A network isolation device and method for transmitting data between network isolation systems
By pre-allocating addresses in the address pool based on business type and policy configuration relationships, the problem of limited concurrent connections in cross-network secure data exchange products is solved, improving the performance of new connection creation and throughput, and meeting the needs of high throughput and high concurrency.
Patent Information
- Application Number
- CN202310557993.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-15
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2043-05-15
AI Technical Summary
Existing cross-network secure data exchange products, when transmitting data between the front-end and back-end via a single pair of IP addresses, are limited by the number of concurrent connections, resulting in low performance in new connection establishment and throughput, and failing to meet the requirements of high throughput and high concurrency.
By pre-allocating addresses in the address pool according to service type and policy configuration, the mapping relationship between addresses and service types can be dynamically adjusted to achieve address sharing for different service types and improve the concurrent connection capability between the front-end and back-end.
It improves the creation and throughput performance of cross-network secure data exchange products, meeting the data transmission needs of massive services.
Smart Images

Figure CN116582328B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security, and more specifically, the embodiments of this application relate to a network isolation device and a method for transmitting data between network isolation systems. Background Technology
[0002] In industries with high requirements for isolation and compliance, cross-network secure data exchange products are deployed across different networks as the sole channel for network isolation and data transfer to achieve regional network isolation and secure cross-network data exchange. This allows the cross-network secure data exchange products, in conjunction with network gateways or optical gateways, to form a complete cross-network data transfer solution. Cross-network secure data exchange products can be applied to network isolation scenarios across various industries. To meet the demands of complex and high-volume business operations, these products must satisfy users' requirements for high throughput and high concurrency.
[0003] like Figure 1 As shown, the cross-network secure data exchange product consists of a front-end (i.e., a network isolation device) and a back-end (i.e., another network isolation device), forming a single device, namely the cross-network secure data exchange product 130. Communication between the two network areas can be achieved by configuring proxy policies (i.e., policies supported by each service type). Through policy configuration, the front-end can forward messages sent by a client located in the first network 110 to the back-end, which then forwards the messages to the server located in the second network 120, thus completing communication between the client and server in the two isolated networks; alternatively, the client can send messages to the back-end, which forwards the messages to the front-end, which then forwards the messages to the server, thus completing communication between the client and server in the two isolated networks.
[0004] like Figure 1 As shown, some cross-network secure data exchange products in related technologies use a pair of IP addresses to carry data transmission between the front-end and back-end, completing the communication from the real client to the server. A proprietary protocol is used between the front-end and back-end to achieve network isolation and improve data security. However, using a single IP address to carry all data transmission between the front-end and back-end results in a limitation on the number of concurrent connections available between the front-end and back-end, which is restricted by a single IP address. When the number of client connections is too large, insufficient concurrent connections between the front-end and back-end lead to low device creation and throughput performance. Summary of the Invention
[0005] The purpose of this application is to provide a network isolation device and a method for transmitting data between network isolation systems. The embodiments of this application determine the pre-allocation strategy for addresses in the address pool based on the relationship between the number of IP addresses in the address pool and the number of service types. If the pre-allocation result obtained according to the pre-allocation strategy is used to record the addresses in the address pool pre-allocated for each service type, the embodiments of this application do not completely isolate the pre-allocated addresses for different service types during specific address allocation. That is, when selecting the transmission address and port for the data packet to be transmitted based on the pre-allocation result, the available address can be adjusted according to the service type and strategy configuration to achieve a certain degree of sharing.
[0006] In a first aspect, embodiments of this application provide a network isolation device, comprising: a configuration module configured to: pre-allocate addresses in an address pool to obtain a local address pre-allocation result, wherein the local address pre-allocation result is determined by comparing the number of local service types with the number of addresses in the local address pool; maintain the local address pre-allocation result and the address usage status of the local address pool; a connection module configured to obtain a local data transmission address and port for a data packet to be transmitted from the peer based on the local address pre-allocation result; and a data transmission module configured to send the local data packet to be transmitted to the peer network isolation device based on the peer data transmission address and port.
[0007] Some embodiments of this application determine the address allocation strategy by comparing the number of service types supported by the corresponding network isolation device (e.g., the local network isolation device and the peer network isolation device) with the number of addresses in the address pool, and pre-allocate the addresses in the address pool according to the allocation strategy to obtain the local address pre-allocation result. Then, data transmission addresses and ports are allocated to the data packets to be transmitted according to the local address pre-allocation result. When selecting data transmission addresses and ports from the address pre-allocation result for the data packets to be transmitted, the correspondence between addresses and service types recorded in the address pre-allocation result can be adjusted.
[0008] In some embodiments, the configuration module further includes: an address pool module, configured to: calculate the remaining available addresses in the subnet where the transmission port address is located to obtain a set of addresses to be allocated; equally distribute all addresses in the set of addresses to be allocated to the network isolation device and the peer network isolation device to obtain the local address pool and the peer address pool; determine an address pre-allocation strategy according to the relationship between the number of local service types and the number of addresses in the local address pool, and complete the pre-allocation of addresses in the local address pool according to the address pre-allocation strategy to obtain the local address pre-allocation result; and a record table module, configured to store the local address pre-allocation result and the address usage status of the local address pool.
[0009] Some embodiments of this application obtain an address pool corresponding to each network isolation device by equally dividing the multiple addresses of the transmission port address in the same subnet, and then pre-allocating the addresses in the address pool of each network isolation device according to the address pool to obtain the address pre-allocation result of each end.
[0010] In some embodiments, the address pool module is further configured to: if it is confirmed that the number of local service types is greater than the number of addresses in the local address pool, then assign a first tag to each service type and use the addresses in the local address pool as first local address pre-allocation result information; if it is confirmed that the number of local service types is equal to the number of addresses in the local address pool, then pre-allocate each address in the local address pool to a service type, obtain the correspondence between each address and port and the service type, and use the correspondence as at least part of the information in the second local address pre-allocation result information; if it is confirmed that the number of local service types is less than the number of addresses in the local address pool, then assign each address in the local address pool to a service type, and pre-allocate the remaining addresses in the local address pool according to the policy number of the service type; record the addresses and ports pre-allocated for each service type to obtain the correspondence; and use the correspondence as at least part of the information in the third local address pre-allocation result.
