Star private network interconnection and intercommunication method and system based on multipath transmission
By adopting a star interconnection method with multiple transmission between private networks, bandwidth and security issues in traditional communication methods are solved, efficient and secure multi-private network communication is achieved, suitable for large-scale scenarios, and the privacy of private network information is protected.
Patent Information
- Application Number
- CN202510048438.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-13
- Publication Date
- 2025-05-09
AI Technical Summary
When the prior art communicates between multiple private networks, the bandwidth rate is limited, making it difficult to meet the needs of large-scale service communications. In addition, data transmission in traditional single paths has security problems, such as being easily monitored.
The star private network interconnection method based on multiple transmission is adopted to communicate through the proxy server and the core server to realize the replacement of IP packet headers, ensuring the security and efficiency of data packets during transmission.
It improves the bandwidth guarantee and security of communication between private networks, is suitable for large-scale private network communication scenarios, allows private networks to independently manage IP addresses, avoids the needs of IP address conflicts and unified configuration, and protects the privacy and security of private network information.
Smart Images

Figure CN119966948A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network communication, and in particular to a star-shaped private network interconnection method and system based on multi-path transmission. Background Art
[0002] The current network environment is highly open and rapidly developing. Private networks have become a common and vital component due to their security, flexibility, high performance and scalability. With the expansion of business, the demand for private network interconnection, such as cross-regional and cross-departmental enterprise network interconnection, distributed system or microservice architecture network interconnection, and remote office secure network interconnection, is growing rapidly. However, due to factors such as geographical location and security policies, multiple different private networks often require unified configuration and management, which increases management difficulty and maintenance costs, and cannot guarantee the flexibility of communication between multiple private networks. In addition, the data transmission bandwidth rate of a traditional single path is limited, and it will cause security issues such as easy eavesdropping. Therefore, it is necessary to conduct research on a star-shaped private network interconnection method based on multi-channel transmission.
[0003] OpenVPN (Open Virtual Private Network) can realize communication between private networks independently. The principle of this method is: based on the original network, let the clients in the two private networks connect to the OpenVPN server respectively and establish a VPN (Virtual Private Network) tunnel. After the tunnel is established, an IP address will be assigned to each connected device, so that the virtual channels between the devices can communicate with each other and solve the problem of communication between different private networks. The client and the server rely on a single path for communication, and the maximum bandwidth rate is limited. It is difficult to meet the large-scale business communication needs between multiple private networks and cannot be applied to large-scale private network communication scenarios. By assigning an IP address to each device, the virtual channels between the devices can communicate with each other, and the problem of IP conflicts between private networks can be avoided. However, this will cause a large amount of network information to be shared between the private networks, which cannot meet the secure and transparent private network communication scenarios. Multiple remote networks are connected together through VPN tunnels, allowing multiple private networks to communicate. However, it relies on a centralized VPN server and network architecture, which requires centralized management of configurations such as virtual IP address ranges and routing settings. If the number of private networks is increased or the size of private networks is increased, it is necessary to re-plan the IP address allocation for the private networks, which will lead to complex configuration and poor flexibility, and cannot be applied to highly complex private network communication scenarios. Summary of the invention
[0004] The object of the present invention is to provide a method and system for interconnecting star-shaped private networks based on multi-channel transmission, so as to solve at least one technical problem existing in the above-mentioned background technology.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] In a first aspect, the present invention provides a star-type private network interconnection method based on multi-channel transmission, comprising:
[0007] Carry out the network configuration process;
[0008] Replace the IP packet header in the upstream communication process; replace the destination IP field in the local proxy server and replace the source IP field in the peer proxy server;
[0009] Replacement of IP packet header in the downlink communication process; replacement of the destination IP field in the peer proxy server and replacement of the source IP field in the local proxy server.
