Cloud networking system, secure access method, device, and storage medium

By introducing GWLB connection components and security management VPC between TR and GWLB, the security issue of VPC mutual access in TR networking scenarios is resolved, and simplified access and low-latency transmission of security services are achieved.

CN115913617BActive Publication Date: 2025-10-14ALIBABA (CHINA) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202211177346.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-26
Publication Date
2025-10-14
Estimated Expiration
2042-09-26

AI Technical Summary

Technical Problem

In cloud computing, cross-Virtual Private Cloud (VPC) intercommunication in forwarding router (TR) networking scenarios can lead to security degradation. This raises the question of how to address the security issues of intercommunication between services in different VPCs.

Method used

Introduce security management VPC and add a GWLB connection component between the forwarding router (TR) and the gateway load balancing device (GWLB) as a routing medium. By configuring secure routing information, the interconnection of security services is achieved, and security authentication is provided by using the GWLB connection component and security service nodes.

Benefits of technology

It provides security services during VPC inter-access, simplifies access to security services, reduces transmission latency, and improves security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913617B_ABST
    Figure CN115913617B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a cloud networking system, a secure access method, equipment and a storage medium. In the TR-based networking system, a security control VPC is introduced, GWLB is used in the security control VPC, and GWLB is used as an exposed object for providing external security services. Since GWLB and TR are not in the same plane, a new product object, i.e., a GWLB connection component, is further added in the networking system as a routing medium between TR and GWLB, the interconnection between TR and GWLB is realized, and by configuring security routing information on TR that points to the GWLB connection component by default, security services can be provided in the service access process between two customer VPCs corresponding to the security routing information, secure intercommunication is realized, and the security problem faced when customer VPCs intercommunicate in the TR networking scenario is solved. Furthermore, it is also conducive to simplifying the access implementation of security services in the TR networking scenario, the traffic forwarding path is shorter, and it is conducive to reducing the transmission delay on the path.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of cloud computing, and particularly relates to a cloud networking system, a secure access method, equipment and a storage medium. BACKGROUND

[0002] With the development of cloud computing technology, a user can construct a virtual private cloud (VPC) on a cloud network, the VPC is an isolated virtual network environment allowing the user to manage and configure policies by himself / herself, different VPCs are isolated from each other, and the security of data and services is realized.

[0003] In actual application, different VPCs can need to interwork, and then a transit router (TR) appears, the interworking between different VPCs can be realized through the TR, and services between different VPCs can visit each other, which is referred to as a TR networking scenario.

[0004] However, the original intention of the VPC is security isolation, after the interworking between different VPCs, the services between different VPCs can visit each other, which is equivalent to the degradation of the security of the VPC, and therefore the TR networking scenario faces the security problem of cross-VPC visiting. SUMMARY

[0005] Aspects of the present application provide a cloud networking system, a secure access method, equipment and a storage medium to solve the security problem of cross-VPC visiting faced by the TR networking scenario.

[0006] The present application provides a cloud networking system, comprising a transit router (TR) and a plurality of customer virtual private clouds (VPCs) interconnected with the TR; the services between the plurality of customer VPCs are visited through the TR; the cloud networking system further comprises a security control VPC, the security control VPC comprises a gateway type load balancing device (GWLB) and a plurality of security service nodes interconnected with the GWLB, and is configured to provide security services externally; a GWLB connection component is further deployed in the cloud networking system, the GWLB connection component is used as a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB respectively; the TR is configured with at least one piece of security routing information pointing to the GWLB connection component by default, and is used to provide security services for a service access process between two customer VPCs corresponding to each piece of security routing information through the GWLB connection component and the GWLB using the security service nodes in the security control VPC.

[0007] The embodiment of the application further provides a secure access method applied to a forwarding router TR in a cloud networking system, which comprises the following steps: receiving a first tunnel message from any customer VPC in the cloud networking system, wherein the first tunnel message is obtained by tunnel encapsulating an original message in which the any customer VPC requests a target service from another customer VPC; if the routing information corresponding to the first tunnel message belongs to secure routing information, sending the first tunnel message to a GWLB connection component in the cloud networking system, so as to use a secure service node in a secure control VPC to perform secure authentication on the original message by a GWLB in the secure control VPC; wherein the secure routing information is directed to the GWLB connection component, the GWLB connection component serves as a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB respectively, and the GWLB is interconnected with the secure service node.

[0008] The embodiment of the application further provides a secure access method applied to a gateway-type load balancing device GWLB connection component in a cloud networking system, which comprises the following steps: receiving a first tunnel message sent by a forwarding router TR in the cloud networking system, wherein the first tunnel message is obtained by tunnel encapsulating an original message in which any customer VPC in the cloud networking system requests a target service from another customer VPC; analyzing the original message from the first tunnel message, and sending the original message to a GWLB in a secure control VPC, so as to load balance the original message to a secure service node in the secure control VPC by the GWLB for secure authentication; the GWLB connection component serves as a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB respectively, and the GWLB is interconnected with the secure service node.

[0009] The embodiment of the application further provides a secure access method applied to a virtual private cloud VPC connection component in a cloud networking system, which comprises the following steps: receiving an original message in which a client in a customer VPC requests to access a target service; encapsulating the original message into a first tunnel message according to preconfigured routing information directed to a forwarding router TR; and sending the first tunnel message to the TR, so as to perform service intercommunication between the TR and another customer VPC providing the target service.

[0010] The embodiment of the present application provides a security access device which can be located in a forwarding router TR in a cloud networking system and is implemented, the device comprises: a storage module configured to store at least one piece of security routing information which is directed to a gateway type load balancing device GWLB connection component in the cloud networking system; a receiving module configured to receive a first tunnel message from any customer VPC in the cloud networking system, wherein the first tunnel message is obtained by tunnel encapsulation according to an original message which requests a target service from another customer VPC; and a sending module configured to send the first tunnel message to the GWLB connection component in the case that the routing information corresponding to the first tunnel message is the security routing information, so that the original message is subjected to security authentication by a security service node in a security control VPC through a GWLB in the security control VPC; wherein the GWLB connection component is a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB respectively, and the GWLB is interconnected with the security service node.

[0011] The embodiment of the present application provides a forwarding router which can be applied to a cloud networking system and comprises a storage and a processor; the storage is configured to store a computer program and at least one piece of security routing information which is directed to a gateway type load balancing device GWLB connection component in the cloud networking system; and the processor is coupled with the storage and is configured to execute the computer program so as to execute steps in a method which can be executed by the forwarding router and is provided by the embodiment of the present application.

[0012] The embodiment of the present application provides a security access device which can be located in a GWLB connection component of a gateway type load balancing device GWLB in a cloud networking system and is implemented, the device comprises: a receiving module configured to receive a first tunnel message sent by a forwarding router TR in the cloud networking system, wherein the first tunnel message is obtained by tunnel encapsulation according to an original message which requests a target service from another customer VPC in any customer VPC in the cloud networking system; an encapsulation module configured to parse the original message from the first tunnel message; and a sending module configured to send the original message to a GWLB in a security control VPC, so that the GWLB load balances the original message to a security service node in the security control VPC for security authentication; wherein the GWLB connection component is a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB respectively, and the GWLB is interconnected with the security service node.

[0013] An embodiment of the present application provides a cloud computing device that can be implemented as a gateway-type load balancing device GWLB connection component in a cloud networking system, including: a memory and a processor; the memory is used to store a computer program, and the processor, coupled to the memory, is used to execute the computer program to execute the steps in the method provided in the embodiment of the present application that can be performed by the GWLB connection component.

[0014] An embodiment of the present application provides a cloud computing device that can be implemented as a virtual private cloud (VPC) connection component in a cloud networking system, including: a memory and a processor; the memory is used to store a computer program, and the processor, coupled to the memory, is used to execute the computer program to execute the steps in the method provided in the embodiment of the present application that can be executed by the VPC connection component.

[0015] An embodiment of the present application provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the processor is enabled to implement the steps of the methods provided in the embodiments of the present application.

[0016] In an embodiment of the present application, a security control VPC is introduced in a TR-based networking system, and GWLB is used in the security control VPC, and GWLB is used as an exposed object for providing security services to the outside world. Since GWLB and TR are not on the same plane, a new product object, namely the GWLB connection component, is further added to the networking system as a routing medium between TR and GWLB to achieve interconnection between TR and GWLB, and by configuring security routing information pointing to the GWLB connection component by default on TR, it is possible to provide security services during service access between the two customer VPCs corresponding to the security routing information, realize secure mutual access, and solve the security problems faced when customer VPCs visit each other in the TR networking scenario.

[0017] In addition, in the embodiment of the present application, the method of directly adding a GWLB connection component between TR and GWLB is conducive to simplifying the access implementation of security services in the TR networking scenario. The mutual access traffic between customer VPCs only needs to flow into GWLB through TR and GWLB connection components to use security services. The traffic forwarding path is shorter, which is conducive to reducing the transmission delay on the path. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0019] Figure 1a A schematic diagram of the structure of a cloud networking system provided by an exemplary embodiment of the present application;

[0020] Figure 1b Another structural schematic diagram of a cloud network system provided for an exemplary embodiment of the present application;

[0021] Figure 2a A flowchart of a security access method provided for an exemplary embodiment of the present application;

[0022] Figure 2b A flowchart of another security access method provided for an exemplary embodiment of the present application;

[0023] Figure 2c A flowchart of yet another security access method provided for an exemplary embodiment of the present application;

[0024] Figure 3a A structural schematic diagram of a security access device provided for an exemplary embodiment of the present application;

[0025] Figure 3b A structural schematic diagram of another security access device provided for an exemplary embodiment of the present application;

[0026] Figure 3c A structural schematic diagram of yet another security access device provided for an exemplary embodiment of the present application;

[0027] Figure 4 A structural schematic diagram of a forwarding router provided for an exemplary embodiment of the present application. DETAILED DESCRIPTION

[0028] In order to make the objectives, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described below in conjunction with the specific embodiments of the present application and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all the other embodiments obtained by those of ordinary skill in the art without any creative work, fall within the scope of protection of the present application.

