Data transmission method and device for VPN tunnel service, electronic equipment and storage medium
By matching and processing visual networked VPN tunnel packets using the matching strategy generated by the AI model on the router, the problem of lack of data transmission permission control and insufficient real-time performance in the prior art is solved, and more efficient and accurate data service behavior detection is achieved.
Patent Information
- Application Number
- CN202510334420.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-05-30
AI Technical Summary
The existing video networked VPN tunnels lack access to in and out interception permissions for data services, which leads to increased costs for customers to deploy security boundary equipment. In addition, traditional security detection technology is insufficient in real time and cannot cope with dynamically changing network traffic.
The matching strategy stored in the multi-service terminal device on the router is adopted to match the target network data packets according to the target matches, and a matching strategy is generated through the preset AI model, the target execution action corresponding to the matching result is determined, and the data packets are processed according to the action.
It realizes more accurate and real-time data business behavior detection, replaces manual configuration of complex rules and strategies, and reduces labor costs and network operation and maintenance pressure.
Smart Images

Figure CN120075119A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission, and particularly to a data transmission method and device for VPN tunnel services, an electronic device, and a storage medium. Background Art
[0002] In e-government projects, the VVoE video networking protocol driver can be used to establish a video networking VPN tunnel with a video networking aggregation router to carry e-government network application service data.
[0003] Currently, the following video networking VPN tunnels for carrying data services do not have inbound and outbound interception permissions, and customers need to deploy security boundary devices on the application service side, increasing costs.
[0004] The video networking aggregation router is used as the called end, and the VVoE protocol driver is used as the calling end. By default, any calling end will force the establishment of a video networking VPN tunnel with the called end (the called end does not support rejection), but the VPN tunnel permissions between classified hosts and the video networking aggregation router need to be manually reviewed and planned.
[0005] Traditional security detection technologies are based on offline data analysis, with insufficient real-time performance, unable to handle large and dynamically changing network traffic, and with high labor costs. Summary of the Invention
[0006] In view of the above problems, a data transmission method and device for VPN tunnel services, an electronic device, and a storage medium are proposed to overcome the above problems or at least partially solve the above problems, including:
[0007] A data transmission method is applied to a router, and the router includes multi-service terminal devices. The method includes:
[0008] Receiving a target network data packet sent by a first service terminal, where the router is used for data transmission between the first service terminal and a second service terminal;
[0009] Using a matching strategy stored in the multi-service terminal device to match the target network data packet according to a target matching item to obtain a matching result corresponding to the target matching item. The matching strategy includes one or more matching items and execution actions, and the matching strategy is generated by training a preset AI model based on data packets collected and processed by the router;
[0010] Determining a target execution action corresponding to the matching result;
[0011] Processing the target network data packet according to the target execution action.
[0012] Optionally, matching the target network data packet according to the target matching item by using the matching policy stored in the multi-service terminal device to obtain the matching result corresponding to the target matching item, including:
[0013] Analyze the target network data packet to obtain a network number and / or a network sub-number;
[0014] Use the matching policy stored in the multi-service terminal device to match the network number and / or the network sub-number to obtain a matching result.
[0015] Optionally, determining the target execution action corresponding to the matching result, including:
[0016] When the target matching result is that all of the one or more target matching items are successfully matched, determine that the target execution action is an allow action;
[0017] When the target matching result is that there is an unmatched target item among the one or more target matching items, determine that the target execution action is a discard action.
[0018] Optionally, processing the target network data packet according to the target execution action, including:
[0019] When the target execution action is an allow action, determine the service data routing type of the target network data packet based on the matching policy;
[0020] Establish a virtual private network tunnel according to the service data routing type;
[0021] Transmit the target network data packet by using the virtual private network tunnel.
