SD-WAN data encryption transmission method, device and equipment

By deploying SDWAN-CPE devices in the data center, user side and cloud service side, encrypting with SM4 and SM2 algorithms, and monitoring the link quality adjustment path, the problem of insufficient data transmission flexibility and security in traditional WAN is solved, and economical, secure and flexible data transmission is achieved.

CN120498645APending Publication Date: 2025-08-15INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510544919.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

Data transmission in traditional WANs is poor in flexibility and security, with high costs, inflexible bandwidth expansion, high management complexity, and insufficient data security and privacy protection.

Method used

SDWAN-CPE devices are deployed in the data center, user side and cloud service side, access the Internet through fixed public network IP, establish tunnel connections, and end-to-end encryption is performed using SM4 symmetric key algorithm and SM2 public key algorithm, monitoring link quality indicators and adjusting the optimal path, and separating the control surface and user surface for management.

Benefits of technology

It realizes economical, secure and flexible data transmission paths, reduces network connection costs, improves bandwidth utilization and business continuity, enhances security and privacy protection, and simplifies operation and maintenance management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498645A_ABST
    Figure CN120498645A_ABST
Patent Text Reader

Abstract

The invention provides an SD-WAN data encryption transmission method, device and equipment, and belongs to the technical field of data transmission. SDWAN-CPE equipment is deployed in a data center to serve as main and standby nodes, the data center is accessed to the Internet through a fixed public network IP, and a tunnel is established to be connected to a user side Client, a management all-in-one machine and a cloud service side SDWAN-CPE; an SDWAN-Client is deployed in the application all-in-one machine, and a tunnel access scheduling all-in-one machine is established based on a mobile network or an internet line and an SDWAN-CPE at a data center side; sDWAN-CPE equipment is deployed at a cloud service side, the Internet is accessed through a fixed public network IP, a tunnel is established to connect a user side Client, communication with a management and management all-in-one machine side is carried out through the tunnel, an MPLS special line is replaced by an Internet bandwidth and a mobile network, and tunnels are established at a data center, the user side and the cloud service side, so that the network flexibility is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data transmission technology, and in particular to an SD-WAN data encryption transmission method, device, and equipment. Background Art

[0002] A wide area network (WAN), also known as an extranet or public network, is a long-distance network that connects computers in local or metropolitan area networks (LANs) across different regions. It typically spans a large physical area, ranging from tens to thousands of kilometers. It can connect multiple regions, cities, and countries, or even span multiple continents and provide long-distance communications, forming an international long-distance network. However, traditional WANs typically rely on MPLS (Multi-Protocol Label Switching) lines to provide high-quality quality of service (QoS) and ensure the performance of critical business applications. This can be problematic due to high costs, inflexible bandwidth expansion, complex management, and insufficient data security and privacy protection.

[0003] Therefore, how to ensure the flexibility of data transmission between the data center and the all-in-one machine has become a technical problem that needs to be solved urgently by those skilled in the art. Summary of the Invention

[0004] The present invention provides an SD-WAN data encryption transmission method, device and equipment to solve the defects of poor flexibility and security of data transmission between a data center and an all-in-one machine in the prior art.

[0005] In a first aspect, the present invention provides an SD-WAN data encryption transmission method, comprising:

[0006] Deploy SDWAN-CPE devices in the data center as active and standby nodes, access the Internet through fixed public IP addresses, and establish tunnels to the user-side client, integrated management appliance, and cloud service-side SDWAN-CPE.

[0007] Deploy SDWAN-Client in the application all-in-one machine, and establish a tunnel access to the scheduling all-in-one machine with the SDWAN-CPE on the data center side based on the mobile network or Internet line;

[0008] The SDWAN-CPE device is deployed on the cloud service side, accesses the Internet through a fixed public IP, establishes a tunnel to connect to the user-side Client, and communicates with the integrated management machine side through the tunnel.

[0009] According to an SD-WAN data encryption transmission method provided by the present invention, the SDWAN-CPE device is used to:

[0010] Establish network connection between the LAN side and the data center or cloud service side through the static routing protocol, and interconnect with the scheduling all-in-one machine;

[0011] After the interconnection is completed, the quality indicators of all available links between the data center, the user side and the cloud service side are monitored, and the optimal path is adjusted based on the quality indicators.

