it is determined that the virtual switch has the need to transmit data packets to the target customer gateway. At this time, the IPSec VPN gateway can first assume the responsibility of encryption processing, encrypt the data packet to be encrypted according to the IPSec SA information, and encapsulate it into a complete target packet, and send it to the target customer gateway (see the above - mentioned embodiment).

[0064] Optionally, the virtual switch may perform VXLAN (Virtual Extensible Local Area Network) encapsulation on the data packet to be encrypted and then send it to the IPSec VPN gateway. After receiving the data packet to be encrypted, the IPSec VPN gateway first de-VXLAN-encapsulates it, then encrypts the data packet to be encrypted according to the IPSec SA information and encapsulates it into a complete target message, and sends it to the target customer gateway.

[0065] S302. Query the virtual switch information based on the data packet to be encrypted.

[0066] In this embodiment, the virtual switch information may include the computing node information where the virtual switch is located. The IPSec VPN gateway may query the VPC controller for the computing node information where the virtual switch that sends the data packet to be encrypted is located, and the VPC controller stores the information of each computing node and the virtual switches it includes.

[0067] S303. Establish an encrypted connection with the virtual switch according to the virtual switch information, and send the IPSec SA information to the virtual switch through the encrypted connection.

[0068] In this embodiment, the IPSec VPN gateway may establish an encrypted connection with the virtual switch according to the virtual switch information, send the IPSec SA information to the virtual switch through the encrypted connection, and then the virtual switch will be responsible for the encryption processing according to the IPSec SA information. The IPSec VPN gateway only needs to fill in the message information and encapsulate it into a complete target message, reducing the pressure on the IPSec VPN gateway.

[0069] Based on any of the above embodiments, after encryption, the virtual switch may encapsulate the encrypted data packet. Optionally, it may perform VXLAN encapsulation, query the VPC routing table and then send it to the IPSec VPN gateway. After receiving the encrypted data packet, the IPSec VPN gateway first de-VXLAN-encapsulates it and then fills in the message information for the encrypted data packet. In addition, in the above embodiments, the virtual switch adds an identifier to the encrypted data packet, and the identifier may be added in the VXLAN encapsulation format.

[0070] Based on any of the above embodiments, according to a mechanism of the IPSec protocol, after encrypting a certain amount of data (preset encryption length threshold) using the IPSec SA information, the IPSec SA information will expire and become invalid. Since the IPSec SA information may be used by different virtual switches to encrypt data, and when the IPSec VPN gateway receives the encrypted data packet sent by the virtual switch, it cannot directly know from the encrypted data packet how much data length the virtual switch encrypted using the IPSec SA information. Therefore, in this embodiment, after encrypting the packet to be sent using the IPSec SA information, the virtual switch can add the length of the packet to be sent (i.e., the length of the encrypted data) to the encrypted data packet, and at the same time, it can also add the identification information of the IPSec SA information to the encrypted data packet (the preset encryption length thresholds of different IPSec SA information may be different, and the identification information of the IPSec SA information can be the IPSec SA information number or name, etc.). Then, after the IPSec VPN gateway receives the encrypted data packet sent by the virtual switch, it can accumulate the length of the encrypted data carried in the encrypted data packet encrypted using the IPSec SA information to obtain the cumulative length of the encrypted data, and compare the cumulative length of the encrypted data with the preset encryption length threshold corresponding to the IPSec SA information. If the cumulative length of the encrypted data exceeds the preset encryption length threshold, then at this time the IPSec SA information expires and becomes invalid, and the IPSec VPN gateway re-negotiates with the target customer gateway to determine the updated security association information.

[0071] Optionally, the length of the encrypted data carried in the encrypted data packet and the identification information of the security association information can also be added in the VXLAN encapsulation format.

[0072] Based on any of the above embodiments, according to another mechanism of the IPSec protocol, the IPSec SA information, especially the key therein, has a certain lifetime, and it will expire and become invalid after exceeding the lifetime. It is necessary for the IPSec VPN gateway to re-negotiate with the target customer gateway to determine and update the IPSec SA information. If the IPSec VPN gateway determines that the IPSec SA information needs to be updated, it will send the updated IPSec SA information to the virtual switch through an encrypted connection. In addition, the IPSec SA information can also be destroyed. For example, when the connection between the IPSec VPN gateway and the target customer gateway is disconnected, if the IPSec VPN gateway determines that the IPSec SA information is destroyed, it will send an instruction to delete the IPSec SA information to the virtual switch through an encrypted connection, so that the virtual switch deletes the stored IPSec SA information.

[0073] Refer to Figure 4 ,Figure 4 The figure is a schematic flowchart of a packet processing method provided by an embodiment of the present disclosure. The method of this embodiment can be applied to a virtual switch in a cloud computing node. The packet processing method includes:

[0074] S401. Receive a packet to be sent sent by a virtual machine of the cloud computing node.