[0022] Optionally, before matching the target network data packet according to the target matching item by using the matching policy stored in the multi-service terminal device to obtain the matching result corresponding to the target matching item, further including:
[0023] Determine the header of the target network data packet;
[0024] Based on the header, determine whether the target network data packet is a packet in a preset format;
[0025] When it is determined that the target network data packet is a packet in a preset format, execute matching the target network data packet by using the matching policy stored in the multi-service terminal device to obtain a matching result;
[0026] When it is determined that the target network data packet is not a packet in a preset format, generate a prompt message.
[0027] Optionally, before matching the target network data packet according to the target matching item by using the matching policy stored in the multi-service terminal device to obtain the matching result corresponding to the target matching item, it further includes:
[0028] Determine whether the target network data packet has been modified;
[0029] If it is determined that the target network data packet has been modified, then correct the target network data packet by using the matching policy stored in the multi-service terminal device.
[0030] Optionally, it further includes:
[0031] Store the target network data packet and the corresponding execution action.
[0032] A data transmission device, the router includes a multi-service terminal device, and the device includes:
[0033] A target network data packet sending module, configured to receive the target network data packet sent by the first service terminal, and the router is used for data transmission between the first service terminal and the second service terminal;
[0034] A matching module, configured to match the target network data packet according to the target matching item by using the matching policy stored in the multi-service terminal device to obtain the matching result corresponding to the target matching item, where the matching policy includes one or more matching items and execution actions, and the matching policy is generated by a preset AI model based on the data packets collected and processed by the router;
[0035] A target execution action determination module, configured to determine the target execution action corresponding to the matching result;
[0036] A network data packet processing module, configured to process the target network data packet according to the target execution action.
[0037] An electronic device, including a processor, a memory, and a computer program stored on the memory and capable of running on the processor, where when the computer program is executed by the processor, it implements the data transmission method described above.
[0038] A computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it implements the data transmission method described above.
[0039] The embodiments of the present invention have the following advantages:
[0040] In an embodiment of the present invention, a router may receive a target network data packet sent by a first service terminal, and the router is used for data transmission between the first service terminal and a second service terminal; the target network data packet is matched according to a target matching item by using a matching strategy stored in a multi-service terminal device to obtain a matching result corresponding to the target matching item. The matching strategy includes one or more matching items and execution actions, and the matching strategy is generated by training a preset AI model based on data packets collected and processed by the router in history; determine a target execution action corresponding to the matching result; process the target network data packet according to the target execution action, so as to replace manual configuration of frequently and complex rule strategies through AI training, thereby realizing more accurate and real-time detection of data service behaviors. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions of the present invention, the drawings required for the description of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0042] Figure 1 is a flowchart of the steps of a data transmission method provided by an embodiment of the present invention;
[0043] Figure 2a is a flowchart of the steps of another data transmission method provided by an embodiment of the present invention;
[0044] Figure 2b is a schematic diagram of a visual networking data transmission architecture provided by an embodiment of the present invention;
[0045] Figure 3 is a flowchart of the steps of another data transmission method provided by an embodiment of the present invention;
[0046] Figure 4 is a schematic diagram of a V2V data transmission provided by an embodiment of the present invention;
[0047] Figure 5 is a schematic diagram of the structure of a data transmission device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0048] In order to make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the drawings and specific embodiments. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the protection scope of the present invention.
[0049] Reference Figure 1 , which shows the step flowchart of a data transmission method for a VPN tunnel service provided by an embodiment of the present invention. It is applied to a router, and the router includes multi-service terminal devices. Specifically, the following steps may be included:
[0050] Step S101: Receive a target network data packet sent by a first service terminal. The router is used for data transmission between the first service terminal and the second service terminal;
[0051] In practical applications, both the first service terminal and the second service terminal are connected to the router. The first service terminal can send a target network data packet to the router, and then the router can perform data transmission according to the received target network data packet.
[0052] In an embodiment of the present invention, the first service terminal, the second service terminal, and the router are devices in a vision network, and the corresponding target network data packet can be data transmitted in the vision network v2v protocol.
[0053] Moreover, to ensure data security, the first service terminal and the second service terminal can be divided into a classified area and an unclassified area. The classified area can be used to store classified data, and the unclassified area can be used to store unclassified data.
