A method, apparatus, system, electronic device, and storage medium for accelerating cloud access.
By combining the SDWAN controller and the WireGuard protocol, the account information of enterprise employees is automatically migrated to the same regional access point, solving the problem of low-speed cloud access for enterprise employees when they are on business trips in different locations, and realizing seamless cloud acceleration and efficient cloud resource access.
Patent Information
- Application Number
- CN202211733514.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-30
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2042-12-30
AI Technical Summary
When employees are traveling to different locations, they cannot access the cloud network through the nearest access point, resulting in low-speed cross-regional internet connections that affect cloud access speed. Furthermore, existing solutions require manual intervention and user operation, making configuration complex and unfriendly.
An SDWAN controller is introduced to centrally manage access points in the cloud network. The WireGuard protocol enables smooth switching between clients and access points and automatically migrates account information to access points in the same region. By combining the SDWAN controller and the WireGuard protocol, the cloud migration of clients is accelerated.
It enables cross-regional cloud access acceleration without manual intervention or user awareness, improving cloud access speed, simplifying the configuration process, reducing message exchange complexity, and improving access efficiency.
Smart Images

Figure CN116233216B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a cloud acceleration method, apparatus, system, electronic device, and storage medium. Background Technology
[0002] Cloud computing resource pools and services are typically divided and deployed geographically, with resources in different regions connected via high-speed links. Enterprises usually apply for cloud resources in the nearest region based on their geographical location. Administrators then assign accounts to the employees who need the resources and activate client access services, enabling employees to access the cloud network through the access point in that region.
[0003] However, cloud access via client software has a certain degree of mobility. For example, when employees travel to other locations, because the company has not opened relevant access services in the employee's location, the access point in the employee's location does not have the employee's relevant information. Therefore, the employee can only access the cloud network through the low-speed cross-regional Internet access point in the company's location, and then access the cloud network through that access point. Summary of the Invention
[0004] In view of the above problems, embodiments of this application provide a cloud access acceleration method, apparatus, system, electronic device, and storage medium to overcome or at least partially solve the above problems.
[0005] A first aspect of this application provides a cloud access acceleration method applied to a first access point, the method comprising:
[0006] Establish a connection with the client and determine the client's location;
[0007] Determine whether the location of the specified territory is outside the territory of the first access point;
[0008] If the location of the client is outside the territory of the first access point, the location and account information of the client are sent to the SDWAN controller to request the SDWAN controller to determine the second access point and synchronize the account information of the client to the second access point. The second access point is an access point whose territory includes the location of the client.
[0009] The system receives the public IP address of the second access point sent by the SDWAN controller and sends the public IP address of the second access point to the client, so that the client can access the cloud network through the nearest Internet in the same region.
[0010] Optionally, the connection established with the client is based on the WireGuard protocol;
[0011] Sending the public IP address of the second access point to the client includes:
[0012] Based on the notification message structure newly added to the WireGuard protocol, a notification message carrying the public IP address of the second access point is generated;
[0013] The notification message is sent to the client.
[0014] Optionally, the notification message includes at least the following:
[0015] The instruction message is a message type used to notify the client to update the IP address of the access point;
[0016] A random key encrypted using the client's public key;
[0017] The public IP address of the second access point, encrypted using the random key.
[0018] Optionally, the connection established with the client is based on the WireGuard protocol;
[0019] Determining the geographical location of the client includes:
[0020] Obtain the handshake initialization message used during the process of establishing a WireGuard connection between the first access point and the client;
[0021] Obtain the client's public IP address from the handshake initialization message;
[0022] The location of the client is determined based on the IP address database and the client's public IP address.
[0023] A second aspect of this application provides a cloud access acceleration method applied to a client, the method comprising:
[0024] A connection is established with the first access point via a cross-regional Internet, and cloud network access is performed through the first access point;
[0025] The system receives the public IP address of the second access point sent by the first access point. The second access point is an access point that the SDWAN controller determines based on the location of the client and synchronizes the client's account information.
[0026] Based on the public IP address of the second access point, a connection is established with the second access point via the nearest Internet in the same region, and cloud network access is performed through the second access point.
[0027] Optionally, the connections established with the first access point and the second access point are based on the WireGuard protocol;
[0028] The cloud network access via the first access point includes:
[0029] Cloud network access is achieved through a tunnel between the first WireGuard virtual port of the client and the second WireGuard virtual port corresponding to the public IP address of the first access point;
[0030] Accessing the cloud network through the second access point includes:
[0031] Cloud network access is achieved through a tunnel between the first WireGuard virtual port and the third WireGuard virtual port, wherein the third WireGuard virtual port is the second WireGuard virtual port after the corresponding IP address has been adjusted to the public IP address of the second access point.
[0032] Optionally, the connections established with the first access point and the second access point are based on the WireGuard protocol;
[0033] The step of receiving the public IP address of the second access point sent by the first access point includes:
[0034] Receive a notification message sent by the first access point carrying the public IP address of the second access point. The notification message is generated according to the notification message structure added to the WireGuard protocol.
[0035] The step of establishing a connection with the second access point via a nearby internet connection in the same region includes:
[0036] Send a handshake initialization message to the second access point via the nearest Internet in the same region;
[0037] Receive the handshake response message returned by the second access point via the nearest Internet in the same region.