[0075] In this embodiment, when a virtual machine in a certain VPC of a cloud computing node needs to send a packet to a target customer gateway, it will send the packet to be sent to the virtual switch of the cloud computing node.

[0076] S402. According to the encryption policy in the IPSec SA information, determine whether the packet to be sent needs to be encrypted. If it is determined that encryption is required, encrypt the packet to be sent according to the key in the IPSec SA information to obtain an encrypted packet; wherein, the IPSec SA information is pre-sent by the IPSec VPN gateway to the virtual switch.

[0077] In this embodiment, the IPSec VPN gateway negotiates with the target customer gateway in advance to determine the IPSec SA information, and sends the IPSec SA information to the virtual switch of the cloud computing node connected to the IPSec VPN gateway. Optionally, an encrypted connection can be established between the virtual switch and the IPSec VPN gateway, and the IPSec SA information sent by the VPN gateway is received through the encrypted connection.

[0078] When the virtual switch needs to send a packet to the target customer gateway, it can check according to the encryption policy in the IPSec SA information to determine whether the packet to be sent needs to be encrypted. If it is determined that encryption is required, encrypt the packet to be sent according to the key in the IPSec SA information to obtain an encrypted packet. Specifically, ESP encryption is performed on the packet to be sent according to the key in the IPSec SA information.

[0079] S403. Send the encrypted packet to the IPSec VPN gateway, so that the IPSec VPN gateway fills the packet information for the encrypted packet, encapsulates it into a complete target packet, and sends it to the target customer gateway.

[0080] In this embodiment, the virtual switch sends the encrypted packet to the IPSec VPN gateway. The IPSec VPN gateway can execute the method embodiment on the IPSec VPN gateway side as described above, which will not be elaborated here.

[0081] Based on the above embodiments, optionally, the virtual switch may add an identifier to the encrypted data packet that has been encrypted according to the IPSec SA information, which is used to indicate that the data packet has been encrypted according to the IPSec SA information. After receiving the data packet, if the IPSec VPN gateway recognizes that the data packet carries the identifier, it may determine that the data packet has been encrypted according to the IPSec SA information and skip the encryption process.

[0082] Based on any of the above embodiments, after encrypting the data packet to be sent using the IPSec SA information, the virtual switch may add the length of the data packet to be sent (i.e., the length of the data being encrypted) to the encrypted data packet. At the same time, the virtual switch may also add the identification information of the IPSec SA information (the identification information of the IPSec SA information may be the IPSec SA information number or name, etc.) to the encrypted data packet. So that after the IPSec VPN gateway receives the encrypted data packet sent by the virtual switch, it can accumulate the length of the encrypted data carried in the encrypted data packet encrypted using the IPSec SA information to obtain the cumulative length of the encrypted data, and compare the cumulative length of the encrypted data with the preset encryption length threshold corresponding to the IPSec SA information. If the cumulative length of the encrypted data exceeds the preset encryption length threshold, the IPSec SA information expires and becomes invalid at this time, and the IPSec VPN gateway re-negotiates with the target customer gateway to determine the updated security association information.

[0083] Optionally, after encryption, the virtual switch may encapsulate the encrypted data packet. Optionally, it may perform VXLAN encapsulation and then send it to the IPSec VPN gateway. After receiving the encrypted data packet, the IPSec VPN gateway first performs VXLAN decapsulation and then fills in the packet information for the encrypted data packet. In addition, in the above embodiments, when the virtual switch adds an identifier to the encrypted data packet, the identifier may be added in the VXLAN encapsulation format.

[0084] Optionally, the virtual switch may also update or delete the IPSec SA information. The specific process is as follows:

[0085] Receive the updated IPSec SA information sent by the IPSec VPN gateway through the encrypted connection and update the current IPSec SA information to the updated IPSec SA information; or

[0086] Receive the instruction sent by the IPSec VPN gateway to delete the IPSec SA information through the encrypted connection and delete the current IPSec SA information.

[0087] The packet processing method of this embodiment encrypts the data packet according to the IPSec SA information pre - sent by the IPSec VPN gateway through the virtual switch of the cloud computing node, and sends it to the IPSec VPN gateway. The IPSec VPN gateway fills the packet information for the encrypted data packet, encapsulates it into a complete target packet, and sends the target packet to the target customer gateway. It makes full use of the computing power resources of each computing node, so that the IPSec VPN gateway does not need to perform encryption processing, solves the performance bottleneck problem of the IPSec VPN gateway in the scenario of too many virtual switches, and ensures the transmission of packets.