[0012] According to an SD-WAN data encryption transmission method provided by the present invention, monitoring the quality indicators of all available links between the data center, the user side, and the cloud service side includes:

[0013] Determine the delay, jitter, and packet loss rate of all available links between the data center, the user side, and the cloud service side;

[0014] The delay, jitter and packet loss rate are input into a quality indicator determination model, the quality indicator is determined by weighted summation, and the path with the best quality indicator is used as the optimal path.

[0015] According to an SD-WAN data encryption transmission method provided by the present invention, after determining the quality index by weighted summation, the method further includes:

[0016] When there are multiple available links, determining a quality indicator of each of the available links;

[0017] Based on the quality indicator, a corresponding traffic ratio is allocated to each of the available links.

[0018] According to the present invention, a SD-WAN data encryption transmission method further includes:

[0019] When data is transmitted between the data center, the user side and the cloud service side, all transmitted data is end-to-end encrypted using the SM4 symmetric key algorithm;

[0020] During the end-to-end encrypted key exchange process, the one-time key is asymmetrically encrypted using the SM2 public key algorithm.

[0021] According to an SD-WAN data encryption transmission method provided by the present invention, the SM4 symmetric key algorithm is used to perform end-to-end encryption on all transmitted data, further comprising:

[0022] Perform key expansion from the initial multi-bit master key to generate a series of round keys;

[0023] Divide the plaintext into a multi-bit database, and perform an XOR operation with the first round key in the round key to achieve an initial round transformation;

[0024] After completing the initial round transformation, perform a preset number of iterative round transformations, each of which includes SubBytes, ShiftRows, MixColumns, and AddRoundKey;

[0025] After completing the iterative round transformation, a final round transformation is performed, wherein the final round transformation includes SubBytes, ShiftRows and AddRoundKey.

[0026] According to the present invention, a SD-WAN data encryption transmission method further includes:

[0027] Separating the control plane and the user plane;

[0028] A centralized SD-WAN controller controls the separated control plane and selects transmission paths based on predefined service policies and real-time monitored network status information.

[0029] The encrypted data packets are forwarded through the separated user plane.

[0030] According to the present invention, a SD-WAN data encryption transmission method further includes:

[0031] Use the SM3 hash function to map messages of any length into a hash value of a preset number of bits;

[0032] The message digest is calculated using the hash value and used for digital signature.

[0033] In a second aspect, the present invention further provides an SD-WAN data encryption transmission device, comprising:

[0034] On the data center side, it is used to deploy SDWAN-CPE devices in the data center as active and standby nodes, access the Internet through fixed public IP addresses, and establish tunnels to user-side clients, integrated management appliances, and SDWAN-CPE on the cloud service side.

[0035] On the user side, it is used to deploy the SDWAN-Client in the application all-in-one machine, and establish a tunnel access to the scheduling all-in-one machine with the SDWAN-CPE on the data center side based on the mobile network or Internet line;

[0036] The cloud service side is used to deploy the SDWAN-CPE device on the cloud service side, access the Internet through a fixed public IP, establish a tunnel to connect the user side Client, and communicate with the integrated machine side through the tunnel.

[0037] In a third aspect, the present invention also provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the SD-WAN data encryption transmission method as described above is implemented.

[0038] In a fourth aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements any of the SD-WAN data encryption transmission methods described above.

[0039] In a fifth aspect, the present invention also provides a computer program product, comprising a computer program, which, when executed by a processor, implements any of the above-described SD-WAN data encryption transmission methods.