[0038] A third aspect of this application provides a cloud access acceleration method applied to an SDWAN controller, the method comprising:
[0039] Receive the client's location and account information sent by the first access point;
[0040] Based on the information of all access points stored in the SDWAN controller and the location of the client, a second access point whose location range includes the location is determined;
[0041] The client's account information is sent to the second access point, and the public IP address of the second access point is sent to the first access point, so as to control the first access point to migrate the client's traffic to the second access point.
[0042] Optionally, the method further includes:
[0043] Traffic statistics of the client are obtained from the second access point at set intervals, and the account information of the client sent by the SDWAN controller is retrieved from the second access point.
[0044] A fourth aspect of this application provides a cloud access acceleration device applied to a first access point, the device comprising:
[0045] The processing module is used to establish a connection with the client and determine the client's location.
[0046] The determination module is used to determine whether the location is outside the geographical area of the first access point;
[0047] The sending module is configured to send the client's location and account information to the SDWAN controller when the location is outside the territory of the first access point, so as to request the SDWAN controller to determine a second access point and synchronize the client's account information to the second access point, wherein the second access point is an access point whose territory includes the location.
[0048] The transmission module is used to receive the public IP address of the second access point sent by the SDWAN controller, and send the public IP address of the second access point to the client, so that the client can access the cloud network through the nearest Internet in the same region.
[0049] A fifth aspect of this application provides a cloud acceleration device applied to a client, the device comprising:
[0050] The first access module is used to establish a connection with the first access point via the cross-regional Internet and to access the cloud network through the first access point.
[0051] The first receiving module is used to receive the public IP address of the second access point sent by the first access point. The second access point is an access point determined by the SDWAN controller based on the location of the client and synchronized with the client's account information.
[0052] The second access module is used to establish a connection with the second access point through the nearest Internet in the same region based on the public IP address of the second access point, and to access the cloud network through the second access point.
[0053] A sixth aspect of this application provides a cloud access acceleration device applied to an SDWAN controller, the device comprising:
[0054] The information receiving module is used to receive the client's location and account information sent by the first access point;
[0055] The access point determination module is used to determine a second access point whose geographical range includes the geographical location, based on the information of all access points stored by the SDWAN controller and the geographical location of the client.
[0056] The information transmission module is used to send the client's account information to the second access point and send the public IP of the second access point to the first access point, so as to control the first access point to migrate the client's traffic to the second access point.
[0057] A seventh aspect of this application provides a cloud access acceleration system, the system comprising a first access point, a second access point, an SDWAN controller, and a client, wherein:
[0058] When the first access point establishes a connection with the client, it executes the cloud access acceleration method as described in the first aspect to request the SDWAN controller to determine the second access point, synchronize the client's account information to the second access point, and enable the client to access the cloud network through the nearest Internet in the same region.
[0059] An eighth aspect of this application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the cloud acceleration method described in the first, second, or third aspect.
[0060] A ninth aspect of this application provides a computer-readable storage medium having a computer program / instructions stored thereon, which, when executed by a processor, implements the steps of the cloud acceleration method as described in the first, second, or third aspect.
[0061] A tenth aspect of this application provides a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of the cloud acceleration method described in the first, second, or third aspect.
[0062] The embodiments of this application have the following advantages:
[0063] In this embodiment, an SDWAN controller is introduced to centrally manage all access points in the cloud network. The SDWAN controller finds a second access point in the same region as the client and synchronizes the client's account information to the second access point, enabling the client to switch to the second access point to access the cloud network. This changes the client's access from a low-speed cross-regional cloud access method to a higher-speed intra-regional cloud access method. Furthermore, it enables the client to subsequently access cloud resources in the region where the first access point is located through the high-speed cloud connection network between access points, thereby accelerating the client's cloud access. Attached Figure Description
[0064] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0065] Figure 1 This is a schematic diagram of the basic model of existing client software cloud migration services;
[0066] Figure 2 This is a diagram illustrating the existing low-speed cross-regional cloud access.
[0067] Figure 3 This is a schematic diagram of existing solutions for low-speed cross-regional cloud access;
[0068] Figure 4 This is a flowchart illustrating an implementation of a cloud acceleration method according to an embodiment of this application;
[0069] Figure 5 This is a schematic diagram illustrating the implementation process of cloud acceleration according to an embodiment of this application;
[0070] Figure 6 This is a schematic diagram of a connection switching process in an embodiment of this application;
[0071] Figure 7 This is a flowchart illustrating another cloud acceleration method implemented in this application.
[0072] Figure 8 This is a flowchart illustrating another cloud acceleration method in the embodiments of this application;
[0073] Figure 9 This is a schematic diagram of the structure of a cloud acceleration device according to an embodiment of this application;
[0074] Figure 10 This is a schematic diagram of another cloud acceleration device according to an embodiment of this application;
[0075] Figure 11 This is a schematic diagram of another cloud acceleration device according to an embodiment of this application;
[0076] Figure 12 This is a schematic diagram of an electronic device according to an embodiment of this application. Detailed Implementation
[0077] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0078] With the widespread adoption of cloud computing, more and more enterprises are gradually deploying their business application systems in the cloud to reduce construction and maintenance costs and improve efficiency, thus accelerating their cloud transformation process. Cloud computing vendors also provide various solutions, such as smart gateway hardware and dedicated client software, to meet enterprises' cloud adoption needs.
[0079] Cloud computing resource pools and services are generally divided and deployed according to regions. Resources in different regions are connected through high-speed links, and enterprise users usually choose the nearest region to purchase cloud services.
