Virtual private network VPC physical service mapping processing method and device

By encapsulating the VPCGW native interface into a service interface and assigning authorization codes, efficient mapping of virtual private networks is achieved, and the mapping problem of cross-regional cross-cloud instances in large cloud environments is solved, operating costs and risks are reduced, and mapping efficiency and disaster recovery capabilities are improved.

CN120528890APending Publication Date: 2025-08-22CHINA CONSTRUCTION BANK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510687708.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

The existing technology cannot meet the requirements of frequent database delivery efficiency and refined management in large cloud environments. Traditional web interfaces or single call interfaces cannot effectively solve the problem of virtual private network VPC physical service mapping across regions and across cloud instances, and there are problems such as high manual operation costs and high risks.

Method used

The virtual private cloud gateway VPCGW native interface is encapsulated as a VPCGW service interface, and the product gateway registration authorization code is assigned to the front-end application. Through the interface checksum mapping operation type determination, the mapping of the local network address of the virtual private network to the virtual network address of the front-end application is realized.

Benefits of technology

It improves the mapping efficiency of cloud networks, reduces manual operation costs, reduces the risk of operational errors, and improves the mapping efficiency and disaster recovery capabilities of cross-regional cross-cloud instances.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528890A_ABST
    Figure CN120528890A_ABST
Patent Text Reader

Abstract

The invention provides a virtual private network VPC physical service mapping processing method and device. The method comprises the following steps: packaging a virtual private cloud gateway VPCGW native interface into a VPCGW service interface; distributing a product gateway registration authorization code for the front-end application; the product gateway registration authorization code comprises authorization information of a front-end application; receiving request data of a front-end application, wherein the request data of the front-end application comprises a virtual network address of the front-end application; verifying request data of the front-end application according to the product gateway registration authorization code, and determining a mapping operation type and mapping operation parameters according to a virtual network address of the front-end application after verification succeeds; mapping the local network address of the virtual private network to the front-end application virtual network address according to the mapping operation type or the mapping operation parameter; according to the invention, by migrating the mapping service to the virtual private cloud gateway VPCGW, physical service mapping based on the VPCGW is realized, and the cloud network mapping efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of cloud computing technology, and in particular to a device and method for managing physical mapping rules of a virtual private network (VPC). Background Art

[0002] VPC physical service mapping maps underlay network addresses to overlay networks through VPCGW cluster groups in cloud environments, allowing virtual servers in the overlay network to access services deployed in the underlay, such as overlay VMs accessing underlay databases. Large cloud environments typically have multiple cloud instances in multiple regions. Existing technologies use traditional web interfaces or single-call interfaces to achieve this, which cannot meet the frequent database delivery efficiency and refined management requirements of large cloud environments.

[0003] Therefore, a new virtual private network (VPC) physical service mapping processing method is urgently needed to solve the above problems. Summary of the Invention

[0004] An embodiment of the present invention provides a virtual private network (VPC) physical service mapping processing method, which improves cloud network mapping efficiency. The virtual private network (VPC) physical service mapping processing method includes:

[0005] Encapsulate the virtual private cloud gateway VPCGW native interface as a VPCGW service interface; allocate a product gateway registration authorization code to the front-end application; the product gateway registration authorization code includes the authorization information of the front-end application;

[0006] Receive request data from a front-end application, where the request data includes a virtual network address of the front-end application;

[0007] Verify the request data of the front-end application according to the product gateway registration authorization code. After successful verification, determine the mapping operation type and mapping operation parameters according to the virtual network address of the front-end application;

[0008] Mapping is performed from the local network address of the virtual private network to the front-end application virtual network address according to the mapping operation type or mapping operation parameters.

[0009] An embodiment of the present invention further provides a virtual private network (VPC) physical service mapping processing device, which improves cloud network mapping efficiency. The virtual private network (VPC) physical service mapping processing device includes:

[0010] An interface encapsulation module is used to encapsulate the native interface of the virtual private cloud gateway VPCGW into a VPCGW service interface; allocate a product gateway registration authorization code to the front-end application; the product gateway registration authorization code includes the authorization information of the front-end application;

[0011] A request data receiving module, configured to receive request data from a front-end application, wherein the request data from the front-end application includes a virtual network address of the front-end application;

[0012] The data verification and parsing module is used to verify the request data of the front-end application according to the product gateway registration authorization code. After successful verification, the mapping operation type and mapping operation parameters are determined according to the virtual network address of the front-end application;

[0013] The VPCGW mapping module is used to map the local network address of the virtual private network to the virtual network address of the front-end application according to the mapping operation type or mapping operation parameters.

