Private network data transmission method and device
By establishing a pre-defined proxy network of proxy nodes and intermediate nodes in a private network, the high cost and security issues of data interaction between different private networks are solved, and fast and secure data transmission is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-07-19
- Publication Date
- 2026-03-03
AI Technical Summary
Data interaction between different private networks is costly, time-consuming, and carries load and security risks due to data traffic needing to be forwarded through a central server.
Access request data is obtained through proxy nodes, address matching is performed, a preset proxy network is established, and data is transmitted using intermediate nodes or intermediate lower-level nodes to avoid forwarding by the central server.
It reduces connection costs, avoids load and data security issues, and enables rapid data exchange between private networks.
Smart Images

Figure CN116846971B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network technology, and in particular to a method and apparatus for private network data transmission. Background Technology
[0002] With the development of industrial digitalization, more and more data collection and processing processes need to involve data in multiple private domain networks (or private networks). Because different private domain networks are not interconnected, and even sub-networks within a private domain network may not be interconnected, data cannot be exchanged between different private domain networks or between non-interconnected sub-networks within the same private domain network, forming "data silos".
[0003] In related technologies, to solve the aforementioned data interoperability problem, one approach is to establish dedicated lines and networks to achieve physical connectivity between private networks. However, this solution incurs significant costs in terms of dedicated line setup and hardware, and waiting for the dedicated line to be set up when a new private network joins is time-consuming and slow to respond. Another approach is to build a VPN (Virtual Private Network) server on an external network, with private networks connecting to this server to achieve network interoperability. However, this solution requires traffic to be forwarded through a central server, i.e., an external VPN server, and all traffic must pass through this server for forwarding, raising issues of load and data security. Summary of the Invention
[0004] To provide a basic understanding of some aspects of the disclosed embodiments, a brief summary is given below. This summary is not intended as a general commentary, nor is it intended to identify key / important components or describe the scope of protection of these embodiments, but rather as a prelude to the detailed description that follows.
[0005] In view of the shortcomings of the prior art described above, the present invention discloses a private network data transmission method and apparatus to solve the technical problems of high cost, data traffic needing to be forwarded through an external central server, and load and data security issues in the methods provided in the above-mentioned related technologies for connecting non-interconnected private networks.
[0006] This invention provides a method for data transmission in a private network. The method includes obtaining access request data for a service request in the private network through a proxy node. The access request data includes the target address of the target service and the request access data. A first match is performed between the target address and the proxy node address of the proxy node. If the first match fails, the proxy node is used as the initial current node, and the intermediate node determination step is repeated until a preset termination condition is met. The intermediate node determination step includes: the current node transparently transmitting the target address to a parent node, triggering the parent node to perform a second match between the target address and multiple parent node addresses of the parent node. If the second match fails, the parent node is used as the new current node. The preset proxy network is the parent node of the current node. The preset proxy network is constructed based on multiple preset nodes, where at least two preset nodes belong to different private networks. The addresses of the multiple parent nodes include the parent node's own route and the subordinate routes of each subordinate node under the parent node. The preset termination condition includes a second successful match and the parent node being any one of the top-level nodes. If the second match is successful, the parent node at the time of the second successful match is determined as an intermediate node. Based on the matching result between the target address and the parent node's own route, the requested access data is transmitted to the target service through the intermediate node or an intermediate subordinate node. The intermediate subordinate node is a subordinate node of the intermediate node in the preset proxy network.
[0007] In one embodiment of the present invention, based on the matching result of the target address and the upper-level self-route, the request access data is transmitted to the target service through the intermediate node or the intermediate lower-level node, including: if the target address matches the upper-level self-route; sending a first reply message of the request access data to the proxy node through the intermediate communication interface of the intermediate node, the first reply message including the intermediate address of the intermediate node, to trigger the proxy node to establish a first communication connection link with the intermediate node, so that the proxy node transmits the request access data to the target service through the intermediate node.
[0008] In one embodiment of the present invention, after the proxy node establishes a first communication connection link with the intermediate node, the method further includes at least one of the following: the intermediate node obtains feedback data from the target service based on the request access data, transmits the feedback data to the proxy node through the first communication connection link, so as to transmit the feedback data to the request service through the proxy node; the proxy node sends a connection success message to the request service and receives data to be transmitted sent by the request service, the proxy node sends the data to be transmitted to the intermediate node through the first communication connection link, and the intermediate node transmits the data to be transmitted to the target service through the intermediate node.
[0009] In one embodiment of the present invention, the method of transmitting the requested access data to the target service through the intermediate node or intermediate subordinate node according to the matching result of the target address and the upper-level self-route includes: if the target address does not match the upper-level self-route, then the intermediate node sends an active addressing message to each subordinate node of the intermediate node in the preset proxy network, so as to determine a subordinate node as the intermediate subordinate node based on the feedback message of the received active addressing message, and transmits the requested access data to the target service through the intermediate subordinate node; sends a first reply message of the requested access data to the proxy node through the intermediate communication interface of the intermediate node, the first reply message including the intermediate address of the intermediate node, so as to trigger the proxy node to establish a first communication connection link with the intermediate node; and sends a second reply message of the requested access data to the intermediate node through the subordinate communication interface of the intermediate subordinate node, the second reply message including the subordinate address of the intermediate subordinate node, so as to trigger the intermediate node to establish a second communication connection link with the intermediate subordinate node.
[0010] In one embodiment of the present invention, after the proxy node establishes a first communication connection link with the intermediate node and the intermediate node establishes a second communication connection link with the intermediate lower-level node, the method further includes at least one of the following: the intermediate lower-level node obtains feedback data from the target service based on the request access data, transmits the feedback data to the intermediate node through the second communication connection link, and the intermediate node transmits the obtained feedback data to the proxy node through the first communication connection link, so as to transmit the feedback data to the request service through the proxy node; the proxy node sends a connection success message to the request service and receives data to be transmitted sent by the request service, the proxy node sends the data to be transmitted to the intermediate node through the first communication connection link, and the intermediate node transmits the obtained data to be transmitted to the intermediate lower-level node through the second communication connection link, so as to transmit the data to be transmitted to the target service through the intermediate lower-level node.
[0011] In one embodiment of the present invention, if the first match is successful, the proxy node is determined as an intermediate node.
[0012] In one embodiment of the present invention, the intermediate node determination step is repeated until the parent node is a top-level node. The method further includes: generating a connection failure message through the top-level node; transmitting the connection failure message through all traversed nodes to a proxy node, wherein the traversed nodes are nodes in the preset proxy network that have obtained the requested access data; and sending connection rejection information to the request service through the proxy node, wherein the connection rejection information is generated by the proxy node based on the connection failure message.
[0013] In one embodiment of the present invention, the current node transparently transmits the target address to the upper-level node, including: the current node generating a request identifier for the access request data; generating an addressing message based on the request identifier and the target address; and the current node transparently transmitting the addressing message to the upper-level node.
[0014] In one embodiment of the present invention, before repeatedly executing the intermediate node determination step, the method further includes: the node to be joined to the network opens a first communication port and a second communication port, the first communication port being used to communicate with the network service corresponding to the node to be joined, and the second communication port being used to communicate with the already joined nodes in the preset proxy network; after the node to be joined connects to the selected node, it sends the address and identity information of the node to be joined to the selected node, so that the selected node records the identity information of the node to be joined and adds the address of the node to be joined to the selected node's set of selected node addresses, the selected node being a preset node in the preset proxy network, the preset proxy network including at least one preset node; if the selected node is the top-level node of the preset proxy network, it is determined that the network to be joined is connected to the preset proxy network; if the selected node has a predecessor node in the preset proxy network, the added set of selected node addresses is reported to the predecessor node, so that the added set of selected node addresses is included in the selected node's set of selected node addresses. The node address set is added to the previous node's address set. If the previous node is a top-level node, it is determined that the network to be connected to the network is connected to the preset proxy network. If the previous node has a node to be reported in the preset proxy network, the added previous node address set is sent to the node to be reported, so that the added previous node address set is added to the node to be reported's address set, and the node to be reported is set as the new previous node. The steps of adding the added previous node address set to the node to be reported, adding the added previous node address set to the node to be reported, and setting the node to be reported as the new previous node are repeated until the node to be reported is a top-level node, and it is determined that the network to be connected to the network is connected to the preset proxy network. The previous node is the parent node of the selected node in the preset proxy network, and the node to be reported is the parent node of the previous node in the preset proxy network.