[0029] The existing TR networking scenario faces the problem of how to solve the security problem during cross-VPC visits. To address this technical problem, in an embodiment of the present application, a security control VPC is introduced in a TR-based networking system, and GWLB is used in the security control VPC, and GWLB is used as an exposed object for providing security services to the outside world; since GWLB and TR are no longer on the same plane, a new product object, namely the GWLB connection component, is further added to the networking system as a routing medium between TR and GWLB to achieve interconnection between TR and GWLB, and by configuring the default security routing information pointing to the GWLB connection component on TR, it is possible to provide security services during the service access between the two customer VPCs corresponding to the security routing information, realize secure mutual access, and solve the security problems faced by customer VPCs during mutual access in the TR networking scenario.

[0030] In addition, in the embodiment of the present application, the method of directly adding a GWLB connection component between TR and GWLB is conducive to simplifying the access implementation of security services in the TR networking scenario. The mutual access traffic between customer VPCs only needs to flow into GWLB through TR and GWLB connection components to use security services. The traffic forwarding path is shorter, which is conducive to reducing the transmission delay on the path.

[0031] The following describes in detail the technical solutions provided by various embodiments of the present application in conjunction with the accompanying drawings.

[0032] Figure 1a This is a schematic diagram of the structure of a cloud networking system provided by an exemplary embodiment of this application. Figure 1a As shown, the system 100 includes: a Transit Router (TR) 10, and multiple customer VPCs (Customer VPCs) interconnected with the TR 10. Figure 1a In the figure, two customer VPCs are used as an example, namely customer VPC 11 and customer VPC 12.

[0033] In this embodiment, the TR 10 refers to a network element instance with a traffic forwarding function, and can perform traffic forwarding between different network instances. In this embodiment, the network instance mainly refers to a customer VPC, but is not limited thereto, and can also be a Virtual Border Router (VBR) instance or a Cloud Connect Network (CCN) instance. It should be noted that the customer VPCs interconnected by the TR in this embodiment can be located in the same region (Region) or different regions, that is, the TR can forward traffic within the same region or between different regions. It should be noted that the TR can have various implementation forms, and in addition to being implemented in the form of a router, it can also be implemented in the form of a gateway, for example, it can be implemented as a Transit Gateway (TGW). In this embodiment, the TR 10 is taken as an example and is illustrated in the form of a TGW. Figure 1a In this embodiment, the TR 10 has rich network interconnection and routing management functions such as interconnection with a customer VPC, support for a routing table, and permission to add a routing entry or a routing policy, in order to implement interconnection and traffic forwarding of different customer VPCs.

[0034] In this embodiment, the customer VPC is a VPC, which is a logically isolated network environment constructed on a physical network by using virtualization technology. The physical network includes various physical resources, such as physical machines, switches, or gateways. One or more customer VPCs can be deployed on the physical resources in a region, and the same customer VPC is usually deployed in a region. Each customer VPC includes at least one computing node, which can be an Elastic Compute Service (ECS) instance, a bare-metal server, a virtual machine, or the like. The customer VPC is deployed in a region, specifically, the computing nodes in the customer VPC are deployed on the physical machines in the region. Various services can be deployed on these computing nodes, and optionally, one service or multiple services can be deployed in the same VPC. In addition, the same service in the same VPC can be provided by multiple service instances or by one service instance. Optionally, the service instance that can provide the service can be a container, a virtual machine, or an application deployed on the computing node.

[0035] The customer VPCs can be located in the same region or different regions; each region includes one or more availability zones (AZs), and for the customer VPCs located in the same region, they can be located in the same availability zone or distributed in different availability zones. In addition, for the same customer VPC, it can be located in the same availability zone in the same region or distributed in different availability zones in the same region, that is, implemented across availability zones; or it can also be implemented across regions, that is, the same customer VPC is distributed in different regions, and specifically can be distributed in different availability zones in different regions. In this embodiment, for the case that the same customer VPC is distributed in one or more availability zones, it can also be referred to as the customer VPC including at least one availability zone. In Figure 1a In this embodiment, the customer VPC 11 includes two availability zones AZ1 and AZ2, that is, the customer VPC 11 is distributed in the availability zones AZ1 and AZ2; correspondingly, the customer VPC 12 includes two availability zones AZ3 and AZ4, that is, the customer VPC 12 is distributed in the two availability zones AZ3 and AZ4.

[0036] In this embodiment, in order to meet the networking requirements in a larger range, such as enterprise-level networking requirements, interconnection is needed between multiple customer VPCs. Specifically, multiple customer VPCs are interconnected through the TR 10, and service interconnection can be performed through the TR 10. As shown in Figure 1a The customer VPC 11 and the customer VPC 12 are interconnected through the TR 10. In this embodiment, the TR 10 does not belong to the customer VPC, but belongs to a system-level network element instance, which can be optionally deployed in the system VPC of the cloud networking system 100. Considering that the TR 10 is not in the same plane as the customer VPC, one belongs to the system VPC and the other is the customer VPC, in order to realize the interconnection between the customer VPC and the TR 10, the present embodiment proposes a product object, that is, a VPC connection component (VPCAttachment), which is deployed in the customer VPC and mounted under the TR 10, used for interconnecting with the TR 10, and further realizing the interconnection between the customer VPC where the VPC connection component is located and the TR 10. As shown in Figure 1aAs shown, the VPC connection component 11a is deployed in the customer VPC 11, the VPC connection component 12a is deployed in the customer VPC 12, and the VPC connection component 11a and the VPC connection component 12a are interconnected with the TR 10 respectively. Wherein, mounting the VPC connection component under the TR 10 refers to adding the identification of the VPC connection component on the TR 10, and establishing the binding relationship between the TR 10 and the VPC connection component. In addition, in order to achieve the purpose of interconnecting multiple customer VPCs through the TR 10, the VPC connection component is configured with routing information pointing to the TR 10 by default, based on which all the messages reaching the VPC connection component in the customer VPC will be sent to the TR 10. Of course, before sending the message to the TR 10, the message can also be tunnel encapsulated by using the tunnel protocol used by the customer VPC. In order to facilitate the distinction and description, in the embodiments of the present application, the message before tunnel encapsulation is referred to as the original message, and the message after tunnel encapsulation is referred to as the tunnel message. That is to say, the VPC connection component not only has the routing function but also has the tunnel encapsulation and decapsulation functions.

[0037] In the embodiment, each customer VPC has its own available IP address network segment, and the service instance in the customer VPC can allocate an IP address from the IP address network segment of the customer VPC. From the perspective of access role, the service instance in the customer VPC is divided into a client that initiates an access request and a server that provides a service. In the embodiment, the client in the customer VPC 11 is in the availability zone AZ1, the server in the customer VPC 12 is in the availability zone AZ4, and the client in the customer VPC 11 can access the service provided by the server in the customer VPC 12 through the TR 10. For the convenience of description, the service provided by the server in the customer VPC 12 is referred to as the target service. Figure 1a In the embodiment, the client in the customer VPC 11 is in the availability zone AZ1, the server in the customer VPC 12 is in the availability zone AZ4, and the client in the customer VPC 11 can access the service provided by the server in the customer VPC 12 through the TR 10. For the convenience of description, the service provided by the server in the customer VPC 12 is referred to as the target service. Figure 1a As shown, the VPC connection component 11a is deployed in the customer VPC 11, the VPC connection component 12a is deployed in the customer VPC 12, and the VPC connection component 11a and the VPC connection component 12a are interconnected with the TR 10 respectively. Wherein, mounting the VPC connection component under the TR 10 refers to adding the identification of the VPC connection component on the TR 10, and establishing the binding relationship between the TR 10 and the VPC connection component. In addition, in order to achieve the purpose of interconnecting multiple customer VPCs through the TR 10, the VPC connection component is configured with routing information pointing to the TR 10 by default, based on which all the messages reaching the VPC connection component in the customer VPC will be sent to the TR 10. Of course, before sending the message to the TR 10, the message can also be tunnel encapsulated by using the tunnel protocol used by the customer VPC. In order to facilitate the distinction and description, in the embodiments of the present application, the message before tunnel encapsulation is referred to as the original message, and the message after tunnel encapsulation is referred to as the tunnel message. That is to say, the VPC connection component not only has the routing function but also has the tunnel encapsulation and decapsulation functions.

[0038] Step 1, the client in the customer VPC 11 initiates an original message for accessing the target service to the VPC connection component 11a in the customer VPC 11, which can be a service request but is not limited thereto.

[0039] In the embodiment, the original packet initiated by the client has five-tuple information, the source IP address in the five-tuple information is the IP address of the client, the source port number is the port number of the client, the destination IP address is the IP address of the target service (or service end), the destination port number is the port number of the target service (or service end), and the transmission protocol can be TCP or UDP, which is not limited in the embodiment.

[0040] In step 2, the VPC connection component 11a receives the original packet initiated by the client, encapsulates the original packet into a first tunnel packet based on the locally pre-configured default routing information pointing to the TR 10, and sends the first tunnel packet to the TR 10.

[0041] Specifically, the VPC connection component 11a adds first tunnel encapsulation information to the original packet to generate a first tunnel packet. The first tunnel encapsulation information includes a tunnel ID corresponding to the client VPC 11 and tunnel five-tuple information, the source IP address in the tunnel five-tuple information is the IP address corresponding to the VPC connection component 11a, which can be the IP address of the VPC connection component 11a itself or the IP address of the virtual network card device carrying the VPC connection component 11a, the source port number is a randomly allocated port number or a default port number, the destination IP address is the IP address of the TR 10, and the destination port number is the port number of the TR 10.

[0042] In step 3, the TR 10 encapsulates the first tunnel packet into a second tunnel packet according to the pre-configured routing information between the client VPC 11 and the client VPC 12, and sends the second tunnel packet to the VPC connection component 12a in the client VPC 12.

[0043] Specifically, the TR 10 replaces the first tunnel encapsulation information in the first tunnel packet with second tunnel encapsulation information to obtain a second tunnel packet. The second tunnel encapsulation information includes a tunnel ID corresponding to the client VPC 12 and tunnel five-tuple information, the source IP address in the tunnel five-tuple information is the IP address of the TR 10, the source port number is the port number of the TR 10, the destination IP address is the IP address corresponding to the VPC connection component 12a, which can be the IP address of the VPC connection component 12a itself or the IP address of the virtual network card device carrying the VPC connection component 12a, and the destination port number is a randomly allocated port number or a default port number. In order to realize cross-VPC intercommunication, the TR 10 has a tunnel decapsulation and re-encapsulation function in addition to the cross-VPC routing function.

