Working method of multiple SDP controllers based on cluster

Through the clustered multi-SDP controller architecture and load balancing algorithm, the problems of high concurrency and single-point failure of the SDP system are solved, and efficient resource utilization and system robustness are achieved.

CN120512435APending Publication Date: 2025-08-19西交网络空间安全研究院 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510560434.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-08-19

AI Technical Summary

Technical Problem

When existing SDP systems face a large number of sudden authentication requests, their performance will deteriorate, their system will be paralyzed, and there are problems with the coordination working mode after deploying multiple SDP controllers.

Method used

Adopting a cluster-based multi-SDP controller architecture, the requests are allocated to multiple independent SDP controllers through the load balancing server. Load balancing algorithms such as polling, weighted polling, and minimum connection algorithm are used to achieve uniform distribution of resources and fault tolerance, and dynamic access policies are configured to improve system resilience.

Benefits of technology

It solves the problems of high concurrency and single point failure, optimizes resource utilization, improves system performance and reliability, avoids resource waste, and enhances system robustness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120512435A_ABST
    Figure CN120512435A_ABST
Patent Text Reader

Abstract

A working method of multiple SDP controllers based on a cluster comprises the steps that the cluster is composed of the multiple SDP controllers, and at least one load balancing server is arranged for the cluster; the load balancing server receives the SPA data packet of one SDP client and forwards the SPA data packet to one SDP controller in the cluster, and the SDP controller receiving the SPA data packet performs authentication information verification; and if the verification is passed, the SDP controller determines a list of SDP gateways which can be connected with the SDP client, and notifies the SDP gateways in the list to accept communication from the SDP client. And the SDP controller sends the SDP gateway list to the load balancer, and the load balancer sends the SDP gateway list to the SDP client. And the SDP client sends the SPA data packet to the SDP gateway. And if the verification is not passed, the SDP controller discards the SPA data packet sent by the SDP client. According to the invention, a plurality of SDP controllers can be promoted to work coordinately, load balancing is promoted, comprehensive system toughness is improved, and the risk of single point failure (SPoF) is relieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security, and in particular relates to a working method of a cluster-based multi-SDP controller. Background Art

[0002] Software Defined Perimeter (SDP) is a network security technology architecture based on the concept of zero trust. It creates a logical, dynamic security boundary based on policies to isolate services from insecure networks. Before access is authorized, users and devices are authenticated to ensure they can securely connect to isolated services. Unauthorized users and devices cannot connect to protected resources. The core concept of SDP is to hide core network assets and facilities through the SDP architecture, preventing them from being directly exposed to the internet and protecting them from external security threats.

[0003] SDP consists of three major components: the SDP client, the SDP gateway, and the SDP controller. The SDP controller is the brain of SDP, primarily responsible for host authentication and policy delivery. It can also be used to authenticate and authorize SDP clients and configure connections to the SDP gateway.

[0004] However, when an SDP controller faces a sudden and large number of authentication requests, the SDP system may experience performance degradation and even system failure. To address this issue, multiple SDP controllers are often deployed in applications to monitor and process SPA packets. However, deploying multiple SDP controllers presents the challenge of coordinating their operations. Summary of the Invention

[0005] In order to overcome the shortcomings of the above-mentioned prior art, the purpose of the present invention is to provide a cluster-based multi-SDP controller working method, so as to enable multiple SDP controllers to coordinate work, promote load balancing, enhance the overall system resilience, and mitigate the risk of single point of failure (SPoF).

[0006] In order to achieve the above object, the technical solution adopted by the present invention is:

[0007] A cluster-based multi-SDP controller operation method includes a cluster consisting of multiple SDP controllers, wherein each SDP controller in the cluster is independent of each other and can communicate with each other through a network, and each SDP controller runs its own service; at least one load balancing server is set for the cluster;

[0008] The load balancing server receives a SPA data packet from an SDP client, and forwards the SPA data packet to an SDP controller in the cluster, and the SDP controller that receives the SPA data packet verifies the authentication information;

[0009] If the verification is successful, the SDP controller determines the list of SDP gateways that the SDP client can connect to, and notifies the SDP gateways in the list to accept communications from the SDP client; the SDP controller sends the SDP gateway list to the load balancer, and the load balancer sends the SDP gateway list to the SDP client. The SDP client sends an SPA data packet to the SDP gateway, and the SDP gateway verifies the SPA data packet. After the verification is successful, the SDP gateway establishes a two-way encrypted connection with the SDP client, otherwise the SDP gateway discards the SPA data packet sent by the SDP client;

[0010] If the verification fails, the SDP controller discards the SPA data packet sent by the SDP client.