[0010] As a further limitation of the first aspect of the present invention, the network configuration process includes:
[0011] Proxy server configuration: The private network administrator configures information on his own proxy server, including the available legal IP address pool and the private network terminal IP for interconnection;
[0012] Proxy server information sharing: After the proxy server configuration is completed, the proxy server will automatically share the IP address of the terminal device accessing the private Internet and the identification information of the proxy server;
[0013] Legal address allocation of proxy servers: Each proxy server allocates new IP addresses to other private network terminal devices based on the legal IP address pool configured by the administrator;
[0014] Update of the mapping table of the proxy server: After the legal address of the proxy server is allocated, the terminal device IP, the legal IP of the terminal device, and the terminal device proxy server identifier form a mapping relationship. The mapping relationships of all terminal devices form a mapping table and are stored in the proxy server;
[0015] Routing configuration: The private network administrator needs to configure static routing to ensure that the data flow to other private network terminal devices is directed to the local proxy server.
[0016] As a further limitation of the first aspect of the present invention, the replacement of the IP data packet header in the uplink communication process includes:
[0017] SP1 generates a data stream with source address SP1 and destination address SP4;
[0018] After being transmitted in private network A, the data stream is directed to proxy server 1;
[0019] The data flow enters from the SP network port and is directed to the virtual network port tun of proxy server 1 according to the routing table of the private network server;
[0020] Process the data packet at the tun port; if the data packet is a communication data packet between private network terminals, replace the IP header field and encapsulate the header; if the data packet is a notification message between proxy servers, extract the shared information in the data packet and update the mapping table;
[0021] The virtual network port tun on the proxy server is bound to multiple public network ports. Each public network port establishes a socke connection with the core proxy. After the data packet is processed, the corresponding socket connection is selected according to the multi-channel transmission scheduling plan;
[0022] The data packet encapsulated with the custom header is sent out as the data part through the socket connection;
[0023] The data stream is sent from proxy server 1 and reaches the core server after being transmitted through the public network;
[0024] After the data stream reaches the core proxy server, it reads the destination proxy identifier of the identification header, and then forwards the data packet encapsulated with the identification header through the socket connection between the core proxy server and proxy server 2;
[0025] After the data stream reaches the proxy server 2, the outermost IP header is removed and the data packet is processed; if the data packet is a communication data packet between private network terminals, the identification header is unsealed and the IP header field is replaced; if the data packet is a notification message between proxy servers, the shared information in the data packet is extracted and the mapping table is updated;
[0026] The data flow is exported from the UP port according to the routing of the proxy server;
[0027] The data stream is transmitted through private network B and reaches UP1.
[0028] As a further limitation of the first aspect of the present invention, if the data packet is a communication data packet between private network terminals, IP header field replacement and header encapsulation are performed, including: replacing the destination IP field of the IP data packet header according to the mapping table; updating the checksum field of the IP data packet header; encapsulating a new custom identification header, the header consisting of a 1-byte source agent identifier, a 1-byte destination agent identifier and a 2-byte packet sequence number, the source agent identifier is the current proxy server identifier, and the destination agent identifier is queried by the mapping table.
[0029] As a further limitation of the first aspect of the present invention, if the data packet is a communication data packet between private network terminals, the identification header is unpacked and the IP header field is replaced, including: reading the source agent identifier of the identification header and unpacking it; reading the source IP field of the internal IP header, querying the mapping table according to the source agent identifier and the source IP field, and replacing the source IP field with a legal IP address of the private network; updating the checksum field of the IP header; and handing the data packet to the virtual port tun of the proxy server.
[0030] As a further limitation of the first aspect of the present invention, the replacement of the IP data packet header in the downlink communication process includes:
[0031] UP1 replies with a data stream, with the source address being SP1 and the destination address being SP4. After being transmitted in private network B, the data stream is directed to proxy server 2. The data stream enters through the UP network port and is directed to the virtual network port tun of proxy server 2 according to the routing of the private network server.
