Access method, access device, electronic device and computer program product

By configuring routing policies and a dual-network card architecture for the request subject, the problem of VPN devices being unable to correctly determine the data path due to conflicts between the internal network IP address and the external system IP address is solved, achieving precise communication path control and compliant access in high-security scenarios.

CN120639746APending Publication Date: 2025-09-12KE COM (BEIJING) TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511021304.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-23
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

When the enterprise business system interacts with external systems, the conflict between the internal network IP address and the external system IP address causes the VPN device to be unable to correctly determine the data path, resulting in interaction failure. In addition, after NAT conversion, the system is not registered in the secure authentication network and cannot pass the authentication.

Method used

By configuring routing policies for the request subject, clarifying the association between the external network address and the internal network card, dynamically matching the target network card as the source address, and combining the front-end machine's dual network card architecture and security plug-in, precise control of the communication path can be achieved, avoiding security authentication issues caused by NAT conversion.

Benefits of technology

It achieves precise control of communication paths in a multi-network card environment, improves the security and compliance of network access, ensures the accuracy and stability of internal and external network communications, and is suitable for compliance access verification in high-security scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639746A_ABST
    Figure CN120639746A_ABST
Patent Text Reader

Abstract

The invention provides an access method, an access device, an electronic device and a computer program product. The access method comprises the steps that a routing strategy is configured for an extranet address which can be accessed by a request main body, and the routing strategy represents the incidence relation between the extranet address and an internal network card of the request main body; in response to an access request of a request main body to a target address, determining a target network card suitable for the target address according to a routing policy; and accessing the target address by taking the network address of the target network card as the source address of the request main body.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular to an access method, an access device, an electronic device, and a computer program product. Background Art

[0002] When enterprise business systems interact with external systems, they must establish a secure connection through a VPN (Virtual Private Network) device. However, when the internal network IP (Internet Protocol) address conflicts with the external system IP address, the VPN device cannot correctly determine the data path, causing interaction failure.

[0003] Related technologies use NAT (Network Address Translation) to resolve this issue by translating the business system's IP address to a new, non-conflicting address. However, in high-security scenarios like finance, VPNs require dedicated lines to secure, authenticated networks (such as financial metropolitan area networks) and complete IP access authentication before accessing external systems. However, NAT-translated IP addresses are not registered on the secure, authenticated network and fail authentication. Consequently, even after resolving the IP conflict, access remains impossible. Summary of the Invention

[0004] The present disclosure provides an access method, an access device, an electronic device, and a computer program product.

[0005] According to one aspect of the present disclosure, an access method is provided, comprising: configuring a routing policy for an external network address accessible to a requesting subject, the routing policy representing an association between the external network address and an internal network card of the requesting subject; determining, in response to an access request by the requesting subject to a target address, a target network card applicable to the target address according to the routing policy; and accessing the target address using the network address of the target network card as the source address of the requesting subject.

[0006] According to one aspect of the technical solution, by configuring the routing strategy of the external network address and the internal network card, intelligent matching of the source address and the target address of the access request is achieved, thereby accurately controlling the communication path in a multi-network card environment, avoiding the security authentication problems caused by NAT conversion, and improving the security and compliance of network access.

[0007] In some embodiments, a routing policy is configured for an external network address accessible to a requesting subject, including: determining a first routing policy associated with the external network address and a first internal network card, wherein the first internal network card is a network interface for the requesting subject to perform data interaction with the external network address, and the routing prefix of the network address of the first internal network card is different from the routing prefix of the external network address; and determining a second routing policy associated with the internal network address interval of the requesting subject and a second internal network card, wherein the second internal network card provides a network interface for data interaction for any network address in the internal network address interval and different from the external network address.

[0008] According to one aspect of the technical solution, by configuring routing strategies associated with corresponding internal network cards for different network addresses, refined control of external network access paths in a multi-network card environment is achieved, which not only ensures the connectivity of cross-segment communications, but also avoids security authentication problems caused by address conflicts and NAT conversion, thereby improving the security of system access and the flexibility of network configuration.