[0011] In one embodiment, the load balancer is a software device or a hardware device. When it is a software device, it is installed on the application running on the SDP controller to achieve load balancing; when it is a hardware device, it is an independent hardware running load balancing software.

[0012] In one embodiment, the load balancer is responsible for accepting access requests from SDP clients and forwarding the access requests to an SDP controller in the cluster according to a load balancing algorithm.

[0013] In one embodiment, the load balancing algorithm selects an SDP controller to forward the SPA data packet according to a predefined policy, and the predefined policy is a round-robin algorithm or a weighted round-robin algorithm.

[0014] In one embodiment, the SDP controller that receives the SPA data packet performs authentication information verification, and the implementation method is as follows:

[0015] Use the pre-configured key to decrypt the SPA data packet and verify the decrypted information.

[0016] In one embodiment, the SDP controller determines a list of SDP gateways to which the SDP client can connect, as follows:

[0017] The SDP controller groups users and resources according to the configuration and configures different policies for different user groups. That is, the SDP controller determines the resources that users can access based on their roles or user groups. At the same time, it adjusts the user's resource access rights in real time based on the analysis results given by the risk assessment, dynamically generates a minimum permission access control policy, and sends it to the SDP client and SDP gateway.

[0018] In one embodiment, the SDP controller notifies the SDP gateways in the gateway list to accept communications from the SDP client.

[0019] In one embodiment, if an SDP controller in a cluster fails, all tasks of the failed SDP controller are distributed to other healthy SDP controllers in the cluster. This is achieved as follows:

[0020] The load balancer regularly checks the health status of each SDP controller in the cluster and adjusts traffic distribution based on the health check results to prevent requests from being forwarded to faulty nodes. That is, when an SDP controller fails, the load balancer forwards requests to other SDP controllers that are working normally.

[0021] In one embodiment, if the verification fails, the SDP controller and the SDP gateway discard the SPA data packet sent by the SDP client.

[0022] In one embodiment, a timeout retransmission mechanism is set for the SDP client; a timer and a time threshold are set on the SDP client, and the SDP system uses single-packet authorization and authentication SPA technology. After the SDP client sends an SPA data packet, its timer is started. When the timer value is equal to the time threshold, and the SDP client does not receive a response data packet sent by the load balancer or SDP gateway, the SDP client resends the SPA data packet to the load balancer or SDP gateway until it is sent successfully.

[0023] Compared with the prior art, the present invention has the following beneficial effects:

[0024] Currently, multiple SDP controllers primarily operate in active-standby mode. In this mode, the standby controller serves as a backup, and remaining in standby mode wastes resources. Furthermore, this mode doesn't address high concurrency. The cluster-based multi-SDP controller operation method proposed in this invention uses a load balancer to distribute SDP client requests to multiple SDP controllers with the same functionality within the cluster. This approach addresses high concurrency and single-point-of-failure issues, while also fully utilizing resources and avoiding waste. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 It is a schematic diagram of the principle of the present invention.

[0026] Figure 2 It is a schematic flow chart of the present invention. DETAILED DESCRIPTION

[0027] The embodiments of the present invention are described in detail below with reference to the accompanying drawings and examples.

[0028] like Figure 1 As shown, the present invention provides a cluster-based multi-SDP controller working method, including n SDP controllers, n>1, and the n SDP controllers are independent of each other and constitute a cluster. Each SDP controller in the cluster runs its own service and can communicate with each other over the network to collaboratively provide services to the SDP client.

[0029] The present invention sets at least one load balancing server for the cluster, referring to Figure 2 As shown, the load balancing server is used to forward the access request of the SDP client to the SDP controller. The SDP client sends the access request (i.e., SPA packet) to the load balancer. The load balancing server forwards the received SPA packet to an SDP controller in the cluster. The SDP controller verifies the authentication information of the SPA packet.

[0030] If verification succeeds, the SDP controller determines a list of SDP gateways to which the SDP client can connect and notifies the listed SDP gateways to accept communications from the SDP client. The SDP controller sends this list of SDP gateways to the load balancer. The load balancer sends this list of SDP gateways to the SDP client. The SDP client then sends an SPA packet to the SDP gateway in the list, which then verifies the SPA packet. If verification succeeds, the SDP gateway establishes a two-way encrypted connection with the SDP client. Otherwise, the SDP gateway discards the SPA packet sent by the SDP client.