[0011] Some embodiments of this application determine the pre-allocation address strategy by comparing the number of service types supported by the corresponding end with the number of addresses in the address pool. If the former is greater than the latter, no corresponding address is pre-allocated for each service type; instead, the address in the address pool is directly used as the pre-allocation result. If the two are equal, one address from the address pool is allocated to each service type, resulting in a one-to-one correspondence between service types and addresses. This one-to-one relationship is used as part (and may further include the number of strategies initiated by each service type) or all of the information in the address pre-allocation result. If the former is less than the latter, in the case of allocating one address to each service type, more than one address may be allocated for service types with a large number of supported strategies. This results in a correspondence between each service type and the pre-allocated address, and this one-to-one relationship is used as part (and may further include the number of strategies initiated by each service type) or all of the information in the address pre-allocation result. It is understood that the method for obtaining the address pre-allocation result of the peer end is the same as the strategy for obtaining the address pre-allocation result of the local end.
[0012] In some embodiments, the second local address pre-allocation result and the third local address pre-allocation result are also used to record the number of strategies initiated for each service type at the current time.
[0013] Some embodiments of this application can adjust the correspondence between addresses and service types in the address pre-allocation results according to the number of recorded policies, so as to adjust the available addresses of the data to be transmitted according to the service type and policy configuration, thereby changing the mapping relationship between addresses and service types in the address pre-allocation results.
[0014] In some embodiments, the connection module includes: an address acquisition module, configured to acquire the local data transmission address and the port of the data to be transmitted from the peer end by querying the local address pre-allocation result based on the service type of the data to be transmitted from the peer end; and a connection judgment module, configured to obtain the local data transmission address and port by calling the address acquisition module if the data packet to be transmitted from the peer end is the first packet, and to obtain the local data transmission address and port by calling the record table module if the data packet to be transmitted from the peer end is not the first packet, and to provide the local data transmission address and the port to the data transmission module of the peer end.
[0015] In some embodiments of this application, when there is a specific data packet to be transmitted, the data transmission address and port of the peer network isolation device are obtained through the peer address pre-allocation result, and then the data packet to be transmitted is provided to the peer.
[0016] In some embodiments, the address acquisition module is further configured to: if it is confirmed that the service type of the data to be transmitted by the peer is a first type, then read the next address and port from the local address pool as the data transmission address and the port.
[0017] In some embodiments of this application, when the number of service types is greater than the number of policies, the addresses in the address pool are read sequentially to complete the address allocation, which can improve the utilization efficiency of the addresses in the address pool and ensure the efficient use of scarce resources (i.e., addresses).
[0018] In some embodiments, the address acquisition module is further configured to: if it is confirmed that the service type to which the data to be transmitted by the peer belongs does not belong to the first type, then firstly search the local address pool address usage status for the data transmission address and port used to transmit the service type to which the data to be transmitted by the peer belongs to obtain the local data transmission address and port; if the local address pool address usage status information does not find the data transmission address and port used to transmit the data to be transmitted by the peer, then further query the local address pre-allocation result to see if there is a service type without a startup policy; if so, then obtain the local data transmission address and port from the pre-allocated address corresponding to the service type without a startup policy; otherwise, preferentially obtain the local data transmission address and port from the pre-allocated address corresponding to the service type with fewer startup policies.
[0019] In some embodiments of this application, when allocating local data transmission addresses and ports for data to be transmitted on the peer end, the local end adjusts the data transmission addresses and ports corresponding to each service type in the address pre-allocation result according to the local end's attribute information. That is, when searching for data transmission addresses and ports for data to be transmitted on the peer end, the address pre-allocation result can be adjusted according to the service type and device policy configuration to achieve sharing.
[0020] Secondly, some embodiments of this application provide a method for transmitting data between network isolation systems, wherein the network isolation system includes a first network isolation device communicating with a client and a second network isolation device communicating with a server. The method includes: receiving a message to be transmitted; if it is confirmed that a new connection needs to be established for the message to be transmitted, obtaining the peer data transmission address and port by querying the peer address pre-allocation result or the peer address pool address usage status, wherein the peer address pre-allocation result is determined by comparing the size relationship between the number of peer service types and the number of addresses in the peer address pool; and sending the local data message to be transmitted to the peer network isolation device through the peer data transmission address and port.
[0021] In some embodiments, before obtaining the peer data transmission address and port by querying peer address pre-allocation result information or peer address pool address usage status information, the method further includes: configuring the peer transmission port address; calculating the remaining available addresses in the subnet where the peer transmission port address is located to obtain a set of addresses to be allocated; equally distributing all addresses in the set of addresses to be allocated to the first network isolation device and the second network isolation device as address pools for the corresponding network isolation devices; and completing the pre-allocation of addresses in the peer address pool according to the relationship between the number of peer service types and the number of addresses in the peer address pool to obtain the peer address pre-allocation result.
[0022] In some embodiments, the step of pre-allocating the addresses in the address pool according to the relationship between the number of service types and the number of addresses in the address pool to obtain the address pre-allocation result includes: if it is confirmed that the number of peer service types is greater than the number of addresses in the peer address pool, then assigning a first type tag to each service type and using the addresses in the peer address pool as the peer address pre-allocation result; if it is confirmed that the number of peer service types is equal to the number of addresses in the peer address pool, then pre-allocating each address in the peer address pool to a service type, obtaining the correspondence between each address and port and the service type, and using the correspondence as at least part of the information in the peer address pre-allocation result; if it is confirmed that the number of peer service types is less than the number of addresses in the peer address pool, then assigning each address in the peer address pool to a service type, and pre-allocating the remaining addresses in the peer address pool again according to the policy number of the service type; recording the addresses and ports pre-allocated for each service type to obtain the correspondence; and using the correspondence as at least part of the information in the peer address pre-allocation result.
[0023] In some embodiments, obtaining the peer data transmission address and port by querying the peer address pre-allocation result or the peer address pool address usage status includes: if it is confirmed that the service type of the data packet to be transmitted on the local end belongs to the first type, then read the next address and port from the first peer address pre-allocation result as the data transmission address and the port.