[0015] In one embodiment of the present invention, the method further includes: acquiring a newly added proxy network, the newly added proxy network being constructed based on multiple newly added nodes, at least two of which belong to different private networks; controlling the top-level node of the preset proxy network to connect with a target newly added node in the newly added proxy network; sending the top-level node address and top-level node identity information of the top-level node to the target newly added node, so that the target newly added node records the top-level node identity information and adds the top-level node address to the target newly added node address set of the target newly added node; if the target newly added node is the top-level node of the newly added proxy network, determining that the top-level node has accessed the newly added proxy network; if the target newly added node has a predecessor node in the newly added proxy network, reporting the added target newly added node address set to the new predecessor node, so that the added target newly added node address set is added to the new predecessor node address set of the new predecessor node; if the new predecessor node is the top-level node of the newly added proxy network... The process involves determining if the top-level node is connected to the new proxy network. If the new parent node has a reporting node in the new proxy network, the added set of addresses of the new parent node is sent to the reporting node to add the added set of addresses of the new parent node to the reporting node's reporting address set. The reporting node is then designated as the new parent node. This process is repeated until the reporting node becomes the top-level node of the new proxy network. The top-level node is then confirmed to be connected to the new proxy network. The new parent node is the parent node of the target new node in the new proxy network, and the reporting node is the parent node of the new parent node in the new proxy network.
[0016] In one embodiment of the present invention, the method further includes: obtaining a node change instruction, the node change instruction including a change node, the change node being a preset node in the preset proxy network other than the selected node; after connecting the node to be connected to the change node, sending the address of the node to be connected and the identity information of the node to be connected to the change node to the change node, so that the change node records the identity information of the node to be connected and adds the address of the node to be connected to the change node address set of the change node; if the change node is a top-level node of the preset proxy network, determining that the network to be connected is connected to the preset proxy network; if the change node has a previous node in the preset proxy network, reporting the added set of change node addresses to the previous node, so as to add the added set of change node addresses to the previous node's set of previous node addresses; if the previous node is a top-level node, determining that the network to be connected is connected to the preset proxy network. In a proxy network, if the node to be changed has a change reporting node in the preset proxy network, the added set of addresses of the node to be changed is sent to the change reporting node to add the added set of addresses of the node to the change reporting node's change reporting address set, and the change reporting node is designated as the new node to be changed. This process is repeated until the change reporting node is a top-level node, at which point the node to be added to the network is determined to have completed the node change. The node to be changed is the parent node of the node to be changed in the preset proxy network, and the change reporting node is the parent node of the node to be changed in the preset proxy network.
[0017] This invention also provides a private network data transmission device, comprising a proxy node for acquiring access request data for a service request in the private network, the access request data including the target address of the target service and the requested access data; a first matching module for performing a first match between the target address and the proxy node address of the proxy node; and a second matching module for, if the first match fails, repeatedly executing the intermediate node determination step with the proxy node as the initial current node until a preset termination condition is met, the intermediate node determination step including the current node forwarding the target address to a parent node, triggering the parent node to perform a second match between the target address and multiple parent node addresses of the parent node, and if the second match fails, setting the parent node as the new current node. The parent node is the node above the current node in the preset proxy network. The preset proxy network is constructed based on multiple preset nodes, where at least two preset nodes belong to different private networks. The addresses of the multiple parent nodes include the parent node's own route and the route of each subordinate node of the parent node. The preset termination condition includes a second successful match and the parent node being any one of the top-level nodes. The data transmission module is used to determine the parent node at the time of the second successful match as an intermediate node if the second match is successful, and to transmit the requested access data to the target service through the intermediate node or intermediate subordinate node according to the matching result of the target address and the parent node's own route. The intermediate subordinate node is a subordinate node of the intermediate node in the preset proxy network.
[0018] The beneficial effects of this invention are:
[0019] By acquiring access request data for services within the private network through proxy nodes, the target address of the access request data is first matched with the proxy node address. If the first match fails, the target address is forwarded to the proxy node's superior node in the preset proxy network, and then matched with the superior node address. If the second match fails, the target address is forwarded to the next higher-level node for a second match. If the second match succeeds, the access request data is transmitted to the target service through the superior node or its subordinate nodes. In this way, by connecting the proxy nodes in the private network through software, a preset proxy network is established. Only the deployed nodes in the private network need to have the ability to access the external network, eliminating the need for dedicated lines. The connection in the private network can be direct or relayed through superior nodes, without the need for a single central server, thus reducing costs and avoiding load and data security issues. Attached Figure Description
[0020] Figure 1This is a flowchart illustrating a private network data transmission method in an embodiment of the present invention;
[0021] Figure 2 This is a schematic diagram of a network access process in an embodiment of the present invention;
[0022] Figure 3 This is a schematic flowchart of a private network data transmission method in an embodiment of the present invention;
[0023] Figure 4 This is a schematic flowchart of another private network data transmission method in an embodiment of the present invention;
[0024] Figure 5 This is a schematic diagram of the structure of a private network data transmission device in an embodiment of the present invention;
[0025] Figure 6 This is a schematic diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0026] The following specific examples illustrate the implementation of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that, unless otherwise specified, the following embodiments and sub-samples in the embodiments can be combined with each other.
[0027] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.
[0028] In the following description, numerous details are explored to provide a more thorough explanation of embodiments of the invention. However, it will be apparent to those skilled in the art that embodiments of the invention may be practiced without these specific details. In other embodiments, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring embodiments of the invention.
[0029] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for the embodiments of this disclosure described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion.
[0030] Unless otherwise stated, the term "multiple" means two or more.
[0031] In this embodiment of the disclosure, the character " / " indicates that the objects before and after it are in an "or" relationship. For example, A / B means: A or B.
[0032] The term "and / or" describes an association between objects, indicating that three relationships can exist. For example, A and / or B means: A or B, or A and B.
[0033] Combination Figure 1 As shown, Figure 1 This is a flowchart illustrating a private network data transmission method provided in an embodiment of the present invention, such as... Figure 1 As shown, steps S110-S140 are described in detail below:
[0034] Step S110: Obtain access request data for services requested in the private network through the proxy node.
[0035] The access request data includes the target address of the target service and the access request data. The target service can be located through the target address. For example, the target address includes, but is not limited to, information such as IP address and port number. The access request data can be data such as a request body. The specific structure and content of the access request data can also be defined by those skilled in the art as needed.
[0036] It should be noted that the target service requested by the requesting service can be another service located on the same private network as the requesting service, whose data is not originally interoperable with the data of the requesting service. Alternatively, the target service requested by the requesting service can be another service located on a different private network, where the requesting service and target service on the two private networks are not originally interoperable, as described in the background section.
[0037] Step S120: Perform a first match between the target address and the proxy node address of the proxy node.
[0038] The number of proxy node addresses and subsequent current node addresses can be one or more. A proxy node address is an address that the proxy node itself can access, and if the proxy node has subordinate nodes, the proxy node address also includes addresses that the subordinate nodes can access. In other words, the proxy node address includes the proxy node's own routes and the routes of each subordinate node's subordinate self. Proxy node addresses can be obtained from the proxy node's routing table. If the destination address is the same as a proxy node address, or the destination address is within the range accessible by a certain proxy node address, then it is considered a successful first match; otherwise, if every proxy node address is different from the destination address, then it is considered a failed first match.
[0039] In this embodiment, if the proxy node address has both addresses that the proxy node itself can access and addresses that its subordinate nodes can access, then in order to improve matching efficiency, the first matching can be performed on the addresses that the proxy node itself can access, and then the first matching can be performed on the addresses that its subordinate nodes can access.