[0031] If the verification fails, the SDP controller directly discards the SPA data packet sent by the SDP client.

[0032] In this invention, the load balancer is responsible for accepting access requests from SDP clients and forwarding them (i.e., SPA packets) to an SDP controller in the cluster based on a load balancing algorithm. This load balancing algorithm selects an available SDP controller based on a predefined strategy (e.g., round-robin, weighted round-robin, minimum connections, etc.), forwards the SPA packet to the selected SDP controller, and the SDP controller processes the request and returns a response to the load balancer, which then returns the response to the SDP client.

[0033] In the present invention, the predefined strategies can be selected based on demand. For example, when the performance and processing capabilities of all SDP controllers are substantially the same, or for simple applications that do not need to consider the current load or performance differences of the servers, or do not need to maintain session state, a polling strategy can be used to evenly distribute requests and avoid overload.

[0034] The weighted round-robin algorithm assigns a weight to each SDP controller based on its performance differences. This weight reflects the controller's processing power. When a new request arrives, the algorithm determines which SDP controller to assign the request to based on its weight. The higher the weight, the greater the probability of selection for request allocation. In other words, the higher the weight, the more requests it receives. When SDP controllers vary significantly in performance and processing power, weighted round-robin can be used to rationally allocate requests. By adjusting weights, resource utilization and system performance can be improved.

[0035] The minimum number of connections algorithm is a dynamically adjusted load balancing algorithm that balances load based on the current connection status of SDP controllers. When a request arrives, the SDP controller with the fewest connections is selected to handle it. Implementation typically requires periodic monitoring of the number of connections per SDP controller and dynamic adjustment. This algorithm dynamically distributes requests based on the current connection load of each SDP controller and is suitable for most load balancing scenarios.

[0036] The load balancer of the present invention can be a software device or a hardware device. A software load balancer, such as Nginx load balancing, implements load balancing by installing additional software on the SDP controller's application. Advantages of software load balancing include being environment-specific, simple to configure, flexible, and cost-effective. However, since the software runs on the SDP controller's application, it consumes a certain amount of system resources. Furthermore, the software's scalability and security may be affected by the SDP controller's application limitations and inherent bugs.

[0037] Hardware load balancers are standalone hardware running load balancing software. These devices are independent of the SDP controller and offer higher overall performance and a variety of load balancing strategies. The advantages of hardware load balancers include high performance, scalability, and high security.

[0038] Through load balancing, the present invention can distribute the centralized access requests of multiple SDP clients as evenly as possible across multiple SDP controllers in the cluster. This optimizes resource utilization and improves performance. Furthermore, load balancing prevents the SDP controller from becoming a single point of failure, thereby enhancing the robustness of the overall system.

[0039] In an embodiment of the present invention, the SDP controller that receives the SPA data packet performs authentication information verification, and the implementation method is as follows:

[0040] The SPA data packet is decrypted using the pre-configured key and the decrypted information is verified, including user identity verification and timestamp / one-time token inspection.

[0041] In an embodiment of the present invention, the SDP controller determines a list of SDP gateways to which the SDP client can connect, and the implementation method is as follows:

[0042] The SDP controller groups users and resources according to the configuration and configures different policies for different user groups. That is, the SDP controller determines the resources that users can access based on their roles or user groups. At the same time, it adjusts the user's resource access rights in real time based on the analysis results given by the risk assessment, dynamically generates a minimum permission access control policy, and sends it to the SDP client and SDP gateway.

[0043] Specifically, each user type has different access requirements and permissions to resources. The SDP controller is configured to classify users according to their roles or user groups. For example, different types of users are divided into groups with different permissions. At the same time, resources are also divided into different categories, such as internal data, external interfaces, sensitive information, etc. Through this grouping method, the SDP controller can manage user access rights to resources in a more refined manner. For example, user A may only be able to access ordinary daily data, while user B can access a wider range of resources, and user C may only be able to access specific resources related to a certain project. This grouping strategy helps to implement the principle of least privilege, that is, users can only access the resources necessary to complete their work, thereby reducing potential security risks.

[0044] The SDP controller also configures access policies for different user groups. These policies include, but are not limited to, access time limits, access frequency limits, data transmission encryption requirements, and authentication methods. For example, user B might be required to undergo two-factor authentication and require full data transmission encryption when accessing sensitive data; while user C might only be allowed access to limited public information during a specific time period.