[0032] Process the data packet at the tun port; if the data packet is a communication data packet between private network terminals, replace the IP header field and encapsulate the header; if the data packet is a notification message between proxy servers, extract the shared information in the data packet and update the mapping table;
[0033] The virtual network port tun on the proxy server is bound to multiple public network ports. Each public network port establishes a socke connection with the core proxy. After the data packet is processed, the corresponding socket connection is selected according to the multi-channel transmission scheduling plan;
[0034] The data packet encapsulated with the custom header is sent out as the data part through the socket connection; the data stream is sent out from the proxy server 2 and reaches the core server after being transmitted through the public network; after the data stream reaches the core proxy server, the destination proxy identifier of the identification header is read, and then the data packet encapsulated with the identification header is forwarded through the socket connection between the core proxy server and the proxy server 1;
[0035] After the data stream reaches the proxy server 1, the outermost IP header is removed and the data packet is processed; if the data packet is a communication data packet between private network terminals, the identification header is unsealed and the IP header field is replaced; if the data packet is a notification message between proxy servers, the shared information in the data packet is extracted and the mapping table is updated;
[0036] The data flow is exported from the SP port according to the routing of the proxy server; the data flow is transmitted through private network A to reach SP1.
[0037] As a further limitation of the first aspect of the present invention, if the data packet is a communication data packet between private network terminals, the identification header is unpacked and the IP header field is replaced, including: replacing the destination IP field of the IP data packet header according to the mapping table; updating the checksum field of the IP data packet header; encapsulating a new custom identification header, the header consisting of a 1-byte source agent identifier, a 1-byte destination agent identifier and a 2-byte packet sequence number, the source agent identifier is the proxy server identifier, and the destination agent identifier can be queried by a mapping table.
[0038] In a second aspect, the present invention provides a non-transitory computer-readable storage medium, which is used to store computer instructions. When the computer instructions are executed by a processor, the star-type private network interconnection method based on multi-channel transmission as described in the first aspect is implemented.
[0039] In a third aspect, the present invention provides a computer device comprising a memory and a processor, wherein the processor and the memory communicate with each other, the memory stores program instructions executable by the processor, and the processor calls the program instructions to execute the star-type private network interconnection method based on multi-path transmission as described in the first aspect.
[0040] In a fourth aspect, the present invention provides an electronic device, comprising: a processor, a memory and a computer program; wherein the processor is connected to the memory, the computer program is stored in the memory, and when the electronic device is running, the processor executes the computer program stored in the memory so that the electronic device executes instructions for implementing the star-type private network interconnection method based on multi-path transmission as described in the first aspect.
[0041] The beneficial effects of the present invention are as follows: a multi-channel transmission scheme is adopted between servers, which has higher bandwidth guarantee and security guarantee, and is suitable for large-scale private network communication scenarios; IP address conflicts between terminal devices between private networks are allowed, and private networks are allowed to independently perform network segment management and address allocation, without requiring unified configuration or division of all private networks, thus maximizing mutual transparency between private networks and protecting the privacy and security of private network information (network topology, network segment allocation, etc.); it has good scalability and manageability, and allows flexible access to private networks.
[0042] Additional advantages of the present invention will be more clearly given in the following description or learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0044] Figure 1 This is a network topology diagram of a star-shaped private network interconnection based on multi-channel transmission according to an embodiment of the present invention.
[0045] Figure 2 This is a schematic diagram of the uplink communication process between SP1 and UP1 according to an embodiment of the present invention.
[0046] Figure 3 This is a schematic diagram of the downlink communication process between SP1 and UP1 according to an embodiment of the present invention. DETAILED DESCRIPTION
[0047] The embodiments of the present invention are described in detail below, and examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements with the same or similar functions. The embodiments described below by the accompanying drawings are exemplary and are only used to explain the present invention, and cannot be interpreted as limiting the present invention.
[0048] It should be understood by those skilled in the art that unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by those skilled in the art to which this invention belongs.
[0049] It should also be understood that terms, such as those defined in commonly used dictionaries, should be understood to have a meaning consistent with that in the context of the prior art and will not be interpreted in an idealized or overly formal sense unless as defined herein.
[0050] Those skilled in the art will appreciate that, unless otherwise stated, the singular forms "a", "an", "said" and "the" used herein may also include plural forms. It should be further understood that the term "comprising" used in the specification of the present invention refers to the presence of the features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements and / or groups thereof.
[0051] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. Different embodiments or examples described in this specification and features of different embodiments or examples may be combined and combined by those skilled in the art without contradiction.