[0040] By performing a first match between the target address and the proxy node address, it can be determined whether the proxy node has the ability or possibility to access the target service (the proxy node of the target service is a subordinate node of the proxy node). If the first match fails, it means that the proxy node of the target service is not the proxy node that obtains the requested access data or a subordinate node of the proxy node.
[0041] Step S130: If the first match fails, the proxy node is used as the initial current node, and the intermediate node determination step is repeated until the preset termination condition is met.
[0042] In this embodiment, the intermediate node determination step includes: the current node transparently transmits the target address to the upper-level node, triggering the upper-level node to perform a second matching between the target address and multiple upper-level node addresses.
[0043] If the second match fails, the parent node is taken as the new current node. Since the address of the parent node can be an address that the parent node itself can directly access, or it can be the address of the current node and the addresses of other lower-level nodes (other nodes besides the current node, if they exist), the number of parent node addresses is generally multiple. However, it is possible that the parent node itself does not have an accessible address configured. In this case, the parent node address is the same as the current node address, and the number of multiple parent node addresses may also be one. In this case, "one parent node address" can be regarded as multiple parent node addresses consisting of "current node address + empty parent node address", which does not violate the original intention of the solution provided in this embodiment.
[0044] The current node address is the address that the current node itself can access. If the current node has subordinate nodes, the current node address also includes the addresses that those subordinate nodes can access. In other words, the current node address includes the current node's own routes and the routes of each of its subordinate nodes' subordinates. The current node address can be obtained from the current node's routing table. If the destination address is the same as a current node address, or the destination address is within the range accessible by a current node address, then the second match is successful. Otherwise, if every current node address is different from the destination address, the second match fails.
[0045] In this embodiment, if the current node address has addresses accessible to both the current node itself and its subordinate nodes, then to improve matching efficiency, a second matching can be performed on the addresses accessible to the current node itself, followed by a second matching on the addresses accessible to the subordinate nodes. Multiple parent node addresses include the parent node's own parent route and the subordinate routes of each subordinate node under the parent node. That is, each node's routing table contains address information accessible to the node itself (node's own route) and address information accessible to its subordinate nodes reported by the subordinate nodes of that node (subordinate's own route). For details, please refer to the relevant description of the current node address in the above embodiments. The meaning of the parent node address here is similar to that of the current node address (the current node is not a proxy node), and will not be repeated here.
[0046] The preset termination conditions include a successful second match, or the parent node being a top-level node. In other words, assuming the node currently receiving the request data is the top-level node (root node) of the preset proxy network, there is no higher-level node available for data transmission, thus the process ends, and no intermediate node is determined. When the second match is successful, that is, the routing table of a certain node X includes the target address, it means that a node capable of accessing the target service has been found. At this point, the request data transmission can be stopped, the search objective is achieved, and node X is designated as an intermediate node.
[0047] The parent node is the node one level above the current node in the preset proxy network. The preset proxy network is built based on multiple preset nodes, of which at least two preset nodes belong to different private networks. This preset proxy network can be a tree network, etc.
[0048] In this embodiment, the current node can be a proxy node corresponding to the requested service, or a non-top-level node such as the proxy node's parent node A or parent node B. When the current node is a proxy node, it means that the current node directly establishes a connection with the requested service and obtains the requested access data. When the current node is a node other than the proxy node, i.e., the aforementioned parent node, it means that the parent node receives the target address transmitted through its corresponding lower-level node.
[0049] In this embodiment, when the target address does not exist in its own routing table, it uses an addressing message to search for it from the superior node.
[0050] Addressing messages use TCP to transmit JSON strings. An example addressing message format is as follows:
[0051] {
[0052] "target":"target IP:port",
[0053] "id":"Unique ID",
[0054] "type":"address"
[0055] }
[0056] In one embodiment, before step S130, i.e., before repeatedly executing the intermediate node determination step, the step of adding the proxy node to the preset proxy network is performed. Taking a proxy node that has not joined the preset proxy network as a node to be added to the network and a request service as a service to be added to the network as an example, this method includes: the node to be added to the network opens a first communication port and a second communication port. The first communication port is used to communicate with the service to be added to the network corresponding to the node to be added to the network, and the second communication port is used to communicate with nodes that have already joined the network in the preset proxy network (i.e., preset nodes that have previously successfully joined the preset proxy network); after the node to be added to the network connects to the selected node, it sends the address of the node to be added to the network and the identity information of the node to be added to the selected node, so that the selected node records the identity information of the node to be added to the set of selected node addresses of the selected node. The selected node is a preset node in the preset proxy network, and the preset proxy network includes at least one preset node; if the selected node is the top-level node of the preset proxy network, it is determined that the network to be added to the preset proxy network is connected; if the selected node has a predecessor node in the preset proxy network ( That is, if the selected node has a parent node in the preset proxy network (the preset proxy network is a tree structure), the added set of selected node addresses is reported to the previous node, so that the added set of selected node addresses is added to the previous node's set of parent node addresses. If the previous node is a top-level node, it is determined that the network to be joined is connected to the preset proxy network. If the previous node has a node to be reported in the preset proxy network, the added set of parent node addresses is sent to the node to be reported, so that the added set of parent node addresses is added to the node to be reported's set of reported addresses. The process of adding the node to be reported as the new parent node and repeating the steps of sending the added parent node address set to the node to be reported to add the added parent node address set to the node to be reported's address set, and then adding the node to be reported as the new parent node, continues until the node to be reported becomes a top-level node. This determines that the network to be joined has accessed the preset proxy network, with the parent node being the superior node of the selected node in the preset proxy network, and the node to be reported being the superior node of the parent node in the preset proxy network. It should be noted that the network to be joined includes, but is not limited to, the network that sends access request data in the above embodiments, and the nodes to be joined include, but are not limited to, proxy nodes before joining the preset proxy network. Each preset node (except the top-level node) in the preset proxy network can be joined using the method provided in this embodiment. In this embodiment, unless otherwise specified, the superior node can generally be considered as the parent node of a node in the proxy network.In other words, when a node in a private network wants to join a preset proxy network, which includes one or more preset nodes, a preset node can be selected as the chosen node for the node seeking to join. In other words, after joining the preset proxy network, the chosen node becomes the node's parent node. After establishing a connection between the node seeking to join and the chosen node, the address accessible to the node seeking to join (i.e., the node's address) is sent to the chosen node. This allows the chosen node's routing table to be updated based on this address, adding it to its routing table. If the chosen node is a top-level node in the preset proxy network, the process ends. If the chosen node is not a top-level node, the address is updated level by level in the routing tables of each of the chosen node's parent nodes. See the relevant documentation for details. Figure 2 , Figure 2 This is a schematic diagram of a network access process provided in an embodiment of the present invention, such as... Figure 2 As shown, firstly, the node to be added to the network (referred to as "node" in this diagram) opens a SOCKS5 port (an example of a first communication port) for other services to connect to the proxy network. The node also opens a communication port (an example of a second communication port) for other proxy nodes to connect to. The node uses TCP to connect to its parent node and reports its name and manually configured accessible IP range (i.e., reporting the address and identity information of the node to be added). The parent node (selected node) records the name and stores the IP range in its own routing table (the set of selected node addresses). If the parent node itself has a parent node, it sends a routing report message to the parent node to report its updated routing table, and so on, until the top-level node. Proxy network access is then complete. For example, a node can transmit the address and identity information of the node to be added through an entry message, which can be achieved by transmitting a JSON file via TCP. An example JSON format is as follows:
[0057]
[0058]
[0059] For example, when updating the routing table, it's necessary to report its own routes to the parent node to facilitate addressing by other branch nodes. This can be achieved through route reporting messages, which use TCP to transmit JSON strings. An example route reporting message format is as follows:
[0060]
[0061] In one embodiment, the address of the node to be added to the network, i.e., the accessible IP range configured for the node, is unique within the same network. This ensures that only one node is configured for a service within the network. The address of this node is also different from the addresses of the selected node and its existing subordinate nodes in the preset proxy network. This ensures that when accessing a service through the selected node, two services matching the address requirements will not be found due to address conflicts. The configuration of the node address can be done manually, according to certain address requirements known to those skilled in the art. The configuration of the node address can also be achieved through other methods known to those skilled in the art, which will not be elaborated upon here.