[0054] Step S102: Use the matching strategy stored in the multi-service terminal device to match the target network data packet according to the target matching item, and obtain the matching result corresponding to the target matching item. The matching strategy includes one or more matching items and execution actions, and the matching strategy is generated by training a preset AI model based on the data packets historically collected and processed by the router;
[0055] In an embodiment of the present invention, a service terminal device can be set on the router. The service terminal device can collect the data received and processed on the router, and then can organize and train the historically collected and processed data packets through a preset AI model to generate a matching strategy. The matching strategy can be used to distinguish whether the data carried in the target network data packet is all allowed to be transmitted. Furthermore, corresponding actions can be performed on the data packet according to whether the data is allowed to be transmitted. Thus, the matching strategy at least includes a matching item for judging whether the data packet is allowed to be transmitted and managed, and the execution action corresponding to each matching item. In practical applications, the execution action can be divided into a discard action or an allow action.
[0056] In practical applications, matching can be performed according to one or more target matching items respectively, and then the matching results corresponding to all matching items can be obtained.
[0057] In an embodiment of the present invention, before step S102, it may further include: determining whether the target network data packet is modified; if it is determined that the target network data packet is modified, the matching strategy stored in the multi-service terminal device is used to correct the target network data packet.
[0058] In practical applications, the multi-service terminal device can determine whether the target network data packet is modified according to the received target network data packet. In the case where it is determined that the target network data packet has been manually modified, to ensure system security, the data repair of the multi-service terminal device can be started. Furthermore, even if the data transmission system is invaded and tampered with, it can ensure that the data can be safely transmitted without being affected by the tampering.
[0059] Step S103, determining the target execution action corresponding to the matching result;
[0060] After determining the matching result, since in the stored matching strategy, the matching items and the execution actions correspond to each other, thus, the corresponding target execution action can be determined according to the matching result of the matching items.
[0061] Step S104, processing the target network data packet according to the target execution action.
[0062] After determining the target execution action, the corresponding target execution action can be performed on the target network data packet.
[0063] In an embodiment of the present invention, when the target matching result is that one or more target matching items are all successfully matched, the target execution action is determined to be the release action; when the target matching result is that there is one or more target items in the target matching items that are not successfully matched, the target execution action is determined to be the discard action.
[0064] In practical applications, when each item is successfully matched, it is determined that the data in the target network data packet is the actually required data. If there is one item that is not successfully matched, it means that the data is not the data that the second service terminal needs to process, and then the discard action can be performed.
[0065] In an embodiment of the present invention, step 104 may include the following sub-steps:
[0066] Sub-step S11, when the target execution action is the release action, determining the service data flow type of the target network data packet based on the matching strategy;
[0067] Among them, the service data flow type can be divided into a unidirectional type or a bidirectional type according to the data classification type. For classified data, the unidirectional type of service data flow type can be set to ensure data transmission security, and for unclassified data, the bidirectional type of service data flow type can be set.
[0068] Sub-step S12: Establish a virtual private network (VPN) tunnel according to the type of business data flow direction;
[0069] After determining the type of business data flow direction, a corresponding VPN tunnel can be established. For example, for unidirectional data, a VPN tunnel for unidirectional data transmission can be established, and for bidirectional data, a VPN tunnel for bidirectional data transmission can be established.
[0070] Sub-step S13: Transmit the target network data packets using the VPN tunnel.
[0071] After establishing the VPN tunnel, data can be transmitted between the router and the second service terminal based on the VPN tunnel.
[0072] In an embodiment of the present invention, after processing each target network data packet, the router can store the target network data packet and the corresponding execution action for use as training materials for the AI model in the next cycle.
[0073] In an embodiment of the present invention, the V-MSH device of the router can report the original data pre-collected for AI autonomous learning, accurately verify the original data, intelligently verify the matching rules, and intelligently modify and distribute the matching rules, thereby realizing the modification of the business rule strategy without manual intervention.