[0045] After determining the resources that the user can access and the corresponding access policies, the SDP controller will generate a minimum privilege access control policy.

[0046] The SDP controller dynamically generates a minimum privilege access control policy and sends it to the SDP client and SDP gateway. The SDP client is the host that initiates the connection and is usually deployed on end-user devices such as personal computers and smartphones. The SDP client is responsible for communicating with the SDP controller and passing the user's access request to the SDP controller for verification. If the user's request is allowed, the user will obtain resource access rights. The SDP gateway is a device responsible for providing resource access services to authorized users and is deployed at the edge of the network. The SDP gateway only provides resource access services to users authorized by the SDP controller. By default, the SDP gateway rejects all communications from all hosts other than the SDP controller. The SDP gateway will only accept connections from the SDP client after the SDP controller issues an instruction.

[0047] When a user accesses a resource, the SDP client establishes a two-way encrypted connection with the SDP gateway based on the issued access control policy. The SDP client communicates with the resource server through the SDP gateway using a two-way encrypted data channel. Throughout this process, the SDP controller monitors the network communication status and data flow in real time to ensure the security and reliability of data transmission.

[0048] In an embodiment of the present invention, the SDP controller notifies the SDP gateways in the gateway list to accept communications from the SDP client. The SDP controller sends the SDP gateway list accessible to the SDP client to the load balancer. The load balancer sends the SDP gateway list to the SDP client.

[0049] In an embodiment of the present invention, if an SDP controller in a cluster fails, all tasks of the failed SDP controller will be assigned to other normal SDP controllers in the cluster. This process will not affect the operation of the entire cluster. The implementation method is as follows:

[0050] The load balancer regularly checks the health of each SDP controller in the cluster and adjusts traffic distribution based on the health check results to prevent requests from being forwarded to faulty nodes. That is, when an SDP controller fails, the load balancer forwards requests to other functioning SDP controllers. This improves the availability and reliability of the SDP system.

[0051] Specifically, the load balancer can detect the health status of the SDP controller through a variety of health check mechanisms, such as TCP check, custom script detection, etc. When the load balancer finds that an SDP controller is abnormal through health check, it will immediately remove it from the available pool and stop sending new requests to it. At this time, the load balancer will redistribute the traffic originally allocated to the faulty controller to other normally functioning SDP controllers according to the preset traffic distribution strategy. This method of dynamically adjusting traffic distribution ensures that even in the event of partial controller failure, the entire system can still operate normally and will not cause service interruption due to single point failure. Accordingly, after the SDP controller returns to normal, the load balancer will confirm its status through health check and re-add it to the traffic forwarding list.

[0052] Data packets may be lost or delayed due to various reasons (such as network congestion, transmission errors, and device failures). If the SPA data packet sent by the SDP client is lost or damaged, it may cause the SDP client to wait indefinitely, resulting in low SDP system efficiency. Therefore, in an embodiment of the present invention, a timeout retransmission mechanism is provided for the SDP client to effectively improve the communication reliability between the SDP client and the load balancer or SDP gateway, thereby improving the operating efficiency of the SDP system.

[0053] Specifically, a timer and time threshold are set on the SDP client. The timer is used to record the time that has passed since the SDP client sent the SPA packet. The time threshold represents the maximum time the SDP client must wait if it does not receive a response. Typically, the time threshold is set appropriately based on the network environment and business requirements to balance communication efficiency and reliability. When the SDP client needs to communicate with the SDP controller or SDP gateway, it first sends an SPA packet. This packet contains authentication information, such as user identity and timestamp. After sending the packet, the SDP client immediately starts its timer and begins waiting for a response packet. While the timer is running, the SDP client continuously checks the timer value and whether a response packet has been received. If the SDP client receives a response packet from the SDP controller or SDP gateway before the timer value reaches the time threshold, it indicates that the SDP controller or SDP gateway has received the SPA packet sent by the SDP client and has verified it successfully. At this point, the timer stops. If the timer value is equal to the time threshold and the SDP client still has not received the response data packet, it means that the SPA data packet sent by the SDP client may have been lost or damaged. At this time, the SDP client will automatically trigger the timeout retransmission mechanism and resend the SPA data packet to the SDP controller or SDP gateway.