[0024] In some embodiments, obtaining the peer data transmission address and port by querying the peer address pre-allocation result or the peer address pool address usage status includes: if it is confirmed that the service type to which the data to be transmitted belongs does not belong to the first type, then firstly, the peer data transmission address and port are obtained by searching the peer address pool address usage status for the pre-allocated address and port corresponding to the service type to which the data to be transmitted belongs; if the process of searching the peer data transmission address and port from the peer address pool address usage status fails, then the peer address pre-allocation result is queried to see if there is a service type without a startup policy; if so, the peer data transmission address and port are obtained from the pre-allocated address corresponding to the service type without a startup policy; otherwise, the peer data transmission address and port are obtained preferentially from the pre-allocated address corresponding to the service type with fewer startup policies.
[0025] In some embodiments, after sending the local data packet to be transmitted to the peer network isolation device through the peer data transmission address and the port, the method further includes: releasing the data transmission address and port if it is confirmed that the local data packet to be transmitted is an end packet.
[0026] Thirdly, this application provides an electronic device including a memory and a processor, wherein the memory stores a computer program, and the processor, when executing the computer program, can perform the following operations: completing the pre-allocation of addresses in an address pool to obtain a local address pre-allocation result, wherein the local address pre-allocation result is determined by comparing the number of local service types with the number of addresses in the local address pool; maintaining the local address pre-allocation result and the address usage status of the local address pool; obtaining the local data transmission address and port for the data packet to be transmitted from the peer based on the local address pre-allocation result; and sending the local data packet to be transmitted to the peer network isolation device based on the peer data transmission address and port. Attached Figure Description
[0027] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0028] Figure 1 An architecture diagram of an isolated network system provided in the embodiments of this application;
[0029] Figure 2 A functional module composition diagram of the front-end / back-end device provided in the embodiments of this application;
[0030] Figure 3 This is a functional module composition diagram of the configuration module provided in the embodiments of this application;
[0031] Figure 4 A functional module composition diagram of the connection module provided in the embodiments of this application;
[0032] Figure 5 One of the flowcharts for a method of transmitting data between network isolation systems provided in the embodiments of this application;
[0033] Figure 6 A second flowchart illustrating a method for transmitting data between network isolation systems provided in this application embodiment;
[0034] Figure 7 This is a schematic diagram of the electronic device provided in the embodiments of this application. Detailed Implementation
[0035] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.
[0036] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.
[0037] At least to address the technical problems existing in the background section, some embodiments of this application are based on address pools, pre-allocating address pool addresses according to the relationship between address pool addresses and service types, and dynamically adjusting available addresses according to address availability and device policy configuration, so that the pre-allocated addresses of different service types are not completely isolated, increasing the available concurrent connections between the front-end and back-end, and improving the creation and throughput performance of cross-network secure data exchange products.
[0038] In other words, some embodiments of this application provide a method for improving the creation and throughput performance of cross-network secure data exchange products based on address pools. The original method of transmitting all data between the front-end and back-end via a single IP pair is replaced with an address pool-based method for exchanging data between the front-end and back-end. After configuring the transmission port address, the address pool is automatically calculated. Addresses in the address pool are pre-allocated based on the relationship between the address pool and the service type. Available addresses are dynamically adjusted according to address availability and device policy configuration, ensuring that pre-allocated addresses for different service types are not completely isolated. This increases the number of concurrent connections available between the front-end and back-end, thereby improving the creation and throughput performance of cross-network secure data exchange products and better meeting the data transfer needs of massive services.
[0039] Please refer to Figure 2 , Figure 2 The diagram shows the composition of the pre- or post-functional modules provided in some embodiments of this application. Unlike related technologies, the network isolation device in the embodiments of this application includes a pre- or post-module that dynamically configures the address pool address to realize the transmission of data packets.
[0040] like Figure 2 As shown, this application embodiment provides a network isolation device (i.e., front-end or back-end), the network isolation device including: a configuration module 110, a connection module 120 and a data transmission module 130.
[0041] Configuration module 110 is configured to: complete the pre-allocation of addresses in the address pool to obtain the local address pre-allocation result, wherein the local address pre-allocation result is determined by comparing the size relationship between the number of local service types and the number of addresses in the local address pool; and maintain the local address pre-allocation result and the address usage status of the local address pool.
[0042] For example, if the network isolation device is a front-end device, the local address pre-allocation result is the same as the address pre-allocation result obtained by the configuration module in the front-end device; if the network isolation device is a back-end device, the local address pre-allocation result is the same as the address pre-allocation result obtained by the configuration module in the back-end device.
[0043] The connection module 120 is configured to obtain the local data transmission address and port of the data packet to be transmitted from the peer based on the local address pre-allocation result.
[0044] For example, if the network isolation device is a front-end device, the local address pre-allocation result is the address pre-allocation result obtained by the configuration module in the front-end device, and the data packets to be transmitted at the other end are the data packets to be transmitted from the back-end device; if the network isolation device is a back-end device, the local address pre-allocation result is the address pre-allocation result obtained by the configuration module in the back-end device, and the data packets to be transmitted at the other end are the data packets to be transmitted from the front-end device.
[0045] The data transmission module 130 is configured to send the local data packet to be transmitted to the peer network isolation device based on the peer data transmission address and port.
[0046] For example, some embodiments of this application determine the address allocation strategy by comparing the number of service types supported by the corresponding network isolation device (e.g., the local network isolation device and the peer network isolation device) with the number of addresses in the address pool, and pre-allocate the addresses in the address pool according to the allocation strategy to obtain the local address pre-allocation result. Then, data transmission addresses and ports are allocated to the data packets to be transmitted according to the local address pre-allocation result. When selecting data transmission addresses and ports from the address pre-allocation result for the data packets to be transmitted, the correspondence between addresses and service types recorded in the address pre-allocation result can be adjusted.
[0047] In other words, some embodiments of this application provide network isolation devices that are either front-end or back-end devices. Both the front-end and back-end devices in these embodiments include three modules: a configuration module, a connection module, and a data transmission module. The configuration module calculates the address pool address after configuring the transmission port address (similar to a gateway address) for the front-end and back-end devices, and maintains the usage of the address pool address. The connection module is responsible for obtaining the data transmission address and port from the address pool for both the front-end and back-end devices. The back-end device (or the front-end device, i.e., the device acting as the real server proxy) sends its own data transmission address and port to the corresponding peer device for subsequent data transmission. The data transmission module is responsible for performing data transmission for both the front-end and back-end devices after obtaining their data transmission addresses and ports. When the message is an end message, the record table module is called to release resources and update the status table.