[0074] In an embodiment of the present invention, the router can receive the target network data packets sent by the first service terminal. The router is used for data transmission between the first service terminal and the second service terminal; the target network data packets are matched according to the target matching items using the matching strategy stored in the multi-service terminal device, and the matching results corresponding to the target matching items are obtained. The matching strategy includes one or more matching items and execution actions, and the matching strategy is generated by a preset AI model based on the data packets collected and processed by the router's history; determine the target execution action corresponding to the matching result; process the target network data packets according to the target execution action, thereby replacing the manual configuration of frequently and complex rule strategies through AI training, and realizing more accurate and real-time detection of data service behaviors.
[0075] Refer to Figure 2a , which shows the step flowchart of another data transmission method for VPN tunnel services provided by an embodiment of the present invention, applied to a router. The router includes a multi-service terminal device, and specifically may include the following steps:
[0076] Step S201: Receive the target network data packets sent by the first service terminal. The router is used for data transmission between the first service terminal and the second service terminal;
[0077] In practical applications, the first service terminal and the second service terminal are both connected to a router. The first service terminal can send a target network data packet to the router, and then the router can perform data transmission according to the received target network data packet.
[0078] In an embodiment of the present invention, the first service terminal, the second service terminal, and the router are devices in a visual networking, and the corresponding target network data packet can be data transmitted in the visual networking v2v protocol.
[0079] Moreover, to ensure data security, the first service terminal and the second service terminal can be divided into a classified area and an unclassified area. The classified area can be used to store classified data, and the unclassified area can be used to store unclassified data.
[0080] Step S202: Analyze the target network data packet to obtain a network number and / or a network sub-number;
[0081] In practical applications, data transmission can be performed between the first service terminal and the second service terminal through the network number and the network sub-number. Therefore, the network number and the network sub-number can be obtained by analyzing the target network data packet.
[0082] Step S203: Use the matching strategy stored in the multi-service terminal device to match the network number and / or the network sub-number to obtain a matching result. The matching strategy includes one or more matching items and execution actions;
[0083] In the matching strategy, the network number range and the network sub-number range of the first service terminal that can communicate with the second service terminal can be preset.
[0084] Furthermore, after the network number and the network sub-number are obtained by analysis, it can be determined whether the network number obtained by analyzing the target network data packet is within the network number range and whether the network sub-number is within the network sub-number range.
[0085] Refer to Figure 2b , which is a schematic diagram of a visual networking data transmission architecture in an embodiment of the present invention, including: application service platform A, application service platform B, VVoE protocol driver host C, VVoE protocol driver host D, and a visual networking aggregation router. A V-MSH is set on the visual networking aggregation router, and the matching strategy pre-trained by the artificial intelligence training platform is stored in the V-MSH.
[0086] Among them, the setting of the architecture matching strategy based on Figure 2b can be divided into the following process:
[0087] (1) Service pre-configuration:
[0088] The service port G0 / 1 of the Visual Networking Aggregation Router is connected to the application service platform A in the classified area, the service port G0 / 2 is connected to the application service platform B in the unclassified area, and the Visual Networking port G0 / 8 is connected to the Visual Networking. After network access, the Visual Networking number 01001 is enabled, and the number of sub-numbers enabled is 200. The office computers in the classified and unclassified office areas are respectively installed with the VVoE protocol driver. The PCs are connected to the Visual Networking and the Visual Networking numbers are enabled after network access. The range of Visual Networking numbers assigned to the VVoE protocol driver host in area C is 02001 - 02100, and the number of sub-numbers for each Visual Networking number is 1. The range of Visual Networking numbers assigned to the VVoE protocol driver host in area D is 03001 - 03100, and the number of sub-numbers for each Visual Networking number is 1.
[0089] (2) Artificial Intelligence Training Platform Collection Area:
[0090] The following basic business rule models are collected on the V-MSH device of the Visual Networking Aggregation Router:
[0091] Collection Rule 1: The Visual Networking VPN tunnel established by the Visual Networking number 01001 of the called end and the sub-numbers in the area ID range of 0 - 100 is bound to the service port G0 / 1.