[0009] In some embodiments, in response to the access request of the request subject to the target address, the target network card suitable for the target address is determined in accordance with the routing policy, including: based on the routing policy, when the target address is the external network address, the first internal network card is used as the target network card; and when the target address is in the internal network address range and does not belong to any internal network address of the external network address, the second internal network card is used as the target network card.

[0010] According to one aspect of the technical solution, automatic path selection of access requests is achieved by dynamically matching the corresponding internal network card according to the target address, which ensures the accuracy and security of internal and external network communications, avoids access failures caused by address errors or NAT conversion, and improves the stability of network communications and the intelligence level of policy execution.

[0011] In some implementations, the further step includes: a security plug-in of the front-end processor triggered by the access request reads network information from a network system where the front-end processor is located, and generates a message including the network address of the target network card.

[0012] According to one aspect of the technical solution, by integrating a security plug-in into the front-end machine, dynamically reading network information and generating a message carrying the target network card address, real-time linkage between access requests and network environment is achieved, the traceability and security of the communication process are enhanced, and compliance access verification in high-security scenarios such as finance is effectively supported.

[0013] In some embodiments, after configuring a routing policy for an external network address accessible to the request subject, it also includes: configuring a persistent identifier for the routing policy, wherein the routing policy with the persistent identifier is in a valid state after the front-end processor running the routing policy is restarted.

[0014] According to one aspect of the technical solution, by configuring a persistent identifier for the routing policy, it is ensured that the front-end can retain and automatically restore the key routing configuration after restart, effectively improving the stability and continuity of the network policy and avoiding access interruption or policy failure caused by device restart.

[0015] In some implementations, after accessing the target address using the network address of the target network card as the source address of the request subject, the method includes: verifying the message by the security authentication network corresponding to the target address to determine the access validity of the source address.

[0016] According to one aspect of the technical solution, by verifying the source address of the message through the security authentication network after accessing the target address, dynamic verification of the access rights of the requesting subject is achieved, ensuring the compliance and security of the communication process, which is particularly suitable for scenarios with strict access control requirements such as finance.

[0017] In some embodiments, the security authentication network corresponding to the target address verifies the message to determine the access validity of the source address, including: determining whether the network address in the message is recorded in the registered address library of the security authentication network; and when the network address is recorded in the registered address library, determining that the access validity of the source address is valid; or, when the network address is not recorded in the registered address library, determining that the access validity of the source address is invalid.

[0018] According to one aspect of the technical solution, by verifying the source address of the message through the security authentication network after accessing the target address, dynamic verification of the access rights of the requesting subject is achieved, ensuring the compliance and security of the communication process, which is particularly suitable for scenarios with strict access control requirements such as finance.

[0019] In some embodiments, after determining the access validity of the source address, the method includes issuing an admission ticket to the source address with valid access validity, so that the source address with the admission ticket can access the target address.

[0020] According to one aspect of the technical solution, by comparing the source address of the access request with the registered address library of the security authentication network in real time, the access effectiveness of the source address can be accurately judged, thereby achieving automatic interception of illegal access and rapid release of compliant access, effectively ensuring the trustworthiness and controllability of network communications in high-security scenarios.

[0021] In some implementations, before responding to the access request of the request subject to the target address, the method further includes: responding to a call instruction to a front-end processor, and obtaining the access request by the front-end processor.

[0022] According to another aspect of the present disclosure, an access device is provided, including: a front-end processor, the front-end processor being configured with a first internal network card and a second internal network card, the first internal network card being a network interface for data interaction between a requesting entity and an external network address, the routing prefix of the network address of the first internal network card being different from the routing prefix of the external network address, the second internal network card providing a network interface for data interaction for any internal network address that is in the internal network address range and does not belong to the external network address; and an electronic device, the electronic device being used for the access method described in any embodiment of the present disclosure, so as to select an internal network card in the front-end processor that is suitable for the target address.

[0023] According to another aspect of the present disclosure, an electronic device is provided, comprising: a memory storing execution instructions; and a processor executing the execution instructions stored in the memory, so that the processor executes the access method described in any embodiment of the present disclosure.