[0014] An embodiment of the present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the above-mentioned virtual private network (VPC) physical service mapping processing method is implemented.

[0015] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the computer program implements the above-mentioned virtual private network (VPC) physical service mapping processing method.

[0016] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the above-mentioned virtual private network (VPC) physical service mapping processing method.

[0017] The virtual private network (VPC) physical service mapping processing method and device of the embodiment of the present invention include: encapsulating the native interface of the virtual private cloud gateway (VPCGW) as a VPCGW service interface; allocating a product gateway registration authorization code to the front-end application; the product gateway registration authorization code includes the authorization information of the front-end application; receiving the request data of the front-end application, the request data of the front-end application includes the virtual network address of the front-end application; verifying the request data of the front-end application according to the product gateway registration authorization code, and after the verification is successful, determining the mapping operation type and mapping operation parameters according to the virtual network address of the front-end application; mapping the local network address of the virtual private network to the virtual network address of the front-end application according to the mapping operation type or the mapping operation parameters; the embodiment of the present invention realizes physical service mapping based on VPCGW by migrating the mapping service to the virtual private cloud gateway (VPCGW), thereby improving the cloud network mapping efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative work. In the drawings:

[0019] Figure 1 This is an example diagram of a virtual private network (VPC) physical service mapping processing method according to an embodiment of the present invention;

[0020] Figure 2 This is a diagram showing a specific example of VPC mapping in an embodiment of the present invention;

[0021] Figure 3 This is a specific flowchart of VPC mapping in an embodiment of the present invention;

[0022] Figure 4 This is a diagram illustrating a structure of a virtual private network (VPC) physical service mapping processing device according to an embodiment of the present invention;

[0023] Figure 5 A diagram illustrating a specific system example of virtual private network (VPC) physical service mapping processing in an embodiment of the present invention;

[0024] Figure 6 Schematic diagram of the computer device structure according to an embodiment of the present invention. DETAILED DESCRIPTION

[0025] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0026] The inventors' research found that in a general cloud environment, from the perspective of safe and stable operation, the VPC native interface is not allowed to be exposed to the outside world. Therefore, the current physical mapping relies on the demand change work order. After the change is reviewed, the change implementation personnel operate through the interface or call the application programming interface; the general cloud environment only provides the VPC native interface and web page, which can only realize the addition, deletion, query, and modification of a single physical service mapping; the specific target cluster group to be migrated to depends on manual query.

[0027] As can be seen, existing solutions in large, tightly controlled cloud organizations require manual implementation, requiring high labor costs, including change review and the manual entry of numerous parameter fields. This often carries the risk of operational errors. In large cloud environments with numerous clusters, each change requires manual secondary confirmation of the cluster group to be migrated. Furthermore, the user interface and API operations are not isolated for tenants, allowing manual manipulation of physical mappings across the cloud environment, further increasing implementation risks, especially when deleting physical mappings.

[0028] Therefore, based on the defects of the prior art, the inventors proposed a virtual private network (VPC) physical service mapping processing method according to an embodiment of the present invention.

[0029] Figure 1 : This is an example diagram of a virtual private network VPC physical service mapping processing method according to an embodiment of the present invention. Figure 1 As shown, the method includes:

[0030] Step 101: Encapsulate the native interface of the virtual private cloud gateway VPCGW as a VPCGW service interface; allocate a product gateway registration authorization code to the front-end application; the product gateway registration authorization code includes the authorization information of the front-end application;

[0031] Step 102: Receive request data from a front-end application, where the request data includes a virtual network address of the front-end application.

[0032] Step 103: Verify the request data of the front-end application according to the product gateway registration authorization code. After successful verification, determine the mapping operation type and mapping operation parameters according to the virtual network address of the front-end application.

[0033] Step 104: Map the local network address of the virtual private network to the front-end application virtual network address according to the mapping operation type or mapping operation parameters.