[0088] Reference Figure 5 , Figure 5 is a signaling diagram of the packet processing method provided by an embodiment of the present disclosure. Based on the above embodiment, the packet processing method includes:

[0089] S501. The IPSec VPN gateway negotiates with the target customer gateway to determine the IPSec SA information;

[0090] S502. The virtual machine of the VPC of the cloud computing node sends the first packet to be sent to the virtual switch of the cloud computing node;

[0091] S503. The virtual switch encapsulates the first packet to be sent and sends it to the IPSec VPN gateway;

[0092] Optionally, the virtual switch performs VXLAN encapsulation on the first packet to be sent (without encryption), queries the VPC routing table and then sends it to the IPSec VPN gateway;

[0093] S504. The IPSec VPN gateway encrypts and encapsulates the first packet to be sent into a complete first target packet according to the IPSec SA information;

[0094] Optionally, if the virtual switch performs VXLAN encapsulation on the first packet to be sent, after receiving the first packet to be sent, the IPSec VPN gateway first de - encapsulates the VXLAN, and then encrypts and encapsulates the first packet to be sent into a complete target packet according to the IPSec SA information;

[0095] S505. The IPSec VPN gateway queries the VPC controller for the computing node information where the virtual switch sending the packet to be sent is located;

[0096] S506. The VPC controller sends the computing node information to the IPSec VPN gateway;

[0097] S507. The IPSec VPN gateway establishes an encrypted connection with the virtual switch and sends the IPSec SA information to the virtual switch through the encrypted connection;

[0098] S508. The virtual machine in the VPC of the cloud computing node sends the second packet to be sent to the virtual switch;

[0099] Wherein, the second packet to be sent here is the packet to be sent subsequent to the first packet to be sent in step S502;

[0100] S509. The virtual switch encrypts the second packet to be sent according to the IPSec SA information to obtain an encrypted packet and sends it to the IPSec VPN gateway;

[0101] Optionally, the virtual switch performs VXLAN encapsulation on the encrypted packet and then sends it to the IPSec VPN gateway;

[0102] S510. The IPSec VPN gateway fills the packet information in the encrypted packet and encapsulates it into a complete target packet;

[0103] S511. The IPSec VPN gateway sends the target packet to the target customer gateway;

[0104] Optionally, in S512, the IPSec SA information is updated or destroyed between the IPSec VPN gateway and the target customer gateway;

[0105] S513. The IPSec VPN gateway queries the computing node information where the virtual switch is located from the VPC controller;

[0106] S514. The VPC controller sends the computing node information to the IPSec VPN gateway;

[0107] S515. The IPSec VPN gateway establishes an encrypted connection with the virtual switch and updates or destroys the IPSec SA information in the virtual switch.

[0108] Corresponding to the message processing method on the IPSec VPN gateway side in the above embodiment, Figure 6 This is the structural block diagram of the message processing device provided by the embodiments of the present disclosure, which is applied to the cloud IPSec VPN gateway. For the sake of convenience of description, only the parts related to the embodiments of the present disclosure are shown. Referring to Figure 6 , the message processing device 600 includes: a receiving unit 601, a processing unit 602, and a sending unit 603.

[0109] Among them, a receiving unit 601 is configured to receive an encrypted data packet sent by a virtual switch of a cloud computing node, where the encrypted data packet is encrypted by the virtual switch according to security association information of an Internet security protocol; the security association information is pre-sent by the virtual private network gateway;

[0110] A processing unit 602 is configured to fill message information into the encrypted data packet and encapsulate it into a complete target message;

[0111] A sending unit 603 is configured to send the target message to a target customer gateway.

[0112] In one or more embodiments of the present disclosure, before receiving the encrypted data packet sent by the virtual switch of the cloud computing node, the processing unit 602 is further configured to perform a negotiation process with the target customer gateway to determine the security association information;

[0113] The sending unit 603 is further configured to establish an encrypted connection with the virtual switch and send the security association information to the virtual switch through the encrypted connection.

[0114] In one or more embodiments of the present disclosure, the sending unit 603 is further configured to receive a data packet to be encrypted sent by the virtual switch;

[0115] The processing unit 602 is further configured to encrypt and encapsulate the data packet to be encrypted into a complete target message according to the security association information; the sending unit 603 is further configured to send the target message to the target customer gateway;

[0116] The processing unit 602 is further configured to query the virtual switch information based on the data packet to be encrypted;

[0117] The sending unit 603 is further configured to establish an encrypted connection with the virtual switch according to the virtual switch information and send the security association information to the virtual switch through the encrypted connection.

[0118] In one or more embodiments of the present disclosure, the encrypted data packet carries an identifier added by the virtual switch to indicate that the data packet has been encrypted according to the security association information;

[0119] When the processing unit 602 fills message information into the encrypted data packet and encapsulates it into a complete target message, it is configured to:

[0120] If it is recognized that the encrypted data packet carries the identifier, the encryption process is skipped, and the encrypted data packet is added with header information and tail information of an encapsulated security payload and encapsulated into a complete target message.