[0080] like Figure 1 The diagram illustrates the basic model of existing client software cloud migration services. It uses a Point of Presence (POP) in the North China region as an example. Figure 1 Taking POP1 as an example, the client software on users 1 and 2's devices migrates to the cloud through the following steps:
[0081] (1) Enterprises apply for cloud resources (i.e. cloud resources) in the nearest region based on their geographical location. The administrator opens the client access service through the control flow between the cloud platform and POP1 and assigns accounts (such as users 1 and 2) to the enterprise employees who need them.
[0082] (2) Employees log in to the client software, and through the Virtual Private Network (VPN) service provided by the software, they access the cloud provider POP1 in the same region via the nearest Internet in the same region, and then through the high-speed cloud connection network where POP1 is located for acceleration, and enter the cloud gateway to access cloud resources.
[0083] Considering that cloud-based services using client software have a certain degree of mobility, such as scenarios where company employees travel across regions for business.
[0084] like Figure 2As shown, when an employee (i.e., business travel user 2) travels to (South China), because the company has not opened relevant services in South China, there is no relevant information about the business travel user on the POP corresponding to the Yunnan region. Therefore, business travel user 2 can only access the POP corresponding to the North China region through the low-speed cross-regional Internet to access cloud resources in the North China region.
[0085] like Figure 3 As shown, to accelerate cloud resource access for traveling employees, the current mainstream solution is for enterprise administrators to temporarily migrate employee accounts to the corresponding POP in the South China region via the cloud platform. Traveling employees then log in to the corresponding POP in the South China region through their client, and the connection is routed to the cloud via a high-speed link between the South China POP and the corresponding POP in the North China region to access cloud resources in the North China region. Once the employee returns from their business trip, the enterprise disables the roaming function for that employee account.
[0086] The above solution has the following problems:
[0087] First, account migration requires manual intervention from the backend, which is not user-friendly for enterprise users who travel frequently.
[0088] Second, employees need to manually change the access region, and the whole process cannot be done without the employees' awareness.
[0089] Third, the software clients provided by mainstream cloud vendors generally use traditional VPN protocols such as SSLVPN and OPENVPN. These protocols have two characteristics: First, they are large and comprehensive, resulting in complicated configuration and difficult configuration migration; second, the negotiation and exchange are complex, requiring negotiation between two protocols, Transmission Control Protocol (TCP) and Secure Socket Layer (SSL), and multiple rounds of exchange, making the protocols themselves too bloated.
[0090] To address the problems existing in the aforementioned related technologies, this application proposes an intelligent cross-regional cloud acceleration solution that requires no manual intervention, is imperceptible to the user, and is conducted without their knowledge.
[0091] The cloud acceleration method provided in this application will be described in detail below with reference to the accompanying drawings and through some embodiments and application scenarios.
[0092] Firstly, referring to Figure 4 The diagram shown is an implementation flowchart of a cloud access acceleration method provided in this application embodiment. The method is applied to a first access point and may include the following steps:
[0093] Step S11: Establish a connection with the client and determine the client's location.
[0094] In practice, the Software Defined Wide Area Network (SDWAN) controller pre-activates client access services for clients at the first access point and assigns accounts to clients, enabling clients to access cloud networks through the first access point, such as accessing cloud resources within the geographical area of the first access point.
[0095] The first access point confirms whether the client is a legitimate user based on the client's account information (i.e., the client whose account information is stored by the first access point). If the client is confirmed to be a legitimate user, the first access point establishes a connection with the client and simultaneously determines the client's geographical location (i.e., its geographical location).
[0096] Step S12: Determine whether the location of the territory is outside the territory of the first access point.
[0097] In practice, the first access point needs to determine whether the client accessing the cloud is located in the same region as itself, so as to filter out clients accessing the cloud from different regions and perform subsequent cloud acceleration.
[0098] Understandably, a region typically has only one access point. This access point connects to devices or device clusters in the resource pool of that region (i.e., the area where the access point is located), as well as access points in other regions, via a high-speed cloud network, thereby accelerating cloud access for clients accessing that access point. However, clients of business travelers usually access this access point via a low-speed cross-regional internet connection. This cross-regional cloud access method significantly impacts the client's cloud access speed, thus requiring cloud acceleration for these clients.
[0099] Step S13: If the location of the client is outside the territory of the first access point, send the location and account information of the client to the SDWAN controller to request the SDWAN controller to determine the second access point and synchronize the account information of the client to the second access point. The second access point is an access point whose territory includes the location of the client.
[0100] In practical implementation, SDWAN technology is introduced into cloud access scenarios. Access points in each region are responsible for basic network connections and traffic forwarding, while the SDWAN controller centrally manages all access points in the network; that is, the SDWAN controller possesses information on all access points. After receiving the client's location and account information from the first access point, the SDWAN controller can determine the geographical area of that location, locate the corresponding second access point, and send the client's account information to that second access point. This enables the client's account to migrate across regions, allowing the second access point to subsequently recognize the client as a legitimate user and provide cloud access acceleration services.
[0101] The SDWAN controller can connect to each access point through an encrypted control channel using either Secure Shell (SSH) or Secure Hypertext Transfer Protocol (HTTPS). This facilitates the SDWAN controller issuing control commands to the access points and the access points reporting status information to the SDWAN controller. As a result, the SDWAN controller can achieve centralized management and automated orchestration of each access point in the network, and can automatically complete cross-regional account migration operations for clients.