[0052] To facilitate understanding of the present invention, the present invention is further explained below with reference to specific embodiments in conjunction with the accompanying drawings, and the specific embodiments do not constitute a limitation on the embodiments of the present invention.
[0053] Those skilled in the art should understand that the drawings are merely schematic diagrams of embodiments, and the components in the drawings are not necessarily necessary for implementing the present invention.
[0054] Example 1
[0055] In this embodiment 1, a star-shaped private network interconnection method based on multi-channel transmission is provided, and the network topology is as follows: Figure 1 As shown, it includes the following main functional bodies: terminal equipment, proxy server, core proxy server, private network administrator. Multiple private networks communicate through proxy servers and core servers. The star-shaped private network interconnection method based on multi-channel transmission is deployed on the proxy server and the core proxy server.
[0056] The implementation process of a star-shaped private network interconnection method based on multi-channel transmission is as follows:
[0057] Step A: Complete the allocation of local legal IP address pool and routing configuration.
[0058] Step B: Replacement of IP data packet header in the uplink communication process: Replacement of the destination IP field in the local proxy server and replacement of the source IP field in the peer proxy server.
[0059] Step C: Replacement of IP data packet header in the downlink communication process: Replacement of the destination IP field in the peer proxy server and replacement of the source IP field in the local proxy server.
[0060] Step A network configuration process is as follows:
[0061] Step A1: Proxy server configuration. The private network administrator configures information on his own proxy server, including the available legal IP address pool and the private network terminal IP for interconnection.
[0062] Step A2: Sharing of proxy server information: After configuration is completed, the proxy servers inform each other of the identification information of the access proxy servers and the IP addresses of the terminal devices connected to the private network.
[0063] Step A3: Proxy server legal address allocation: Each proxy server allocates new IP addresses to other private network terminal devices based on the legal IP address pool configured by the administrator.
[0064] Step A4: Update the mapping table of the proxy server. After the allocation is completed, the terminal device IP, the terminal device legal IP, and the terminal device proxy server identifier form a mapping relationship. The mapping relationships of all terminal devices form a mapping table and are stored in the proxy server.
[0065] Step A5: Routing configuration: The private network administrator needs to ensure that the data flow to other private network terminal devices is directed to the local proxy server through static routing configuration or other methods.
[0066] Step B and step C constitute a complete data communication process. Taking the communication between SP1 of private network A and UP1 of private network B as an example, the detailed process is as follows.
[0067] Step B: The replacement process of the IP data packet header in the uplink communication process is as follows: Figure 2 As shown (taking the uplink process of communication between SP1 and UP1 as an example):
[0068] Step B1: SP1 generates a data stream, the source address is SP1, and the destination address is SP4.
[0069] Step B2: After being transmitted in private network A, the data stream is directed to proxy server 1.
[0070] Step B3: The data flow enters from the SP network port and is directed to the virtual network port tun of the proxy server 1 according to the routing table of the private network server.
[0071] Step B4: Process the data packet from the tun port.
[0072] Step B4-1: If the data packet is a communication data packet between private network terminals, perform IP header field replacement and header encapsulation.
[0073] Step B4-1-1: Replace the destination IP field in the IP data packet header according to the mapping table.
[0074] Step B4-1-2: Update the checksum field in the IP data packet header.
[0075] Step B4-1-3: Encapsulate a new custom identification header, which consists of a 1-byte source agent identification and a 1-byte destination agent identification. The source agent identification is the identification of the proxy server, and the destination agent identification can be queried from the mapping table.
[0076] Step B4-2: If the data packet is a notification message between proxy servers, extract the shared information in the data packet and update the mapping table.
[0077] Step B5: The virtual network port tun on the proxy server is bound to multiple public network ports, and each public network port establishes a socke connection with the core proxy. After the data packet processing is completed, the corresponding socket connection is selected according to the multiplex transmission scheduling scheme.
[0078] Step B6: The data packet encapsulated with the custom header is sent out as the data part through the socket connection.
[0079] Step B7: The data stream is sent from the proxy server 1 and reaches the core server after being transmitted through the public network.
[0080] Step B8: After the data stream reaches the core proxy server, the destination proxy identifier of the identification header is read, and then the data packet encapsulated with the identification header is forwarded through the socket connection between the core proxy server and the proxy server 2.