[0048] The following is combined Figure 3 The functional module composition diagram of the configuration module is illustrated exemplarily.
[0049] like Figure 3 As shown, in some embodiments of this application, the configuration module further includes: an address pool module 111 and a record table module 112.
[0050] Address pool module 111 is configured to: calculate the remaining available addresses in the subnet where the transmission port address is located, obtaining a set of addresses to be allocated; evenly distribute all addresses in the set of addresses to be allocated to the network isolation device to which the address module belongs and the peer network isolation device, obtaining the local address pool (i.e., the address pool corresponding to the network isolation device where the address module is located) and the peer address pool; determine an address pre-allocation strategy according to the relationship between the number of local service types and the number of addresses in the local address pool, and complete the pre-allocation of addresses in the local address pool according to the address pre-allocation strategy, obtaining the local address pre-allocation result. It is understood that the peer network isolation device will complete the address pre-allocation based on the peer address pool; that is, the address module of the peer network isolation device is at least configured to: determine an address pre-allocation strategy according to the relationship between the number of peer service types and the number of addresses in the peer address pool, and complete the pre-allocation of addresses in the peer address pool according to the address pre-allocation strategy, obtaining the peer address pre-allocation result.
[0051] For example, in some embodiments of this application, the address pool module is further configured to: if it is confirmed that the number of local service types is greater than the number of addresses in the local address pool, then assign a first tag to each service type and use the addresses in the local address pool as first local address pre-allocation result information; if it is confirmed that the number of local service types is equal to the number of addresses in the local address pool, then pre-allocate each address in the local address pool to a service type, obtain the correspondence between each address and port and the service type, and use the correspondence as at least part of the information in the second local address pre-allocation result information; if it is confirmed that the number of local service types is less than the number of addresses in the local address pool, then assign each address in the local address pool to a service type, and pre-allocate the remaining addresses in the local address pool according to the policy number of the service type; record the addresses and ports pre-allocated for each service type to obtain the correspondence; and use the correspondence as at least part of the information in the third local address pre-allocation result.
[0052] For example, in some embodiments of this application, the second local address pre-allocation result and the third local address pre-allocation result are also used to record the number of policies initiated for each service type at the current time. Some embodiments of this application can adjust the correspondence between addresses and service types in the address pre-allocation result based on the recorded number of policies, thereby enabling the adjustment of the available addresses for data to be transmitted based on service type and policy configuration, thus changing the mapping relationship between addresses and service types in the address pre-allocation result.
[0053] In other words, some embodiments of this application determine the pre-allocation address strategy by comparing the number of service types supported by the corresponding end with the number of addresses in the address pool. If the former is greater than the latter, no corresponding address is pre-allocated for each service type; instead, the address in the address pool is directly used as the pre-allocation result. If the two are equal, one address from the address pool is allocated to each service type, resulting in a one-to-one correspondence between service types and addresses. This one-to-one relationship is used as part (and may further include the number of strategies initiated by each service type) or all of the information in the address pre-allocation result. If the former is less than the latter, in the case of allocating one address to each service type, more than one address may be allocated for service types with a large number of supported strategies. This results in a correspondence between each service type and the pre-allocated address, and this one-to-one relationship is used as part (and may further include the number of strategies initiated by each service type) or all of the information in the address pre-allocation result. It is understood that the method for obtaining the address pre-allocation result of the peer end is the same as the strategy for obtaining the address pre-allocation result of the local end.
[0054] The record table module 112 is configured to store the local address pre-allocation results and the local address pool address usage status. It is understood that the record table module of the peer network isolation device is used to store the peer address pre-allocation results and the peer address pool address usage status.
[0055] Some embodiments of this application obtain an address pool corresponding to each network isolation device by equally dividing the multiple addresses of the transmission port address in the same subnet, and then pre-allocating the addresses in the address pool of each network isolation device according to the address pool to obtain the address pre-allocation result of each end.
[0056] In other words, in some embodiments of this application, the address pool module 111 is used to calculate the remaining available addresses in the subnet where the transmission port address is located after the user configures the transmission port address, and to evenly distribute the addresses to the front and back ends as address pool addresses. The number of addresses in the address pool is compared with the number of service types supported by the device. When the number of addresses in the address pool is less than the number of service types, the service type in the record table is null (i.e., the first type), and the result is written to the corresponding table (i.e., the service type is written to the corresponding table, but the correspondence between the service type and the address is not recorded in the corresponding table). When the number of addresses in the address pool is equal to the number of service types, one IP address is pre-allocated for each service type according to the service type, and the result is written to the corresponding table (i.e., the second local address pre-allocation result or the second peer address pre-allocation result is obtained). When the number of addresses in the address pool is greater than the number of service types, one IP address is pre-allocated for each service type according to the service type, and the excess IP addresses are pre-allocated according to the number of policies supported by each service type, prioritizing services with more policies, and the result is written to the corresponding table (i.e., the third local address pre-allocation result or the third peer address pre-allocation result is obtained). The record table module 112 records and maintains the usage of the corresponding address pool, including an address pool and service type mapping table (used to record the local address pre-allocation results) and an address pool address status table (used to record the local address pool address usage status). The mapping table records the relationship between service type, pre-allocated address, and the number of enabled policies for that service type. When the service type is not null, the number of enabled policies for the service type is checked periodically, and the mapping table is updated accordingly. The status table records the address pool address, port, service information, and last usage time. The usage time of the data transmission address and port in the status table is checked periodically, and resources are released and the record table is updated promptly when the address pool address usage status or the remote address pre-allocation result is obtained in the same way, except that the remote network isolation device performs the address pre-allocation process. To avoid repetition, this will not be elaborated further.
[0057] The following is combined Figure 4 The functional module composition diagram of the address pool module is illustrated by example.
[0058] like Figure 4 As shown, in some embodiments of this application, the connection module includes: an address acquisition module 122 and a connection judgment module 121.
[0059] The address acquisition module 122 is configured to obtain the local data transmission address and the port of the data to be transmitted from the peer based on the service type of the data to be transmitted from the peer by querying the local address pre-allocation result.