[0102] Step S14: Receive the public IP address of the second access point sent by the SDWAN controller, and send the public IP address of the second access point to the client so that the client can access the cloud network through the nearest Internet in the same region.
[0103] In practice, the first access point forwards the public IP address of the second access point to the client, so that the client can access the second access point via a higher-speed local internet connection based on the public IP address of the second access point. This optimizes the client's access to the first access point from a low-speed cross-regional internet connection to a connection via a higher-speed local internet connection to the second access point, and then to the first access point via a high-speed link (such as a cloud connection network) between the second and first access points, thereby accelerating the client's cross-regional cloud access.
[0104] The technical solution of this application embodiment introduces an SDWAN controller to centrally manage all access points in the cloud network. The SDWAN controller finds a second access point in the same region as the client and synchronizes the client's account information to the second access point, enabling the client to switch to the second access point to access the cloud network. This changes the client's access from a low-speed cross-regional cloud access mode to a higher-speed intra-regional cloud access mode. Furthermore, it enables the client to subsequently access cloud resources in the region where the first access point is located through the high-speed cloud connection network between access points, thereby accelerating the client's cloud access.
[0105] The following combination Figure 5 The above technical solution will be further explained below. This application provides an implementation process for cloud acceleration, including:
[0106] 1. The client of user 2 on a business trip establishes a connection with POP1 (i.e., the first access point) based on the WireGuard protocol and accesses cloud resources in the North China region (i.e., the area where the first access point is located). At this time, user 2's traffic enters POP1 through the low-speed cross-regional Internet.
[0107] It should be noted that, in order to achieve a seamless user experience, the client must be able to smoothly switch from one access point (such as a server or server cluster) to another.
[0108] To achieve the smooth handover described above, the access VPN protocol used must meet the following three requirements:
[0109] Ⅰ. Simple configuration and easy management, making it easy to migrate account information between access points in different regions.
[0110] II. The negotiation and exchange process is simple, and the handover from one access point to another can be completed with fewer message exchanges.
[0111] III. The client's routing information must not change throughout the entire process.
[0112] As the foregoing analysis of related technologies shows, traditional VPN protocols such as SSLVPN and OPENVPN are complex to configure and have complicated message exchanges, failing to meet the requirements. Therefore, this application introduces the WireGuard protocol, which the client uses to establish a VPN connection with the access point.
[0113] Understandably, the WireGuard protocol solidifies the information that other protocols, such as algorithms, need to negotiate, making configuration very simple and enabling the handshake to be completed and a connection established within one round trip time (RTT).
[0114] like Figure 6 As shown, the process of establishing a connection between a client and an access point (first access point or second access point) based on the WireGuard protocol may include: the client sending a handshake initialization message to the access point (i.e., Figure 5 As shown in ①); the access point returns a handshake response message to the client (i.e. Figure 5 ②) shown.
[0115] Because the WireGuard protocol uses virtual tunnel technology, it supports traffic forwarding through virtual tunnels. Therefore, when the actual IP address information of the virtual tunnel between the access point and the client changes (i.e., switching from the first access point to the second access point), the WireGuard virtual ports at both ends of the virtual tunnel do not change. Only the actual IP address corresponding to the WireGuard virtual port on the access point side is updated from the public IP address of the first access point to the public IP address of the second access point. For example, the client first accesses the cloud network through the tunnel between its own first WireGuard virtual port and the second WireGuard virtual port corresponding to the public IP address of the first access point. After switching to the second access point, the client will access the cloud network through the tunnel between the first WireGuard virtual port and the third WireGuard virtual port. The third WireGuard virtual port is the second WireGuard virtual port whose corresponding IP address has been adjusted to the public IP address of the second access point. At this time, the client's inbound traffic still enters the virtual tunnel through the client's WireGuard virtual port, so the client's routing information does not change.
[0116] 2. After the client establishes a connection with POP1, POP1 can determine that the connection was established by a legitimate user based on the stored account information, and determine the location of the legitimate user.
[0117] In practice, POP1 obtains the handshake initialization message used to establish a WireGuard connection with the client, and obtains the client's public IP address from the handshake initialization message. Based on the IP address database (which contains the correspondence between IP addresses and actual physical addresses) and the public IP address, POP1 determines the client's geographical location. This geographical location is usually smaller than the cloud vendor's regional division (i.e., the geographical range of each access point). At this time, POP1 can determine that the geographical location of user 2 is outside the geographical range of POP1 (i.e., the North China region).
[0118] 3. After determining that User 2 is outside the area of POP1, POP1 notifies the SDWAN controller (i.e., ...) of User 2's account information and location through the SDWAN control channel. Figure 5As shown in ③), the SDWAN controller, as the centralized control device in the network, stores the information of all POPs. Based on the location of User 2, the controller selects the nearest region, the South China region, and synchronizes User 2's account information to the corresponding POP2 in the South China region (i.e., Figure 5 As shown in ④), POP2 (i.e., the second access point) returns a message indicating successful account synchronization (i.e., ...). Figure 5 As shown in ⑤), the SDWAN controller then returns the public IP address of POP2 to POP1 (i.e., Figure 5 ⑥) shown.
[0119] 4. POP1 generates a notification message carrying the public IP address of the second access point according to the notification message structure newly added in the WireGuard protocol, and sends the notification message to the client (i.e., Figure 5 ⑦) shown.