[0081] Step B9: After the data stream reaches the proxy server 2, the outermost IP header is removed and data packet processing is performed.
[0082] Step B9-1: If the data packet is a communication data packet between private network terminals, perform identification header decapsulation and IP header field replacement.
[0083] Step B9-1-1: Read the source agent identification in the identification header and unpack it.
[0084] Step B9-1-2: Read the source IP field of the internal IP header, query the mapping table according to the source agent identifier and the source IP field, and replace the source IP field with the legal IP address of this private network.
[0085] Step B9-1-3: Update the checksum field of the IP header.
[0086] Step B9-1-4: The data packet is handed over to the virtual port tun of the proxy server.
[0087] Step B9-2: If the data packet is a notification message between proxy servers, extract the shared information in the data packet and update the mapping table.
[0088] Step B10: The data flow is exported from the UP port according to the routing of the proxy server.
[0089] Step B11: The data stream is transmitted through private network B and reaches UP1.
[0090] Step C: Replacement of IP packet header in downlink communication process Figure 3 As shown (taking the downlink process of communication between SP1 and UP1 as an example):
[0091] Step C1: UP1 replies with a data stream whose source address is SP1 and whose destination address is SP4.
[0092] Step C2: After being transmitted in private network B, the data stream is directed to proxy server 2.
[0093] Step C3: The data flow enters from the UP network port and is directed to the virtual network port tun of the proxy server 2 according to the routing of the private network server.
[0094] Step C4: Process the data packet from the tun port.
[0095] Step C4-1: If the data packet is a communication data packet between private network terminals, perform IP header field replacement and header encapsulation.
[0096] Step C4-1-1: Replace the destination IP field in the IP data packet header according to the mapping table.
[0097] Step C4-1-2: Update the checksum field in the IP data packet header.
[0098] Step C4-1-3: Encapsulate a new custom identification header, which consists of a 1-byte source agent identification and a 1-byte destination agent identification. The source agent identification is the identification of the proxy server, and the destination agent identification can be queried from the mapping table.
[0099] Step C4-2: If the data packet is a notification message between proxy servers, extract the shared information in the data packet and update the mapping table.
[0100] Step C5: The virtual network port tun on the proxy server is bound to multiple public network ports, and each public network port establishes a socke connection with the core proxy. After the data packet processing is completed, the corresponding socket connection is selected according to the multiplex transmission scheduling scheme.
[0101] Step C6: The data packet encapsulated with the custom header is sent out through the socket connection as the data part.
[0102] Step C7: The data stream is sent from the proxy server 2 and reaches the core server after being transmitted through the public network.
[0103] Step C8: After the data stream reaches the core proxy server, the destination proxy identifier of the identifier header is read, and then the data packet encapsulated with the identifier header is forwarded through the socket connection between the core proxy server and the proxy server 1.
[0104] Step C9: After the data stream reaches the proxy server 1, the outermost IP header is removed and data packet processing is performed.
[0105] Step C9-1: If the data packet is a communication data packet between private network terminals, perform identification header decapsulation and IP header field replacement.
[0106] Step C9-1-1: Read the source agent identification in the identification header and unpack it.
[0107] Step C9-1-2: Read the source IP field of the internal IP header, query the mapping table according to the source agent identifier and the source IP field, and replace the source IP field with the legal IP address of this private network.
[0108] Step C9-1-3: Update the checksum field of the IP header.
[0109] Step C9-1-4: The data packet is handed over to the virtual port tun of the proxy server.
[0110] Step C9-2: If the data packet is a notification message between proxy servers, extract the shared information in the data packet and update the mapping table.
[0111] Step C10: The data flow is exported from the SP port according to the routing of the proxy server.
[0112] Step C11: The data stream is transmitted through private network A and reaches SP1.
[0113] In this embodiment, the private networks of different regions and organizations are interconnected, which meets the high bandwidth requirements of large-scale private network communications and realizes the high efficiency of communication between private networks. Private networks are allowed to independently manage network segments and allocate addresses. Even if there is an IP address conflict between terminal devices in private networks, there is no need to make unified adjustments, which protects the privacy and security of private network information (network topology, network segment allocation, etc.). The star network design has good scalability and allows flexible access to private networks.