[0044] In step 4, the VPC connection component 12a parses the second tunnel packet to obtain the original packet, and sends the original packet to the service end in the AZ4 in the client VPC 12, so that the service end provides the target service for the client.

[0045] After the server provides the target service for the client, the server returns the service result to the client by using the process shown in steps 5-8. Steps 5-8 are the reverse process of steps 1-4, and the processing operations are the same or similar, which will not be described in detail here.

[0046] In the above service access process, there may be a security risk for the client VPC 11 and the client VPC 12. In order to ensure the security of the client VPC intercommunication, the security management VPC 13 is introduced in the cloud networking system 100 in the embodiment of the present application. The security management VPC 13 is also a VPC, which has the general attributes and characteristics of a VPC, and will not be described in detail. The security management VPC 13 can be provided by a third-party service provider, or can be provided by a cloud vendor of the cloud networking system 100, or can be provided by the client itself, and no limitation is made on this. The security management VPC 13 includes a plurality of security service nodes, which are used to provide security services externally, specifically, to provide security services in the service intercommunication process of the client VPC, to ensure the security of the client VPC. Through these security services, it can be configured which traffic can be released, and which traffic cannot be released, i.e., needs to be filtered or discarded, so as to ensure the security of the client VPC intercommunication.

[0047] In the embodiment, the form of the security service provided by the security management VPC 13 externally is not limited, and correspondingly, the implementation form of the security service node is also not limited. For example, the security service node can be, but is not limited to, a firewall, an intrusion detection and prevention system, a deep packet inspection system, etc. In the embodiment, the security management VPC 13 can only include the same type of security service node, for example, all security service nodes are firewalls, so as to provide one type of security service externally; of course, the security management VPC 13 can also include a plurality of different security service nodes at the same time, for example, the security management VPC 13 includes a firewall and a deep packet inspection system at the same time, so as to provide different security services externally, and no limitation is made on this. Figure 1a In the embodiment, the security management VPC 13 includes two availability zones, which are availability zone AZ5 and availability zone AZ6, and the security service node is taken as an example of a firewall for illustration, but is not limited to this. It is explained that, Figure 1a In the embodiment, the availability zones included in each VPC can be the same availability zone or different availability zones. For example, the availability zone AZ1 and the availability zone AZ3 are the same availability zone, and the availability zone AZ2 and the availability zone AZ4 are the same availability zone; of course, the availability zone AZ1 and the availability zone AZ3 can be different availability zones, and the availability zone AZ2 and the availability zone AZ4 can be different availability zones.

[0048] In the embodiment, the security management VPC 13 provides security services for each customer VPC in the cloud networking system 100. In order to ensure high availability and scalability of the security management VPC 13, a gateway load balancer (GWLB) is used in the security management VPC 13. The security service nodes in the security management VPC 13 that provide security services are mounted behind the GWLB. The security management VPC 13 exposes a service object to the outside world as the GWLB, thereby providing a load-balanced security service to the outside world. Based on the GWLB, the availability of deploying, expanding and managing security service nodes in the security management VPC 13 becomes simple and cost-effective. However, because the GWLB and the TR are not in the same plane and cannot be directly interconnected, in order to realize communication between the client and the server, the TR uses tunneling technology, while the GWLB does not use tunneling technology, so the two cannot be directly interconnected. Therefore, in the cloud networking system 100 of the embodiment, a new product object, i.e., a GWLB attachment 14, is added as a routing medium between the TR and the GWLB, realizing interconnection between the TR and the GWLB.

[0049] The GWLB attachment of the embodiment is a logical product object with a traffic forwarding function, which can be regarded as a special type of terminal endpoint of a private link. Compared with the endpoint of a traditional private link, the special type of endpoint has more functions. The GWLB attachment has at least the following functions: on the one hand, the GWLB attachment 14 can be associated with a specified GWLB and can be directly connected to the associated GWLB. It can be understood that the GWLB attachment has load balancing capability, and the traffic aggregated to the GWLB attachment can be loaded to each security service node by the GWLB for security processing; on the other hand, the GWLB attachment 14 is similar to the VPC attachment and can be interconnected with the TR 10, and can be used as the next hop in the routing information of the TR 10. When the routing configuration is performed on the TR 10, the GWLB attachment can be configured as the next hop. It can be understood that the GWLB attachment has gateway capability and has an aggregation effect on the boundary traffic from the gateway TR 10 in the TR networking. In short, the GWLB attachment 14 of the embodiment combines the gateway and load balancing capabilities, which can aggregate the traffic from the gateway boundary in the TR networking on the one hand, and can load balance the aggregated traffic to each security service node by means of the load balancing capability of the GWLB on the other hand. In addition, the GWLB attachment also combines the tunnel encapsulation and decapsulation functions to adapt to the tunnel function of the TR 10.

[0050] Based on the above, the security routing information can also be configured on the TR 10 to point to the GWLB connection component by default, and the security routing information refers to routing information that needs to use the security management VPC to provide security services. Each piece of security routing information involves two customer VPCs, indicating that the traffic between the two customer VPCs needs to be securely processed. Optionally, the traffic between the two customer VPCs can support one-way security processing or two-way security processing. For the security routing information, the next hop is the GWLB connection component 14, which is used to introduce the traffic between the two customer VPCs that needs to be securely processed into the security management VPC through the GWLB connection component 14 for security processing.

[0051] In this embodiment, the security routing information involves traffic between two customer VPCs, and the security routing information includes network segment information of the two customer VPCs it involves. If it is one-way security processing, the security routing information indicates that all traffic from one customer VPC to another customer VPC needs to be securely processed by the security service node in the security management VPC 13. If it is two-way security processing, the security routing information indicates that all traffic between the two customer VPCs needs to be securely processed by the security service node in the security management VPC 13. Taking customer VPC 11 and customer VPC 12 as an example, a security routing information that supports one-way security processing can be configured: customer VPC 11->customer VPC 12 needs to be securely processed, and the next hop is the GWLB connection component. The network segment information of customer VPC 11 and the network segment information of customer VPC 12 are included in the security routing information. Taking customer VPC 11 and customer VPC 12 as an example, a security routing information that supports two-way security processing can be configured: customer VPC 11->customer VPC 12 needs to be securely processed, and customer VPC 12->customer VPC 11 needs to be securely processed, and the next hop is the GWLB connection component. The network segment information of customer VPC 11 and the network segment information of customer VPC 12 are included in the security routing information.

[0052] Based on the above security routing information, the TR 10 can introduce the traffic between the two customer VPCs that needs to be securely processed through the GWLB connection component and the GWLB into the security management VPC 13 for security processing. That is, during the service access process between the two customer VPCs corresponding to the security routing information, the GWLB connection component and the GWLB can use the security service node in the security management VPC to provide security services for the service access process, realize secure access, and solve the security problems faced by the customer VPCs during intercommunication in the TR networking scenario.

[0053] It is noted that in addition to configuring secure routing information, regular routing information can also be configured on TR 10. Regular routing information also involves two customer VPCs, but the traffic between the two customer VPCs does not need to be securely processed. In other words, no security processing is required. For this type of routing information, the service access process between the two customer VPCs can be processed according to the process described in steps 1-8 above, which will not be specifically described in this embodiment of the application.

[0054] Furthermore, based on the addition of the security control VPC and GWLB connection components, and in combination with the secure routing information and regular routing information pre-configured on TR 10, any client in any customer VPC in the cloud networking system 100 can initiate service access to another customer VPC. The VPC connection component in any customer VPC can receive an original message initiated by a client in its customer VPC, encapsulate the original message into a first tunnel message, and send the first tunnel message to TR 10 based on the routing information directed to TR 10. TR 10 can receive the first tunnel message from any customer VPC and identify whether the routing information corresponding to the first tunnel message is secure routing information. If the routing information corresponding to the first tunnel message is secure routing information, it will send the first tunnel message to the GWLB connection component 14, so that the original message can be securely authenticated through the GWLB using the security service node in the security control VPC 13.

[0055] Specifically, when identifying whether the routing information corresponding to the first tunnel message is secure routing information, TR 10 can parse the original message from the first tunnel message and determine the network segment information of the source customer VPC and the destination customer VPC based on the source IP address and destination IP address in the original message. If the source IP address in the original message is the IP address of the client, the network segment information of the customer VPC to which the client belongs can be determined based on the client IP address. This customer VPC is also the source customer VPC. Correspondingly, if the destination IP address in the original message is the IP address of the target service or server, the network segment information of the customer VPC to which the target service or server belongs can be determined based on the IP address of the target service or server. This customer VPC is also the destination customer VPC. The network segment information of the source customer VPC and the destination customer VPC is matched against at least one piece of secure routing information. If a piece of secure routing information is matched, the routing information corresponding to the first tunnel message is determined to be secure routing information, and the matched secure routing information is the routing information corresponding to the first tunnel message.

[0056] The GWLB connection component 14 can receive the first tunnel message sent by the security control VPC 13, parse the original message from the first tunnel message, and send the original message to the GWLB, so that the GWLB load balances the original message to the security service node in the security control VPC for security authentication. Furthermore, the GWLB connection component 14 can also optionally perform session management on the first tunnel message and record session information corresponding to the first tunnel message. This session information includes the first tunnel encapsulation information corresponding to the first tunnel message and the five-tuple information in the original message, so that the first tunnel message can be returned to the TR 10 based on this session information if the original message passes security authentication.