[0092] Collection Rule 2: The Visual Networking VPN tunnel established by the Visual Networking number 01001 of the called end and the sub-numbers in the area ID range of 101 - 200 is bound to the service port G0 / 2.
[0093] Collection Rule 3: For the called end with the Visual Networking number 01001 and sub-numbers in the area ID range of 0 - 100, the Visual Networking VPN tunnel is allowed to be successfully established by the calling end with the Visual Networking number range of 02001 - 02100 and the device with the sub-number ID of 9. Those that do not meet the requirements are discarded.
[0094] Collection Rule 4: For the called end with the Visual Networking number 01001 and sub-numbers in the area ID range of 101 - 200, the Visual Networking VPN tunnel is allowed to be successfully established by the calling end with the Visual Networking number range of 03001 - 03100 and the devices with the sub-number ID range of 0 - 200. Those that do not meet the requirements are discarded.
[0095] Collection Rule 5: The data flow of the service port G0 / 1 of the Visual Networking Aggregation Router device is unidirectional (only allowing application data download and not allowing upload).
[0096] Collection Rule: The data flow of the service port G0 / 2 of the Visual Networking Aggregation Router device is bidirectional (allowing application data download and upload).
[0097] The example is as follows:
[0098] 01) In the classified office area, there is a PC with a VVoE protocol driver. The main calling end's Visual Networking number is 02001, and the sub-number is 9. The called end's Visual Networking number of the Visual Networking aggregation router is 01001, and the sub-number is 10. When the V-MSH device receives a request, it matches rules 03 and 05 and allows the establishment of a Visual Networking VPN tunnel to access application service data.
[0099] 02) In the unclassified office area, there is a PC with a VVoE protocol driver. The main calling end's Visual Networking number is 03003, and the sub-number is 9. The called end's Visual Networking number of the Visual Networking aggregation router is 01001, and the sub-number is 11. When the V-MSH device receives a request, it matches rules 03 and 04 and rejects the establishment of a Visual Networking VPN tunnel to access application service data.
[0100] 03) In the unclassified office area, there is a PC with a VVoE protocol driver. The main calling end's Visual Networking number is 03004, and the sub-number is 100. The called end's Visual Networking number of the Visual Networking aggregation router is 01001, and the sub-number is 101. When the V-MSH device receives a request, it matches rules 04 and 06 and allows the establishment of a Visual Networking VPN tunnel to access application service data.
[0101] 04) In the classified office area, there is a PC with a VVoE protocol driver. The main calling end's Visual Networking number is 02003, and the sub-number is 9. The called end's Visual Networking number of the Visual Networking aggregation router is 01001, and the sub-number is 100. When the V-MSH device receives a request, it matches rule 04 and does not allow the establishment of a Visual Networking VPN tunnel to access application service data.
[0102] Step S204, determine the target execution action corresponding to the matching result;
[0103] Step S205, process the target network data packet according to the target execution action.
[0104] In the embodiment of the present invention, the router can first receive the target network data packet, then parse it to obtain the network number and network sub-number, then match according to the network number and network sub-number to determine the target execution action, and then execute, so that the configuration of frequently and complex rule policies can be replaced by AI training, thereby realizing more accurate and real-time detection of data service behaviors.
[0105] Refer to Figure 3 , which shows the step flowchart of another data transmission method for VPN tunnel services provided by an embodiment of the present invention, applied to a router. The router includes multi-service terminal devices, and specifically may include the following steps:
[0106] Step S301, receive the target network data packet sent by the first service terminal. The router is used for data transmission between the first service terminal and the second service terminal;
[0107] In practical applications, both the first service terminal and the second service terminal are connected to a router. The first service terminal can send a target network data packet to the router, and then the router can perform data transmission based on the received target network data packet.