[0114] Example 2
[0115] This embodiment 2 provides a non-transitory computer-readable storage medium, which is used to store computer instructions. When the computer instructions are executed by a processor, the star-type private network interconnection method based on multi-channel transmission as described in embodiment 1 is implemented.
[0116] Example 3
[0117] This embodiment 3 provides a computer device, including a memory and a processor, the processor and the memory communicate with each other, the memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute the star-type private network interconnection method based on multi-path transmission as described in embodiment 1.
[0118] Example 4
[0119] This embodiment 4 provides an electronic device, including: a processor, a memory and a computer program; wherein the processor is connected to the memory, and the computer program is stored in the memory. When the electronic device is running, the processor executes the computer program stored in the memory so that the electronic device executes instructions for implementing the star-type private network interconnection method based on multi-path transmission as described in embodiment 1.
[0120] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0121] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0122] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0123] These computer program instructions can also be loaded onto a computer or other programmable data processing device, and a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0124] Although the above describes the specific implementation mode of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art without creative work on the basis of the technical solution disclosed in the present invention should be included in the scope of protection of the present invention.
Claims
1. A star-shaped private network interconnection method based on multi-channel transmission, characterized in that: include: Carry out the network configuration process; Replacement of IP packet header in the uplink communication process; The destination IP field is replaced in the local proxy server, and the source IP field is replaced in the peer proxy server; Replacement of IP packet header in the downlink communication process; replacement of the destination IP field in the peer proxy server and replacement of the source IP field in the local proxy server.
2. The method for interconnecting star-shaped private networks based on multi-channel transmission according to claim 1, characterized in that: The network configuration process includes: Proxy server configuration: The private network administrator configures information on his own proxy server, including the available legal IP address pool and the private network terminal IP for interconnection; Proxy server information sharing: After the proxy server configuration is completed, the proxy server will automatically share the IP address of the terminal device accessing the private Internet and the identification information of the proxy server; Legal address allocation of proxy servers: Each proxy server allocates new IP addresses to other private network terminal devices based on the legal IP address pool configured by the administrator; Update of the mapping table of the proxy server: After the legal address of the proxy server is allocated, the terminal device IP, the legal IP of the terminal device, and the terminal device proxy server identifier form a mapping relationship. The mapping relationships of all terminal devices form a mapping table and are stored in the proxy server; Routing configuration: The private network administrator needs to configure static routing to ensure that the data flow to other private network terminal devices is directed to the local proxy server.
3. The method for interconnecting star-shaped private networks based on multi-channel transmission according to claim 1, characterized in that: The replacement of IP packet header in the upstream communication process includes: SP1 generates a data stream with source address SP1 and destination address SP4; After being transmitted in private network A, the data stream is directed to proxy server 1; The data flow enters from the SP network port and is directed to the virtual network port tun of proxy server 1 according to the routing table of the private network server; Process the data packet at the tun port; if the data packet is a communication data packet between private network terminals, replace the IP header field and encapsulate the header; if the data packet is a notification message between proxy servers, extract the shared information in the data packet and update the mapping table; The virtual network port tun on the proxy server is bound to multiple public network ports. Each public network port establishes a socke connection with the core proxy. After the data packet is processed, the corresponding socket connection is selected according to the multi-channel transmission scheduling plan; The data packet encapsulated with the custom header is sent out as the data part through the socket connection; The data stream is sent from proxy server 1 and reaches the core server after being transmitted through the public network; After the data stream reaches the core proxy server, it reads the destination proxy identifier of the identification header, and then forwards the data packet encapsulated with the identification header through the socket connection between the core proxy server and proxy server 2; After the data stream reaches the proxy server 2, the outermost IP header is removed and the data packet is processed; if the data packet is a communication data packet between private network terminals, the identification header is unsealed and the IP header field is replaced; if the data packet is a notification message between proxy servers, the shared information in the data packet is extracted and the mapping table is updated; The data flow is exported from the UP port according to the routing of the proxy server; The data stream is transmitted through private network B and reaches UP1.