[0057] Continuing from the above, GWLB receives the original message sent by the GWLB connection component 14. On the one hand, it performs session management on the original message, maintains the session connection to which the original message belongs, and records the session information of the original message, which may include the five-tuple information of the original message, etc. On the other hand, it load balances the original message to the target security service node in the security management VPC, so that the target security service node performs security authentication on the original message based on the local security policy; if the original message passes the security authentication, the target security service node generates a security message based on the original message and returns the security message to the GWLB. Optionally, if the original message fails the security authentication, the target security service node can discard the original message. Optionally, the security message has the same payload information as the original message and contains the five-tuple information in the original message. The difference is that the message format is different. Optionally, GWLB can adopt various load balancing algorithms, such as hashing the five-tuple of the original message, so as to load balance the original message to the target security service node in the security control VPC, and can load balance the original messages belonging to the same session to the same security service node as much as possible, but is not limited to this.

[0058] After receiving the security packet, the GWLB returns the security packet to the GWLB connection component 14; the GWLB connection component 14 is also configured to receive the security packet returned by the GWLB, regenerate the first tunnel packet according to the session information corresponding to the first tunnel packet and the security packet, and return the first tunnel packet to the TR 10. Specifically, the GWLB connection component 14 can match the five-tuple information in the original packet carried in the security packet in the session information corresponding to each tunnel packet, so as to determine that the security packet corresponds to the session information corresponding to the first tunnel packet; then, according to the first tunnel encapsulation information in the session information corresponding to the first tunnel packet, the security packet is tunnel encapsulated to obtain the first tunnel packet again. For example, the first tunnel encapsulation information can be added to the security packet to obtain the first tunnel packet. Alternatively, the GWLB can determine according to the above session information that the first tunnel packet needs to be returned to the TR 10, or also maintain routing information pointing to the TR 10, and based on the routing information, the first tunnel packet obtained by re-encapsulation can be sent to the TR 10.

[0059] Further, the TR 10 also receives the first tunnel message returned by the TR, and according to the security routing information corresponding to the first tunnel message, the first tunnel message can be encapsulated into a second tunnel message and provided to another customer VPC providing the target service, so that the another customer VPC provides the target service for any customer VPC requesting the target service. Specifically, according to the security routing information corresponding to the first tunnel message, the second tunnel encapsulation information can be determined, and the first tunnel encapsulation information corresponding to the first tunnel message is replaced with the second tunnel encapsulation information to obtain the second tunnel message. The first tunnel encapsulation information includes the tunnel ID corresponding to any customer VPC requesting the target service and the corresponding tunnel five-tuple information, the source IP address in the tunnel five-tuple information is the IP address corresponding to the VPC connection component in any customer VPC, the source port number is a randomly allocated port number or a default port number, the destination IP address is the IP address of the TR 10, and the destination port number is the port number of the TR 10. According to the network segment information of another customer VPC in the security routing information corresponding to the first tunnel message, it can be determined who the another customer VPC is, and then based on the corresponding relationship between the customer VPC and the tunnel ID, the tunnel ID corresponding to the another customer VPC can be determined; in addition, the IP address corresponding to the VPC connection component in the another customer VPC can also be determined as the destination IP address in the second tunnel encapsulation information, which points to the target service. In the case that there are multiple IP addresses corresponding to the VPC connection component in the another customer VPC, and all of the multiple IP addresses can point to the target service, a hash algorithm or a random selection algorithm can be used to select an IP address from the multiple IP addresses. For example, the tunnel five-tuple information in the first tunnel message can be hashed, and the IP address corresponding to the hash result is determined according to the hash result. Accordingly, the second tunnel encapsulation information is determined, which includes the tunnel ID corresponding to the another customer VPC providing the target service and the corresponding tunnel five-tuple information, the source IP address in the tunnel five-tuple information is the IP address of the TR 10, the source port number is the port number of the TR 10, the destination IP address is the IP address corresponding to the VPC connection component in the another customer VPC, and the destination port number is a randomly allocated port number or a default port number or a default port number.

[0060] It is explained that in the above embodiment, when determining the IP address corresponding to the VPC connection component in another customer VPC as the destination IP address in the second tunnel encapsulation information, it is not limited whether the client and the server must be located in the same availability zone. In an optional embodiment, according to the application requirement, the client and the server need to be located in the same availability zone, when determining the IP address corresponding to the VPC connection component in another customer VPC, the availability zone where the client is located can be combined to determine, specifically, the IP address located in the availability zone where the client is located can be selected from the multiple IP addresses corresponding to the VPC connection component in another customer VPC, as the destination IP address in the second tunnel encapsulation information. Wherein, TR 10 can obtain the availability zone information where the client is located according to the user's configuration information, or the availability zone information where the client is located can also be carried in the message header of the original message, and TR 10 obtains the availability zone information where the client is located from the message header of the original message by analyzing the first tunnel message.

[0061] Wherein, after the second tunnel message is sent to the VPC connection component in another customer VPC, the VPC connection component parses the security message from the second tunnel message, provides the security message to the server, and the server provides the target service. The service result can pass through the VPC connection component in another customer VPC, TR 10, the VPC connection component in any customer VPC initiating service access, and finally reach the client. In this process, the encapsulation and decapsulation process of the message will also be involved, which will not be described in detail.

[0062] The above describes the security access process in which the routing information corresponding to the first tunnel message belongs to the security routing information. Alternatively, the routing information corresponding to the first tunnel message can also be regular routing information. In the case that the routing information corresponding to the first tunnel message is regular routing information, TR 10 can directly determine the second tunnel encapsulation information according to the regular routing information corresponding to the first tunnel message, replace the first tunnel encapsulation information corresponding to the first tunnel message with the second tunnel encapsulation information, obtain the second tunnel message, and send the second tunnel message to the VPC connection component in another customer VPC providing the target service; the VPC connection component parses the security message from the second tunnel message, provides the security message to the server, and the server provides the target service. The service result can pass through the VPC connection component in another customer VPC, TR 10, the VPC connection component in any customer VPC initiating service access, and finally reach the client. In this process, the encapsulation and decapsulation process of the message will also be involved, which will not be described in detail.

[0063] In order to more clearly understand the process of secure intercommunication between customer VPCs in the cloud networking system 100 provided by the embodiments of the present application, the process of secure intercommunication between customer VPCs in the cloud networking system 100 provided by the embodiments of the present application will be described in combination with Figure 1aTaking a process that a client in the customer VPC 11 accesses a target service provided by a service end in the customer VPC 12 through the TR 10 as an example, the entire service access process is exemplarily described in combination with Figure 1a

[0064] Step 1, a client in the customer VPC 11 initiates an original message for accessing a target service to the VPC connection component 11a in the customer VPC 11, which can be a service request but is not limited thereto.

[0065] Step 2, the VPC connection component 11a receives the original message initiated by the client, encapsulates the original message into a first tunnel message based on the default routing information pointing to the TR 10 pre-configured locally, and sends the first tunnel message to the TR 10.

[0066] Step 2.1, the TR 10 receives the first tunnel message sent by the VPC connection component 11a, and sends the first tunnel message to the GWLB connection component 14 in a case that the routing information corresponding to the first tunnel message belongs to the security routing information.

[0067] Step 2.2, the GWLB connection component 14 receives the first tunnel message sent by the security control VPC 13, parses the original message from the first tunnel message, and sends the original message to the GWLB.

[0068] Step 2.3, the GWLB receives the original message sent by the GWLB connection component 14, load balances the original message to a target security service node in the security control VPC, so that the target security service node performs security authentication on the original message based on a local security policy.

[0069] Step 2.4, in a case that the original message passes the security authentication, the target security service node generates a security message according to the original message, and returns the security message to the GWLB.

[0070] Step 2.5, the GWLB receives the security message, and returns the security message to the GWLB connection component 14.

[0071] Step 2.6, the GWLB connection component 14 receives the security message, regenerates the first tunnel message and returns the first tunnel message to the TR 10.

[0072] Step 3, the TR 10 encapsulates the first tunnel message into a second tunnel message according to the security routing information pre-configured between the customer VPC 11 and the customer VPC 12, and sends the second tunnel message to the VPC connection component 12a in the customer VPC 12.

[0073] ​Step 4, the VPC connection component 12a parses the second tunnel message to obtain a security message, and sends the security message to a service end in the AZ4 in the customer VPC 12, so that the service end provides a target service for the client.

[0074] Step 5, the service end returns a service result to the VPC connection component 12a.

[0075] Step 6, the VPC connection component 12a encapsulates the service result into a third tunnel message, and sends the third tunnel message to the TR 10.

[0076] The third tunnel message corresponds to third tunnel encapsulation information, and the third tunnel encapsulation information includes a tunnel ID corresponding to the customer VPC 12 and tunnel five-tuple information, wherein a source IP address in the tunnel five-tuple information is an IP address corresponding to the VPC connection component 12a, a source port number is a randomly allocated port number, a destination IP address is an IP address of the TR 10, and a destination port number is a port number of the TR 10.

[0077] Step 7, the TR 10 encapsulates the third tunnel message into a fourth tunnel message, and sends the fourth tunnel message to the VPC connection component 11a.

[0078] Further optionally, in step 7, if the pre-configured security routing information between the customer VPC 11 and the customer VPC 12 needs one-way security processing, after receiving the third tunnel message sent by the VPC connection component 12a, the TR 10 directly encapsulates the third tunnel message into the fourth tunnel message, and sends the fourth tunnel message to the VPC connection component 11a.

[0079] Further optionally, in step 7, if the pre-configured security routing information between the customer VPC 11 and the customer VPC 12 needs two-way security processing, before step 7 is performed, the TR 10 can process the third tunnel message by referring to the processes in steps 2.1-2.6, and then perform the operation of encapsulating the third tunnel message into the fourth tunnel message and sending the fourth tunnel message to the VPC connection component 11a in step 7 when the third tunnel message is received again from the GWLB connection component 14. The process of processing the third tunnel message by referring to steps 2.1-2.6 is the same as or similar to the process of processing the first tunnel message, and will not be described here.

[0080] Specifically, the third tunnel encapsulation information corresponding to the third tunnel message is replaced by fourth tunnel encapsulation information to obtain the fourth tunnel message. The fourth tunnel encapsulation information includes a tunnel ID corresponding to the customer VPC 11 and tunnel five-tuple information, wherein a source IP address in the tunnel five-tuple information is an IP address of the TR 10, a source port number is a port number of the TR 10, a destination IP address is an IP address corresponding to the VPC connection component 11a, and a destination port number is a randomly allocated port number.