[0060] For example, in some embodiments of this application, the address acquisition module 122 is further configured to: if it is confirmed that the service type of the data to be transmitted by the peer is a first type, then read the next address and port from the local address pool as the data transmission address and the port. In some embodiments of this application, when the number of service types is greater than the number of policies, the addresses in the address pool are read sequentially to complete the address allocation, which can improve the utilization efficiency of addresses in the address pool and ensure the efficient use of scarce resources (i.e., addresses).
[0061] For example, in some embodiments of this application, the address acquisition module 122 is further configured to: if it is confirmed that the service type to which the data to be transmitted from the peer belongs is not a first type, then firstly search the local address pool address usage status for the data transmission address and port used to transmit the service type to which the data to be transmitted from the peer belongs to obtain the local data transmission address and port; if the local address pool address usage status information does not find the data transmission address and port used to transmit the data to be transmitted from the peer, then further query the local address pre-allocation result to see if there is a service type without an activation policy; if so, obtain the local data transmission address and port from the pre-allocated address corresponding to the service type without an activation policy; otherwise, preferentially obtain the local data transmission address and port from the pre-allocated address corresponding to the service type with fewer activation policies. In some embodiments of this application, when allocating the local data transmission address and port for the peer's data to be transmitted, the local data transmission address and port corresponding to each service type in the address pre-allocation result are adjusted according to the local attribute information. That is, when searching for the data transmission address and port for the peer's data to be transmitted, the address pre-allocation result can be adjusted according to the service type and device policy configuration to achieve sharing.
[0062] The connection judgment module 121 is configured to obtain the local data transmission address and port by calling the local address acquisition module if the data packet to be transmitted on the other end is the first packet, and to obtain the local data transmission address and port by calling the local record table module if the data packet to be transmitted on the other end is not the first packet, and to provide the local data transmission address and port to the data transmission module of the other end.
[0063] It is understood that the local end and the remote end in the above embodiments are determined for a specific example, that is, in an example, if the local end is the front end, the remote end is the back end, and if the local end is the back end, the remote end is the front end.
[0064] In some embodiments of this application, when there is a specific data packet to be transmitted, the data transmission address and port of the peer network isolation device are obtained through the peer address pre-allocation result, and then the data packet to be transmitted is provided to the peer.
[0065] In other words, some embodiments of this application include a connection determination module and an address acquisition module. For example, the connection determination module determines whether the message sent by the client is a new connection. If it is a new connection, the address acquisition module is called to obtain the data transmission address and port and update the status table. The subsequent (or preceding, i.e., the device acting as the real server proxy) device sends the data transmission address and port to the corresponding peer device for subsequent data transmission. If it is not a new connection, the record table module is called to read the data transmission address and port corresponding to the service from the status table and update the last usage time, then hand it over to the data transmission module for data transmission. The address acquisition module calls the record table module to read the corresponding table and obtain the data transmission address and port according to the service type. If the service type is null (i.e., the first type is marked), the address and port are retrieved from the address pool according to the status table order. If it is not null, the address and port are first retrieved from the pre-allocated address corresponding to that service type according to the status table (used to record the address usage status of the corresponding address pool). If this fails, the corresponding table (used to record the corresponding address pre-allocation results) is queried to see if there is a service type without a startup policy. If there is a service type without a startup policy, the address and port are retrieved from the pre-allocated address status table corresponding to that service type. Otherwise, the address and port are retrieved from the pre-allocated address status table corresponding to the service type with fewer startup policies. The retrieved transmission port address and port are then returned to the connection determination module.
[0066] The following is combined Figure 5 Exemplary illustration of running in Figure 2 Data transmission methods on network isolation devices at both ends.
[0067] like Figure 5 As shown, some embodiments of this application provide a method for transmitting data between network isolation systems. The network isolation system includes a first network isolation device communicating with a client and a second network isolation device communicating with a server. The method includes: S101, receiving a message to be transmitted; S102, if it is confirmed that a new connection needs to be established for the message to be transmitted, obtaining the peer data transmission address and port by querying the peer address pre-allocation result or the peer address pool address usage status, wherein the peer address pre-allocation result is determined by comparing the size relationship between the number of peer service types and the number of addresses in the peer address pool; S103, sending the local data message to be transmitted to the peer network isolation device through the peer data transmission address and port.
[0068] The following example illustrates a method for obtaining the pre-allocation result of the peer address. It can be understood that the method for obtaining the pre-allocation result of the local address is the same, only the network isolation device used is different.
[0069] In some embodiments of this application, before obtaining the peer data transmission address and port by querying peer address pre-allocation result information or peer address pool address usage status information as described in S102, the method further includes the following method for obtaining peer address pre-allocation results, which can be executed by the peer network isolation device:
[0070] The first step is to configure the peer's transmission port address.
[0071] The second step is to calculate the remaining available addresses in the subnet where the peer's transmission port address is located, and obtain the set of addresses to be allocated.
[0072] The third step is to equally distribute all addresses in the set of addresses to be allocated to the first network isolation device and the second network isolation device, as address pools for the corresponding network isolation devices.
[0073] The fourth step is to pre-allocate the addresses in the peer address pool according to the relationship between the number of peer service types and the number of addresses in the peer address pool, and obtain the peer address pre-allocation result.
[0074] For example, in some embodiments of this application, the fourth step of pre-allocating the addresses in the address pool according to the relationship between the number of service types and the number of addresses in the address pool, and obtaining the address pre-allocation result, includes, for example,: if it is confirmed that the number of peer service types is greater than the number of addresses in the peer address pool, then a first type label is assigned to each service type and the addresses in the peer address pool are used as the peer address pre-allocation result; if it is confirmed that the number of peer service types is equal to the number of addresses in the peer address pool, then each address in the peer address pool is pre-allocated to a service type, obtaining the correspondence between each address and port and the service type, and the correspondence is used as at least part of the information in the peer address pre-allocation result; if it is confirmed that the number of peer service types is less than the number of addresses in the peer address pool, then each address in the peer address pool is assigned to a service type, and the remaining addresses in the peer address pool are pre-allocated again according to the policy number of the service type; the addresses and ports pre-allocated for each service type are recorded to obtain the correspondence; and the correspondence is used as at least part of the information in the peer address pre-allocation result.