[0054] The present invention can add an SDP controller to the cluster and add the IP address of the newly added SDP controller to the load balancer. At the same time, the load balancer has the function of automatically detecting and isolating faulty nodes. The load balancer adopts a health check mechanism to regularly send probe requests (such as UDP connections, TCP connections, etc.) to the SDP controller to confirm the health status of the SDP controller. Once it is detected that a certain SDP controller cannot respond normally or the response time is too long, the load balancer will automatically mark it as unavailable and stop distributing new requests to it. This mechanism can ensure that the requests of the SDP client are always sent to the normal SDP controller, thereby avoiding service interruption caused by single point failure.

[0055] Therefore, the online or offline of some SDP controllers in the cluster will not interrupt the service of the entire SDP controller cluster system.

Claims

1. A cluster-based multi-SDP controller working method, characterized in that: A cluster is formed by a plurality of SDP controllers, wherein each SDP controller in the cluster is independent of each other and can communicate with each other through a network, and each SDP controller runs its own service; at least one load balancing server is set for the cluster; The load balancing server receives a SPA data packet from an SDP client, and forwards the SPA data packet to an SDP controller in the cluster, and the SDP controller that receives the SPA data packet verifies the authentication information; If the verification is successful, the SDP controller determines a list of SDP gateways to which the SDP client can connect, and notifies the SDP gateways in the list to accept communications from the SDP client; The SDP controller sends the SDP gateway list to the load balancer, and the load balancer sends the SDP gateway list to the SDP client. The SDP client sends an SPA packet to the SDP gateway, and the SDP gateway verifies the SPA packet. If the verification is successful, the SDP gateway establishes a two-way encrypted connection with the SDP client. Otherwise, the SDP gateway discards the SPA packet sent by the SDP client. If the verification fails, the SDP controller discards the SPA data packet sent by the SDP client.

2. The cluster-based multi-SDP controller operation method according to claim 1, characterized in that: The load balancer is a software device or a hardware device. When it is a software device, it is installed on the application running on the SDP controller to achieve load balancing; when it is a hardware device, it is an independent hardware running the load balancing software.

3. The cluster-based multi-SDP controller operation method according to claim 1, characterized in that: The load balancer is responsible for accepting access requests from SDP clients and forwarding the access requests to an SDP controller in the cluster according to a load balancing algorithm.

4. The cluster-based multi-SDP controller operation method according to claim 1, characterized in that: The load balancing algorithm selects an SDP controller to forward the SPA data packet according to a predefined strategy, and the predefined strategy is a round-robin algorithm or a weighted round-robin algorithm.

5. The cluster-based multi-SDP controller operation method according to claim 1, characterized in that: The SDP controller that receives the SPA data packet performs authentication information verification, and the implementation method is as follows: Use the pre-configured key to decrypt the SPA data packet and verify the decrypted information.

6. The cluster-based multi-SDP controller operation method according to claim 1, characterized in that: The SDP controller determines a list of SDP gateways to which the SDP client can connect, and the implementation method is as follows: The SDP controller groups users and resources according to the configuration and configures different policies for different user groups. That is, the SDP controller determines the resources that users can access based on their roles or user groups. At the same time, it adjusts the user's resource access rights in real time based on the analysis results given by the risk assessment, dynamically generates a minimum permission access control policy, and sends it to the SDP client and SDP gateway.

7. The cluster-based multi-SDP controller operation method according to claim 1, characterized in that: The SDP controller notifies the SDP gateways in the gateway list to accept communications from the SDP client.

8. The cluster-based multi-SDP controller operation method according to claim 1, characterized in that: If an SDP controller in a cluster fails, all tasks of the failed SDP controller will be distributed to other healthy SDP controllers in the cluster. This is achieved as follows: The load balancer regularly checks the health status of each SDP controller in the cluster and adjusts traffic distribution based on the health check results to prevent requests from being forwarded to faulty nodes. That is, when an SDP controller fails, the load balancer forwards requests to other SDP controllers that are functioning normally.

9. The cluster-based multi-SDP controller operation method according to claim 1, characterized in that: If the verification fails, the SDP controller and SDP gateway discard the SPA data packet of the SDP client.

10. The cluster-based multi-SDP controller working method according to claim 1, characterized in that: Set up a timeout retransmission mechanism for the SDP client; set a timer and time threshold on the SDP client. The SDP system uses single-packet authorization and authentication SPA technology. After the SDP client sends the SPA data packet, its timer is started. When the timer value is equal to the time threshold, and the SDP client does not receive a response data packet sent by the load balancer or SDP gateway, the SDP client resends the SPA data packet to the load balancer or SDP gateway until it is sent successfully.