[0081] Step 8, the VPC connection component 11a parses the fourth tunnel message to obtain a service result, and sends the service result to the client.

[0082] Further optionally, in the case that the routing information corresponding to the first tunnel message belongs to the regular routing information, steps 2.1-2.6 can be skipped, and steps 3-8 are directly entered.

[0083] In the above embodiments of the present application, in the TR-based cloud networking system, the security management VPC is introduced, the GWLB is used in the security management VPC, and the GWLB is taken as an exposed object for providing security services. Since the GWLB is no longer in the same plane as the TR, a new product object, i.e., the GWLB connection component, is further added in the networking system as a routing medium between the TR and the GWLB, to realize the interconnection between the TR and the GWLB. Further, by configuring the security routing information on the TR that points to the GWLB connection component by default, the security services can be provided in the service access process between the two customer VPCs corresponding to the security routing information, the secure intercommunication is realized, and the security problem faced by the customer VPCs in the TR networking scenario is solved.

[0084] In addition, it should be noted that, in addition to directly adding the GWLB connection component between the TR and the GWLB to realize the interconnection between the TR and the GWLB in the present embodiment, the GWLB connection component can also be added between the TR and the GWLB in the following manner. Figure 1b As shown in the figure, an intermediate VPC is added between the TR and the GWLB, the VPC connection component and the GWLB endpoint (GWLBe) corresponding to the GWLB are deployed in the intermediate VPC, the GWLBe is interconnected with the GWLB, the GWLBe is interconnected with the VPC connection component, and the VPC connection component is interconnected with the TR 10. Figure 1b In the present embodiment, the intermediate VPC includes two availability zones AZ7 and AZ8, but is not limited thereto. Figure 1bIn the system shown, the security access process between the TR and the firewall includes steps 3.1-3.8, and the traffic forwarding path is relatively long and the transmission delay is relatively large, but the security service access in the TR networking scenario can be realized and the security problem in the TR networking scenario can be solved. Compared with the way of realizing the interconnection between the TR and the GWLB through the intermediate VPC, the VPC connection component and the GWLB, in the embodiment of the present application, the GWLB connection component is directly added between the TR and the GWLB, and the interconnection between the TR and the GWLB is realized by the GWLB connection component, which is beneficial to simplify the implementation of the security service access in the TR networking scenario. Moreover, the intercommunication traffic between the customer VPCs only needs to flow into the GWLB through the TR and the GWLB connection component and then use the security service, and the traffic forwarding path is relatively short, which is beneficial to reduce the transmission delay on the path.

[0085] Steps 3.1-3.8 are described simply as follows: step 3.1, the TR sends a first tunnel message to the VPC connection component in the intermediate VPC; step 3.2, the VPC connection component in the intermediate VPC parses the original message from the first tunnel message and sends the original message to the GWLB; step 3.3, the GWLB sends the original message to the GWLB; step 3.4, the GWLB balances the original message to a security service node (for example, a certain firewall) for security authentication; step 3.5, the security service node generates a security message according to the original message in the case that the original message passes the security authentication, and sends the security message to the GWLB; step 3.6, the GWLB sends the security message to the GWLB; step 3.7, the GWLB sends the security message to the VPC connection component in the intermediate VPC; and step 3.8, the VPC connection component in the intermediate VPC re-encapsulates the security message into the first tunnel message and returns it to the TR. Figure 1b Steps 1-8 in the above embodiment are the same as or similar to steps 1-8 in the above embodiment, and will not be described again. Figure 1a Steps 1-8 in the above embodiment are the same as or similar to steps 1-8 in the above embodiment, and will not be described again.

[0086] In the embodiment of the present application, the GWLB connection component is a logical product object with traffic forwarding function as a network element instance, and its traffic forwarding function can be carried by a virtual network card device. Accordingly, the security routing information and the conventional routing information are configured on the virtual network card device, and the virtual network card device is interconnected with the TR. However, it should be noted that the GWLB connection component does not belong to the customer VPC or the security control VPC, but belongs to the system VPC, and the GWLB connection component is invisible to the customer, so it does not need to consume the virtual network card resources in the customer VPC and the security control VPC, which is beneficial to save the network card resources of the customer VPC.

[0087] Similarly, the VPC connection component in the customer VPC also has a traffic forwarding function, and the traffic forwarding function of the VPC connection component can be carried by a virtual network card device. Correspondingly, the routing information pointing to the TR is configured on the virtual network card device, and the virtual network card device is interconnected with the TR. Further, in the case that the customer VPC includes at least one availability zone, the VPC connection component in the customer VPC can include a virtual network card device corresponding to each availability zone, that is, at least one virtual network card device can be configured for each availability zone, and preferably, one availability zone corresponds to one virtual network card device. Each virtual network card device is responsible for receiving a request message initiated by a client in the corresponding availability zone to access a target service, encapsulating the request message into a first tunnel message, and sending the first tunnel message to the TR based on the routing information pointing to the TR. Specifically, the virtual network card device also has a tunnel encapsulation and decapsulation function, can add first tunnel encapsulation information to the request message to generate a first tunnel message, and the first tunnel encapsulation information includes a tunnel identifier ID corresponding to the customer VPC to which the virtual network card device belongs, an IP address of the virtual network card device as a source IP address, and an IP address of the TR as a destination IP address.

[0088] In an optional embodiment, the virtual network card device can be an elastic network interface (ENI). The ENI is a virtual network card bound to various VPCs (for example, customer VPCs and system VPCs). For example, the ENI provides a private IP address for a VPC connection component or a GWLB connection component bound to the ENI. The private IP address can be an IP address in the VPC to which the ENI belongs, that is, an IP address of the VPC connection component or the GWLB connection component carried by the ENI. In this embodiment, the main function of the ENI is to interconnect with the TR and be responsible for traffic forwarding with the TR.

[0089] In an optional embodiment, the cloud networking system of the present embodiment further comprises a management and control node. The management and control node belongs to a control plane node, and is configured to provide a human-computer interaction interface for a customer, and to receive various requests from the customer and respond to the requests. Specifically, the management and control node can respond to a creation request of a forwarding router to create a TR in a system VPC, and respond to a routing configuration operation to configure at least one piece of security routing information on the created TR. In addition, a VPC connection component is deployed in each of two customer VPCs corresponding to each piece of security routing information, and an identifier of the deployed VPC connection component is added to the TR to establish an association between the VPC connection component and the TR. In addition, in a cloud networking scenario based on a TR, when a customer needs to introduce a GWLB-based service, a GWLB connection component can also be created for the GWLB service through the management and control node. Specifically, the management and control node can also respond to a creation request of a GWLB connection component to deploy the GWLB connection component in a system VPC and specify a GWLB associated with the GWLB connection component. In the present embodiment, the GWLB points to a security management and control service. Further, an identifier of the GWLB connection component is added to the TR to establish a correspondence between the TR and the GWLB connection component, so that the GWLB connection component can be used as a next hop in the security routing information. It should be noted that the creation of the GWLB connection component and the creation of the TR are relatively independent, and the customer can create them flexibly according to application requirements.

[0090] It should be noted that in the cloud networking system, there can be one or more TRs, and Figure 1a In the present embodiment, a TR is taken as an example for illustration. In the case of multiple TRs, each TR has a corresponding GWLB connection component, and the GWLB connection components corresponding to the multiple TRs can be associated with the same GWLB, i.e., the multiple TRs can use the services provided by the VPC where the same GWLB is located.

[0091] It should be noted that the cloud networking system provided by the embodiments of the present application is not only applicable to the scenario of introducing a security control VPC, but can be extended to the scenario of introducing any GWLB-based intermediate service VPC. The intermediate service VPC refers to a VPC that can provide some intermediate service in the service intercommunication process between customer VPCs through a TR. For example, the intermediate service VPC can be a data cleaning service, a data computing service, or a security service. Based on this, the embodiments of the present application further provide another cloud networking system. The cloud networking system includes a TR and a plurality of customer VPCs interconnected with the TR. The plurality of customer VPCs perform service intercommunication through the TR. Further, the cloud networking system further includes an intermediate service VPC. The intermediate service VPC includes a GWLB and a plurality of intermediate service nodes interconnected with the GWLB, and is configured to provide an intermediate service externally. Further, the cloud networking system further includes a GWLB connection component. The GWLB connection component is a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB, respectively. Based on this, at least one security routing information pointing to the GWLB connection component is configured on the TR. The TR can use the intermediate service nodes in the intermediate service VPC through the GWLB connection component and the GWLB to provide an intermediate service for the service access process between the two customer VPCs corresponding to each security routing information. For the definitions, descriptions, and detailed descriptions of the related components or objects in the cloud networking system, please refer to the foregoing embodiments, which will not be described here.

[0092] In addition to the cloud networking system described above, the embodiments of the present application further provide the following several security access methods. These security access methods are described from the perspectives of the TR, the GWLB connection component, and the VPC connection component, respectively. For details, please refer to the method embodiments shown in Figures 2a-2c

[0093] Figure 2a A flowchart of a security access method provided by an exemplary embodiment of the present application is shown. The method is described from the perspective of a forwarding router TR, as shown in Figure 2a The method includes the following steps.

[0094] 21a, receiving a first tunnel packet from any customer VPC in the cloud networking system. The first tunnel packet is obtained by tunneling an original packet according to a request of the any customer VPC to another customer VPC for a target service;

[0095] 22a, if the routing information corresponding to the first tunnel packet belongs to security routing information, sending the first tunnel packet to the GWLB connection component in the cloud networking system, so as to use the security service node in the security control VPC to perform security authentication on the original packet through the GWLB in the security control VPC.

[0096] ​In the embodiment, in the cloud networking system, a new product object, i.e., a GWLB connection component, is added; the GWLB connection component is connected with the TR and the GWLB as a routing medium between the TR and the GWLB, and the GWLB is connected with a security service node in the security control VPC.

[0097] In the embodiment, the TR is preconfigured with at least one kind of security routing information pointing to the GWLB connection component by default, each piece of security routing information involves two customer VPCs and indicates that the traffic between the two customer VPCs needs to be subjected to security processing. Optionally, the traffic between the two customer VPCs can support one-way security processing or bidirectional security processing.