[0075] The implementation process of S102 is illustrated below.
[0076] In some embodiments of this application, the step S102 of obtaining the peer data transmission address and port by querying the peer address pre-allocation result or the peer address pool address usage status includes, for example: if it is confirmed that the service type of the data packet to be transmitted on the local end belongs to the first type, then the next address and port are read from the first peer address pre-allocation result as the data transmission address and the port. If it is confirmed that the service type of the data to be transmitted does not belong to the first type, then the peer data transmission address and port are obtained by first searching the peer address pool address usage status for the pre-allocated address and port corresponding to the service type of the data to be transmitted. If the process of searching the peer data transmission address and port from the peer address pool address usage status fails, then it is queried whether there is a service type without an activation policy in the peer address pre-allocation result. If so, the peer data transmission address and port are obtained from the pre-allocated address corresponding to the service type without an activation policy. Otherwise, the peer data transmission address and port are obtained preferentially from the pre-allocated address corresponding to the service type with fewer activation policies.
[0077] In some embodiments of this application, after sending the local data packet to be transmitted to the peer network isolation device through the peer data transmission address and the port, the method further includes: releasing the data transmission address and port if the local packet to be transmitted is confirmed to be an end packet.
[0078] The following is combined Figure 6 This application provides exemplary methods for transmitting data between network-isolated systems, illustrating some embodiments thereof.
[0079] like Figure 5 As shown, some embodiments of this application provide a method for transmitting data between network isolation systems, namely a method for improving the performance of cross-network secure data exchange products based on address pooling, which includes the following steps:
[0080] S111, User configures the front and rear transmission port addresses.
[0081] Users configure the transmission port addresses for the front and rear devices, which are used for communication between the front and rear devices.
[0082] S112, Calculate the addresses available for use in the address pool.
[0083] For example, based on the transmission port address and the subnet mask, the available IP addresses are automatically calculated and evenly distributed to the front and back ports as address pool addresses.
[0084] S113, compare the number of IP addresses in the address pool with the number of service types, for example, obtain the service types and the number of service types based on the pre- or post-license documents.
[0085] Compare the number of available IPs in the address pool with the number of service types supported by the device. If the number of IPs in the address pool is less than the number of service types, execute S114; if the number of IPs in the address pool is equal to the number of service types, execute S115; if the number of IPs in the address pool is less than the number of service types, execute S116.
[0086] S114, update the corresponding table, the business type is null (i.e., the first type of marker), execute S117.
[0087] S115, update the mapping table, pre-allocate an IP address for each service for data transmission, record the number of policies enabled for each service type, and execute S117.
[0088] S116, Update the corresponding table, pre-allocate one IP for each service type, and pre-allocate any extra IPs according to the number of policies supported by each service type, and record the number of policies enabled for each service type.
[0089] S117, Operation Correspondence Table.
[0090] This table records the address pre-allocation results. It should be noted that it also updates the address pool's address usage status to obtain a corresponding status table. This step involves storing the table and initiating a query of its contents. It's understandable that the data transmission address and port are only queried when the other end has data to transmit.
[0091] S121, the front-end (or back-end, i.e., the device that acts as the real client proxy) receives client messages.
[0092] S122, Determine if it is a new connection
[0093] Determine whether a new connection needs to be established based on the client message. If a new connection needs to be established, execute S123; otherwise, execute S127.
[0094] S123, the front-end (or back-end, i.e. the device that is the real client proxy) communicates with the peer device's transmission port address and listening port through the transmission port address and random port number, requesting the peer device's peer data transmission address and port.
[0095] S124: After receiving the request, the back-end (or front-end, i.e., the device that is the real server proxy) obtains the data transmission address and port.
[0096] The process of obtaining the peer's data transmission address and port includes, for example, the following: Figure 6 The process from S131 to S135.
[0097] S131, determine whether obtaining the address and port based on the service type was successful, that is, query the data transmission address and port for transmitting data of that service type based on the service type of the data to be transmitted.
[0098] Query the corresponding table to obtain the address and port based on the service type. If the service type is null, retrieve the address and port according to the status table and execute S135. If the service type is not null, retrieve the address and port from the pre-allocated address corresponding to the service type according to the status table. If successful, execute S135; otherwise, proceed to S132.
[0099] S132, query the corresponding table to see if there are any business types that do not have the policy enabled. If yes, execute S134; otherwise, execute S133.
[0100] S134, for service types without enabled policies, obtain the address and port from the status table for the pre-allocated address, and continue to execute S135.
[0101] S133: For service types with a small number of startup strategies, the pre-allocated address and port are obtained from the status table.
[0102] S135 returns the obtained address and port, and updates the status table.
[0103] S125, the backend (or frontend, i.e., the device that is the actual server proxy) returns the data transmission address and port to the peer device.
[0104] S126, the front-end (or back-end, i.e., the device that is the real client proxy) synchronous response process obtains the data transmission address and port of the peer.
[0105] S128, at this point, the front-end (or back-end, i.e., the device that is the real client proxy) has its own data transmission address and port and the data transmission address and port of the peer device, and can forward the client's messages to the peer for subsequent data transmission.
[0106] S129, the back-end (or front-end, i.e., the device that is actually acting as the proxy for the server) forwards the client's message to the server.
[0107] S127 determines whether it is a terminated message. Instead of proceeding to S128, proceed to S130.
[0108] S130: After communication is completed, release the address pool address port of the front and rear terminals and update the status table.
[0109] The following example illustrates the data transmission method provided in some embodiments of this application.
[0110] This invention uses a data exchange product that supports four business types, including protocol proxy, with a support strategy ratio of 10:10:1:1 (where protocol proxy accounts for 10 instances). Taking the addition of an HTTP proxy strategy, the data exchange direction is as follows: the front-end forwards the client's HTTP message to the back-end, and the back-end sends the client's HTTP message to the server. The invention illustrates the proxy process as follows:
[0111] 1) The user configures the front-end and rear-end transmission port addresses as 1.1.2.1 / 28 and 1.1.2.2 / 28, respectively, for communication between the front-end and rear-end devices.
[0112] 2) After configuring the transmission port address, the system automatically calculates 12 available IP addresses based on the subnet mask, and distributes them equally among the front and back ports, 6 each, as the address pool addresses.