[0040] The present invention provides an SD-WAN data encryption transmission method, device and equipment. The method deploys SDWAN-CPE equipment in a data center as a primary and backup node, accesses the Internet through a fixed public IP, and establishes a tunnel to connect to the user-side Client, the integrated management machine and the cloud service side SDWAN-CPE; deploys SDWAN-Client in the application integrated machine, and establishes a tunnel access scheduling integrated machine with the SDWAN-CPE on the data center side based on a mobile network or Internet line; deploys SDWAN-CPE equipment on the cloud service side, accesses the Internet through a fixed public IP, establishes a tunnel to connect to the user-side Client, and communicates with the integrated management machine side through the tunnel, uses Internet bandwidth and mobile network to replace MPLS dedicated lines, establishes tunnels between the data center, the user side and the cloud service side, realizes a stable data transmission path, and effectively improves network flexibility. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0042] Figure 1 This is a flowchart of the SD-WAN data encryption transmission method provided in this embodiment;

[0043] Figure 2 This is a network topology diagram of the SD-WAN data encryption transmission method provided by this implementation;

[0044] Figure 3 This is a schematic diagram of the structure of the SD-WAN data encryption transmission device provided in this embodiment;

[0045] Figure 4 Schematic diagram of the structure of the electronic device provided in this embodiment. DETAILED DESCRIPTION

[0046] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0047] Figure 1 This is a flow chart of the SD-WAN data encryption transmission method provided in this embodiment. Figure 2 This is a network topology diagram of the SD-WAN data encryption transmission method provided by this implementation.

[0048] like Figure 1 As shown in Figure 2, the SD-WAN data encryption transmission method provided in this embodiment is mainly applied in data centers and all-in-one machines. The all-in-one machines include a scheduling all-in-one machine and an application all-in-one machine. The method mainly includes the following steps:

[0049] 101. Deploy SDWAN-CPE devices in the data center as active and standby nodes, access the Internet through fixed public IP addresses, and establish tunnels to connect to the user-side client, the integrated management machine, and the cloud service-side SDWAN-CPE.

[0050] In a specific implementation, SDWAN-CPE (Software-Defined WAN Customer Edge) refers to a hardware device deployed at an enterprise branch office or remote location to connect the enterprise's internal network with the external WAN. It integrates multiple network functions, such as routing, switching, and firewalling, and is flexibly configured and managed through a software-defined approach. Compared to traditional hardware routers, SDWAN-CPE offers greater flexibility and scalability, better adapting to the changing needs of enterprise networks.

[0051] Therefore, physical or virtualized SDWAN-CPE devices are deployed in the data center as primary and backup nodes to improve system redundancy and stability. These devices connect to the Internet via fixed public IP addresses and establish tunnels to user-side clients, integrated management appliances, and cloud-side SDWAN-CPE, providing a stable data transmission path.

[0052] 102. Deploy SDWAN-Client in the application all-in-one machine, and establish a tunnel access scheduling all-in-one machine based on the mobile network or Internet line and the SDWAN-CPE on the data center side.

[0053] At the same time, SDWAN-Client is deployed in the application all-in-one machine, relying on 4G / 5G mobile network or Internet line to establish a tunnel access scheduling all-in-one machine with SDWAN-CPE on the data center side to ensure secure access to data.

[0054] 103. Deploy SDWAN-CPE equipment on the cloud service side, access the Internet through a fixed public IP, establish a tunnel to connect to the user-side client, and communicate with the integrated management machine side through the tunnel.

[0055] The cloud service side also deploys SDWAN-CPE devices, accesses the Internet through a fixed public IP, establishes a tunnel to connect to the user-side client, and communicates with the integrated management machine through the tunnel to ensure the security and reliability of cross-regional data transmission.

[0056] like Figure 2 As shown, SDWAN-CPE devices are deployed in the data center, user side and cloud service side respectively. Based on the principle of network topology construction, connections are established through the allocation of IP addresses and tunnel protocols, such as the General Routing Encapsulation Protocol (GRE). The principle is to encapsulate the original IP data packet P original Add a new GRE header H based on GRE , forming a new data packet P new , which can be expressed as: P new =H GRE +P original , in order to achieve communication connections between different network nodes.

[0057] By combining SD-WAN features with advanced encryption standards solutions, SDWAN-CPE devices are deployed physically or virtualized to establish tunnels between the data center, user side, and cloud service side to achieve stable data transmission paths, providing users with economical and secure data transmission channels. This ensures efficient and reliable data exchange, especially in data transmission scenarios between data centers and all-in-one devices.