[0034] In an embodiment, encapsulating the VPCGW native interface into the VPCGW service interface may include: when encapsulating the VPCGW native interface into the VPCGW service interface, adaptively encapsulating the VPCGW native interface according to attributes of the front-end application.

[0035] During specific implementation, the VPCGW native interface adaptability is encapsulated into various VPCGW service interfaces based on the front-end application to be processed. The VPCGW service interface can become a service that can be called externally across regions and cloud instances. This cross-regional and cross-cloud instance service based on the VPCGW service interface can improve disaster recovery capabilities and data redundancy in actual financial scenarios, and avoid the spread of single point failures.

[0036] In an embodiment, verifying the request data of the front-end application according to the product gateway registration authorization code may include: performing execution permission verification on the request data of the front-end application according to the execution permission information in the VPCGW database to determine the execution permission of the front-end application.

[0037] In an embodiment, after verifying the request data of the front-end application according to the product gateway registration authorization code, it can also include: binding the product gateway registration authorization code with the IP address and device information of the front-end application to determine the mapping operation range of the front-end application; updating the product gateway registration authorization code according to a predetermined period, and notifying the front-end application to replace the product gateway registration authorization code after the update.

[0038] During the specific implementation, different product gateway registration authorization codes are first assigned to different front-end applications. According to the product gateway registration authorization code, the front-end application is checked for permissions. If the verification is successful, the tenant ID that the front-end application can operate is configured in the relevant database of the virtual private cloud gateway VPCGW. The front-end application can only add, modify, and query physical mappings for tenants that have been previously applied for and configured. If the verification is unsuccessful, an error message is returned to the corresponding front-end application. Among them, the virtual network address to which the tenant ID belongs and its subnet configuration information are recorded in the database.

[0039] In an embodiment, the mapping operation types include: mapping addition, mapping deletion, mapping query, and mapping migration; the mapping operation parameters include: the local network address of the virtual private network corresponding to the mapping; Figure 2 FIG. 1 is a specific example diagram of VPC mapping in an embodiment of the present invention. Figure 2 As shown, mapping the local network address of the virtual private network to the front-end application virtual network address according to the mapping operation type or mapping operation parameters may include:

[0040] Step 201: Add a mapping from the local network address of the virtual private network to the virtual network address of the front-end application;

[0041] Step 202: Delete the mapping from the local network address of the virtual private network to the virtual network address of the front-end application;

[0042] Step 203: Query the mapping between the local network address of the virtual private network and the virtual network address of the front-end application;

[0043] Step 204: Migrate the mapping of the local network address of the virtual private network to the virtual network address of the front-end application.

[0044] When implementing it specifically, Figure 3 A specific flow chart of VPC mapping in an embodiment of the present invention is shown in FIG. Figure 3As shown, VPC mapping includes VPC physical mapping rule generation, VPC physical mapping rule migration, VPC physical mapping rule query and modification, self-service configuration management, and address management query and analysis.

[0045] VPC physical mapping rule generation, including single IP single vport mapping and multiplexed IP multiple vport mapping;

[0046] Single IP single vport mapping is to associate and map a local network IP address with a unique virtual port number, which is used to achieve one-to-one network service access, and each mapping corresponds to a specific service; multiplexed IP multi-vport mapping is to associate and map a local network IP address with multiple virtual port numbers, allowing multiple different services to share one IP address and distinguish different services through different ports to improve IP resource utilization.

[0047] VPC physical mapping rule migration includes: when the cloud environment changes, such as server migration and network reconstruction; transfer the existing VPC physical mapping rules to the new cloud environment to ensure the continuity of network services.

[0048] Query and modify VPC physical mapping rules, including querying and modifying VPC physical mapping rules within a VPC and querying and modifying global VPC physical mapping rules within a cloud instance;

[0049] Query and modify VPC physical mapping rules within a VPC, including querying and deleting mapping rules. Querying mapping rules involves finding the specific configuration parameters of a set VPC physical mapping rule and obtaining mapping-related data. Deleting mapping rules involves removing no longer needed VPC physical mapping rules and releasing related network resources.