[0098] Further optionally, the security routing information involves the traffic between two customer VPCs, and the security routing information includes the network segment information of the two customer VPCs involved. If it is one-way security processing, the security routing information indicates that all the traffic from one customer VPC to another customer VPC needs to be subjected to security processing by the security service node in the security control VPC. If it is bidirectional security processing, the security routing information indicates that all the traffic between the two customer VPCs needs to be subjected to security processing by the security service node in the security control VPC 13. Based on this, the TR can use the security service node in the security control VPC to provide security services for the service access process of the two customer VPCs corresponding to each piece of security routing information through the GWLB connection component and the GWLB.

[0099] Specifically, the TR can receive a first tunnel message from any customer VPC in the cloud networking system, and the first tunnel message is obtained by tunnel encapsulating an original message according to a request for a target service from the any customer VPC to another customer VPC. If the routing information corresponding to the first tunnel message belongs to security routing information, the first tunnel message is sent to the GWLB connection component in the cloud networking system to use the security service node in the security control VPC to perform security authentication on the original message through the GWLB in the security control VPC.

[0100] Further optionally, the method further includes the step of identifying whether the routing information corresponding to the first tunnel message belongs to security routing information. The step specifically includes: parsing the original message from the first tunnel message, determining the network segment information of the source customer VPC and the destination customer VPC according to the source IP address and the destination IP address in the original message, matching the network segment information of the source customer VPC and the destination customer VPC in at least one piece of security routing information, and determining that the routing information corresponding to the first tunnel message is security routing information if the matching is successful.

[0101] Further optionally, the method further comprises: receiving a first tunnel message returned by the GWLB connection component, the first tunnel message being regenerated by the GWLB connection component according to a security message returned by the GWLB in a case that the original message passes the security authentication, the security message being generated by a security service node in the security management VPC according to the original message in a case that the original message passes the security authentication; encapsulating the first tunnel message into a second tunnel message, and providing the second tunnel message to another customer VPC, so as to enable the another customer VPC to provide the target service for any customer VPC.

[0102] Further optionally, the encapsulating the first tunnel message into the second tunnel message comprises: replacing first tunnel encapsulation information corresponding to the first tunnel message with second tunnel encapsulation information according to security routing information corresponding to the first tunnel message, to obtain the second tunnel message; the second tunnel encapsulation information comprises a tunnel identifier ID corresponding to the another customer VPC, and a source IP address in the second tunnel encapsulation information is an IP address of the TR and a destination IP address is an IP address corresponding to a VPC connection component in the another customer VPC; the first tunnel encapsulation information comprises a tunnel ID corresponding to any customer VPC, and a source IP address in the first tunnel encapsulation information is an IP address corresponding to a VPC connection component in any customer VPC and a destination IP address is an IP address of the TR.

[0103] In the embodiment, a new product object, i.e., a GWLB connection component, is added in the cloud networking system, as a routing medium between the TR and the GWLB, to realize interconnection between the TR and the GWLB, and by configuring default security routing information pointing to the GWLB connection component on the TR, security services can be provided in a service access process between two customer VPCs corresponding to the security routing information, security intercommunication is realized, and the security problem faced by the customer VPCs in the TR networking scenario when intercommunicating is solved.

[0104] Figure 2b Another flowchart of a security access method provided by the exemplary embodiments of the present application is provided; the method is described from the perspective of the GWLB connection component, as shown in Figure 2b The method comprises:

[0105] 21b, receiving a first tunnel message sent by a forwarding router TR in a cloud networking system, the first tunnel message being obtained by tunnel encapsulation according to an original message in which any customer VPC in the cloud networking system requests a target service from another customer VPC;

[0106] 22b, parsing the original message from the first tunnel message, and sending the original message to a GWLB in a security management VPC, so as to enable the GWLB to load balance the original message to a security service node in the security management VPC for security authentication.

[0107] In the embodiment, a new product object, i.e., a GWLB connection component, is added in the cloud networking system; the GWLB connection component is connected with the TR and the GWLB respectively as a routing medium between the TR and the GWLB, and the GWLB is connected with a security service node in the security control VPC.

[0108] In the embodiment, the TR can receive a first tunnel message from any customer VPC in the cloud networking system, the first tunnel message being obtained by tunnel encapsulation according to an original message of the any customer VPC requesting a target service from another customer VPC; if the routing information corresponding to the first tunnel message belongs to security routing information, the first tunnel message is sent to the GWLB connection component in the cloud networking system.

[0109] In the embodiment, in addition to being connected with the TR and the GWLB respectively, the GWLB connection component can also receive the first tunnel message sent by the TR in the cloud networking system, parse the original message from the first tunnel message, and send the original message to the GWLB in the security control VPC, so that the GWLB performs load balancing on the original message to the security service node in the security control VPC for security authentication. The GWLB connection component also has the functions of message transceiving and decapsulation (or parsing).

[0110] Further optionally, the method further includes: recording the session information corresponding to the first tunnel message before sending the original message to the GWLB; and receiving a security message returned by the GWLB after sending the original message to the GWLB, the security message being generated and provided to the GWLB by the security service node in the security control VPC according to the original message in the case that the original message passes the security authentication; further, the first tunnel message is regenerated according to the session information corresponding to the first tunnel message and the security message, and returned to the TR, so that the TR encapsulates the first tunnel message into a second tunnel message and provides the second tunnel message to another customer VPC, so as to make the another customer VPC provide the target service for the any customer VPC. As can be seen, in the embodiment, the GWLB connection component also has the functions of message encapsulation, session recording and maintenance, etc.

[0111] In the embodiment, a new product object, i.e., a GWLB connection component, is added in the cloud networking system; the GWLB connection component is connected with the TR and the GWLB respectively as a routing medium between the TR and the GWLB, and the GWLB is connected with a security service node in the security control VPC.

[0112] Figure 2cA flowchart of another security access method provided for the exemplary embodiments of the present application is shown in FIG. 21c. The method is described from the perspective of a VPC connection component, as shown in FIG. 21c, and includes the following steps: Figure 2c

[0113] 21c, receiving an original packet from a client in a customer VPC where the VPC connection component is located, where the client requests to access a target service;

[0114] 22c, encapsulating the original packet into a first tunnel packet according to pre-configured routing information pointing to a TR;

[0115] 23c, sending the first tunnel packet to the TR, so as to perform service intercommunication with another customer VPC in a cloud networking system that provides the target service through the TR.

[0116] In this embodiment, a new product object, i.e., a GWLB connection component, is added in the cloud networking system. The GWLB connection component serves as a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB, respectively. In the security control VPC, the GWLB is interconnected with the security service node.

[0117] When the client in the customer VPC requests to access the target service, the original packet is sent to the VPC connection component. The VPC connection component receives the original packet and encapsulates the original packet into a first tunnel packet according to pre-configured routing information pointing to the TR. The first tunnel packet is sent to the TR. The TR can receive the first tunnel packet, and if the routing information corresponding to the first tunnel packet belongs to security routing information, the first tunnel packet is sent to the GWLB connection component in the cloud networking system. The GWLB connection component receives the first tunnel packet sent by the TR, parses the original packet from the first tunnel packet, and sends the original packet to the GWLB in the security control VPC, so that the GWLB performs security authentication on the original packet by load balancing the original packet to the security service node in the security control VPC.

[0118] In this embodiment, a new product object, i.e., a GWLB connection component, is added in the cloud networking system. The GWLB connection component serves as a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB, respectively. In the security control VPC, the GWLB is interconnected with the security service node.

[0119] ​It should be noted that in some of the processes described in this specification, including the processes described with respect to the accompanying figures, multiple processes are presented in sequential order. However, it should be appreciated that unless otherwise stated, these processes can not be performed in the order as described and / or illustrated. That is, unless specifically stated, it is not a requirement that all processes be performed in the order illustrated in any one or more of the figures, or sequential order. Further, it should be noted that certain processes can be performed concurrently. Moreover, it should be noted that one or more processes can be performed by one or more of the entities illustrated in the figures, and / or one or more processes can be performed by a different entity than illustrated in the figures. It should also be noted that one or more processes illustrated in the figures can be performed multiple times (e.g., iterative processes). It is to be understood that the terminology "first," "second," and the like can be used in this disclosure to describe different processes, different devices, different modules, and the like, unless specifically stated otherwise. Such terminology is not intended to limit the order of processes, devices, modules, and the like, unless specifically stated.

[0120] Figure 3a A structure diagram of a security access device is provided for an exemplary embodiment of the present application. The device can be implemented in a forwarding router TR in a cloud networking system, as shown in Figure 3a The device includes a storage module 31a, a receiving module 32a, and a sending module 33a.

[0121] The storage module 31a is configured to store at least one piece of security routing information that points to a GWLB connection component in the cloud networking system. The receiving module 32a is configured to receive a first tunnel message from any customer VPC in the cloud networking system, the first tunnel message being obtained by tunneling an original message according to a request for a target service from any customer VPC to another customer VPC. The sending module 33a is configured to send the first tunnel message to the GWLB connection component in a case where routing information corresponding to the first tunnel message is security routing information, so as to use a security service node in a security control VPC to perform security authentication on the original message by a GWLB in the security control VPC; wherein the GWLB connection component is a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB respectively, and the GWLB is interconnected with the security service node.

[0122] In an optional embodiment, the device further includes an analysis module configured to analyze the original message from the first tunnel message, and determine network segment information of a source customer VPC and a destination customer VPC according to a source IP address and a destination IP address in the original message; and a matching module configured to match the network segment information of the source customer VPC and the destination customer VPC in the at least one piece of security routing information; and determine that the routing information corresponding to the first tunnel message is security routing information if a match is found.

[0123] In an optional embodiment, the receiving module 32a is further configured to receive the first tunnel message returned by the GWLB connection component, the first tunnel message being a security message returned by the GWLB connection component according to the GWLB in the case that the original message passes the security authentication, and the security message being generated according to the original message. Correspondingly, the sending module 33a is further configured to encapsulate the first tunnel message into a second tunnel message, and provide the second tunnel message to another customer VPC, so as to enable the another customer VPC to provide the target service for any customer VPC.