[0108] In an embodiment of the present invention, the first service terminal, the second service terminal, and the router are devices in a vision network, and the corresponding target network data packet can be data transmitted in the vision network v2v protocol.
[0109] Moreover, to ensure data security, the first service terminal and the second service terminal can be divided into a classified area and an unclassified area. The classified area can be used to store classified data, and the unclassified area can be used to store unclassified data.
[0110] Step S302, determine the header of the target network data packet;
[0111] After receiving the target network data packet, the header can be determined from the target network data packet. Among them, the target network data packet can include but is not limited to a header, a source MAC address, a destination MA address, V-MSH configuration data, and message data. The V-MSH configuration data can include a calling number, a called number, a sub-number, an allow action / deny action.
[0112] Step S303, determine whether the target network data packet is a data packet in a preset format based on the header;
[0113] Among them, the preset format can be set according to the actual scenario. For example, the preset format can include the type of the header, the number of fields, etc.
[0114] Step S304, when it is determined that the target network data packet is a data packet in a preset format, perform matching on the target network data packet using a matching policy stored in the multi-service terminal device to obtain a matching result.
[0115] Step S305, when it is determined that the target network data packet is not a data packet in a preset format, generate a prompt message.
[0116] Step S306, use the matching policy stored in the multi-service terminal device to match the target network data packet according to the target matching item to obtain the matching result corresponding to the target matching item. The matching policy includes one or more matching items and execution actions;
[0117] Step S307, determine the target execution action corresponding to the matching result;
[0118] Step S308, process the target network data packet according to the target execution action.
[0119] In the embodiments of the present invention, by obtaining the packet header for screening before matching according to the matching policy, correct data packets can be pre-screened to ensure data security, and the amount of matching in the matching policy process can be reduced, thereby reducing the processing pressure on the router.
[0120] Refer to Figure 4 , which is a schematic diagram of V2V data transmission in the embodiments of the present invention. The data transmission and processing process is as follows:
[0121] In the artificial intelligence training platform area, when a V2V data packet enters the Visual Networking interface, it is detected whether the data packet is a correct Visual Networking message. For example, the packet header, MAC address, etc. can be obtained for verification.
[0122] If it is a correct Visual Networking packet, the Visual Networking message can be unpacked to extract data, and the Visual Networking number in the message is compared with the pre-policy of the V-MSH (Video Multi-Service Hub) device in the artificial intelligence training platform (for example, matching the Visual Networking number and sub-number), and the corresponding actions of the matching policy (such as allowing action / dropping action). Among them, the allowing action selectively establishes a Visual Networking VPN tunnel for the direction of service data (such as unidirectional flow or bidirectional flow).
[0123] After the Visual Networking VPN tunnel is successfully established, the data protocol conversion module can be selected to send the data stream to the service outlet for data stream forwarding.
[0124] It should be noted that the above action processes are all reported by the V-MSH device to the AI for autonomous learning to pre-collect the original data, accurately verify the original data, intelligently verify the matching rules, and intelligently modify and issue the matching rules, without manual intervention to modify the service rule policy.
[0125] In the embodiments of the present invention, the matching rules can be intelligently modified by the AI of the V-MSH device without manual intervention to modify the service rule policy. The data stream rules of the Visual Networking VPN tunnel can be restricted, so as to accurately prevent illegal message attacks and service access control in the network, and selectively establish a Visual Networking VPN tunnel to carry service data, which can reduce unnecessary message transmission in the network, save network resources, reduce the workload of network operation and maintenance, and provide a safe, reliable and stable service guarantee for customer data.
[0126] It should be noted that, for the method embodiments, for the sake of simple description, they are expressed as a series of action combinations. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the described action sequences, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.