[0062] In this embodiment, the implementation of the scheme also supports the merging of multiple proxy networks. Taking the merging of two proxy networks as an example, firstly, a new proxy network is obtained. The new proxy network is built based on multiple new nodes, with at least two new nodes belonging to different private networks. The top-level node of the preset proxy network is controlled to connect with the target new node in the new proxy network (establishing a communication connection; the target new node is one of the new nodes selected from the multiple new nodes in the new proxy network). The top-level node address and top-level node identity information of the top-level node are sent to the target new node, so that the target new node records the top-level node identity information and adds the top-level node address to the target new node's target new node address set. If the target new node is the top-level node of the new proxy network, it is determined that the top-level node has accessed the new proxy network. If the target new node has a parent node in the new proxy network (to distinguish it from the name of the preset proxy network, it can be referred to here as the new parent node, i.e., the parent node of the target new node in the new proxy network is the new parent node), the added target new node address set is reported to the new parent node to ensure that the added target new node is connected to the target new proxy network. The set of addresses for the newly added node is added to the set of addresses for the parent node of the newly added previous node. If the parent node is the top-level node of the newly added proxy network, it is confirmed that the top-level node has been connected to the newly added proxy network. If the parent node has a reporting node in the newly added proxy network, the set of addresses for the newly added parent node is sent to the reporting node to add the set of addresses for the newly added parent node to the reporting node's reporting address set, and the reporting node is set as the new parent node. This process is repeated until the reporting node is the top-level node of the newly added proxy network. The top-level node (the top-level node of the preset proxy network) is confirmed to have been connected to the newly added proxy network. The parent node is the parent node of the target newly added node in the newly added proxy network, and the reporting node is the parent node of the newly added parent node in the newly added proxy network. At this point, the top-level node of the preset proxy network can be used as the node to be added to the network in the above embodiment. Then, the network entry process of the top-level node is executed, and the routing table of the top-level node is added one by one to the routing tables of the target new node and each of the target new node's parent nodes in the new proxy network. The target new node is a new node in the new proxy network. The structure of the new proxy network in this embodiment is similar to that of the preset proxy network. The meanings of the set of addresses of the added parent node and the set of change reporting addresses in the following embodiments are similar to the meanings of the set of selected node addresses, and will not be repeated here.
[0063] In this embodiment, the implementation of the scheme also supports the change of the parent node of a certain node. Taking the need for a parent node change of a node to join the network as an example, the method includes: obtaining a node change instruction, the node change instruction including a change node, the change node being a preset node in the preset proxy network other than the selected node; after connecting the node to join the network to the change node, sending the address of the node to join the network and the identity information of the node to join the network to the change node, so that the change node records the identity information of the node to join the network and adds the address of the node to join the network to the change node's change node address set; if the change node is a top-level node of the preset proxy network, determining that the network to join the network is connected to the preset proxy network; if the change node has a parent node in the preset proxy network (the change node has a parent node, which is referred to as the parent node here for the sake of distinction from the description in the previous embodiment), reporting the added change node address set to the parent node, so that the added change node address set is added to the parent node's change parent node address set, such as... If the previous node is changed to a top-level node (the top-level node of the preset proxy network), it is determined that the network to be connected to the preset proxy network. If there is a change reporting node in the preset proxy network for the previous node, the added set of addresses of the previous node is sent to the change reporting node to add the added set of addresses of the previous node to the change reporting node's change reporting address set, and the change reporting node is set as the new previous node. This process is repeated until the change reporting node becomes a top-level node. It is determined that the node to be connected to the network has completed the node change, and the previous node is the parent node of the previous node in the preset proxy network. The change reporting node is also the parent node of the previous node in the preset proxy network. In other words, changing a node can be considered as re-entering the network for that node, selecting a new preset node as the selected node, and updating the addresses of the selected node and each of its parent nodes. It should be understood that after changing the parent node, this method also includes deleting the address of the node to be added from the routing tables of the original selected node and all its parent nodes. The address deletion action is similar to the addition action; it can be triggered by sending address deletion messages containing the address of the node to be added level by level, thereby deleting the address of the node to be added from the selected node's set of selected node addresses and the reported node's set of reported addresses.
[0064] Step S140: If the second match is successful, the parent node at the time of the second successful match is determined as the intermediate node. Based on the matching result between the target address and the parent's own route, the request access data is transmitted to the target service through the intermediate node or the intermediate lower-level node.
[0065] Among them, the intermediate subordinate nodes are the subordinate nodes of the intermediate nodes in the preset proxy network.
[0066] In other words, if a node in the pre-defined proxy network has the target address in its routing table, and this node has a hierarchical relationship with the proxy node F that initially obtained the request access data, and is the first node with the target address found by the proxy node F by searching upwards with the target address, then this pre-defined node is used as an intermediate node. The target address may be an address that the intermediate node itself can access. In this case, the request access data is directly transmitted to the target service through the intermediate node. The target address may also be a subordinate node (intermediate lower-level node) of the intermediate node other than the nodes that have been traversed before (because none of them match). In this case, the request access data can be transmitted to the target service through the intermediate lower-level node.
[0067] In this embodiment, based on the matching result between the target address and its own upper-level route, the requested access data is transmitted to the target service through an intermediate node or an intermediate lower-level node. This includes: if the target address matches the upper-level route, the intermediate node sends a first reply message containing the requested access data to the proxy node through its intermediate communication interface. The first reply message includes the intermediate address of the intermediate node, triggering the establishment of a first communication connection link between the proxy node and the intermediate node, so that the proxy node transmits the requested access data to the target service through the intermediate node. In other words, the proxy node is the first node in the preset proxy network to obtain the access request data. The proxy node is also the node corresponding to the requested service. When configuring the preset proxy network, nodes with direct or indirect hierarchical relationships can communicate, and data can be transmitted through a first communication connection link established between the proxy node and the intermediate node. The proxy node sends the requested access data to the intermediate node through the first communication connection link, and the intermediate node then sends the requested access data to the target service.
[0068] In this embodiment, after the proxy node establishes a first communication connection link with the intermediate node, the method further includes at least one of the following:
[0069] The intermediate node obtains the feedback data from the target service based on the request access data, and transmits the feedback data to the proxy node through the first communication connection link, so that the proxy node can transmit the feedback data to the request service;
[0070] The proxy node sends a connection success message to the requesting service and receives the data to be transmitted from the requesting service. The proxy node then sends the data to be transmitted to the intermediate node through the first communication connection link, and the intermediate node transmits the data to the target service.
[0071] In other words, since the proxy node and the intermediate node have established a communication link, other data can be transmitted through this communication channel. This data transmission can be unilateral, meaning the requesting service sends the data to be transmitted to the intermediate node through the proxy node, and the intermediate node then forwards the data to the target service. This data transmission can also be bidirectional, meaning the requesting service sends the data to be transmitted to the intermediate node through the proxy node, the intermediate node then forwards the data to the target service, the target service generates response data (feedback data) based on the data to be transmitted, and sends the response data to the intermediate node, which then sends it to the requesting service via the proxy node.
[0072] In another embodiment, based on the matching result between the target address and its own upper-level route, the requested access data is transmitted to the target service through an intermediate node or an intermediate lower-level node, including: if the target address does not match the upper-level route, the intermediate node sends an active addressing message to each of its subordinate nodes in a preset proxy network, so as to determine a subordinate node as an intermediate lower-level node based on the feedback message of the received active addressing message, and transmits the requested access data to the target service through the intermediate lower-level node; the intermediate node sends a first reply message of the requested access data to the proxy node through its intermediate communication interface, the first reply message including the intermediate address of the intermediate node, to trigger the proxy node to establish a first communication connection link with the intermediate node, the proxy node being the current node that first obtains the access request data; the intermediate lower-level node sends a second reply message of the requested access data to the intermediate node through its lower-level communication interface, the second reply message including the lower-level address of the intermediate lower-level node, to trigger the intermediate node to establish a second communication connection link with the intermediate lower-level node.