[0113] 3) Compare the number of available IPs in the address pool (6) with the number of service types supported by the device (4). The number of IPs in the address pool is greater than the number of service types.
[0114] 4) One IP address is pre-allocated for each service type. If there are more than two IP addresses, the service type is supported by a policy ratio of 3:3:1:1, prioritizing services with more policies. The allocation result is 2, 2, 1, 1. The number of policies enabled for each service type is recorded and the corresponding table is updated.
[0115] 5) Receive client messages from the front end.
[0116] 6) Determine whether it is a new connection based on the client message. If it is a new connection, proceed to step 7; otherwise, proceed to step 16.
[0117] 7) The front-end communicates with the peer device's transmission port address and listening port through the transmission port address and random port number to request the peer device's data transmission address and port.
[0118] 8) After receiving the request, the backend obtains the data transmission address and port.
[0119] 9) Query the corresponding table, obtain the address and port according to the service type of the protocol proxy, and obtain the address and port from the pre-allocated address corresponding to the service type according to the status table. If successful, proceed to step 15). If unsuccessful, proceed to step 12.
[0120] 10) Query the corresponding table to see if there are any business types that do not have the policy enabled. If yes, proceed to step 11; otherwise, proceed to step 12.
[0121] 11) For the pre-allocated address corresponding to the service type for which the policy is not enabled, obtain the address and port from the status table and proceed to step 12.
[0122] 12) For service types with fewer startup strategies, the pre-allocated address and port are obtained from the status table.
[0123] 13) Return the obtained address and port, and update the status table.
[0124] 14) The data transmission address and port are then returned to the peer device.
[0125] 15) Pre-synchronization steps 10) to 13) obtain the data transmission address and port.
[0126] 16) At this point, the front-end device has its own data transmission address and port, as well as the data transmission address and port of the peer device. It can then forward the client's messages to the peer device for subsequent data transmission.
[0127] 17) The client message is then forwarded to the server.
[0128] 18) Determine if it is a termination message. If not, proceed to step 16; if yes, proceed to step 19.
[0129] 19) After communication is completed, release the address pool address port of the pre- and post-addressers and update the status table.
[0130] like Figure 7 As shown, this application provides an electronic device 500, including a memory 510 and a processor 520. The memory 510 stores a computer program. When the processor 520 reads the program from the memory via a bus 530 and executes the computer program, it can perform the following operations: pre-allocate addresses in an address pool to obtain a local address pre-allocation result, wherein the local address pre-allocation result is determined by comparing the number of local service types with the number of addresses in the local address pool; maintain the local address pre-allocation result and the address usage status of the local address pool; obtain the local data transmission address and port for the data packet to be transmitted from the peer based on the local address pre-allocation result; and send the local data packet to be transmitted to the peer network isolation device based on the peer data transmission address and port.
[0131] Processor 520 can process digital signals and can include various computing architectures. For example, it can be a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements multiple instruction set combinations. In some examples, processor 520 can be a microprocessor.
[0132] The memory 510 can be used to store instructions executed by the processor 520 or data related to the execution of instructions. These instructions and / or data may include code used to implement some or all of the functions of one or more modules described in the embodiments of this application. The processor 520 of the embodiments of this disclosure can be used to execute the instructions in the memory 510 to implement… Figure 5 or Figure 6 The method shown. Memory 510 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memory well known to those skilled in the art.
[0133] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
[0134] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0135] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0136] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.
[0137] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0138] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
Claims
1. A network isolation device, characterized in that, The network isolation device includes: The configuration module is configured as follows: Complete the pre-allocation of addresses in the address pool to obtain the local address pre-allocation result, wherein the local address pre-allocation result is determined by comparing the size relationship between the number of local service types and the number of addresses in the local address pool; Maintain the local address pre-allocation results and the local address pool address usage status; The connection module is configured to obtain the local data transmission address and port of the data packet to be transmitted from the peer based on the local address pre-allocation result; The data transmission module is configured to send the local data packet to be transmitted to the network isolation device located at the other end based on the data transmission address and port of the other end; The configuration module further includes: The address pool module is configured as follows: Calculate the remaining available addresses in the subnet where the transmission port address is located to obtain the set of addresses to be allocated; All addresses in the set of addresses to be allocated are equally distributed to the network isolation device and the peer network isolation device to obtain the local address pool and the peer address pool. The address pre-allocation strategy is determined according to the relationship between the number of local service types and the number of addresses in the local address pool, and the address pre-allocation in the local address pool is completed according to the address pre-allocation strategy to obtain the local address pre-allocation result. The record table module is configured to store the local address pre-allocation results and the local address pool address usage status.
2. The network isolation device as described in claim 1, characterized in that, The address pool module is also configured to: If it is confirmed that the number of local service types is greater than the number of addresses in the local address pool, then a first tag is assigned to each service type and the address in the local address pool is used as the first local address pre-allocation result; If it is confirmed that the number of local service types is equal to the number of addresses in the local address pool, then each address in the local address pool is pre-assigned to a service type to obtain the correspondence between each address and port and the service type, and the correspondence is used as at least part of the information in the second local address pre-assignment result information; If it is confirmed that the number of local service types is less than the number of addresses in the local address pool, then each address in the local address pool is assigned to a service type, and the remaining addresses in the local address pool are pre-allocated according to the policy number of the service type; the addresses and ports pre-allocated for each service type are recorded to obtain the correspondence; the correspondence is used as at least part of the information in the third local address pre-allocation result.
3. The network isolation device as described in claim 2, characterized in that, The second local address pre-allocation result and the third local address pre-allocation result are also used to record the number of strategies initiated for each service type at the current time.
4. The network isolation device as described in claim 1, characterized in that, The connection module includes: The address acquisition module is configured to obtain the local data transmission address and the port of the data to be transmitted by querying the local address pre-allocation result based on the service type of the data to be transmitted by the peer. The connection judgment module is configured to obtain the local data transmission address and port by calling the address acquisition module if the data packet to be transmitted from the peer is the first packet, and to obtain the local data transmission address and port by calling the record table module if the data packet to be transmitted from the peer is not the first packet, and to provide the local data transmission address and port to the data transmission module of the peer.