[0127] Referring to Figure 5 , a schematic structural diagram of a data transmission device for VPN tunnel services provided by an embodiment of the present invention is shown. It is applied to a router, and the router includes multi-service terminal devices, which may specifically include the following modules:
[0128] A target network data packet sending module 501, configured to receive a target network data packet sent by a first service terminal, and the router is used for data transmission between the first service terminal and a second service terminal;
[0129] A matching module 502, configured to match the target network data packet according to a target matching item by using a matching strategy stored in the multi-service terminal device, and obtain a matching result corresponding to the target matching item. The matching strategy includes one or more matching items and execution actions, and the matching strategy is generated by training a preset AI model based on the data packets collected and processed by the router. The matching strategy is generated by training a preset AI model based on the data packets collected and processed by the router;
[0130] A target execution action determination module 503, configured to determine a target execution action corresponding to the matching result;
[0131] A network data packet processing module 504, configured to process the target network data packet according to the target execution action;
[0132] In an embodiment of the present invention, the matching module 502 may include the following sub-modules:
[0133] A data packet parsing sub-module, configured to parse the target network data packet to obtain a network number and / or a network sub-number;
[0134] A matching sub-module, configured to match the network number and / or the network sub-number by using a matching strategy stored in the multi-service terminal device to obtain a matching result.
[0135] In an embodiment of the present invention, the target execution action determination module 503 may include the following sub-modules:
[0136] The passing action determination sub-module is used to determine that the target execution action is a passing action when the target matching result is that all of the one or more target matching items are successfully matched;
[0137] The discarding action determination sub-module is used to determine that the target execution action is a discarding action when the target matching result is that there are target items among the one or more target matching items that are not successfully matched.
[0138] In an embodiment of the present invention, the network data packet processing module 504 may include the following sub-modules:
[0139] The service data routing type determination sub-module is used to determine the service data routing type of the target network data packet based on the matching policy when the target execution action is a passing action;
[0140] The virtual private network tunnel determination sub-module is used to establish a virtual private network tunnel according to the service data routing type;
[0141] The target network data packet transmission sub-module is used to transmit the target network data packet by using the virtual private network tunnel.
[0142] In an embodiment of the present invention, the device may further include:
[0143] The packet header determination module is used to determine the packet header of the target network data packet;
[0144] The data packet format judgment is used to judge whether the target network data packet is a data packet of a preset format based on the packet header;
[0145] The execution module is used to execute the matching of the target network data packet by using the matching policy stored in the multi-service terminal device to obtain a matching result when it is determined that the target network data packet is a data packet of a preset format.
[0146] The prompt message generation module is used to generate a prompt message when it is determined that the target network data packet is not a data packet of a preset format.
[0147] In an embodiment of the present invention, the device may further include:
[0148] The data packet modification judgment module is used to judge whether the target network data packet is modified;
[0149] The data correction module is used to correct the target network data packet by using the matching policy stored in the multi-service terminal device if it is determined that the target network data packet is modified.
[0150] In an embodiment of the present invention, the device may further include:
[0151] A data storage module for storing the target network data packet and the corresponding execution action.
[0152] In an embodiment of the present invention, a router may receive a target network data packet sent by a first service terminal, and the router is used for data transmission between the first service terminal and a second service terminal; the target network data packet is matched according to a target matching item by using a matching strategy stored in the multi-service terminal device, and a matching result corresponding to the target matching item is obtained. The matching strategy includes one or more matching items and execution actions, and the matching strategy is generated by a preset AI model based on the data packets collected and processed by the router in history; determining the target execution action corresponding to the matching result; processing the target network data packet according to the target execution action, so as to replace the frequent and complex rule strategy configuration by manual configuration through AI training, thereby realizing more accurate and real-time detection of data service behaviors.
[0153] An embodiment of the present invention further provides an electronic device, which may include a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, the above data transmission method is implemented.
[0154] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the above data transmission method is implemented.
[0155] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For the related parts, refer to the partial description of the method embodiment.
[0156] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments may be referred to each other.
[0157] Those skilled in the art should understand that the embodiments of the present invention may be provided as a method, a device, or a computer program product. Therefore, the embodiments of the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.
[0158] Embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate means for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or means for implementing the functions specified in multiple blocks.