[0050] Query and modify global VPC physical mapping rules within a cloud instance, including: adding a rule backend RS and deleting a rule backend RS. Adding a rule backend RS includes adding a new server to the RS (backend server cluster, Real Server) corresponding to the VPC physical mapping rule to expand mapping service capabilities, improve load, and balance performance; deleting a rule backend RS includes removing the mapping server from the backend server cluster RS ​​corresponding to the VPC physical mapping rule.

[0051] Self-service configuration management includes user management of cloud network address management-related configurations, including setting mapping rules, configuring parameters, and other operations to achieve autonomous VPC physical mapping management.

[0052] Address management query and analysis, including: address management query and address management statistical analysis;

[0053] Address management query includes querying the network address information under management, clarifying the usage status and mapping relationship of the network address; address management statistical analysis includes statistics and analysis of relevant data of the network addresses under management, such as the frequency of network address usage and changes in the number of mapping rules, to provide data support for network optimization.

[0054] The present invention also provides a virtual private network (VPC) physical service mapping processing device, as described in the following embodiments. Since the principle of solving the problem of this device is similar to that of the virtual private network (VPC) physical service mapping processing method, the implementation of this device can refer to the implementation of the virtual private network (VPC) physical service mapping processing method, and the repeated parts will not be repeated.

[0055] Figure 4 FIG. 1 is a structural example diagram of a virtual private network VPC physical service mapping processing device according to an embodiment of the present invention. Figure 4 As shown, the device includes:

[0056] The interface encapsulation module 401 is used to encapsulate the native interface of the virtual private cloud gateway VPCGW into a VPCGW service interface; allocate a product gateway registration authorization code to the front-end application; the product gateway registration authorization code includes the authorization information of the front-end application;

[0057] The request data receiving module 402 is configured to receive request data from a front-end application, wherein the request data from the front-end application includes a virtual network address of the front-end application;

[0058] The data verification and analysis module 403 is used to verify the request data of the front-end application according to the product gateway registration authorization code. After successful verification, the mapping operation type and mapping operation parameters are determined according to the virtual network address of the front-end application.

[0059] The VPCGW mapping module 404 is configured to map the local network address of the virtual private network to the virtual network address of the front-end application according to a mapping operation type or mapping operation parameters.

[0060] In one embodiment, the interface encapsulation module 401 is specifically configured to perform adaptive encapsulation of the VPCGW native interface according to the attributes of the front-end application when encapsulating the VPCGW native interface into the VPCGW service interface;

[0061] In one embodiment, the data verification and analysis module 403 is specifically configured to perform execution permission verification on the request data of the front-end application based on the execution permission information in the VPCGW database to determine the execution permission of the front-end application.

[0062] In one embodiment, the data verification and analysis module 403 is also used to bind the product gateway registration authorization code with the IP address and device information of the front-end application to determine the mapping operation scope of the front-end application; update the product gateway registration authorization code according to a predetermined period, and notify the front-end application to replace the product gateway registration authorization code after the update.

[0063] In one embodiment, the mapping operation types include: mapping addition, mapping deletion, mapping query, and mapping migration; the mapping operation parameters include: a local network address of a virtual private network corresponding to the mapping;

[0064] The VPCGW mapping module 404 is specifically configured to:

[0065] Add mapping from local network address of virtual private network to virtual network address of front-end application;

[0066] Delete the mapping from the local network address of the virtual private network to the virtual network address of the front-end application;

[0067] Query the mapping of the local network address of the virtual private network to the virtual network address of the front-end application;

[0068] Migrate the mapping of the local network address of the virtual private network to the virtual network address of the front-end application.

[0069] The following is a specific example to illustrate the virtual private network (VPC) physical service mapping processing method and device according to an embodiment of the present invention. Figure 5 FIG. 1 is a diagram showing a specific system example of a virtual private network (VPC) physical service mapping process according to an embodiment of the present invention. Figure 5 As shown, the system includes:

[0070] Unified Service Catalog: Provides registration services for the VPCGW service interface, capable of encapsulating the native interface of the virtual private cloud gateway VPCGW as a VPCGW service interface; and allocates product gateway registration authorization codes to front-end applications. Specifically, when calling the VPCGW service interface, the front-end application information is sent and recorded as the "product gateway registration authorization code". The unified service catalog allocates different product gateway registration authorization codes to different front-end applications. The authorization code is authoritative information and is recorded in the database corresponding to the VPCGW application server to prevent the risk of verification bypass. It also implements the authentication and mapping channel management of front-end application interface calls.