[0058] Furthermore, based on the above embodiments, the SDWAN-CPE device in this embodiment is used to: establish network connection between the LAN side and the data center or cloud service side through a static routing protocol, and interconnect with the scheduling all-in-one machine; after completing the interconnection, monitor the quality indicators of all available links between the data center, user side and cloud service side, and adjust the optimal path based on the quality indicators.

[0059] Specifically, considering the possible instability of the public Internet, this embodiment adopts a strategy of multiple physical links working simultaneously. The SD-WAN controller continuously monitors the quality metrics of all available links and automatically adjusts the optimal path based on these parameters. In the link quality assessment, the comprehensive link quality metric Q can be used for measurement. Q can be comprehensively calculated from factors such as latency D, jitter J, and packet loss rate L. For example, in a weighted summation manner, as shown in (1):

[0060] Q = α×D + β×J + γ×L (1)

[0061] Where α, β, and γ are weight coefficients, which are set according to the sensitivity of the service to different metrics, with a value range between 0 and 1, and α + β + γ = 1.

[0062] When there are multiple available links, the traffic ratio can be allocated according to the Q values of each link. Suppose there are n links in total, and the Q value of the i-th link is Q i , then the traffic ratio allocated to the i-th link is as shown in (2):

[0063]

[0064] By determining the quality metrics of each available link, the corresponding traffic ratio can be allocated to each available link based on the quality metrics, achieving fast failover and load balancing, and improving service continuity and overall performance.

[0065] In the process of path selection, the Dijkstra algorithm can be introduced to calculate the optimal path. The network can be represented as a weighted directed graph G = (V, E), where V is the set of nodes, E is the set of edges, and each edge (u, v) ∈ E has a weight w(u, v) representing the cost of the link (such as latency, bandwidth cost, etc.). Let the source node be s and the target node be t. The Dijkstra algorithm maintains a distance array d. Initially, d[s] = 0, and for other nodes v ∈ V - {s}, d[v] = ∞. During the execution of the algorithm, the d array is continuously updated. The node u that is closest to the source node and has not been visited is selected. For the node v adjacent to u, if d[u] + w(u, v) < d[v], then update d[v] = d[u] + w(u, v). Finally, d[t] is the shortest path cost from the source node s to the target node t, and the specific optimal path can be obtained through backtracking.

[0066] Furthermore, based on the above embodiment, this embodiment also includes: when data is transmitted between the data center, the user side, and the cloud service side, the SM4 symmetric key algorithm is used to perform end-to-end encryption on all transmitted data; during the key exchange process of end-to-end encryption, the SM2 public key algorithm is used to perform asymmetric encryption protection on the one-time key.

[0067] Specifically, the transmitting device uses the SM4 symmetric key algorithm to encrypt the transmitted data end-to-end, and the one-time key is asymmetrically encrypted using the SM2 public key algorithm to ensure the security of key exchange. Key expansion is performed from the initial multi-bit (128-bit) master key to generate a series of round keys. The plaintext is divided into multi-bit (128-bit) databases and XORed with the first round key in the round key to achieve the initial round transformation. After the initial round transformation is completed, a preset number of (32) iterative round transformations are performed. Each iterative round transformation includes SubBytes, ShiftRows, MixColumns, and AddRoundKey. After the iterative round transformation is completed, the final round transformation is performed. The final round transformation includes SubBytes, ShiftRows, and AddRoundKey.

[0068] Among them, the SM4 algorithm is a block cipher algorithm with a block length of 128 bits and a key length of 128 bits. In the encryption process, let the input plaintext be M, the initial key be K, and a series of round functions F be calculated, for a total of 32 rounds. The input of each round is the output of the previous round, and let the input of the i-th round be X i-1 , the output is X i , then X i =F(X i-1 ,K i ), where K i is the subkey of round i, which is generated by the initial key K through the key expansion algorithm. The final ciphertext C = X 32 .

[0069] In the key exchange process, the SM2 public key algorithm is used, and the private key of the sender A is d A , the public key is P A , the public key of the receiver B is P B Sender A generates a one-time key K session , using the public key P of the receiver B B K session Encrypt and get ciphertext The encryption formula is Receiver B uses his own private key d B Decrypt and get the original one-time key This ensures the security of key exchange.