[0121] In one or more embodiments of the present disclosure, the encrypted data packet carries the length of the encrypted data and the identification information of the security association information;

[0122] Before encapsulating the encrypted data packet into a complete target message by filling in message information by the processing unit 602, it is further configured to:

[0123] Accumulate the length of the encrypted data carried in the encrypted data packet encrypted with the security association information to obtain the cumulative length of the encrypted data;

[0124] Compare the cumulative length of the encrypted data with a preset encryption length threshold corresponding to the security association information;

[0125] If the cumulative length of the encrypted data exceeds the preset encryption length threshold corresponding to the security association information, re - negotiate with the target customer gateway to determine the updated security association information.

[0126] In one or more embodiments of the present disclosure, the encrypted data packet is encapsulated by the virtual switch after encryption;

[0127] Before filling in message information for the encrypted data packet by the processing unit 602, it is further configured to:

[0128] Decapsulate the encrypted data packet.

[0129] In one or more embodiments of the present disclosure, the sending unit 603 is further configured to:

[0130] If it is determined that the security association information is updated, send the updated security association information to the virtual switch through an encrypted connection; or

[0131] If it is determined that the security association information is destroyed, send an instruction to delete the security association information to the virtual switch through an encrypted connection.

[0132] The device provided in this embodiment can be used to execute the technical solution of the message processing method embodiment on the IPSec VPN gateway side. Its implementation principle and technical effect are similar, and will not be elaborated here in this embodiment.

[0133] Corresponding to the message processing method on the virtual switch side of the cloud computing node in the above - mentioned embodiment, Figure 7 This is a structural block diagram of a message processing device provided in an embodiment of the present disclosure, which is applied to the virtual switch of a cloud computing node. For the sake of convenience of description, only the parts related to the embodiments of the present disclosure are shown. Referring to Figure 7 , the message processing device 700 includes: a receiving unit 701, a processing unit 702, and a sending unit 703.

[0134] Among them, a receiving unit 701 is configured to receive a data packet to be sent sent by a virtual machine of a cloud computing node;

[0135] A processing unit 702 is configured to determine whether the data packet to be sent needs to be encrypted according to an encryption policy in security association information of an Internet security protocol. If it is determined that encryption is required, the data packet to be sent is encrypted according to a key in the security association information to obtain an encrypted data packet; wherein, the security association information is pre-sent by a cloud based on a virtual private network gateway of the Internet security protocol;

[0136] A sending unit 703 is configured to send the encrypted data packet to the virtual private network gateway, so that the virtual private network gateway fills in message information for the encrypted data packet, encapsulates it into a complete target message, and sends it to a target customer gateway.

[0137] In one or more embodiments of the present disclosure, the receiving unit 701 is further configured to:

[0138] Establish an encrypted connection with the virtual private network gateway and receive the security association information sent by the virtual private network gateway through the encrypted connection.

[0139] In one or more embodiments of the present disclosure, after the processing unit 702 encrypts the data packet to be sent according to the key in the security association information to obtain an encrypted data packet, it is further configured to:

[0140] Add an identifier to the encrypted data packet, where the identifier is used to indicate that the data packet has been encrypted according to the security association information; and / or

[0141] Add the length of the encrypted data and the identifier information of the security association information to the encrypted data packet; and / or

[0142] Encapsulate the encrypted data packet.

[0143] In one or more embodiments of the present disclosure, the receiving unit 701 is further configured to receive, through an encrypted connection, updated security association information sent by the virtual private network gateway;

[0144] The processing unit 702 is further configured to update the current security association information to the updated security association information; or

[0145] The receiving unit 701 is further configured to receive, through an encrypted connection, an instruction to delete the security association information sent by the virtual private network gateway;

[0146] The processing unit 702 is further configured to delete the current security association information.

[0147] The device provided in this embodiment can be used to execute the technical solutions of the method embodiments for message processing on the virtual switch side described above. The implementation principle and technical effects are similar, and will not be elaborated here in this embodiment.

[0148] Refer to Figure 8 , which shows a schematic structural diagram of an electronic device 800 suitable for implementing the embodiments of the present disclosure. The electronic device 800 can be a terminal device or a server. Among them, the terminal device can include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, personal digital assistants (PDAs), tablet computers (PADs), portable media players (PMPs), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 8 The electronic device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.

[0149] As Figure 8 shown, the electronic device 800 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 801, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage device 808 into a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 are also stored. The processing device 801, the ROM 802, and the RAM 803 are connected to each other through a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0150] Generally, the following devices can be connected to the I / O interface 805: an input device 806 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 807 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 808 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 809. The communication device 809 can allow the electronic device 800 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 8An electronic device 800 is shown with various devices, but it should be understood that it is not required to implement or have all of the shown devices. Instead, more or fewer devices may be implemented or had.