[0159] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or means for implementing the functions specified in multiple blocks.
[0160] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or means for implementing the functions specified in multiple blocks.
[0161] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they know the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications falling within the scope of the embodiments of the present invention.
[0162] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or terminal device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the element.
[0163] The data transmission method and apparatus, electronic device, and storage medium for the provided VPN tunnel service have been introduced in detail above. In this text, specific examples are used to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A data transmission method for VPN tunnel service, characterized in that: Applied to a router, the router includes a multi-service terminal device, and the method includes: receiving a target network data packet sent by a first service terminal, the router being used for data transmission between the first service terminal and a second service terminal; The target network data packet is matched according to the target matching item using the matching strategy stored in the multi-service terminal device to obtain a matching result corresponding to the target matching item, wherein the matching strategy includes one or more matching items and an execution action, and the matching strategy is generated by training a preset AI model based on the data packet historically collected and processed by the router; Determine a target execution action corresponding to the matching result; The target network data packet is processed according to the target execution action.
2. The method according to claim 1, characterized in that The matching strategy stored in the multi-service terminal device is used to match the target network data packet according to the target matching item to obtain a matching result corresponding to the target matching item, including: Parsing the target network data packet to obtain a network number and / or a network sub-number; The network number and / or the network sub-number are matched using the matching strategy stored in the multi-service terminal device to obtain a matching result.
3. The method according to claim 1 or 2, characterized in that: The determining the target execution action corresponding to the matching result includes: When the target matching result is that the one or more target matching items are all matched successfully, determining that the target execution action is a release action; When the target matching result is that there is an unmatched target item among the one or more target matching items, determining that the target execution action is a discard action.
4. The method according to claim 3, characterized in that The step of executing an action according to the target to process the target network data packet includes: When the target execution action is a release action, determining the business data trend type of the target network data packet based on the matching strategy; Establishing a virtual private network tunnel according to the type of business data trend; The target network data packet is transmitted using the virtual private network tunnel.
5. The method according to claim 1, characterized in that Before the matching strategy stored in the multi-service terminal device is used to match the target network data packet according to the target matching item to obtain the matching result corresponding to the target matching item, the method further includes: Determine the message header of the target network data packet; Determining whether the target network data packet is a data packet in a preset format based on the message header; When it is determined that the target network data packet is a data packet of a preset format, executing the matching strategy stored in the multi-service terminal device to match the target network data packet to obtain a matching result; When it is determined that the target network data packet is a data packet not in a preset format, a prompt message is generated.
6. The method according to claim 1, characterized in that Before the matching strategy stored in the multi-service terminal device is used to match the target network data packet according to the target matching item to obtain the matching result corresponding to the target matching item, the method further includes: Determining whether the target network data packet has been modified; If it is determined that the target network data packet has been modified, the target network data packet is corrected using the matching strategy stored in the multi-service terminal device.
7. The method according to claim 1, characterized in that Also includes: The target network data packet and the corresponding execution action are stored.
8. A data transmission device for VPN tunnel service, characterized in that: The router includes a multi-service terminal device, and the device includes: a target network data packet sending module, used for receiving a target network data packet sent by a first service terminal, and the router is used for data transmission between the first service terminal and a second service terminal; A matching module, configured to match the target network data packet according to the target matching item using the matching strategy stored in the multi-service terminal device to obtain a matching result corresponding to the target matching item, wherein the matching strategy includes one or more matching items and an execution action, and the matching strategy is generated by training a preset AI model based on data packets historically collected and processed by the router; A target execution action determination module, used to determine the target execution action corresponding to the matching result; The network data packet processing module is used to process the target network data packet according to the target execution action.
9. An electronic device, characterized in that: The method comprises a processor, a memory and a computer program stored in the memory and capable of running on the processor, wherein when the computer program is executed by the processor, the method for data transmission of the VPN tunnel service as claimed in any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the data transmission method for the VPN tunnel service according to any one of claims 1 to 7 is implemented.