[0071] VPCGW application front-end interface: The front-end application can use the VPCGW application front-end interface to upload request data and perform subsequent mapping operations. In the embodiment of the present invention, the VPCGW application front-end interface can also provide configuration viewing and modification of the VPCGW mapping service, and provide query, statistics, and analysis of access logs. In the embodiment of the present invention, the VPCGW application front-end interface can use the stable and well-compatible VUE framework to meet the compatibility requirements of the system.

[0072] VPCGW application server: The VPCGW application server first receives the request data of the front-end application; verifies the request data of the front-end application according to the product gateway registration authorization code, and after successful verification, determines the mapping operation type and mapping operation parameters according to the virtual network address of the front-end application; specifically, the VPCGW application server receives the request data of the front-end application in Json format, and implements timeout, flow control, and reversal mechanisms to ensure data consistency in the VPCGW application server; at the same time, the VPCGW application server of the embodiment of the present invention can use different transaction return code designs to distinguish application timeout, data error, etc. when the front-end application calls the VPCGW application server, and provide detailed return codes and return information for the front-end application to handle differently; after determining the mapping operation type and mapping operation parameters, the VPCGW application server maps the local network address of the virtual private network to the virtual network address of the front-end application according to the mapping operation type or mapping operation parameters; the VPCGW application server in the embodiment of the present invention can use a framework verified by large-scale applications to ensure good subsequent scalability;

[0073] In addition to implementing the VPC physical mapping service, the VPCGW application server of the embodiment of the present invention can also set access control in the VPC physical mapping process, including pre-access control, in-process access control, and post-access control. Table 1 is the access control table of the mapping process:

[0074] Table 1 Access control table of the mapping process

[0075]

[0076] Database instance: records the configuration information and access log information required by the VPCGW application server. A database is divided into different databases based on cloud instances, ensuring that cloud instance numbers are unique within the same cloud provider. A modular configuration and standard data format are used, retaining a certain degree of forward-looking and expansion potential to ensure system scalability. By configuring database tables, the present invention can achieve the following:

[0077] (1) Dynamically increase or decrease different cloud instance physical mapping related operations; (2) Dynamically increase or remove verification of applications and operation objects; (3) Mapping switch control: 0-mapping closed; 1-mapping open to a fixed front-end application whitelist; 2-transaction closed; (4) Cross-region mapping control; (5) Mapping port control.

[0078] Verification shows that when the CVM utilization rate of the system application is below 80%, the average response time for querying, adding, modifying, and deleting physical service mappings is under 2 seconds. The maximum throughput of a single 2C8G CVM is 40 transactions per second.

[0079] Based on the above invention concept, Figure 6 As shown, the present invention also proposes a computer device 600, including a memory 610, a processor 620 and a computer program 630 stored in the memory 610 and executable on the processor 620, wherein the processor 620 implements the aforementioned virtual private network VPC physical service mapping processing method when executing the computer program 630.

[0080] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the computer program implements the above-mentioned virtual private network (VPC) physical service mapping processing method.

[0081] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the above-mentioned virtual private network (VPC) physical service mapping processing method.

[0082] The virtual private network (VPC) physical service mapping processing method and device of the embodiment of the present invention include: encapsulating the native interface of the virtual private cloud gateway (VPCGW) as a VPCGW service interface; allocating a product gateway registration authorization code to the front-end application; the product gateway registration authorization code includes the authorization information of the front-end application; receiving the request data of the front-end application, the request data of the front-end application includes the virtual network address of the front-end application; verifying the request data of the front-end application according to the product gateway registration authorization code, and after the verification is successful, determining the mapping operation type and mapping operation parameters according to the virtual network address of the front-end application; mapping the local network address of the virtual private network to the virtual network address of the front-end application according to the mapping operation type or the mapping operation parameters; the embodiment of the present invention realizes physical service mapping based on VPCGW by migrating the mapping service to the virtual private cloud gateway (VPCGW), thereby improving the cloud network mapping efficiency.