[0070] Furthermore, based on the above embodiment, this embodiment also includes: separating the control plane and the user plane; using a centralized SD-WAN controller to control the separated control plane, and selecting a transmission path based on predefined business policies and real-time monitored network status information; and forwarding encrypted data packets through the separated user plane.

[0071] Specifically, in traditional WAN architectures, the control plane and user plane are tightly integrated, limiting network flexibility and increasing management complexity. In an SD-WAN environment, however, the two are clearly separated. The control plane, managed by a centralized SD-WAN controller, selects the optimal path; the user plane, which refers to the CPE (Customer Premises Equipment) at each branch node, focuses on efficiently forwarding encrypted data packets. This separation improves system responsiveness and service quality, simplifies operations for operations and maintenance personnel, and enables unified management and monitoring through a centralized platform, enhancing efficiency and accuracy.

[0072] Furthermore, based on the above embodiment, this embodiment also includes: using the SM3 hash function to map a message of any length into a hash value of a preset number of bits; and calculating a message digest through the hash value for digital signature.

[0073] Specifically, in order to ensure the implementation of security policies, a multi-level security protection mechanism such as authentication, ACL, DPI, IPS, logging and auditing can be set up, and the SM3 hash function can be used to enhance security. The SM3 hash function maps a message M of any length to a 256-bit hash value H. Its calculation process involves multiple steps, including padding, grouping, iterative compression, etc. Assume that after padding and grouping, the message M is obtained as a series of message blocks M. i , the initial value is IV, after a series of compression function CF operations, the final hash value H is obtained, which can be expressed as:

[0074] H=CF(CF(...CF(IV,M1),M2),...,M n ) (3)

[0075] The hash value calculated by the SM3 hash function can be used for data integrity verification and digital signature, etc.

[0076] The SD-WAN data encryption transmission method of the present invention has the following advantages:

[0077] 1) Cost-effectiveness and bandwidth optimization

[0078] SD-WAN allows enterprises to replace or supplement traditional MPLS dedicated lines with more affordable Internet broadband, 4G / 5G mobile networks and other types of connections, thereby significantly reducing the cost of network connections. By dynamically adjusting traffic paths and integrating multiple access technologies, SD-WAN can automatically allocate bandwidth resources according to actual needs, avoiding reserving too much unused capacity for future growth and reducing unnecessary capital expenditures. SD-WAN can monitor the quality indicators of each link (such as latency, jitter, and packet loss rate) in real time and make optimal path decisions based on this data to ensure that critical applications always receive the best performance. Supporting multiple links working simultaneously not only improves the effective utilization of the total bandwidth, but also allows for rapid switching to the backup link when the main link fails, ensuring business continuity.

[0079] 2) Enhanced security and privacy protection

[0080] SD-WAN can implement unified encryption standards for all transmitted data, ensuring high security even at the network edge. It provides more refined authentication mechanisms and access control lists (ACLs), down to the application level, effectively preventing internal threats and external attacks. Many SD-WAN solutions integrate firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), and other functions to form a comprehensive network security platform. They support seamless integration with other security devices and services, such as cloud security service providers, enhancing overall protection capabilities.

[0081] 3) Flexibility and agility

[0082] New devices can be automatically added to the network through pre-configuration, eliminating the need for complex installation and debugging by on-site technicians, significantly reducing deployment time. Centralized monitoring and management of the entire network, either through a cloud-based or local controller, simplifies routine O&M tasks and reduces the potential for human error. SD-WAN provides enterprises with efficient connectivity from branch offices to private clouds, public clouds, and SaaS applications, ensuring the reliability and responsiveness of cloud services. For managed service providers, SD-WAN offers robust multi-tenancy features, enabling independent and secure virtual network environments for different customers.

[0083] 4) Improve business continuity and reliability

[0084] When a link failure is detected, SD-WAN can immediately activate a backup link to continue data transmission, minimizing the risk of service interruption. By building redundant paths and nodes, SD-WAN improves the system's fault tolerance and stability, ensuring that even component failures will not affect the overall network's normal operation. QoS policies are set based on the importance and real-time requirements of applications, prioritizing the application experience of critical services. Continuously collecting and analyzing network traffic information helps enterprises better understand their network behavior patterns and make optimization adjustments accordingly.