[0124] Further optionally, when encapsulating the first tunnel message into the second tunnel message, the sending module 33a is specifically configured to replace first tunnel encapsulation information corresponding to the first tunnel message with second tunnel encapsulation information according to the security routing information corresponding to the first tunnel message, to obtain the second tunnel message; the second tunnel encapsulation information includes a tunnel identifier ID corresponding to the another customer VPC, and the source IP address in the second tunnel encapsulation information is the IP address of the TR, and the destination IP address is the IP address of the VPC connection component in the another customer VPC; the first tunnel encapsulation information includes a tunnel ID corresponding to any customer VPC, and the source IP address in the first tunnel encapsulation information is the IP address of the VPC connection component in any customer VPC, and the destination IP address is the IP address of the TR.

[0125] Figure 3b Another structural schematic diagram of a security access device is provided for the exemplary embodiments of the present application. The device can be located in a GWLB connection component in a cloud networking system, as shown in Figure 3b The device includes an unpackaging module 31b, a receiving module 32b, and a sending module 33b.

[0126] The receiving module 32b is configured to receive a first tunnel message sent by a forwarding router TR in a cloud networking system, the first tunnel message being obtained by tunnel encapsulation according to an original message in which any customer VPC in the cloud networking system requests a target service from another customer VPC. The unpackaging module 31b is configured to parse the original message from the first tunnel message. The sending module 33b is configured to send the original message to a GWLB in a security management VPC, so that the GWLB load balances the original message to a security service node in the security management VPC for security authentication. The GWLB connection component is a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB, and the GWLB is interconnected with the security service node.

[0127] In an optional embodiment, the apparatus further comprises a packaging module and a session management module. The session management module is configured to record session information corresponding to the first tunnel message before sending the original message to the GWLB. The receiving module 32b is further configured to receive a security message returned by the GWLB after sending the original message to the GWLB, the security message being generated according to the original message in the case that the original message passes security authentication. The packaging module is configured to regenerate the first tunnel message according to the session information corresponding to the first tunnel message and the security message. The sending module 33b is further configured to return the first tunnel message to the TR, so that the TR encapsulates the first tunnel message into the second tunnel message and provides the second tunnel message to another customer VPC.

[0128] Figure 3c Another structural schematic diagram of a security access apparatus provided for an exemplary embodiment of the present application is provided. The apparatus can be located in a VPC connection component in a cloud networking system, and is implemented as shown in Figure 3c The apparatus comprises a packaging module 31c, a receiving module 32c and a sending module 33c.

[0129] The receiving module 32c is configured to receive an original message in which a client in a customer VPC where the VPC connection component is located requests to access a target service. The packaging module 31c is configured to encapsulate the original message into a first tunnel message according to pre-configured routing information pointing to a forwarding router TR. The sending module 33c is configured to send the first tunnel message to the TR, so that the TR performs service intercommunication with another customer VPC in the cloud networking system which provides the target service.

[0130] In the above description, detailed functions implemented by each module in each apparatus can refer to the related description in the foregoing method or system embodiments, which will not be described herein again.

[0131] Figure 4 A structural schematic diagram of a forwarding router provided for an exemplary embodiment of the present application is provided. The forwarding router can be implemented as a cloud computing device, comprising a memory 41, a processor 42 and a communication component 43.

[0132] The memory 41 is configured to store computer programs, and can be configured to store other various data to support operations on the forwarding router. Examples of the data include instructions of any application program or method used for operations on the forwarding router, messages, pictures, videos, etc. Further, the memory 41 is further configured to store at least one security routing information pointing to a GWLB connection component in a cloud networking system by default.

[0133] Processor 42 is coupled to memory 41 and configured to execute a computer program in memory 41 to provide security services for the service access process between two customer VPCs corresponding to each secure routing information, using a GWLB connection component in the security control VPC and the GWLB using a security service node in the security control VPC. The GWLB connection component serves as a routing intermediary between the TR and the GWLB, interconnecting with the TR and the GWLB, respectively, and the GWLB is interconnected with the security service node.

[0134] Optionally, the processor 42 is specifically used to: receive a first tunnel message from any customer VPC in the cloud networking system through the communication component 43, where the first tunnel message is obtained by tunnel encapsulating the original message from any customer VPC requesting the target service from another customer VPC; if the routing information corresponding to the first tunnel message is security routing information, send the first tunnel message to the GWLB connection component in the cloud networking system, so that the original message can be securely authenticated using the security service node in the security control VPC through the GWLB in the security control VPC.

[0135] Optionally, the processor 42 is further used to: parse the original message from the first tunnel message, determine the network segment information of the source customer VPC and the destination customer VPC based on the source IP address and the destination IP address in the original message; match the network segment information of the source customer VPC and the destination customer VPC in at least one secure routing information; if there is a match, determine that the routing information corresponding to the first tunnel message is secure routing information.

[0136] Optionally, the processor 42 is further used to: receive a first tunnel message returned by the GWLB connection component through the communication component 43, where the first tunnel message is regenerated by the GWLB connection component based on the security message returned by the GWLB when the original message passes security authentication, and the security message is generated based on the original message; encapsulate the first tunnel message into a second tunnel message, and provide it to another customer VPC, so that the other customer VPC provides the target service for any customer VPC.

[0137] Optionally, the processor 42 is specifically used to: replace the first tunnel encapsulation information corresponding to the first tunnel message with the second tunnel encapsulation information according to the security routing information corresponding to the first tunnel message, to obtain a second tunnel message; the second tunnel encapsulation information includes the tunnel identification ID corresponding to another customer VPC, and the source IP address in the second tunnel encapsulation information is the IP address of TR, and the destination IP address is the IP address corresponding to the VPC connection component in another customer VPC; the first tunnel encapsulation information includes the tunnel ID corresponding to any customer VPC, and the source IP address of the first tunnel encapsulation information is the IP address corresponding to the VPC connection component in any customer VPC, and the destination IP address is the IP address of TR.

[0138] Further, as shown in Figure 4 the forwarding router further comprises a power supply component 44 and other components. Figure 4 Some components are only schematically shown in the figure, and it does not mean that the forwarding router only comprises the components shown in the figure. Figure 4

[0139] Correspondingly, the embodiment of the present application also provides a computer readable storage medium storing a computer program, and the computer program is executed by a processor to enable the processor to implement each step that can be executed by the TR in the above method embodiment.

[0140] The embodiment of the present application provides a cloud computing device, and Figure 4 the forwarding router shown in the figure has the same or similar structure, and is not shown in the figure, and can be referred to the forwarding router shown in the figure. Figure 4 The cloud computing device provided by the embodiment can be implemented as a GWLB connection component in a cloud networking system, comprising a memory and a processor, the memory is used to store a computer program, and the processor is coupled with the memory and used to execute the computer program stored in the memory, so as to: receive a first tunnel message sent by a forwarding router TR in the cloud networking system, the first tunnel message is obtained by tunnel encapsulation according to an original message of any customer VPC in the cloud networking system to another customer VPC requesting a target service; parse the original message from the first tunnel message, and send the original message to a GWLB in a security control VPC, so that the GWLB load balances the original message to a security service node in the security control VPC for security authentication; the GWLB connection component is a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB respectively, and the GWLB is interconnected with the security service node.

[0141] Further optionally, the processor is further used to: record session information corresponding to the first tunnel message before the original message is sent to the GWLB; and receive a security message returned by the GWLB after the original message is sent to the GWLB, the security message is generated according to the original message in the case that the original message passes the security authentication; regenerate the first tunnel message according to the session information corresponding to the first tunnel message and the security message, and return the first tunnel message to the TR, so that the TR encapsulates the first tunnel message into a second tunnel message and provides the second tunnel message to another customer VPC.

[0142] Correspondingly, the embodiment of the present application also provides a computer readable storage medium storing a computer program, and the computer program is executed by a processor to enable the processor to implement each step that can be executed by the GWLB connection component in the above method embodiment.

[0143] The embodiment of the present application provides a cloud computing device, and Figure 4 ​The illustrated forwarding routers have the same or similar structure, and therefore are not shown. For details, refer to Figure 4 The cloud computing device provided by the embodiment can be implemented as a VPC connection component in a cloud networking system, and includes a memory and a processor. The memory is configured to store a computer program. The processor is coupled to the memory and configured to execute the computer program stored in the memory, so as to: receive an original packet in which a client in a customer VPC where the VPC connection component is located requests to access a target service; encapsulate the original packet into a first tunnel packet according to pre-configured routing information pointing to a forwarding router TR; and send the first tunnel packet to the TR, so as to perform service intercommunication with another customer VPC in the cloud networking system which provides the target service through the TR.

[0144] Correspondingly, the embodiment of the present application further provides a computer readable storage medium storing a computer program. When the computer program is executed by a processor, the processor can implement each step that can be executed by the VPC connection component in the above method embodiment.

[0145] The memory in the above embodiment can be implemented by any type of volatile or non-volatile storage devices or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic storage, a flash memory, a magnetic disk or an optical disk.

[0146] The communication component in the above embodiment is configured to facilitate wired or wireless communication between the device where the communication component is located and other devices. The device where the communication component is located can access a wireless network based on a communication standard, such as a WiFi, a 2G, 3G, 4G / LTE, 5G or other mobile communication network, or a combination thereof. In an example embodiment, the communication component receives a broadcast signal or broadcast related information from an external broadcast management system via a broadcast channel. In an example embodiment, the communication component further includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra wide band (UWB) technology, Bluetooth (BT) technology and other technologies.

[0147] The power supply component in the above embodiment provides power for various components of the device where the power supply component is located. The power supply component can include a power management system, one or more power supplies, and other components associated with generating, managing and distributing power for the device where the power supply component is located.

[0148] Those skilled in the art will appreciate that embodiments of the present application can be readily used as a method, a system or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer readable storage media (including, but not limited to, disk memory, CD-ROMs, optical storage devices, etc.) embodying computer readable program code.

[0149] The present application is described in reference to the flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams block or blocks.

[0150] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the function specified in the flowchart illustrations and / or block diagrams block or blocks.

[0151] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart illustrations and / or block diagrams block or blocks.