[0024] According to another aspect of the present disclosure, a readable storage medium is provided, in which execution instructions are stored. When the execution instructions are executed by a processor, they are used to implement the access method described in any embodiment of the present disclosure.

[0025] According to another aspect of the present disclosure, a computer program product is provided, including a computer program, wherein when the computer program is executed by a processor, the access method described in any embodiment of the present disclosure is implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The accompanying drawings illustrate exemplary embodiments of the present disclosure and together with the description serve to explain the principles of the present disclosure. These drawings are included to provide a further understanding of the present disclosure and are incorporated in and constitute a part of this specification.

[0027] Figure 1 Schematic diagram of an application scenario of the access method according to an embodiment of the present disclosure.

[0028] Figure 2 is a flow chart of an access method according to an embodiment of the present disclosure.

[0029] Figure 3 This is a schematic diagram of the flow of an access request according to an embodiment of the present disclosure.

[0030] Figure 4 Schematic diagram of the composition of an access device according to an embodiment of the present disclosure.

[0031] Figure 5 It is a schematic block diagram of the structure of an access device according to an embodiment of the present disclosure.

[0032] Figure 6 is a schematic block diagram of the structure of an electronic device according to one embodiment of the present disclosure. DETAILED DESCRIPTION

[0033] The present disclosure is further described in detail below with reference to the accompanying drawings and examples. It should be understood that the specific examples described herein are intended only to illustrate the relevant content and are not intended to limit the present disclosure. It should also be noted that, for ease of description, only the portions relevant to the present disclosure are shown in the accompanying drawings.

[0034] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in the present disclosure can be combined with each other. The technical solution of the present disclosure will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0035] When an enterprise's business systems interact with external systems, they need to establish secure connections through VPN (Virtual Private Network) devices. However, when the IP (Internet Protocol) address segments of the business system's internal network overlap with the IP addresses of the external systems, this conflict interferes with the VPN device's ability to determine the data exchange path, resulting in interaction failure.

[0036] Related technologies use NAT (Network Address Translation) technology to translate the IP addresses of business systems into new IP addresses that do not conflict with those of external systems. However, in scenarios with high data confidentiality, such as the financial sector, VPN devices must be connected via dedicated lines to secure, authenticated networks (such as financial metropolitan area networks). The secure authentication network then authenticates the business system's IP address before access to external systems. However, the NAT-translated IP address is not registered with the secure authentication network and therefore cannot obtain access credentials. This results in a situation where, even if the IP address conflict is resolved, external systems are still inaccessible.

[0037] To this end, the present disclosure proposes an access method.

[0038] Figure 1 Schematic diagram of an application scenario of the access method according to the embodiment of the present disclosure. Figure 1As shown, in this application scenario, a server 100 and a terminal device 200 may be included. The server 100 and the terminal device 200 may exchange data via a network or Bluetooth connection. The server 100 may be a cloud server or a physical server, and the terminal device 200 may be a smart device such as a computer, mobile phone, or tablet. The server 100 is used to provide the basic data required to run the access method, and the terminal device 200 executes the access method of the present disclosure based on the basic data provided by the server 100.

[0039] Figure 2 Flowchart of the access method according to the embodiment of the present disclosure. Figure 2 As shown, the present disclosure proposes steps S210 to S230, which provide support for the mapping relationship between the target address and the network card by configuring the routing strategy, give full play to the hardware advantages of the dual network cards in the intranet system of the requesting entity, realize accurate addressing and communication in different network environments, and avoid problems such as security authentication failure caused by NAT conversion introduced due to IP address conflicts.

[0040] Step S210: configuring a routing policy for the external network address accessible to the request subject.

[0041] This disclosure mainly addresses the problem of how to avoid the security authentication failure and inability to access the external network caused by the related technology using NAT technology to convert the intranet address in the scenario where the intranet address partially overlaps with the IP address of the external system when the internal device of the enterprise accesses the external system.