[0151] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program code for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device 809, or installed from a storage device 808, or installed from a ROM 802. When the computer program is executed by a processing device 801, the above-described functions defined in the packet processing method on the IPSec VPN gateway side or the virtual switch side of the embodiment of the present disclosure are performed.

[0152] It should be noted that the above computer-readable medium in the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in connection with an instruction execution system, apparatus, or device. And in the present disclosure, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, and the computer-readable signal medium can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0153] The above computer-readable medium can be included in the above electronic device; or it can exist separately and not be assembled into the electronic device.

[0154] The above computer-readable medium carries one or more programs which, when executed by the electronic device, cause the electronic device to perform the methods shown in the above embodiments.

[0155] Computer program code for carrying out operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0156] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code, which contains one or more executable instructions for implementing the specified logical function. It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0157] The units described in the embodiments of the present disclosure may be implemented in software or in hardware. Wherein, the name of the unit does not constitute a limitation on the unit itself in some cases. For example, the first acquisition unit may also be described as "the unit for acquiring at least two Internet protocol addresses".

[0158] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that can be used include: Field Programmable Gate Arrays (FPGAs), Application Specific Integrated Circuits (ASICs), Application Specific Standard Products (ASSPs), Systems on Chip (SOCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0159] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media would include electrical connections based on one or more wires, portable computer disks, hard disks, Random Access Memory (RAM), Read Only Memory (ROM), Erasable Programmable Read Only Memory (EPROM or flash memory), optical fibers, portable compact disk read only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0160] In a first aspect, according to one or more embodiments of the present disclosure, there is provided a message processing method, the method comprising:

[0161] Receiving an encrypted data packet sent by a virtual switch of a cloud computing node, wherein the encrypted data packet is encrypted by the virtual switch according to security association information of an Internet security protocol; the security association information is pre-sent to the virtual switch;

[0162] Filling message information into the encrypted data packet and encapsulating it into a complete target message;

[0163] Sending the target message to a target customer gateway.

[0164] According to one or more embodiments of the present disclosure, before receiving the encrypted data packet sent by the virtual switch of the cloud computing node, it further includes:

[0165] Performing a negotiation process with the target customer gateway to determine the security association information;

[0166] Establishing an encrypted connection with the virtual switch and sending the security association information to the virtual switch through the encrypted connection.

[0167] According to one or more embodiments of the present disclosure, establishing an encrypted connection with the virtual switch and sending the security association information to the virtual switch through the encrypted connection includes:

[0168] Receiving the data packet to be encrypted sent by the virtual switch, encrypting and encapsulating the data packet to be encrypted into a complete target message according to the security association information, and sending it to the target customer gateway;

[0169] Querying the virtual switch information based on the data packet to be encrypted;

[0170] Establishing an encrypted connection with the virtual switch according to the virtual switch information and sending the security association information to the virtual switch through the encrypted connection.

[0171] According to one or more embodiments of the present disclosure, the encrypted data packet carries an identifier added by the virtual switch to indicate that the data packet has been encrypted according to the security association information;

[0172] The filling the encrypted data packet with message information and encapsulating it into a complete target message includes:

[0173] If it is recognized that the encrypted data packet carries the identifier, skip the encryption process, add the header information and trailer information of the encapsulated security payload to the encrypted data packet, and encapsulate it into a complete target message.

[0174] According to one or more embodiments of the present disclosure, the encrypted data packet carries the length of the encrypted data and the identification information of the security association information;

[0175] Before filling the encrypted data packet with message information and encapsulating it into a complete target message, it further includes:

[0176] Accumulating the length of the encrypted data carried in the encrypted data packet encrypted by the security association information to obtain the cumulative length of the encrypted data;

[0177] Comparing the cumulative length of the encrypted data with a preset encryption length threshold corresponding to the security association information;

[0178] If the cumulative length of the encrypted data exceeds the preset encryption length threshold corresponding to the security association information, re - negotiate with the target customer gateway to determine the updated security association information.

[0179] According to one or more embodiments of the present disclosure, the encrypted data packet is encapsulated by the virtual switch after encryption;

[0180] Before filling the message information into the encrypted data packet, the following steps are further included:

[0181] Unencapsulate the encrypted data packet.

[0182] According to one or more embodiments of the present disclosure, the method further includes:

[0183] If it is determined that the security association information is updated, send the updated security association information to the virtual switch through an encrypted connection; or

[0184] If it is determined that the security association information is destroyed, send an instruction to delete the security association information to the virtual switch through an encrypted connection.

[0185] In a second aspect, according to one or more embodiments of the present disclosure, a message processing method is provided. The method includes:

[0186] According to the encryption policy in the security association information of the Internet security protocol, determine whether the data packet to be sent needs to be encrypted. If it is determined that encryption is required, encrypt the data packet to be sent according to the key in the security association information to obtain an encrypted data packet; wherein, the security association information is pre-sent by the cloud based on the virtual private network gateway of the Internet security protocol;

[0187] Send the encrypted data packet to the virtual private network gateway, so that the virtual private network gateway fills the message information into the encrypted data packet, encapsulates it into a complete target message, and sends it to the target customer gateway.