[0120] The notification message shall include at least the following:
[0121] The instruction message is a message type used to notify the client to update the IP address of the access point;
[0122] A random key encrypted using the client's public key;
[0123] The public IP address of the second access point, encrypted using the random key.
[0124] In practice, after receiving the notification message, the client will use its private key to parse the random key from the notification message and obtain the public IP address of the second access point through the random key.
[0125] Understandably, the WireGuard protocol only requires two messages to establish a connection: a handshake initialization message and a handshake response message. Furthermore, the message length is generally less than 200 bytes, facilitating extensions to the protocol message structure. This application adds a notification message type to the WireGuard protocol to notify the peer (e.g., the client) to update the server's (i.e., the access point's) IP address, allowing POP1 to inform the client POP2 of its public IP address via this notification message.
[0126] For example, the structure of the notification message is shown in Table 1 below.
[0127]
[0128] The newly added type "05" is used to identify that the message is used to update the server IP address; the recipient is identified by the initiator; and the data is the new server IP address encrypted and protected using a random key.
[0129] 5. The client and POP2 exchange handshake initialization and handshake response messages via the nearest available internet connection in the same region (i.e., ... Figure 5 As shown in ⑧ and ⑨), after the client and POP2 successfully establish a connection, the client's traffic will be smoothly switched to POP2. That is, the client connects to POP2 as soon as it is nearby, and then the client accesses cloud resources within the local area of POP1 through the high-speed link between POP2 and POP1.
[0130] It should be noted that before the SDWAN controller completes the automatic account migration, clients can still access cloud resources through low-speed links across regions.
[0131] As one possible implementation, the SDWAN controller obtains the client's traffic statistics from the second access point at set intervals, and retrieves the client's account information sent by the SDWAN controller from the POP2.
[0132] Understandably, considering that employee business trips are short-term scenarios, the SDWAN controller can reclaim migrated accounts every 24 hours to save storage resources. Before reclamation, the SDWAN controller can proactively obtain user 2's traffic statistics from POP2 for billing purposes.
[0133] In the above embodiments, such as Figure 6 As shown, the access point switching process involves only three message exchanges: first, a notification message sent by the first access point to the client; then, two negotiation messages used by the client and the second access point to establish a connection based on the WireGuard protocol. Therefore, the entire access point switching process consumes only 1.5 RTTs, effectively reducing overhead. Compared to traditional solutions that require administrator intervention (such as manual account migration in the background) and user cooperation (such as manually changing the access region), this application, by introducing an SDWAN controller and the WireGuard protocol, not only automates and intelligently accelerates the entire cross-regional cloud access process, but also ensures that the client's routing information remains unchanged during the switching process, and traffic is still sent through the WireGuard virtual interface. Therefore, a smooth traffic switch can be completed without the user's awareness.
[0134] Secondly, such as Figure 7 As shown in the embodiments of this application, another cloud acceleration method is also provided, applied to the client. The method includes the following steps:
[0135] Step S21: Establish a connection with the first access point via the cross-regional Internet, and access the cloud network through the first access point;
[0136] Step S22: Receive the public IP address of the second access point sent by the first access point. The second access point is the access point that the SDWAN controller determines based on the location of the client and synchronizes the client's account information.
[0137] Step S23: Based on the public IP address of the second access point, establish a connection with the second access point through the nearest Internet in the same region, and access the cloud network through the second access point.
[0138] The technical solution of this application embodiment introduces an SDWAN controller to centrally manage all access points in the cloud network. The SDWAN controller finds a second access point in the same region as the client and synchronizes the client's account information to the second access point, enabling the client to switch to the second access point to access the cloud network. This changes the client's access from a low-speed cross-regional cloud access mode to a higher-speed intra-regional cloud access mode. Furthermore, it enables the client to subsequently access cloud resources in the region where the first access point is located through the high-speed cloud connection network between access points, thereby accelerating the client's cloud access.
[0139] As one possible implementation, the connection established with the first access point and the second access point is based on the WireGuard protocol;
[0140] The cloud network access via the first access point includes:
[0141] Cloud network access is achieved through a tunnel between the first WireGuard virtual port of the client and the second WireGuard virtual port corresponding to the public IP address of the first access point;
[0142] Accessing the cloud network through the second access point includes:
[0143] Cloud network access is achieved through a tunnel between the first WireGuard virtual port and the third WireGuard virtual port, wherein the third WireGuard virtual port is the second WireGuard virtual port after the corresponding IP address has been adjusted to the public IP address of the second access point.
[0144] As one possible implementation, the connection established with the first access point and the second access point is based on the WireGuard protocol;
[0145] The step of receiving the public IP address of the second access point sent by the first access point includes:
[0146] Receive a notification message sent by the first access point carrying the public IP address of the second access point. The notification message is generated according to the notification message structure added to the WireGuard protocol.
[0147] The step of establishing a connection with the second access point via a nearby internet connection in the same region includes:
[0148] Send a handshake initialization message to the second access point via the nearest Internet in the same region;
[0149] Receive the handshake response message returned by the second access point via the nearest Internet in the same region.
[0150] Thirdly, such as Figure 8 As shown in the embodiment of this application, another cloud access acceleration method is provided, applied to an SDWAN controller. The method includes the following steps:
[0151] Step S31: Receive the client's location and account information sent by the first access point;
[0152] Step S32: Based on the information of all access points stored in the SDWAN controller and the location of the client, determine the second access point whose location range includes the location.