[0042] In the scenario described in this disclosure, the internal network refers to a private network environment built within an enterprise or organization, which usually has a high level of security protection and is accessible only to authorized devices. The internal network of an enterprise usually contains multiple network addresses, which correspond to different internal services or pages. These network addresses have the same routing prefix and constitute a continuous internal network address range. For example, the address range aax0 to aax255 can be used as the internal network address range of an enterprise, where aax is the routing prefix of the range, and the network addresses of all services within the enterprise are allocated and managed within this range. The external network refers to a public network environment that is not controlled by the enterprise or organization and is open to a wider range of users, such as the Internet or network service systems provided by partners, regulators, etc.

[0043] The requesting subject refers to the device used to initiate the access request. As a data interaction node in the enterprise intranet system, it can be a terminal device (such as a computer) used by enterprise employees. The requesting subject is usually deployed in the enterprise's internal network and can communicate with other data interaction nodes or servers in the intranet, but does not have the ability to directly access the external network. In order to achieve access to the external system, the requesting subject needs to send an access request through the network card in the front-end machine. The front-end machine used in this disclosure is configured with two network cards, one of which is used to forward data requested for the internal network, and the other network card is used to forward data requested for the external network. Obviously, the selection of a suitable export network card for the requesting subject depends on the configuration of the routing policy.

[0044] Routing policies are used to specify the subsequent redirection addresses corresponding to access requests. Based on these subsequent redirection addresses, the corresponding target network adapter (NIC) can be determined. For example, the "route add" command can be used to specify the next redirection address for a specific external network address or internal network address range, ensuring that access requests are forwarded along the designated path and enabling refined control of communication paths in a multi-NIC environment. In other words, routing policies can characterize the association between external network addresses and internal network adapters (i.e., the external network address corresponds to the first internal network adapter); of course, they can also characterize the association between internal network address ranges and internal network adapters (i.e., the internal network address range corresponds to the second internal network adapter). The first and second internal network adapters will be discussed later.

[0045] Step S220 , in response to the request subject's access request to the target address, determine a target network card suitable for the target address according to the routing policy.

[0046] The target address is the network address that the requesting entity wants to access. This can be an intranet address, such as an internal database address or an application server address, or an external network address, such as the interface address of a partner service system, the network address of a security authentication platform, or the interface address of a banking system. The target address is an important basis for routing policies to determine communication paths and select egress network adapters.

[0047] An access request is a data exchange instruction initiated by the requesting entity to communicate with a target address. An access request should include the target address, communication protocol, and request content. In this disclosure, the target address in an access request triggers routing policies and serves as the basis for determining the communication path and egress network interface card.

[0048] The target network card is the hardware network interface that redirects the packet to the target address. The target network card is one of the intranet systems. Based on the mapping between network cards and network addresses in the routing policy, the network card corresponding to the target address is selected from the first and second internal network cards in the intranet system as the target network card.

[0049] The first internal network interface is the network interface for data exchange between the requesting entity and the external network address. The routing prefix of the network address of the first internal network interface is different from the routing prefix of the external network address. Therefore, when the network address of the first internal network interface is used as the source address of the requesting entity for external communication, there will be no data path conflict caused by the IP address of the requesting entity being the same as the external website address.

[0050] The second internal network card provides a network interface for data exchange with any network address within the internal network address range that is different from the external network address. The network card address of the second internal network card can be within the internal network address range, and the network address of the second internal network card can be the same as the external network address or its routing prefix. Traffic forwarded through the second internal network card does not need to connect to an external communication link, so data path conflicts will not occur.

[0051] The present disclosure proposes a first internal network card facing the outside and a second internal network card facing the inside, so that the external network is physically isolated from the internal network system. On the basis of avoiding data path conflicts, it also reduces interference from the external network and improves the security of the internal network system.

[0052] Based on the attributes of the first internal network card and the second internal network card, the configured routing policy includes at least a first routing policy characterizing the association between the external network address and the first internal network card; and a second routing policy characterizing the association between the internal network address area and the second internal network card.

[0053] Step S230: access the target address using the network address of the target network card as the source address of the request body.

[0054] The source address is the IP address used by the initiator of the data packet, which is used to identify the source of the data packet and is the basis for data packet security authentication. In this disclosure, the source address is the IP address of the requesting entity that initiates the access request and is the verification basis for the external network to determine the security of the requesting entity.