[0073] For example, proactive addressing messages are used in scenarios where a higher-level node proactively sends a message to a lower-level node to inquire whether a target address exists. Proactive addressing messages use TCP to transmit JSON strings. An example proactive addressing message format is as follows:
[0074] {
[0075] "target":"target IP:port",
[0076] "id":"Unique ID",
[0077] "type":"reverse-address"
[0078] }
[0079] The feedback message is generated by each subordinate node in the preset proxy network based on the received active addressing message. If the target address exists in the subordinate node's own routing table, its feedback message is a positive response; otherwise, it is a negative response.
[0080] In one embodiment, when sending an active addressing message to each subordinate node of the intermediate node in the preset proxy network through the intermediate node, nodes that have previously passed through access request data can be excluded, that is, nodes that have already been traversed are excluded to avoid doing useless work.
[0081] In one embodiment, when an intermediate node sends an active addressing message to each of its subordinate nodes in a preset proxy network, the message is sent level by level according to the hierarchy of the subordinate nodes, that is, the addressing message is sent down layer by layer until the feedback message from a certain layer is an affirmative message.
[0082] In this embodiment, after the proxy node establishes a first communication connection link with the intermediate node, and the intermediate node establishes a second communication connection link with the intermediate subordinate node, the method further includes at least one of the following:
[0083] The intermediate lower-level node obtains the feedback data from the target service based on the request access data, and transmits the feedback data to the intermediate node through the second communication connection link. The intermediate node then transmits the obtained feedback data to the proxy node through the first communication connection link, so that the proxy node can transmit the feedback data to the request service.
[0084] The proxy node sends a connection success message to the requesting service and receives the data to be transmitted from the requesting service. The proxy node sends the data to be transmitted to the intermediate node through the first communication connection link. The intermediate node transmits the acquired data to be transmitted to the intermediate lower-level node through the second communication connection link. The intermediate lower-level node then transmits the data to be transmitted to the target service.
[0085] The data transmission method here is similar to the method of transmitting data directly through intermediate nodes mentioned above. The output transmission can be either unidirectional or bidirectional.
[0086] In one embodiment, if the first match is successful, the proxy node is determined as the intermediate node.
[0087] One possible scenario is that the routing table of the proxy node's parent node happens to contain the target address. In this case, there's no need to check the routing table of the parent node's parent node; the process can be terminated directly, and the request access data can be transmitted to the target service through the current node or one of its other subordinate nodes. Since the current node may have direct access to the target service, or it may have other subordinate nodes, the steps described above for determining which intermediate node should transmit the request access data to the target service can be referenced, and will not be elaborated upon here.
[0088] Another possible scenario is that the proxy node's own routing table happens to store the target address. In this case, there's no need for the parent node to check if the target address exists in its routing table. The request data can be directly transmitted to the target service through the proxy node or its other subordinate nodes. Since the proxy node may have direct access to the target service, or it may have other subordinate nodes, the steps described above for determining which intermediate node transmits the request data to the target service can be referenced and will not be elaborated upon here.
[0089] In one embodiment, the intermediate node determination step is repeated until the parent node becomes the top-level node. The method further includes: sending a connection failure message to the current node through the top-level node; passing the connection failure message through all current nodes to the proxy node, where the proxy node is the current node that first obtains the access request data; and sending a connection rejection message to the request service through the proxy node, where the connection rejection message is generated by the proxy node based on the connection failure message.
[0090] In one embodiment, the intermediate node determination step is repeated until the parent node is the top-level node. The method further includes: generating a connection failure message through the top-level node; passing the connection failure message through all traversed nodes to the proxy node, where the proxy node is the current node that first obtained the access request data, and the traversed nodes are nodes in the preset proxy network that have obtained the requested access data; and sending connection rejection information to the request service through the proxy node, where the connection rejection information is generated by the proxy node based on the connection failure message.
[0091] In other words, if the top-level node's routing table does not contain the target address, it means that no node in the default proxy network can access the target service. At this point, the process ends, but it cannot end silently. The top-level node can generate a connection failure message and transmit it back to the proxy node via the opposite path of the data sent for the request. The proxy node then feeds back the connection failure information (connection rejection information) to the requesting service.
[0092] When the target address is not found in the entire proxy network, a connection failure message should be replied with. This connection failure message can use TCP to transmit a JSON string. An example connection failure message format is as follows:
[0093] {
[0094] "id":"Unique ID",
[0095] "type":"notfound"
[0096] }
[0097] In one embodiment, the current node forwards the target address to the parent node, including: the current node generating a request identifier for the access request data; generating an addressing message based on the request identifier and the target address; and the current node forwarding the addressing message to the parent node. The request identifier can be globally unique, such as the "unique ID" mentioned in this embodiment. When multiple different access request data exist in the preset proxy network, the request identifier can be used to distinguish them, allowing the proxy node to clearly identify which access request data has received a response. The request identifier can also be used to record the matching path of the target address. Thus, if all parent nodes fail to match the target address (i.e., no intermediate node can be found), the preset node with the recorded request identifier can forward a connection failure message back to the proxy node.
[0098] Please see Figure 3 , Figure 3 This is a schematic diagram of a specific process of a private network data transmission method provided in an embodiment of the present invention, such as... Figure 3 As shown, the service (i.e., the request service) uses the Socks5 protocol to connect to the proxy node and sends traffic (access request data). The proxy node parses the destination address of the traffic, checks if it exists in its own routing table, and if so, directly connects and forwards the traffic. If the destination address does not exist in the proxy node's routing table, it generates a unique ID and uses the ID and the destination address to form an addressing message, which is then sent to the parent node. Upon receiving the message, the parent node checks its routing table. If the destination address does not exist, it continues searching upwards. If the destination address exists in the parent node's routing table, it opens a communication port and sends a reply message containing the port number and the unique ID to the lower-level node. The parent node checks its routing table to see if the destination address is a route reported by the lower-level node. If it is a route of the parent node itself, it directly connects to the target service through the parent node. If it is a route reported by the lower-level node, it sends an active addressing message to the lower-level node. Upon receiving the active addressing message, the lower-level node repeats the process of checking its routing table to see if the destination address is a route reported by the lower-level node. Figure 3The omitted steps in the code represent the process where, after receiving an addressing message, the lower-level node repeatedly checks its routing table to see if the destination address matches the route reported by the lower-level node. This process continues until the destination address is found in the routing table of a higher-level node or the top-level node is located. If the destination address is not found even after finding the apex of the tree network (the top-level node), a connection failure message is sent. When the proxy node receives the reply message, it initiates a connection to the specified port and forwards traffic based on the port number and unique ID in the reply message. When the proxy node receives a connection failure message, it replies to the service that the network connection was refused.
[0099] Please see Figure 4 , Figure 4 This is another specific flowchart illustrating the private network data transmission method provided in this embodiment of the invention, such as... Figure 4 As shown, the service (i.e., the request service) uses the Socks5 protocol to connect to the proxy node and sends traffic (access request data). The proxy node parses the destination address of the traffic, checks if it exists in its own routing table, and if it does, it directly connects and forwards the traffic. If the destination address does not exist in the proxy node's routing table, it generates a unique ID and uses the ID and the destination address to form an addressing message, which is then sent to the parent node. The transmission process of the addressing message is described below. Figure 3 The example provided is similar and will not be repeated. When a top-level node is found but no second match has been found, meaning the target address does not exist in the routing table of any node, the top-level node generates a connection failure message and verifies the forwarding order of the addressing message, forwarding it in reverse level by level until it sends feedback to the proxy node. The proxy node then sends a connection refusal message back to the requesting service. The private network data transmission method provided in this disclosure involves obtaining access request data for services requested in the private network through a proxy node. The target address of this access request data is first matched with the address of the proxy node. If the first match fails, the target address is forwarded to the upper-level node of the proxy node in the preset proxy network, and then a second match is performed between the target address and the upper-level node address. If the second match fails, the target address is forwarded to the next higher-level node for a second match. If the second match succeeds, the requested access data is transmitted to the target service through the upper-level node or its subordinate nodes. This method establishes a preset proxy network by connecting the proxy nodes of the private network via software. Only the deployment nodes in the private network need to have the ability to access external networks; dedicated lines are not required. The connection in the private network can be direct or relayed through an upper-level node. A single central server is not needed, reducing costs and avoiding load and data security issues.