[0153] Step S33: Send the client's account information to the second access point and send the public IP of the second access point to the first access point, so as to control the first access point to migrate the client's traffic to the second access point.
[0154] The technical solution of this application embodiment introduces an SDWAN controller to centrally manage all access points in the cloud network. The SDWAN controller finds a second access point in the same region as the client and synchronizes the client's account information to the second access point, enabling the client to switch to the second access point to access the cloud network. This changes the client's access from a low-speed cross-regional cloud access mode to a higher-speed intra-regional cloud access mode. Furthermore, it enables the client to subsequently access cloud resources in the region where the first access point is located through the high-speed cloud connection network between access points, thereby accelerating the client's cloud access.
[0155] As one possible implementation, the method further includes:
[0156] Traffic statistics of the client are obtained from the second access point at set intervals, and the account information of the client sent by the SDWAN controller is retrieved from the second access point.
[0157] For the sake of simplicity, the method embodiments are described as a series of actions. However, those skilled in the art should understand that the embodiments of this application are not limited to the described order of actions, because according to the embodiments of this application, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of this application.
[0158] Fourthly, Figure 9 This is a schematic diagram of a cloud acceleration device according to an embodiment of this application. The device is applied to a first access point and includes:
[0159] The processing module is used to establish a connection with the client and determine the client's location.
[0160] The determination module is used to determine whether the location is outside the geographical area of the first access point;
[0161] The sending module is configured to send the client's location and account information to the SDWAN controller when the location is outside the territory of the first access point, so as to request the SDWAN controller to determine a second access point and synchronize the client's account information to the second access point, wherein the second access point is an access point whose territory includes the location.
[0162] The transmission module is used to receive the public IP address of the second access point sent by the SDWAN controller, and send the public IP address of the second access point to the client, so that the client can access the cloud network through the nearest Internet in the same region.
[0163] The technical solution of this application embodiment introduces an SDWAN controller to centrally manage all access points in the cloud network. The SDWAN controller finds a second access point in the same region as the client and synchronizes the client's account information to the second access point, enabling the client to switch to the second access point to access the cloud network. This changes the client's access from a low-speed cross-regional cloud access mode to a higher-speed intra-regional cloud access mode. Furthermore, it enables the client to subsequently access cloud resources in the region where the first access point is located through the high-speed cloud connection network between access points, thereby accelerating the client's cloud access.
[0164] Optionally, the connection established with the client is based on the WireGuard protocol;
[0165] The transmission module includes:
[0166] The first transmission submodule is used to generate a notification message carrying the public IP address of the second access point according to the notification message structure added to the WireGuard protocol.
[0167] The second transmission submodule is used to send the notification message to the client.
[0168] Optionally, the notification message includes at least the following:
[0169] The instruction message is a message type used to notify the client to update the IP address of the access point;
[0170] A random key encrypted using the client's public key;
[0171] The public IP address of the second access point is encrypted using the random key.
[0172] Optionally, the connection established with the client is based on the WireGuard protocol;
[0173] The processing module includes:
[0174] The first processing submodule is used to obtain the handshake initialization message used by the first access point to establish a WireGuard connection with the client;
[0175] The second processing submodule is used to obtain the client's public IP address from the handshake initialization message;
[0176] The third processing submodule is used to determine the geographical location of the client based on the IP address database and the client's public IP address.
[0177] Fifthly, Figure 10 This is a schematic diagram of another cloud acceleration device according to an embodiment of this application. The device is applied to a client and includes:
[0178] The first access module is used to establish a connection with the first access point via the cross-regional Internet and to access the cloud network through the first access point.
[0179] The first receiving module is used to receive the public IP address of the second access point sent by the first access point. The second access point is an access point determined by the SDWAN controller based on the location of the client and synchronized with the client's account information.
[0180] The second access module is used to establish a connection with the second access point through the nearest Internet in the same region based on the public IP address of the second access point, and to access the cloud network through the second access point.
[0181] The technical solution of this application embodiment introduces an SDWAN controller to centrally manage all access points in the cloud network. The SDWAN controller finds a second access point in the same region as the client and synchronizes the client's account information to the second access point, enabling the client to switch to the second access point to access the cloud network. This changes the client's access from a low-speed cross-regional cloud access mode to a higher-speed intra-regional cloud access mode. Furthermore, it enables the client to subsequently access cloud resources in the region where the first access point is located through the high-speed cloud connection network between access points, thereby accelerating the client's cloud access.
[0182] Optionally, the connections established with the first access point and the second access point are based on the WireGuard protocol;
[0183] The first access module includes:
[0184] The first access submodule is used to access the cloud network through the tunnel between the first WireGuard virtual port of the client and the second WireGuard virtual port corresponding to the public IP address of the first access point.
[0185] The second access module includes:
[0186] The second access submodule is used to access the cloud network through the tunnel between the first WireGuard virtual port and the third WireGuard virtual port. The third WireGuard virtual port is the second WireGuard virtual port after the corresponding IP address is adjusted to the public IP address of the second access point.
[0187] Optionally, the connections established with the first access point and the second access point are based on the WireGuard protocol;
[0188] The first receiving module includes:
[0189] The first receiving submodule is used to receive a notification message sent by the first access point carrying the public IP address of the second access point. The notification message is generated according to the notification message structure added by the WireGuard protocol.