[0188] According to one or more embodiments of the present disclosure, the method further includes:

[0189] Establish an encrypted connection with the virtual private network gateway, and receive the security association information sent by the virtual private network gateway through the encrypted connection.

[0190] According to one or more embodiments of the present disclosure, after encrypting the data packet to be sent according to the key in the security association information to obtain an encrypted data packet, the following steps are further included:

[0191] Add an identifier to the encrypted data packet, and the identifier is used to indicate that the data packet has been encrypted according to the security association information; and / or

[0192] Add the length of the encrypted data and the identification information of the security association information to the encrypted data packet; and / or

[0193] Encapsulate the encrypted data packet.

[0194] According to one or more embodiments of the present disclosure, the method further includes:

[0195] Receive the updated security association information sent by the virtual private network gateway through an encrypted connection, and update the current security association information to the updated security association information; or

[0196] Receive the instruction to delete the security association information sent by the virtual private network gateway through an encrypted connection, and delete the current security association information.

[0197] Thirdly, according to one or more embodiments of the present disclosure, there is provided a packet processing device, including:

[0198] A receiving unit, configured to receive an encrypted data packet sent by a virtual switch of a cloud computing node, where the encrypted data packet is encrypted by the virtual switch according to security association information of an Internet security protocol; the security association information is pre-sent to the virtual switch;

[0199] A processing unit, configured to fill packet information in the encrypted data packet and encapsulate it into a complete target packet;

[0200] A sending unit, configured to send the target packet to a target customer gateway.

[0201] According to one or more embodiments of the present disclosure, before receiving the encrypted data packet sent by the virtual switch of the cloud computing node, the processing unit is further configured to perform a negotiation process with the target customer gateway to determine the security association information;

[0202] The sending unit is further configured to establish an encrypted connection with the virtual switch and send the security association information to the virtual switch through the encrypted connection.

[0203] According to one or more embodiments of the present disclosure, the sending unit is further configured to receive a data packet to be encrypted sent by the virtual switch;

[0204] The processing unit is further configured to encrypt the data packet to be encrypted according to the security association information and encapsulate it into a complete target packet; the sending unit is further configured to send the target packet to the target customer gateway;

[0205] The processing unit is further configured to query the virtual switch information based on the data packet to be encrypted;

[0206] The sending unit is further configured to establish an encrypted connection with the virtual switch according to the virtual switch information and send the security association information to the virtual switch through the encrypted connection.

[0207] According to one or more embodiments of the present disclosure, an identifier is carried in the encrypted data packet, and the identifier is added by the virtual switch and is used to indicate that the data packet has been encrypted according to the security association information;

[0208] When the processing unit fills the encrypted data packet with message information and encapsulates it into a complete target message, it is used for:

[0209] If it is recognized that the encrypted data packet carries the identifier, the encryption process is skipped, and the encrypted data packet is added with the header information and tail information of the encapsulated security payload and encapsulated into a complete target message.

[0210] According to one or more embodiments of the present disclosure, the length of the encrypted data and the identifier information of the security association information are carried in the encrypted data packet;

[0211] Before the processing unit fills the encrypted data packet with message information and encapsulates it into a complete target message, it is also used for:

[0212] Accumulate the length of the encrypted data carried in the encrypted data packet encrypted by the security association information to obtain the cumulative length of the encrypted data;

[0213] Compare the cumulative length of the encrypted data with the preset encryption length threshold corresponding to the security association information;

[0214] If the cumulative length of the encrypted data exceeds the preset encryption length threshold corresponding to the security association information, re-negotiate with the target customer gateway to determine the updated security association information.

[0215] According to one or more embodiments of the present disclosure, the encrypted data packet is encapsulated by the virtual switch after encryption;

[0216] Before the processing unit fills the encrypted data packet with message information, it is also used for:

[0217] Decapsulate the encrypted data packet.

[0218] According to one or more embodiments of the present disclosure, the sending unit is also used for:

[0219] If it is determined that the security association information is updated, send the updated security association information to the virtual switch through an encrypted connection; or

[0220] If it is determined that the security association information is destroyed, send an instruction to delete the security association information to the virtual switch through an encrypted connection.

[0221] Fourthly, according to one or more embodiments of the present disclosure, there is provided a message processing device, including:

[0222] a receiving unit, configured to receive a packet to be sent sent by a virtual machine of the cloud computing node;

[0223] a processing unit, configured to determine whether the packet to be sent needs to be encrypted according to the encryption policy in the security association information of the Internet security protocol. If it is determined that encryption is required, the packet to be sent is encrypted according to the key in the security association information to obtain an encrypted packet; wherein, the security association information is pre-sent by the cloud based on a virtual private network gateway of the Internet security protocol;

[0224] a sending unit, configured to send the encrypted packet to the virtual private network gateway, so that the virtual private network gateway fills in message information for the encrypted packet, encapsulates it into a complete target message, and sends it to a target customer gateway.