[0152] In one typical configuration, the computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0153] The memory can include non-persistent memory and / or volatile memory, such as random access memory (RAM) and / or cache memory, non-volatile memory, such as read-only memory (ROM), EPROM, and / or flash memory, etc. The memory is an example of computer readable media.

[0154] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.

[0155] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusions, so that a process, method, article or apparatus that includes a list of elements does not only include those elements, but also includes other elements not explicitly listed, or further includes elements inherent in such a process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.

[0156] The above only is an embodiment of the present application, and is not used to limit the present application. For those skilled in the art, the present application can have various changes and variations. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application shall be included in the scope of claims of the present application.

Claims

1. A cloud networking system, characterized in that: include: A forwarding router TR, and multiple customer virtual private clouds (VPCs) interconnected with the TR; The multiple customer VPCs perform service mutual access through the TR; The cloud networking system further includes: a security management VPC, wherein the security management VPC includes a gateway load balancing device GWLB and a plurality of security service nodes interconnected with the GWLB for providing security services externally; A GWLB connection component is also deployed in the cloud networking system. The GWLB connection component serves as a routing medium between the TR and the GWLB, interconnecting with the TR and the GWLB respectively. The GWLB connection component is a network element instance with traffic forwarding function, integrating gateway and load balancing functions, and is used to aggregate traffic from gateway boundaries in the TR network and load balance the aggregated traffic to various security service nodes using the load balancing function of the GWLB. The TR is configured with at least one piece of security routing information pointing to the GWLB connection component by default, so as to provide security services for the service access process between two customer VPCs corresponding to each piece of security routing information, through the GWLB connection component and the GWLB using the security service node in the security control VPC; The TR has tunnel decapsulation and recapsulation functions, and the GWLB connection component has tunnel encapsulation and decapsulation functions adapted to the TR.

2. The system according to claim 1, wherein: The TR is specifically configured to: receive a first tunnel message from any customer VPC, where the first tunnel message is obtained by tunnel encapsulating an original message from any customer VPC requesting a target service from another customer VPC; If the routing information corresponding to the first tunnel message is secure routing information, send the first tunnel message to the GWLB connection component, so that the GWLB uses the security service node in the security control VPC to perform security authentication on the original message; The GWLB connection component is used to parse the original message from the first tunnel message and send the original message to the GWLB, so that the GWLB load balances the original message to the security service node in the security management VPC for security authentication.

3. The system according to claim 2, characterized in that The GWLB connection component is further configured to: record session information corresponding to the first tunnel message; and receive a security message returned by the GWLB, regenerate the first tunnel message based on the session information corresponding to the first tunnel message and the security message, and return the message to the TR. The security message is generated by the security service node in the security control VPC based on the original message and sent to the GWLB when the original message passes security authentication. The TR is further configured to receive the first tunnel message returned by the GWLB connection component, encapsulate the first tunnel message into a second tunnel message, and provide the second tunnel message to the other customer VPC, so that the other customer VPC provides the target service for any of the customer VPCs.

4. The system according to any one of claims 1 to 3, characterized in that: A VPC connection component is deployed in each of the multiple customer VPCs; the VPC connection component is configured with default routing information pointing to the TR, which is used to encapsulate the original message in the customer VPC requesting access to the target service into a first tunnel message, and send the first tunnel message to the TR, so as to achieve service exchange with another customer VPC providing the target service through the TR.

5. The system according to any one of claims 1 to 3, characterized in that: Also includes: Control nodes, used to execute: In response to the forwarding router creation request, create a forwarding router TR in the system VPC, and in response to the route configuration operation, configure at least one secure routing information on the TR, deploy VPC connection components in the two customer VPCs corresponding to each secure routing information, and add identifiers of the VPC connection components to the TR; and / or In response to a creation request of a GWLB connection component, the GWLB connection component is deployed in the system VPC and a GWLB associated with the GWLB connection component is specified; and an identifier of the GWLB connection component is added to the TR to establish a corresponding relationship between the TR and the GWLB connection component.

6. A secure access method, characterized in that: The method is applied to a forwarding router TR in a cloud networking system, and includes: Receiving a first tunnel message from any customer VPC in the cloud networking system, where the first tunnel message is obtained by tunnel encapsulating an original message from any customer VPC requesting a target service from another customer VPC; If the routing information corresponding to the first tunnel message is secure routing information, the first tunnel message is sent to the GWLB connection component in the cloud networking system, so that the GWLB in the security control VPC uses the security service node in the security control VPC to perform security authentication on the original message; Among them, the security routing information points to the GWLB connection component, and the GWLB connection component serves as a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB respectively, and the GWLB is interconnected with the security service node; the GWLB connection component is a network element instance with traffic forwarding function, integrating gateway and load balancing functions, and is used to aggregate traffic from the gateway boundary in the TR network, and with the help of the load balancing function of the GWLB, load balance the aggregated traffic to each security service node; the TR has tunnel decapsulation and recapsulation functions, and the GWLB connection component has tunnel encapsulation and decapsulation functions adapted to the TR.

7. The method according to claim 6, characterized in that Also includes: Parsing the original message from the first tunnel message, and determining the network segment information of the source customer VPC and the destination customer VPC based on the source IP address and the destination IP address in the original message; According to the network segment information of the source customer VPC and the destination customer VPC, the network segment information is matched in at least one secure routing information; if there is a match, the routing information corresponding to the first tunnel message is determined to be secure routing information.

8. The method according to claim 6 or 7, characterized in that Also includes: receiving a first tunnel message returned by the GWLB connection component, where the first tunnel message is regenerated by the GWLB connection component based on the security message returned by the GWLB when the original message passes security authentication, and the security message is generated based on the original message; The first tunnel message is encapsulated into a second tunnel message, and the second tunnel message is provided to the other customer VPC, so that the other customer VPC provides the target service for any of the customer VPCs.

9. The method according to claim 8, characterized in that Encapsulating the first tunnel message into a second tunnel message includes: According to the security routing information corresponding to the first tunnel message, the first tunnel encapsulation information corresponding to the first tunnel message is replaced with the second tunnel encapsulation information to obtain a second tunnel message; The second tunnel encapsulation information includes a tunnel identification ID corresponding to the other customer VPC, and the source IP address in the second tunnel encapsulation information is the IP address of the TR, and the destination IP address is the IP address corresponding to the VPC connection component in the other customer VPC; The first tunnel encapsulation information includes the tunnel ID corresponding to any customer VPC, and the source IP address of the first tunnel encapsulation information is the IP address corresponding to the VPC connection component in any customer VPC, and the destination IP address is the IP address of the TR.

10. A secure access method, characterized in that: A gateway load balancing device GWLB connection component applied to a cloud networking system, the method comprising: Receiving a first tunnel message sent by a forwarding router TR in the cloud networking system, where the first tunnel message is obtained by tunnel encapsulating an original message from any customer VPC in the cloud networking system requesting a target service from another customer VPC; Parsing the original message from the first tunnel message, and sending the original message to a GWLB in the security control VPC, so that the GWLB load balances the original message to a security service node in the security control VPC for security authentication; The GWLB connection component serves as a routing medium between the TR and the GWLB, and is interconnected with the TR and the GWLB respectively. The GWLB is interconnected with the security service node. The GWLB connection component is a network element instance with traffic forwarding function, integrating gateway and load balancing functions, and is used to aggregate traffic from the gateway boundary in the TR network, and load balance the aggregated traffic to each security service node with the help of the GWLB's load balancing function. The TR has tunnel decapsulation and recapsulation functions, and the GWLB connection component has tunnel encapsulation and decapsulation functions adapted to the TR.

11. The method according to claim 10, characterized in that Also includes: Before sending the original message to the GWLB, recording the session information corresponding to the first tunnel message; as well as After sending the original message to the GWLB, receiving a security message returned by the GWLB, where the security message is generated based on the original message when the original message passes security authentication; The first tunnel message is regenerated according to the session information corresponding to the first tunnel message and the security message, and is returned to the TR, so that the TR encapsulates the first tunnel message into a second tunnel message and provides it to the other customer VPC.

12. A forwarding router, applicable to a cloud networking system, characterized in that: include: memory and processor; The memory is used to store a computer program and at least one piece of security routing information that defaults to a gateway-type load balancing device GWLB connection component in a cloud networking system; the processor, coupled to the memory, is used to execute the computer program to execute the steps in the method described in any one of claims 6-9.

13. A cloud computing device that can be implemented as a gateway load balancing device (GWLB) connection component in a cloud networking system, characterized in that: include: memory and processor; The memory is used to store a computer program, and the processor, coupled to the memory, is used to execute the computer program to perform the steps in the method according to any one of claims 10 to 11.

14. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the processor is enabled to implement the steps of the method according to any one of claims 6 to 9 and claims 10 to 11.

15. A cloud networking system, characterized in that: include: A forwarding router TR, and multiple customer virtual private clouds (VPCs) interconnected with the TR; The multiple customer VPCs perform service mutual access through the TR; The cloud networking system further includes: an intermediate service VPC, wherein the intermediate service VPC includes a gateway load balancing device GWLB and a plurality of intermediate service nodes interconnected with the GWLB, for providing intermediate services externally; A GWLB connection component is also deployed in the cloud networking system. The GWLB connection component serves as a routing medium between the TR and the GWLB, interconnecting with the TR and the GWLB respectively. The GWLB connection component is a network element instance with traffic forwarding function, integrating gateway and load balancing functions, and is used to aggregate traffic from gateway boundaries in the TR network and load balance the aggregated traffic to various intermediate service nodes with the help of the GWLB's load balancing function. The TR is configured with at least one piece of secure routing information pointing to the GWLB connection component by default, so as to provide intermediate services for the service access process between two customer VPCs corresponding to each piece of secure routing information, through the GWLB connection component and the GWLB using the intermediate service node in the intermediate service VPC; The TR has tunnel decapsulation and recapsulation functions, and the GWLB connection component has tunnel encapsulation and decapsulation functions adapted to the TR.

Citation Information

Patent Citations

  • Secure resource pool realization method and secure resource pool system

    CN107920023A

  • Method and system for achieving VPC peer-to-peer connection in public cloud platform based on openstack

    CN110401588A

  • Scheduling method and device for security service in VPC environment

    CN114244592A