[0085] 5) Promote digital transformation and support emerging application scenarios

[0086] It provides powerful edge computing capabilities, supporting application scenarios such as remote work and video conferencing. Automated tools and an intuitive interface make it easier for IT teams to manage and maintain networks, indirectly enhancing enterprise competitiveness and development potential.

[0087] Based on the same general inventive concept, the present invention also protects an SD-WAN data encryption transmission device. The SD-WAN data encryption transmission device described below and the SD-WAN data encryption transmission method described above can refer to each other.

[0088] Figure 3 This is a structural diagram of the SD-WAN data encryption transmission device provided in this embodiment.

[0089] like Figure 3 As shown, this embodiment provides an SD-WAN data encryption transmission device, including:

[0090] The data center side 301 is used to deploy SDWAN-CPE devices in the data center as active and standby nodes, access the Internet through fixed public IP addresses, and establish tunnels to the user-side clients, integrated management appliances, and SDWAN-CPE devices on the cloud service side.

[0091] The user side 302 is used to deploy the SDWAN-Client in the application integrated machine and establish a tunnel with the SDWAN-CPE on the data center side to access the scheduling integrated machine based on the mobile network or Internet line;

[0092] Cloud service, 303, is used to deploy SDWAN-CPE devices on the cloud service side, access the Internet through a fixed public IP, establish a tunnel to connect to the user-side client, and communicate with the integrated management device side through the tunnel.

[0093] Figure 4 Schematic diagram of the structure of the electronic device provided in this embodiment.

[0094] like Figure 4As shown, the electronic device may include: a processor 410, a communications interface 420, a memory 430, and a communication bus 440, wherein the processor 410, the communications interface 420, and the memory 430 communicate with each other through the communication bus 440. The processor 410 can call the logic instructions in the memory 430 to execute the SD-WAN data encryption transmission method, which includes: deploying an SDWAN-CPE device as a master node in the data center, accessing the Internet through a fixed public network IP, and establishing a tunnel connection to the user-side client and the integrated management machine and the cloud service side SDWAN-CPE; deploying the SDWAN-Client in the application integrated machine, establishing a tunnel access to the scheduling integrated machine with the SDWAN-CPE on the data center side based on a mobile network or Internet line; deploying the SDWAN-CPE device on the cloud service side, accessing the Internet through a fixed public network IP, establishing a tunnel connection to the user-side client, and communicating with the integrated management machine side through the tunnel.

[0095] In addition, the logic instructions in the above-mentioned memory 430 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when sold or used as an independent product. Based on this understanding, the technical solution of the present invention is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0096] On the other hand, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the SD-WAN data encryption transmission method provided by the above methods, which includes: deploying SDWAN-CPE equipment as a master and slave node in a data center, accessing the Internet through a fixed public network IP, and establishing a tunnel to connect to the user-side Client and the integrated management machine and the cloud service side SDWAN-CPE; deploying SDWAN-Client in the application integrated machine, establishing a tunnel access scheduling integrated machine with the SDWAN-CPE on the data center side based on a mobile network or Internet line; deploying the SDWAN-CPE equipment on the cloud service side, accessing the Internet through a fixed public network IP, establishing a tunnel to connect to the user-side Client, and communicating with the integrated management machine side through the tunnel.

[0097] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the SD-WAN data encryption transmission method provided by the above-mentioned methods, the method comprising: deploying an SDWAN-CPE device in a data center as a master / slave node, accessing the Internet through a fixed public network IP, and establishing a tunnel connection to the user-side Client and the integrated management machine and the SDWAN-CPE on the cloud service side; deploying the SDWAN-Client in the application integrated machine, establishing a tunnel access scheduling integrated machine with the SDWAN-CPE on the data center side based on a mobile network or Internet line; deploying the SDWAN-CPE device on the cloud service side, accessing the Internet through a fixed public network IP, establishing a tunnel connection to the user-side Client, and communicating with the integrated management machine side through the tunnel.

[0098] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, i.e., they may be located in one location or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0099] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, or of course, by hardware. Based on this understanding, the essence of the above technical solution or the part that contributes to the existing technology can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or certain parts of the embodiments.