[0225] According to one or more embodiments of the present disclosure, the receiving unit is further configured to:

[0226] establish an encrypted connection with the virtual private network gateway and receive the security association information sent by the virtual private network gateway through the encrypted connection.

[0227] According to one or more embodiments of the present disclosure, after encrypting the packet to be sent according to the key in the security association information to obtain an encrypted packet, the processing unit is further configured to:

[0228] add an identifier to the encrypted packet, where the identifier is used to indicate that the packet has been encrypted according to the security association information; and / or

[0229] add the length of the encrypted data and the identifier information of the security association information to the encrypted packet; and / or

[0230] encapsulate the encrypted packet.

[0231] According to one or more embodiments of the present disclosure, the receiving unit is further configured to receive the updated security association information sent by the virtual private network gateway through the encrypted connection;

[0232] the processing unit is further configured to update the current security association information to the updated security association information; or

[0233] the receiving unit is further configured to receive an instruction to delete the security association information sent by the virtual private network gateway through the encrypted connection;

[0234] The processing unit is further configured to delete the current security association information.

[0235] In a fifth aspect, according to one or more embodiments of the present disclosure, there is provided an electronic device, including: at least one processor and a memory;

[0236] The memory stores computer-executable instructions;

[0237] The at least one processor executes the computer-executable instructions stored in the memory, so that the at least one processor executes the message processing method described in the first aspect above and various possible designs of the first aspect, or the message processing method described in the second aspect above and various possible designs of the second aspect.

[0238] In a sixth aspect, according to one or more embodiments of the present disclosure, there is provided a computer-readable storage medium, in which computer-executable instructions are stored. When a processor executes the computer-executable instructions, the message processing method described in the first aspect above and various possible designs of the first aspect, or the message processing method described in the second aspect above and various possible designs of the second aspect are implemented.

[0239] In a seventh aspect, according to one or more embodiments of the present disclosure, there is provided a computer program product, including computer-executable instructions. When a processor executes the computer-executable instructions, the message processing method described in the first aspect above and various possible designs of the first aspect, or the message processing method described in the second aspect above and various possible designs of the second aspect are implemented.

[0240] The above description is only a preferred embodiment of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present disclosure.

[0241] In addition, although the operations are depicted in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Certain features described in the context of a single embodiment may also be implemented in combination in a single embodiment. On the contrary, the various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0242] Although the subject matter has been described in language specific to structural features and / or methodological acts, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. On the contrary, the specific features and acts described above are merely example forms for implementing the claims.

Claims

1. A message processing method, characterized in that, Including: Receiving an encrypted data packet sent by a virtual switch of a cloud computing node, where the encrypted data packet is obtained by the virtual switch encrypting a data packet according to security association information of an Internet security protocol and adding an encryption identifier; the security association information is pre-negotiated with a target customer gateway and then sent to the virtual switch; the encryption identifier is used to indicate that the data packet has been encrypted according to the security association information; When the encryption identifier is recognized, filling message information into the encrypted data packet and encapsulating it into a complete target message; Sending the target message to the target customer gateway.

2. The method according to claim 1, wherein Before receiving the encrypted data packet sent by the virtual switch of the cloud computing node, it further includes: Carrying out a negotiation process with the target customer gateway to determine the security association information; Establishing an encrypted connection with the virtual switch and sending the security association information to the virtual switch through the encrypted connection.

3. The method according to claim 2, wherein The establishing an encrypted connection with the virtual switch and sending the security association information to the virtual switch through the encrypted connection includes: Receiving a data packet to be encrypted sent by the virtual switch, encrypting and encapsulating the data packet to be encrypted into a complete target message according to the security association information, and sending it to the target customer gateway; Querying the virtual switch information based on the data packet to be encrypted; Establishing an encrypted connection with the virtual switch according to the virtual switch information and sending the security association information to the virtual switch through the encrypted connection.

4. The method according to any one of claims 1-3, characterized in that, The encrypted data packet carries an identifier added by the virtual switch and used to indicate that the data packet has been encrypted according to the security association information; The filling message information into the encrypted data packet and encapsulating it into a complete target message includes: If it is recognized that the encrypted data packet carries the identifier, skipping the encryption process, adding header information and tail information of an encapsulated security payload to the encrypted data packet, and encapsulating it into a complete target message.