[0055] The source address refers to the IP address used by the initiator of a data packet during network communication, which is used to identify the source location of the data packet. In the TCP (Transmission Control Protocol) / IP protocol stack, the source address is an important component of the IP header. It not only provides a path basis for network routing, but is also one of the key information for the receiver to perform security verification. In the technical solution disclosed in the present invention, the source address specifically refers to the IP address used by the requesting subject (such as the front-end or terminal device in the enterprise intranet) to initiate an access request. It is an important basis for the external system to determine whether the request is legal and whether it has access rights. Especially in network environments with high security requirements such as finance and government affairs, the source address usually needs to be consistent with the registration information in the access control mechanism (such as a security authentication network). Otherwise, the security authentication will fail and the access request will be rejected. Therefore, ensuring the accuracy and compliance of the source address is a key link in achieving secure and stable network communications.

[0056] In network environments with high security requirements, such as finance and government affairs, the first internal network card address is usually used as the source address for enterprise equipment to be registered in the security authentication network. This address is the key basis for completing security access authentication and access rights verification. Among them, the security authentication network is a private network environment built for specific organizations or business needs, with access control and security isolation mechanisms. It is usually not open to the public and access is limited to registered IP addresses. This type of network is used to ensure the communication security and data isolation of key business systems, such as the financial metropolitan area network in the financial industry. In a security authentication network, the identity, IP address and other information of the communicating parties are usually subject to strict authentication and registration to ensure the compliance and controllability of network access and prevent unauthorized data interaction and security risks.

[0057] In the present disclosure, if the target network card is the first internal network card, it means that the target address is an external network address, and the IP address of the first internal network card needs to be used as the source address of the request subject. Since the first internal network card is the network address used by the enterprise for external registration, there will be no inconsistency with the address recorded in the registered address library in the security authentication network. Among them, the registered address library records all network addresses registered in the security authentication network, and the addresses in it can obtain access credentials for the corresponding external network system; network addresses not recorded in it have not been registered in the security authentication network. Therefore, when the relevant technology uses NAT technology for address conversion, the new address is not recorded in the registered address library, and it cannot obtain access rights to the target address.

[0058] If the target network card is the second internal network card, it means that the target address is an internal network address and can be accessed through the second internal network card. This physically shields the internal network from the external network, preventing interference and security violations on the internal network from the external network.

[0059] Figure 3 This is a schematic diagram of the flow of an access request according to an embodiment of the present disclosure. Figure 3 This diagram illustrates the complete flow of an access request in a financial industry scenario, from the requesting device (i.e., the requesting subject) to the external system. Throughout this communication process, the access request first selects the appropriate internal network card within the intranet system based on the routing policy, then passes security access authentication within the financial metropolitan area network (MAN), ultimately successfully accessing the target external system.

[0060] As can be seen, the present disclosure, through the routing policy configured within the front-end processor and the dual network interface card architecture, can accurately direct requests to access external systems to the first internal network interface card, which then transmits the request to the access switch, thereby triggering communication with the external system. Because the network address of the first internal network interface card does not conflict with the address of the external system or the financial metropolitan area network, there is no need to set up a NAT translation module between the front-end processor and the access switch during hardware deployment, thereby simplifying the network structure and improving communication efficiency and system stability.

[0061] The intranet system includes multiple requesting devices, intranet switches, front-end processors, and VPN devices. The intranet system is a communication system comprised of an internal network and hardware devices. The internal network has been previously introduced and will not be further elaborated. As the core platform for information flow within an enterprise or organization, the intranet system typically consists of multiple subnets and features high-level access control mechanisms and security protections. Its primary function is to ensure the efficient transmission and secure access of internal data, preventing unauthorized device access and data leakage. In actual deployments, the intranet system may also integrate security components such as firewalls, intrusion detection systems, and log auditing to meet compliance requirements in various business scenarios.