[0100] Furthermore, the private network data transmission method provided in the above embodiments supports dynamic node changes because it utilizes a preset proxy network for data transmission. In other words, within the preset proxy network, nodes can freely change their parent nodes without affecting communication between their child nodes. This preset proxy network is a tree-like network that supports network merging. Top-level nodes in the tree-like network can also have parent nodes added during runtime, merging two tree-like networks into a larger proxy network.
[0101] In another embodiment of this application, a method for constructing a preset proxy network is also provided. The method includes: a node to be joined to the network opens a first communication port and a second communication port. The first communication port is used to communicate with the service corresponding to the node to be joined, and the second communication port is used to communicate with nodes already joined in the preset proxy network (i.e., preset nodes that have previously successfully joined the preset proxy network); after the node to be joined connects to a selected node, it sends its address and identity information to the selected node, so that the selected node records the identity information and adds the address of the node to its set of selected node addresses. The selected node is a preset node in the preset proxy network, and the preset proxy network includes at least one preset node; if the selected node is a top-level node in the preset proxy network, it is determined that the network to be joined has accessed the preset proxy network; if the selected node has a predecessor node in the preset proxy network, the added selected node address set is updated... The process involves reporting to the previous node, adding the selected node address set to the previous node's address set. If the previous node is a top-level node, it is determined that the network to be accessed is connected to the preset proxy network. If the previous node has a node to be reported in the preset proxy network, the added previous node address set is sent to the node to be reported, adding the added previous node address set to the node to be reported's address set, and the node to be reported is designated as the new previous node. This process is repeated until the node to be reported is a top-level node, confirming that the network to be accessed is connected to the preset proxy network, and the previous node is the parent node of the selected node in the preset proxy network, and the node to be reported is the parent node of the previous node in the preset proxy network.
[0102] This preset proxy network also supports network merging. One example merging method includes: obtaining a new proxy network, which is built based on multiple new nodes, with at least two new nodes belonging to different private networks; controlling the connection between the top-level node of the preset proxy network and the target new node in the new proxy network; sending the top-level node address and identity information of the top-level node to the target new node, so that the target new node records the top-level node identity information and adds the top-level node address to its target new node address set; if the target new node is the top-level node of the new proxy network, determining that the top-level node has accessed the new proxy network; if the target new node has a predecessor node in the new proxy network, reporting the added target new node address set to the new predecessor node, so that the added target new node address set is added to the new predecessor node's new predecessor node address set. The point is the top-level node of the newly added proxy network. It is determined that the top-level node has accessed the newly added proxy network. If the newly added parent node has a reporting node in the newly added proxy network, the address set of the newly added parent node is sent to the reporting node to add the address set of the newly added parent node to the reporting node's reporting address set. The reporting node is then used as the new newly added parent node. This process is repeated until the reporting node becomes the top-level node of the newly added proxy network. At this point, it is determined that the top-level node has accessed the newly added proxy network, and the newly added parent node is the parent node of the target newly added node in the newly added proxy network. The reporting node is also the parent node of the newly added parent node in the newly added proxy network. At this point, the top-level node of the preset proxy network can be used as the node to be added to the network in the above embodiment. Then, the network entry process of the top-level node is executed, and the routing table of the top-level node is added one by one to the routing tables of the target newly added node and each parent node of the target newly added node in the newly added proxy network. The target new node is a new node in the new agent network.
[0103] This proxy network also supports changes to the parent node (upper-level node) of preset nodes in the network. An example of an upper-level node change method includes: obtaining a node change instruction, which includes a change node, and the change node is a preset node in the preset proxy network other than the selected node; connecting the node to be joined to the change node, and sending the address and identity information of the node to be joined to the change node, so that the change node records the identity information of the node to be joined and adds the address of the node to be joined to the change node's change node address set; if the change node is a top-level node of the preset proxy network, determining that the network to be joined has accessed the preset proxy network; if the change node has a previous node in the preset proxy network, reporting the added change node address set to the previous node, so that the added change node address set is added to the previous node's previous node address set. If the previous node is a top-level node... The process involves determining that the network to be connected to is accessing a preset proxy network. If a change-reporting node exists in the preset proxy network as the previous node, the added set of addresses of the previous node is sent to the change-reporting node. This adds the set of addresses of the previous node to the change-reporting node's set of change-reporting addresses, and the change-reporting node is then designated as the new previous node. This process is repeated until the change-reporting node becomes a top-level node. At this point, the node change for the node to be connected is confirmed, and the previous node becomes the parent node of the node in the preset proxy network. In other words, changing a node can be considered as re-entering the network connection process for the node to be connected, selecting a new preset node as the selected node, and updating the addresses of the selected node and each of its parent nodes. It should be understood that after completing the change of the parent node, the method also includes deleting the address to be added to the network from the routing tables of the original selected node and all parent nodes of the selected node. The address deletion action is similar to the addition action; it can be triggered by sending address deletion messages containing the address of the node to be added to the network level, thereby deleting the address of the node to be added from the selected node address set of the selected node and the reporting address set of the reporting node. The preset node in the aforementioned preset proxy network can be a node from the same private network or a node from multiple different private networks. Through the implementation of the preset proxy network, data modules that were originally not interconnected in private networks can interact in a software-based manner, resulting in lower cost and greater security. For a detailed description of the implementation of the above method, please refer to the relevant descriptions in the above embodiments regarding the private network data transmission method, which will not be repeated here.
[0104] Understandably, after a newly added node joins the preset proxy network, its address and other information need to be updated in the routing table of the selected node, its parent node, its parent's parent node, and so on, until the routing table of the top-level node is updated. The methods for merging networks and changing parent nodes are similar to those for adding nodes, except that before, after, or simultaneously with a parent node change, the routing tables of the original selected node and its parent node, its parent's parent node, and so on, up to the top-level node, need to be deleted in the first routing update information reported by the selected node to avoid address confusion after the parent node change.
[0105] Combination Figure 5 As shown, this embodiment of the disclosure provides a private network data transmission device, including a proxy node 501, a first matching module 502, a second matching module 503, and a data transmission module 504, wherein:
[0106] Proxy node 501 is used to obtain access request data for services requested in the private network. The access request data includes the target address of the target service and the request access data.
[0107] The first matching module 502 is used to perform a first match between the target address and the proxy node address of the proxy node;
[0108] The second matching module 503 is used to, if the first matching fails, take the proxy node as the initial current node and repeat the intermediate node determination step until the preset end condition is met. The intermediate node determination step includes: the current node forwards the target address to the upper-level node, triggering the upper-level node to perform a second matching between the target address and multiple upper-level node addresses of the upper-level node; if the second matching fails, take the upper-level node as the new current node. The upper-level node is the node above the current node in the preset proxy network. The preset proxy network is built based on multiple preset nodes, of which at least two preset nodes belong to different private networks. The multiple upper-level node addresses include the upper-level self-routes of the upper-level node and the lower-level self-routes of each lower-level node under the upper-level node. The preset end condition includes the second matching succeeding and the upper-level node being any one of the top-level nodes.
[0109] The data transmission module 504 is used to determine the upper-level node when the second match is successful as the intermediate node if the second match is successful. Based on the matching result between the target address and the upper-level routing, the request access data is transmitted to the target service through the intermediate node or the intermediate lower-level node. The intermediate lower-level node is the subordinate node of the intermediate node in the preset proxy network.