5. The network isolation device as described in claim 4, characterized in that, The address acquisition module is further configured to: If it is confirmed that the service type of the data to be transmitted from the peer end is the first type, then the next address and port are read from the local address pool as the data transmission address and the port; wherein the first type represents the service type as null.
6. The network isolation device as described in claim 5, characterized in that, The address acquisition module is further configured to: If it is confirmed that the service type of the data to be transmitted from the peer does not belong to the first type, then the local data transmission address and port are obtained by first searching the local address pool address usage status for the data transmission address and port used to transmit the data to be transmitted from the peer. If the local address pool address usage status information does not find the data transmission address and port used to transmit the data to be transmitted from the peer, then the local address pre-allocation result is further queried to see if there is a service type without an activation policy. If so, the local data transmission address and port are obtained from the pre-allocated address corresponding to the service type without an activation policy. Otherwise, the local data transmission address and port are obtained from the pre-allocated address corresponding to the service type with fewer activation policies.
7. A method for transmitting data between network isolation systems, said network isolation system comprising a first network isolation device communicating with a client and a second network isolation device communicating with a server, characterized in that, The method includes: Receive the message to be transmitted; If it is confirmed that a new connection needs to be established for the message to be transmitted, the peer data transmission address and port are obtained by querying the peer address pre-allocation result. The peer address pre-allocation result is determined by comparing the size relationship between the number of peer service types and the number of addresses in the peer address pool. Send the local data packet to be transmitted to the peer network isolation device through the peer data transmission address and port; The method for determining the pre-allocation result of the peer address includes: The address pre-allocation strategy is determined according to the relationship between the number of service types and the number of addresses in the peer address pool, and the pre-allocation of addresses in the peer address pool is completed according to the address pre-allocation strategy to obtain the peer address pre-allocation result. Before obtaining the peer data transmission address and port by querying the peer address pre-allocation result, the method further includes: Configure the peer's transmission port address; Calculate the remaining available addresses in the subnet where the peer's transmission port address is located to obtain the set of addresses to be allocated; All addresses in the set of addresses to be allocated are equally distributed to the first network isolation device and the second network isolation device, forming an address pool for the corresponding network isolation device. The pre-allocation of addresses in the peer address pool is completed according to the relationship between the number of peer service types and the number of addresses in the peer address pool, thus obtaining the peer address pre-allocation result.
8. The method as described in claim 7, characterized in that, The pre-allocation of addresses in the peer address pool is performed according to the relationship between the number of peer service types and the number of addresses in the peer address pool, resulting in the peer address pre-allocation result, including: If it is confirmed that the number of peer service types is greater than the number of addresses in the peer address pool, then a first type tag is assigned to each service type and the address in the peer address pool is used as the first peer address pre-allocation result. If it is confirmed that the number of peer service types is equal to the number of addresses in the peer address pool, then each address in the peer address pool is pre-assigned to a service type to obtain the correspondence between each address and port and the service type, and the correspondence is used as at least part of the information in the second peer address pre-assignment result; If it is confirmed that the number of peer service types is less than the number of addresses in the peer address pool, then each address in the peer address pool is assigned to a service type, and the remaining addresses in the peer address pool are pre-allocated according to the policy number of the service type; the addresses and ports pre-allocated for each service type are recorded to obtain the correspondence; the correspondence is used as at least part of the information in the third peer address pre-allocation result.
9. The method as described in claim 7, characterized in that, The step of obtaining the peer data transmission address and port by querying the peer address pre-allocation result includes: If it is confirmed that the service type of the data packet to be transmitted on the local end is the first type, then the next address and port are read from the first peer address pre-allocation result as the data transmission address and the port; wherein the first type represents the service type as null.
10. The method as described in claim 7, characterized in that, The step of obtaining the peer data transmission address and port by querying the peer address pre-allocation result includes: If it is confirmed that the service type to which the data to be transmitted belongs does not belong to the first type, then the pre-allocated address and port of the service type to which the data to be transmitted belongs are first searched from the address usage status of the peer address pool to obtain the peer data transmission address and port. If the process of searching for the peer data transmission address and port from the address usage status of the peer address pool fails, then it is queried whether there is a service type without a startup policy in the peer address pre-allocation result. If there is, the peer data transmission address and port are obtained from the pre-allocated address corresponding to the service type without a startup policy. Otherwise, the peer data transmission address and port are obtained from the pre-allocated address corresponding to the service type with fewer startup policies. The first type represents the service type as null.
11. The method as described in claim 7, characterized in that, After sending the local data packet to be transmitted to the peer network isolation device via the peer data transmission address and the port, the method further includes: If it is confirmed that the message to be transmitted on this end is an end message, then the data transmission address and port are released.
12. An electronic device comprising a memory and a processor, wherein, The memory stores a computer program, and the processor, when executing the computer program, can perform the following operations: Complete the pre-allocation of addresses in the address pool to obtain the local address pre-allocation result, wherein the local address pre-allocation result is determined by comparing the size relationship between the number of local service types and the number of addresses in the local address pool; Maintain the local address pre-allocation results and the local address pool address usage status; Based on the pre-allocation result of the local address, obtain the local data transmission address and port of the data packet to be transmitted from the peer. Based on the peer's data transmission address and port, send the local data packet to be transmitted to the peer's network isolation device; The pre-allocation of addresses in the address pool is completed, and the local address pre-allocation result is obtained, including: The address pre-allocation strategy is determined according to the relationship between the number of local service types and the number of addresses in the local address pool, and the address pre-allocation in the local address pool is completed according to the address pre-allocation strategy to obtain the local address pre-allocation result. The step of determining the address pre-allocation strategy based on the relationship between the number of local service types and the number of addresses in the local address pool, and then pre-allocating addresses in the local address pool according to the address pre-allocation strategy to obtain the local address pre-allocation result, specifically includes: Calculate the remaining available addresses in the subnet where the transmission port address is located to obtain the set of addresses to be allocated; All addresses in the set of addresses to be allocated are equally distributed to the network isolation device and the peer network isolation device to obtain the local address pool and the peer address pool. The address pre-allocation strategy is determined based on the relationship between the number of local service types and the number of addresses in the local address pool, and the pre-allocation of addresses in the local address pool is completed according to the address pre-allocation strategy to obtain the local address pre-allocation result.
Citation Information
Patent Citations
Data transmission method and data transmission system based on distributed FTP
CN104519138A