5. The method according to claim 2 or 3, characterized in that, The encrypted data packet carries the length of the encrypted data and the identifier information of the security association information; Before filling message information into the encrypted data packet and encapsulating it into a complete target message, it further includes: Accumulating the length of the encrypted data carried in the encrypted data packet encrypted with the security association information to obtain the cumulative length of the encrypted data; Comparing the cumulative length of the encrypted data with a preset encryption length threshold corresponding to the security association information; If the cumulative length of the encrypted data exceeds the preset encryption length threshold corresponding to the security association information, re-carrying out a negotiation process with the target customer gateway to determine updated security association information.

6. The method according to any one of claims 1 to 3, characterized in that, The encrypted data packet is encapsulated by the virtual switch after encryption; Before filling message information into the encrypted data packet, it further includes: De-encapsulating the encrypted data packet.

7. The method according to any one of claims 1 to 3, characterized in that, The method further includes: If it is determined that the security association information is updated, sending the updated security association information to the virtual switch through the encrypted connection; or If it is determined that the security association information is destroyed, an instruction to delete the security association information is sent to the virtual switch through an encrypted connection.

8. A message processing method, characterized in that, It includes: Receiving a data packet to be sent sent by a virtual machine of a cloud computing node; According to the encryption policy in the security association information of the Internet security protocol, determining whether the data packet to be sent needs to be encrypted. If it is determined that encryption is required, the data packet to be sent is encrypted according to the key in the security association information and an encryption identifier is added to obtain an encrypted data packet; wherein, the security association information is pre-negotiated and determined by a virtual private network gateway of the cloud based on the Internet security protocol and then sent; the encryption identifier is used to indicate that the data packet has been encrypted according to the security association information; Sending the encrypted data packet to the virtual private network gateway, so that when the virtual private network gateway identifies the encryption identifier, the encrypted data packet is filled with message information, encapsulated into a complete target message, and sent to the target customer gateway.

9. The method according to claim 8, characterized in that The method further includes: Establishing an encrypted connection with the virtual private network gateway and receiving the security association information sent by the virtual private network gateway through the encrypted connection.

10. The method according to claim 8 or 9, characterized in that, After encrypting the data packet to be sent according to the key in the security association information to obtain an encrypted data packet, it further includes: Adding an identifier to the encrypted data packet, where the identifier is used to indicate that the data packet has been encrypted according to the security association information; and / or Adding the length of the encrypted data and the identifier information of the security association information to the encrypted data packet; and / or Encapsulating the encrypted data packet.

11. The method according to claim 8 or 9, characterized in that, The method further includes: Receiving the updated security association information sent by the virtual private network gateway through the encrypted connection and updating the current security association information to the updated security association information; or Receiving an instruction to delete the security association information sent by the virtual private network gateway through the encrypted connection and deleting the current security association information.

12. A message processing device, characterized in that, It includes: A receiving unit, configured to receive an encrypted data packet sent by a virtual switch of a cloud computing node, where the encrypted data packet is obtained by encrypting a data packet by the virtual switch according to the security association information of the Internet security protocol and adding an encryption identifier; the security association information is pre-negotiated and determined with a target customer gateway and then sent to the virtual switch; the encryption identifier is used to indicate that the data packet has been encrypted according to the security association information; A processing unit, configured to fill the encrypted data packet with message information and encapsulate it into a complete target message when the encryption identifier is identified; A sending unit, configured to send the target message to the target customer gateway.

13. A message processing device, characterized in that, It includes: A receiving unit, configured to receive a data packet to be sent sent by a virtual machine of a cloud computing node; A processing unit, configured to determine whether the data packet to be sent needs to be encrypted according to the encryption policy in the security association information of the Internet security protocol. If it is determined that encryption is required, the data packet to be sent is encrypted according to the key in the security association information and an encryption identifier is added to obtain an encrypted data packet; wherein the security association information is sent by the cloud after being pre-negotiated and determined with the target customer gateway based on the virtual private network gateway of the Internet security protocol; the encryption identifier is used to indicate that the data packet has been encrypted according to the security association information. A sending unit, configured to send the encrypted data packet to the virtual private network gateway, so that when the virtual private network gateway identifies the encryption identifier, the encrypted data packet is filled with message information, encapsulated into a complete target message, and sent to the target customer gateway.

14. An electronic device, characterized in that, Comprising: At least one processor and a memory; The memory stores computer execution instructions; The at least one processor executes the computer execution instructions stored in the memory, so that the at least one processor executes the method according to any one of claims 1-7 or 8-11.

15. A computer-readable storage medium, characterized in that, Computer execution instructions are stored in the computer-readable storage medium, and when the processor executes the computer execution instructions, the method according to any one of claims 1-7 or 8-11 is implemented.

16. A computer program product, characterized in that, Comprising computer execution instructions, and when the processor executes the computer execution instructions, the method according to any one of claims 1-7 or 8-11 is implemented.

Citation Information

Patent Citations

  • Aggregation of cryptography engines

    US20100217971A1