[0083] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0084] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0085] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0086] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0087] The specific embodiments described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A virtual private network (VPC) physical service mapping processing method, characterized in that: include: Encapsulate the native interface of the virtual private cloud gateway VPCGW as a VPCGW service interface; allocate the product gateway registration authorization code to the front-end application; The product gateway registration authorization code includes the authorization information of the front-end application; Receive request data from a front-end application, where the request data includes a virtual network address of the front-end application; Verify the request data of the front-end application according to the product gateway registration authorization code. After successful verification, determine the mapping operation type and mapping operation parameters according to the virtual network address of the front-end application; Mapping is performed from the local network address of the virtual private network to the front-end application virtual network address according to the mapping operation type or mapping operation parameters.

2. The method according to claim 1, wherein Encapsulate the VPCGW native interface into a VPCGW service interface, including: When encapsulating the VPCGW native interface into the VPCGW service interface, the VPCGW native interface is adaptively encapsulated according to the attributes of the front-end application.

3. The method according to claim 1, wherein Verify the front-end application's request data based on the product gateway registration authorization code, including: Based on the execution permission information in the VPCGW database, the execution permission of the front-end application request data is checked to determine the execution permission of the front-end application.

4. The method according to claim 3, wherein After verifying the front-end application's request data based on the product gateway registration authorization code, it also includes: Bind the product gateway registration authorization code with the IP address and device information of the front-end application to determine the mapping operation scope of the front-end application; update the product gateway registration authorization code according to the scheduled period, and notify the front-end application to replace the product gateway registration authorization code after the update.

5. The method according to claim 1, wherein The mapping operation types include: mapping addition, mapping deletion, mapping query, and mapping migration; the mapping operation parameters include: the local network address of the virtual private network corresponding to the mapping; Mapping the local network address of the virtual private network to the virtual network address of the front-end application based on the mapping operation type or mapping operation parameters includes: Add mapping from local network address of virtual private network to virtual network address of front-end application; Delete the mapping from the local network address of the virtual private network to the virtual network address of the front-end application; Query the mapping of the local network address of the virtual private network to the virtual network address of the front-end application; Migrate the mapping of the local network address of the virtual private network to the virtual network address of the front-end application.

6. A virtual private network (VPC) physical service mapping processing device, characterized in that: include: The interface encapsulation module is used to encapsulate the native interface of the virtual private cloud gateway VPCGW into the VPCGW service interface; it allocates the product gateway registration authorization code to the front-end application; The product gateway registration authorization code includes the authorization information of the front-end application; A request data receiving module, configured to receive request data from a front-end application, wherein the request data from the front-end application includes a virtual network address of the front-end application; The data verification and parsing module is used to verify the request data of the front-end application according to the product gateway registration authorization code. After successful verification, the mapping operation type and mapping operation parameters are determined according to the virtual network address of the front-end application; The VPCGW mapping module is used to map the local network address of the virtual private network to the virtual network address of the front-end application according to the mapping operation type or mapping operation parameters.

7. The device according to claim 6, characterized in that Interface encapsulation module, specifically used for: When encapsulating the VPCGW native interface into the VPCGW service interface, the VPCGW native interface is adaptively encapsulated according to the attributes of the front-end application.

8. The device according to claim 6, wherein Data verification and parsing module, used for: Based on the execution permission information in the VPCGW database, the execution permission of the front-end application request data is checked to determine the execution permission of the front-end application.

9. The device according to claim 8, wherein The data validation and parsing module is also used to: Bind the product gateway registration authorization code with the IP address and device information of the front-end application to determine the mapping operation scope of the front-end application; update the product gateway registration authorization code according to the scheduled period, and notify the front-end application to replace the product gateway registration authorization code after the update.

10. The device according to claim 6, wherein The mapping operation types include: mapping addition, mapping deletion, mapping query, and mapping migration; the mapping operation parameters include: the local network address of the virtual private network corresponding to the mapping; The VPCGW mapping module is specifically used to: Add mapping from local network address of virtual private network to virtual network address of front-end application; Delete the mapping from the local network address of the virtual private network to the virtual network address of the front-end application; Query the mapping of the local network address of the virtual private network to the virtual network address of the front-end application; Migrate the mapping of the local network address of the virtual private network to the virtual network address of the front-end application.

11. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 5 is implemented.

12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.

13. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 5 is implemented.