[0100] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A SD-WAN data encryption transmission method, characterized in that: include: Deploy SDWAN-CPE devices in the data center as active and standby nodes, access the Internet through fixed public IP addresses, and establish tunnels to the user-side client, integrated management appliance, and cloud service-side SDWAN-CPE. Deploy SDWAN-Client in the application all-in-one machine, and establish a tunnel access to the scheduling all-in-one machine with the SDWAN-CPE on the data center side based on the mobile network or Internet line; The SDWAN-CPE device is deployed on the cloud service side, accesses the Internet through a fixed public IP, establishes a tunnel to connect to the user-side Client, and communicates with the integrated management machine side through the tunnel.

2. The SD-WAN data encryption transmission method according to claim 1, characterized in that: The SDWAN-CPE device is used to: Establish network connection between the LAN side and the data center or cloud service side through the static routing protocol, and interconnect with the scheduling all-in-one machine; After the interconnection is completed, the quality indicators of all available links between the data center, the user side and the cloud service side are monitored, and the optimal path is adjusted based on the quality indicators.

3. The SD-WAN data encryption transmission method according to claim 2, characterized in that: The monitoring of quality indicators of all available links between the data center, the user side, and the cloud service side includes: Determine the delay, jitter, and packet loss rate of all available links between the data center, the user side, and the cloud service side; The delay, jitter and packet loss rate are input into a quality indicator determination model, the quality indicator is determined by weighted summation, and the path with the best quality indicator is used as the optimal path.

4. The SD-WAN data encryption transmission method according to claim 3, characterized in that: After determining the quality index by weighted summation, the method further includes: When there are multiple available links, determining a quality indicator of each of the available links; Based on the quality indicator, a corresponding traffic ratio is allocated to each of the available links.

5. The SD-WAN data encryption transmission method according to claim 1, characterized in that: Also includes: When data is transmitted between the data center, the user side and the cloud service side, all transmitted data is end-to-end encrypted using the SM4 symmetric key algorithm; During the end-to-end encrypted key exchange process, the one-time key is asymmetrically encrypted using the SM2 public key algorithm.

6. The SD-WAN data encryption transmission method according to claim 5, characterized in that: The end-to-end encryption of all transmitted data using the SM4 symmetric key algorithm also includes: Perform key expansion from the initial multi-bit master key to generate a series of round keys; Divide the plaintext into a multi-bit database, and perform an XOR operation with the first round key in the round key to achieve an initial round transformation; After completing the initial round transformation, perform a preset number of iterative round transformations, each of which includes SubBytes, ShiftRows, MixColumns, and AddRoundKey; After completing the iterative round transformation, a final round transformation is performed, wherein the final round transformation includes SubBytes, ShiftRows and AddRoundKey.

7. The SD-WAN data encryption transmission method according to any one of claims 1 to 6, characterized in that: Also includes: Separate the control plane and user plane; A centralized SD-WAN controller controls the separated control plane and selects transmission paths based on predefined service policies and real-time monitored network status information. The encrypted data packets are forwarded through the separated user plane.

8. The SD-WAN data encryption transmission method according to any one of claims 1 to 6, characterized in that: Also includes: Use the SM3 hash function to map messages of any length into a hash value of a preset number of bits; The message digest is calculated using the hash value and used for digital signature.

9. An SD-WAN data encryption transmission device, characterized in that: include: On the data center side, it is used to deploy SDWAN-CPE devices in the data center as active and standby nodes, access the Internet through fixed public IP addresses, and establish tunnels to user-side clients, integrated management appliances, and SDWAN-CPE on the cloud service side. On the user side, it is used to deploy the SDWAN-Client in the application all-in-one machine, and establish a tunnel access to the scheduling all-in-one machine with the SDWAN-CPE on the data center side based on the mobile network or Internet line; The cloud service side is used to deploy the SDWAN-CPE device on the cloud service side, access the Internet through a fixed public IP, establish a tunnel to connect the user side Client, and communicate with the integrated machine side through the tunnel.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the SD-WAN data encryption transmission method as described in any one of claims 1 to 8 is implemented.