4. The method for interconnecting star-shaped private networks based on multi-channel transmission according to claim 3, characterized in that: If the data packet is a communication data packet between private network terminals, IP header field replacement and header encapsulation are performed, including: replacing the destination IP field of the IP data packet header according to the mapping table; updating the checksum field of the IP data packet header; encapsulating a new custom identification header, the header consists of a 1-byte source agent identifier, a 1-byte destination agent identifier and a 2-byte packet sequence number, the source agent identifier is the current proxy server identifier, and the destination agent identifier is queried by the mapping table.
5. The method for interconnecting star-shaped private networks based on multi-channel transmission according to claim 3, characterized in that: If the data packet is a communication data packet between private network terminals, the identification header is decapsulated and the IP header field is replaced, including: reading the source agent identification of the identification header and decapsulating it; reading the source IP field of the internal IP header, querying the mapping table according to the source agent identification and the source IP field, and replacing the source IP field with the legal IP address of this private network; updating the checksum field of the IP header; and handing the data packet to the virtual port tun of the proxy server.
6. The method for interconnecting star-shaped private networks based on multi-channel transmission according to claim 1, characterized in that: The replacement of IP packet header in the downlink communication process includes: UP1 replies with a data stream, with the source address being SP1 and the destination address being SP4. After being transmitted in private network B, the data stream is directed to proxy server 2. The data stream enters through the UP network port and is directed to the virtual network port tun of proxy server 2 according to the routing of the private network server. Process the data packet at the tun port; if the data packet is a communication data packet between private network terminals, replace the IP header field and encapsulate the header; if the data packet is a notification message between proxy servers, extract the shared information in the data packet and update the mapping table; The virtual network port tun on the proxy server is bound to multiple public network ports. Each public network port establishes a socke connection with the core proxy. After the data packet is processed, the corresponding socket connection is selected according to the multi-channel transmission scheduling plan; The data packet encapsulated with the custom header is sent out as the data part through the socket connection; the data stream is sent out from the proxy server 2 and reaches the core server after being transmitted through the public network; after the data stream reaches the core proxy server, the destination proxy identifier of the identification header is read, and then the data packet encapsulated with the identification header is forwarded through the socket connection between the core proxy server and the proxy server 1; After the data stream reaches the proxy server 1, the outermost IP header is removed and the data packet is processed; if the data packet is a communication data packet between private network terminals, the identification header is unsealed and the IP header field is replaced; if the data packet is a notification message between proxy servers, the shared information in the data packet is extracted and the mapping table is updated; The data flow is exported from the SP port according to the routing of the proxy server; the data flow is transmitted through private network A to reach SP1.
7. The method for interconnecting star-shaped private networks based on multi-channel transmission according to claim 6, characterized in that: If the data packet is a communication data packet between private network terminals, the identification header is decapsulated and the IP header field is replaced, including: replacing the destination IP field of the IP data packet header according to the mapping table; updating the checksum field of the IP data packet header; encapsulating a new custom identification header, the header consists of a 1-byte source agent identifier, a 1-byte destination agent identifier and a 2-byte packet sequence number, the source agent identifier is the current proxy server identifier, and the destination agent identifier can be queried by a mapping table.
8. A non-transitory computer-readable storage medium, characterized in that: The non-transitory computer-readable storage medium is used to store computer instructions. When the computer instructions are executed by the processor, the star-type private network interconnection method based on multi-channel transmission as described in any one of claims 1-7 is implemented.
9. A computer device, characterized in that: It includes a memory and a processor, the processor and the memory communicate with each other, the memory stores program instructions that can be executed by the processor, and the processor calls the program instructions to execute the star-type private network interconnection method based on multi-channel transmission as described in any one of claims 1-7.
10. An electronic device, characterized in that: include: A processor, a memory and a computer program; wherein the processor is connected to the memory, the computer program is stored in the memory, and when the electronic device is running, the processor executes the computer program stored in the memory so that the electronic device executes instructions for implementing the star-type private network interconnection method based on multi-channel transmission as described in any one of claims 1-7.