[0190] The second access module includes:
[0191] The third access submodule is used to send a handshake initialization message to the second access point via the nearest Internet in the same region;
[0192] The fourth access submodule is used to receive the handshake response message returned by the second access point via the nearest Internet in the same region.
[0193] Sixth aspect, Figure 11 This is a schematic diagram of another cloud acceleration device according to an embodiment of this application. The device is applied to an SDWAN controller and includes:
[0194] The information receiving module is used to receive the client's location and account information sent by the first access point;
[0195] The access point determination module is used to determine a second access point whose geographical range includes the geographical location, based on the information of all access points stored by the SDWAN controller and the geographical location of the client.
[0196] The information transmission module is used to send the client's account information to the second access point and send the public IP of the second access point to the first access point, so as to control the first access point to migrate the client's traffic to the second access point.
[0197] The technical solution of this application embodiment introduces an SDWAN controller to centrally manage all access points in the cloud network. The SDWAN controller finds a second access point in the same region as the client and synchronizes the client's account information to the second access point, enabling the client to switch to the second access point to access the cloud network. This changes the client's access from a low-speed cross-regional cloud access mode to a higher-speed intra-regional cloud access mode. Furthermore, it enables the client to subsequently access cloud resources in the region where the first access point is located through the high-speed cloud connection network between access points, thereby accelerating the client's cloud access.
[0198] Optionally, the device further includes:
[0199] The information processing module is used to obtain the traffic statistics information of the client from the second access point at set intervals, and to retrieve the client's account information sent by the SDWAN controller from the second access point.
[0200] Seventhly, embodiments of this application also provide a cloud access acceleration system, the system comprising a first access point, a second access point, an SDWAN controller, and a client, wherein:
[0201] When the first access point establishes a connection with the client, it executes the cloud access acceleration method as described in the first aspect to request the SDWAN controller to determine the second access point, synchronize the client's account information to the second access point, and enable the client to access the cloud network through the nearest Internet in the same region.
[0202] It should be noted that the device embodiments are similar to the method embodiments, so the description is relatively simple. For relevant details, please refer to the method embodiments.
[0203] This application also provides an electronic device, see embodiments thereof. Figure 12 , Figure 12 This is a schematic diagram of the electronic device proposed in an embodiment of this application. Figure 12 As shown, the electronic device 100 includes a memory 110 and a processor 120. The memory 110 and the processor 120 are connected via a bus for communication. The memory 110 stores a computer program that can run on the processor 120 to implement the steps in the cloud acceleration method disclosed in the embodiments of this application.
[0204] This application also provides a computer-readable storage medium storing a computer program / instructions thereon, which, when executed by a processor, implements the cloud acceleration method disclosed in this application.
[0205] This application also provides a computer program product, including a computer program / instruction that, when executed by a processor, implements the cloud acceleration method disclosed in this application.
[0206] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0207] Those skilled in the art will understand that embodiments of this application can be provided as methods, apparatus, or computer program products. Therefore, embodiments of this application can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of this application can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0208] This application describes embodiments of methods, systems, devices, storage media, and program products according to embodiments of this application with reference to flowchart illustrations and / or block diagrams. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0209] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0210] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0211] Although preferred embodiments of the present application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present application.
[0212] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.
[0213] The above provides a detailed description of the cloud acceleration method, apparatus, system, electronic device, and storage medium provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A method for accelerating cloud access, characterized in that, Applied to a first access point, the method includes: Establish a connection with the client and determine the client's location; Determine whether the location of the specified territory is outside the territory of the first access point; If the location of the client is outside the territory of the first access point, the location and account information of the client are sent to the SDWAN controller to request the SDWAN controller to determine the second access point and synchronize the account information of the client to the second access point. The second access point is an access point whose territory includes the location of the client. The system receives the public IP address of the second access point sent by the SDWAN controller and sends the public IP address of the second access point to the client, so that the client can access the cloud network through the nearest Internet in the same region. The connection established with the client is based on the WireGuard protocol; Sending the public IP address of the second access point to the client includes: Based on the notification message structure newly added to the WireGuard protocol, a notification message carrying the public IP address of the second access point is generated; The notification message is sent to the client.
2. The method according to claim 1, characterized in that, The notification message shall include at least the following: The instruction message is a message type used to notify the client to update the IP address of the access point; A random key encrypted using the client's public key; The public IP address of the second access point is encrypted using the random key.
3. The method according to any one of claims 1-2, characterized in that, The connection established with the client is based on the WireGuard protocol; Determining the geographical location of the client includes: Obtain the handshake initialization message used by the first access point to establish a WireGuard connection with the client; Obtain the client's public IP address from the handshake initialization message; The location of the client is determined based on the IP address database and the client's public IP address.
4. A method for accelerating cloud access, characterized in that, Applied to a client, the method includes: A connection is established with the first access point via a cross-regional Internet, and cloud network access is performed through the first access point; The system receives the public IP address of the second access point sent by the first access point. The second access point is an access point that the SDWAN controller determines based on the location of the client and synchronizes the client's account information. Based on the public IP address of the second access point, a connection is established with the second access point via the nearest Internet in the same region, and cloud network access is performed through the second access point; The connections established with the first access point and the second access point are based on the WireGuard protocol; The cloud network access via the first access point includes: Cloud network access is achieved through a tunnel between the first WireGuard virtual port of the client and the second WireGuard virtual port corresponding to the public IP address of the first access point; Accessing the cloud network through the second access point includes: Cloud network access is achieved through a tunnel between the first WireGuard virtual port and the third WireGuard virtual port, wherein the third WireGuard virtual port is the second WireGuard virtual port after the corresponding IP address has been adjusted to the public IP address of the second access point.