[0110] The private network data transmission device provided in this embodiment obtains access request data for services requested in the private network through a proxy node. The target address of the access request data is first matched with the address of the proxy node. If the first match fails, the target address is forwarded to the upper-level node of the proxy node in the preset proxy network, and then a second match is performed between the target address and the upper-level node address. If the second match fails, the target address is forwarded to the next higher-level node for a second match. If the second match succeeds, the requested access data is transmitted to the target service through the upper-level node or its subordinate node. This establishes a preset proxy network by connecting the proxy nodes of the private network via software. Only the deployment nodes in the private network need to have the ability to access the external network, eliminating the need for dedicated lines. The connection in the private network can be direct or relayed through an upper-level node, without requiring a single central server, thus reducing costs and avoiding load and data security issues.
[0111] Specific limitations regarding the private network data transmission device can be found in the limitations of the private network data transmission method described above, and will not be repeated here. Each module in the aforementioned private network data transmission device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0112] This disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method as described in any of the foregoing embodiments.
[0113] Figure 6 A schematic diagram of a computer system suitable for implementing the embodiments of this application is shown. It should be noted that... Figure 6 The computer system 1000 of the electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0114] like Figure 6As shown, the computer system 1000 includes a Central Processing Unit (CPU) 1001, which can perform various appropriate actions and processes, such as executing the methods described in the above embodiments, based on programs stored in Read-Only Memory (ROM) 1002 or programs loaded from Storage Unit 1008 into Random Access Memory (RAM) 1003. The RAM 1003 also stores various programs and data required for system operation. The CPU 1001, ROM 1002, and RAM 1003 are interconnected via a bus 1004. An Input / Output (I / O) interface 1005 is also connected to the bus 1004.
[0115] The following components are connected to I / O interface 1005: an input section 1006 including a keyboard, mouse, etc.; an output section 1007 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 1008 including a hard disk, etc.; and a communication section 1009 including a network interface card such as a LAN (Local Area Network) card, modem, etc. The communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to I / O interface 1005 as needed. Removable media 1011, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., are installed on drive 1010 as needed so that computer programs read from them can be installed into storage section 1008 as needed.
[0116] Specifically, according to embodiments of this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program including a computer program for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication section 1009, and / or installed from removable medium 1011. When the computer program is executed by central processing unit (CPU) 1001, it performs various functions defined in the system of this application.
[0117] It should be noted that the computer-readable medium shown in the embodiments of this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this application, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying a computer-readable computer program. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media can also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, etc., or any suitable combination thereof.
[0118] This disclosure also provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements any of the methods in this embodiment.
[0119] The computer-readable storage medium in the embodiments of this disclosure will be understood by those skilled in the art: all or part of the steps of the above method embodiments can be implemented by hardware related to computer programs. The aforementioned computer program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disk, or optical disk.
[0120] The electronic device disclosed in this embodiment includes a processor, a memory, a transceiver, and a communication interface. The memory and the communication interface are connected to the processor and the transceiver and complete communication between them. The memory is used to store computer programs, the communication interface is used to perform communication, and the processor and the transceiver are used to run the computer programs, so that the electronic device performs the various steps of the above method.
[0121] In this embodiment, the memory may include random access memory (RAM) and may also include non-volatile memory, such as at least one disk storage device.
[0122] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), graphics processing units (GPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0123] The foregoing description and accompanying drawings fully illustrate embodiments of this disclosure to enable those skilled in the art to practice them. Other embodiments may include structural, logical, electrical, procedural, and other changes. The embodiments represent only possible variations. Individual components and functions are optional unless explicitly required, and the order of operation may vary. Parts and subsamples of some embodiments may be included in or replace parts and subsamples of other embodiments. Moreover, the terminology used in this application is for describing embodiments only and is not intended to limit the claims. As used in the description of embodiments and claims, the singular forms “a,” “an,” and “the” are intended to equally include the plural forms unless the context clearly indicates otherwise. Similarly, the term “and / or” as used herein means including one or more of the associated listed items and all possible combinations thereof. Additionally, when used in this application, the term "comprise" and its variations "comprises" and / or "comprising" refer to the presence of stated subsamples, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other subsamples, wholes, steps, operations, elements, components, and / or groups thereof. Without further limitations, an element defined by the phrase "comprising a..." does not exclude the presence of other identical elements in the process, method, or apparatus that includes the element. In this document, each embodiment may focus on the differences from other embodiments, and similar or identical parts between embodiments can be referred to mutually. For methods, products, etc., disclosed in the embodiments, if they correspond to the method section disclosed in the embodiments, the relevant parts can be referred to the description of the method section.
[0124] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of this disclosure. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0125] The methods and products (including but not limited to devices and equipment) disclosed in the embodiments herein can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For instance, the division of units may be merely a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some sub-samples may be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection of devices or units may be electrical, mechanical, or other forms. Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to implement this embodiment according to actual needs. Furthermore, the functional units in the embodiments of this disclosure may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0126] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. In some alternative implementations, the functions marked in the blocks may occur in a different order than that shown in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. The operations or steps corresponding to different blocks in the descriptions of the flowcharts and block diagrams in the accompanying drawings may also occur in a different order than disclosed in the description; sometimes there is no specific order between different operations or steps. For example, two consecutive operations or steps may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. Each block in a block diagram and / or flowchart, and combinations of blocks in a block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.
Claims
1. A private network data transmission method characterized by, The method comprises: obtaining, by a proxy node, access request data of a request service in a private network, the access request data comprising a target address of a target service and request access data; performing first matching on the target address and a proxy node address of the proxy node; if the first matching fails, taking the proxy node as an initial current node, repeatedly performing an intermediate node determination step until a preset ending condition is reached, the intermediate node determination step comprising: the current node transparently transmitting the target address to a superior node, triggering the superior node to perform second matching on the target address and a plurality of superior node addresses of the superior node, if the second matching fails, taking the superior node as a new current node, the superior node being a superior node of the current node in a preset proxy network, the preset proxy network being constructed based on a plurality of preset nodes, wherein at least two preset nodes belong to different private networks, the plurality of superior node addresses comprising a superior self-routing of the superior node and a subordinate self-routing of each subordinate node subordinate to the superior node, the preset ending condition comprising any one of the second matching success and the superior node being a top node; if the second matching succeeds, determining the superior node at the time of the second matching success as an intermediate node, and transmitting the request access data to the target service through the intermediate node or an intermediate subordinate node according to a matching result of the target address and the superior self-routing, the intermediate subordinate node being a subordinate node of the intermediate node in the preset proxy network.
2. The private network data transmission method of claim 1, wherein, transmitting the request access data to the target service through the intermediate node or an intermediate subordinate node according to a matching result of the target address and the superior self-routing, comprising: if the target address matches the superior self-routing; sending, by the intermediate node, a first reply message of the request access data to the proxy node through an intermediate communication interface of the intermediate node, the first reply message comprising an intermediate address of the intermediate node, to trigger the proxy node to establish a first communication connection link with the intermediate node, so that the proxy node transmits the request access data to the target service through the intermediate node.
3. The private network data transmission method of claim 2, wherein, After the proxy node and the intermediate node establish the first communication connection link, the method further comprises at least one of the following: the intermediate node obtains feedback data fed back by the target service based on the request access data, and transmits the feedback data to the proxy node through the first communication connection link, so as to transmit the feedback data to the request service through the proxy node; the proxy node sends connection success information to the request service, and receives to-be-transmitted data sent by the request service, the proxy node sends the to-be-transmitted data to the intermediate node through the first communication connection link, and transmits the to-be-transmitted data to the target service through the intermediate node.