5. The method according to claim 4, characterized in that, The connections established with the first access point and the second access point are based on the WireGuard protocol; The step of receiving the public IP address of the second access point sent by the first access point includes: Receive a notification message sent by the first access point carrying the public IP address of the second access point. The notification message is generated according to the notification message structure added to the WireGuard protocol. The step of establishing a connection with the second access point via a nearby internet connection in the same region includes: Send a handshake initialization message to the second access point via the nearest Internet in the same region; Receive the handshake response message returned by the second access point via the nearest Internet in the same region.
6. A method for accelerating cloud access, characterized in that, Applied to an SDWAN controller, the method includes: Receive the client's location and account information sent by the first access point; wherein the connection established between the first access point and the client is based on the WireGuard protocol; Based on the information of all access points stored in the SDWAN controller and the location of the client, a second access point whose location range includes the location is determined; The client's account information is sent to the second access point, and the public IP address of the second access point is sent to the first access point, so as to control the first access point to migrate the client's traffic to the second access point; wherein, the first access point generates a notification message carrying the public IP address of the second access point according to the notification message structure added to the WireGuard protocol, and sends the notification message to the client.
7. The method according to claim 6, characterized in that, The method further includes: Traffic statistics of the client are obtained from the second access point at set intervals, and the account information of the client sent by the SDWAN controller is retrieved from the second access point.
8. A cloud entry acceleration device, characterized in that, Applied to a first access point, the device includes: The processing module is used to establish a connection with the client and determine the client's location. The determination module is used to determine whether the location is outside the geographical area of the first access point; The sending module is configured to send the client's location and account information to the SDWAN controller when the location is outside the territory of the first access point, so as to request the SDWAN controller to determine a second access point and synchronize the client's account information to the second access point, wherein the second access point is an access point whose territory includes the location. The transmission module is used to receive the public IP address of the second access point sent by the SDWAN controller, and send the public IP address of the second access point to the client, so that the client can access the cloud network through the nearest Internet in the same region. The connection established with the client is based on the WireGuard protocol; The transmission module includes: The first transmission submodule is used to generate a notification message carrying the public IP address of the second access point according to the notification message structure added to the WireGuard protocol. The second transmission submodule is used to send the notification message to the client.
9. A cloud entry acceleration device, characterized in that, Applied to a client, the device includes: The first access module is used to establish a connection with the first access point via the cross-regional Internet and to access the cloud network through the first access point. The first receiving module is used to receive the public IP address of the second access point sent by the first access point. The second access point is an access point determined by the SDWAN controller based on the location of the client and synchronized with the client's account information. The second access module is used to establish a connection with the second access point through the nearest Internet in the same region based on the public IP address of the second access point, and to access the cloud network through the second access point. The connections established with the first access point and the second access point are based on the WireGuard protocol; The first access module includes: The first access submodule is used to access the cloud network through the tunnel between the first WireGuard virtual port of the client and the second WireGuard virtual port corresponding to the public IP address of the first access point. The second access module includes: The second access submodule is used to access the cloud network through the tunnel between the first WireGuard virtual port and the third WireGuard virtual port. The third WireGuard virtual port is the second WireGuard virtual port after the corresponding IP address is adjusted to the public IP address of the second access point.
10. A cloud entry acceleration device, characterized in that, Applied to an SDWAN controller, the device includes: The information receiving module is used to receive the client's location and account information sent by the first access point; wherein the connection established between the first access point and the client is based on the WireGuard protocol. The access point determination module is used to determine a second access point whose geographical range includes the geographical location, based on the information of all access points stored by the SDWAN controller and the geographical location of the client. The information transmission module is used to send the client's account information to the second access point and send the public IP address of the second access point to the first access point, so as to control the first access point to migrate the client's traffic to the second access point; wherein, the first access point generates a notification message carrying the public IP address of the second access point according to the notification message structure added by the WireGuard protocol, and sends the notification message to the client.
11. A cloud acceleration system, characterized in that, The system includes a first access point, a second access point, an SDWAN controller, and a client, wherein: When the first access point establishes a connection with the client, it executes the cloud access acceleration method as described in any one of claims 1 to 3 to request the SDWAN controller to determine the second access point, synchronize the client's account information to the second access point, and enable the client to access the cloud network through the nearest Internet in the same region.
12. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that, The processor executes the computer program to implement the cloud acceleration method as described in any one of claims 1 to 3, or the processor executes the computer program to implement the cloud acceleration method as described in any one of claims 4 to 5, or the processor executes the computer program to implement the cloud acceleration method as described in claim 6 or 7.
13. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instruction is executed by the processor, it implements the cloud acceleration method as described in any one of claims 1 to 3; or, when the computer program / instruction is executed by the processor, it implements the cloud acceleration method as described in any one of claims 4 to 5; or, when the computer program / instruction is executed by the processor, it implements the cloud acceleration method as described in claim 6 or 7.
Citation Information
Patent Citations
Equipment cross-region access method and device, electronic equipment and storage medium
CN114221955A
Network interconnection method and device, equipment and storage medium
CN115037573A