4. The private network data transmission method of claim 1, wherein, transmitting the request access data to the target service through the intermediate node or an intermediate subordinate node according to a matching result of the target address and the superior self-routing, comprising: if the target address does not match the upper node's own route, sending an active addressing packet to each lower node of the intermediate node in the preset proxy network through the intermediate node, determining a lower node as the intermediate lower node based on a feedback packet received from the active addressing packet, and transmitting the request access data to the target service through the intermediate lower node; sending a first reply packet of the request access data to the proxy node through an intermediate communication interface of the intermediate node, the first reply packet including an intermediate address of the intermediate node, to trigger the proxy node to establish a first communication connection link with the intermediate node; sending a second reply packet of the request access data to the intermediate node through a lower communication interface of the intermediate lower node, the second reply packet including a lower address of the intermediate lower node, to trigger the intermediate node to establish a second communication connection link with the intermediate lower node.
5. The private network data transmission method of claim 3, wherein, After the proxy node and the intermediate node establish the first communication connection link, and the intermediate node and the intermediate lower node establish the second communication connection link, the method further includes at least one of the following: the intermediate lower node acquires feedback data fed back by the target service based on the request access data, transmits the feedback data to the intermediate node through the second communication connection link, the intermediate node transmits the acquired feedback data to the proxy node through the first communication connection link, and the proxy node transmits the feedback data to the request service; the proxy node sends connection success information to the request service and receives to-be-transmitted data sent by the request service, the proxy node sends the to-be-transmitted data to the intermediate node through the first communication connection link, the intermediate node transmits the acquired to-be-transmitted data to the intermediate lower node through the second communication connection link, and the intermediate lower node transmits the to-be-transmitted data to the target service.
6. The private network data transmission method according to any one of claims 1 to 5, wherein, if the first matching is successful, the proxy node is determined as the intermediate node.
7. The private network data transmission method according to any one of claims 1 to 5, wherein, After the intermediate node determination step is repeatedly executed until the upper node is the top node, the method further includes: generating a connection failure message through the top node; transmitting the connection failure message to the proxy node through all the traversed nodes, the traversed nodes being nodes in the preset proxy network that have acquired the request access data; sending a connection rejection information to the request service through the proxy node, the connection rejection information being generated by the proxy node based on the connection failure message.
8. The private network data transmission method according to any one of claims 1 to 5, wherein, The current node transmitting the target address to the upper node includes: the current node generating a request identifier of the access request data; generating an addressing packet based on the request identifier and the target address; the current node transmitting the addressing packet to the upper node.
9. The private network data transmission method according to any one of claims 1 to 5, wherein, Before the intermediate node determination step is repeatedly executed, the method further includes: A first communication port and a second communication port of a to-be-networked node of a to-be-networked network are started, the first communication port is used for communicating with a to-be-networked service corresponding to the to-be-networked node, and the second communication port is used for communicating with a networked node in a preset proxy network; After the to-be-networked node is connected to a selected node, the to-be-networked node address and the to-be-networked node identity information of the to-be-networked node are sent to the selected node, so that the selected node records the to-be-networked node identity information and adds the to-be-networked node address into a selected node address set of the selected node, the selected node is a preset node in the preset proxy network, and the preset proxy network at least includes one preset node; If the selected node is a top node of the preset proxy network, it is determined that the to-be-networked network accesses the preset proxy network; If the selected node has a previous node in the preset proxy network, the added selected node address set is reported to the previous node, so that the added selected node address set is added into a previous node address set of the previous node, if the previous node is a top node, it is determined that the to-be-networked network accesses the preset proxy network, if the previous node has a to-be-reported node in the preset proxy network, the added previous node address set is sent to the to-be-reported node, so that the added previous node address set is added into a to-be-reported address set of the to-be-reported node, and the to-be-reported node is taken as a new previous node, the step of repeatedly performing, if the previous node has a to-be-reported node in the preset proxy network, the added previous node address set is sent to the to-be-reported node, so that the added previous node address set is added into a to-be-reported address set of the to-be-reported node, and the to-be-reported node is taken as a new previous node, until the to-be-reported node is a top node, it is determined that the to-be-networked network accesses the preset proxy network, and the previous node is a superior node of the selected node in the preset proxy network, and the to-be-reported node is a superior node of the previous node in the preset proxy network.
10. The private network data transmission method of claim 9, wherein, The method further comprises: An added proxy network is acquired, the added proxy network is constructed based on a plurality of added nodes, and at least two added nodes belong to different private networks; A top node of the preset proxy network is connected to a target added node in the added proxy network; The top node address and the top node identity information of the top node are sent to the target added node, so that the target added node records the top node identity information and adds the top node address into a target added node address set of the target added node; If the target added node is a top node of the added proxy network, it is determined that the top node accesses the added proxy network; If the target new node has a previous node in the new proxy network, the added target new node address set is reported to the new previous node to add the added target new node address set into the new previous node address set of the new previous node; if the new previous node is a top node of the new proxy network, it is determined that the top node is connected to the new proxy network; if the new previous node has a reporting node in the new proxy network, the added new previous node address set is sent to the reporting node to add the added new previous node address set into the reporting address set of the reporting node, and the reporting node is taken as a new new previous node to repeat the step of adding the added new previous node address set into the reporting address set of the reporting node until the reporting node is a top node of the new proxy network, it is determined that the top node is connected to the new proxy network, the new previous node is a superior node of the target new node in the new proxy network, and the reporting node is a superior node of the new previous node in the new proxy network.
11. The private network data transmission method of claim 9, wherein, The method further comprises: obtaining a node change instruction, the node change instruction comprising a change node, the change node being a preset node in the preset proxy network except the selected node; after connecting the to-be-network-connected node to the change node, sending the to-be-network-connected node address and the to-be-network-connected node identity information of the to-be-network-connected node to the change node, so that the change node records the to-be-network-connected node identity information and adds the to-be-network-connected node address into the change node address set of the change node; if the change node is a top node of the preset proxy network, it is determined that the to-be-network-connected network is connected to the preset proxy network; If the change node has a change previous node in the preset proxy network, the added change node address set is reported to the change previous node to add the added change node address set into the change previous node address set of the change previous node, and if the change previous node is a top node, it is determined that the to-be-network-connected node accesses the preset proxy network, if the change previous node has a change reporting node in the preset proxy network, the added change previous node address set is sent to the change reporting node to add the added change previous node address set to the change reporting address set of the change reporting node, and the change reporting node is taken as a new change previous node to repeat the steps that the change previous node has a change reporting node in the preset proxy network, the added change previous node address set is sent to the change reporting node to add the added change previous node address set to the change reporting address set of the change reporting node, and the change reporting node is taken as a new change previous node until the change reporting node is a top node, it is determined that the to-be-network-connected node completes node change, the change previous node is a superior node of the change node in the preset proxy network, and the change reporting node is a superior node of the change previous node in the preset proxy network.
12. A private network data transmission apparatus characterized by comprising: The device comprises: The agent node is configured to obtain access request data of a request service in a private network, wherein the access request data comprises a target address of a target service and request access data; The first matching module is configured to perform first matching on the target address and the agent node address of the agent node; The second matching module is configured to, if the first matching fails, take the agent node as an initial current node, and repeatedly perform an intermediate node determination step until a preset end condition is reached, wherein the intermediate node determination step comprises: the current node transmits the target address to a superior node, triggers the superior node to perform second matching on the target address and a plurality of superior node addresses of the superior node, if the second matching fails, takes the superior node as a new current node, the superior node is a superior node of the current node in a preset proxy network, the preset proxy network is constructed based on a plurality of preset nodes, at least two preset nodes belong to different private networks, the plurality of superior node addresses comprise a superior self-routing of the superior node and a subordinate self-routing of each subordinate node subordinate to the superior node, and the preset end condition comprises any one of second matching success and the superior node being a top node; The data transmission module is configured to, if the second matching succeeds, determine the superior node at the time of the second matching success as an intermediate node, and transmit the request access data to the target service through the intermediate node or an intermediate subordinate node according to a matching result of the target address and the superior self-routing, wherein the intermediate subordinate node is a subordinate node of the intermediate node in the preset proxy network.
Citation Information
Patent Citations
Cross-domain access processing method, device and electronic device
CN109150677A
Method for establishing communication connection, controller, forwarding equipment, equipment and medium
CN111741508A