[0062] An intranet switch is a network device deployed within an internal network, connecting multiple requesting devices, servers, and front-end processors. It is responsible for forwarding data frames and ensuring communication within the internal network. Typically a Layer 2 or Layer 3 switching device, an intranet switch offers advanced features such as network segmentation, port isolation, flow control, and access control lists. It not only ensures low latency and high bandwidth for internal communications but also enables logical isolation between different business systems through network policies, thereby improving overall network security and manageability.

[0063] The front-end processor (FEP), deployed within the internal network, serves as an intermediary between the requesting device and the external system. It processes and forwards access requests from the requesting device to the external network, and receives responses from the external network and returns them to the requesting device. The disclosed configuration features dual network cards: a first internal network card (Card 1) and a second internal network card (Card 2), connecting to the external and internal networks, respectively. Routing policies and security mechanisms ensure the security and accuracy of data transmission and effectively isolate the internal and external networks. The FEP plays a crucial role in high-security network environments such as finance and government. It serves not only as the gateway for data exchange between internal and external networks but also as a core node for security policy enforcement. The FEP typically requires high-performance hardware, a stable operating system environment, and comprehensive security mechanisms to ensure stable communication capabilities even under high-concurrency access and complex network policies. Furthermore, the FEP can integrate security plug-ins to interface with the security authentication mechanisms of external systems, further enhancing access control compliance.

[0064] VPN devices implement VPN technology, establishing secure, encrypted communication channels over public networks. This allows requesting entities and external systems to transmit sensitive data in insecure network environments while ensuring data confidentiality, integrity, and source authenticity. The VPN devices disclosed herein include access switches, dedicated line switches, a master controller, and slave controllers. The access switch connects the front-end processor (FEP) and the controller, forwarding data frames from the FEP to the next network address for final delivery to external systems. The dedicated line switch connects the controller to the financial metropolitan area network (in other scenarios, it can be another secure, authenticated network). It forwards data frames from the internal network via a dedicated VPN channel and also supports receiving feedback from external systems. Under normal circumstances, the master serves as the controller, allocating traffic and maintaining routing. If the master fails, the slave controller is selected to prevent request failures due to VPN failures.

[0065] In actual deployments, VPN devices often employ a high-availability architecture, ensuring network service continuity through active / standby redundancy. For example, a heartbeat mechanism synchronizes the master and slave nodes. If a master node fails, the system quickly switches to the slave node, ensuring uninterrupted data transmission. Furthermore, to further enhance security, VPN devices typically support bidirectional authentication, traffic encryption, and access logging, meeting the strict data privacy and access auditing requirements of the financial industry.

[0066] In step 301, log in to the front-end processor via the intranet switch.

[0067] This step is the starting point of the entire access process. The user or application establishes a connection with the front-end processor (FEP) through the intranet switch. Identity authentication and permission verification are completed before subsequent operations can be performed. During this stage, the FEP typically records the visitor's identity information, login time, and operation logs to provide a basis for subsequent audits.

[0068] Assuming the intranet address range is aax1 to aax255, the IP address of the network switch can be aax1, the IP address of the front-end processor's second internal network interface card can be aax255, and the IP addresses of other services or web pages in the intranet system should also be between aax1 and aax255. The IP addresses corresponding to all services and web pages in the intranet system share the same routing prefix. This unified routing prefix design helps simplify routing configuration and improve network management efficiency. It also facilitates access control to specific address segments through routing policies and other means, improving network security.

[0069] Since the front-end processor disclosed in the present invention is configured with dual network cards, the IP address of the first external internal network card can be bbca, or other network addresses that are different from the routing prefix of the internal network address interval and different from the IP address of the external system. Therefore, the internal address interval can overlap or partially overlap with the IP address of the external system, and there will be no traffic path conflict problem. This design effectively solves the problem of communication anomalies caused by address overlap in traditional networks, and is particularly suitable for scenarios with multiple subnets and complex address planning in finance, government affairs, etc. Through the flexible configuration of routing policies, even in the case of address conflicts, it can ensure that access requests are accurately sent through the designated network card, avoiding security authentication failures caused by NAT conversion.

[0070] In step 302, a target URL is proposed via the front-end processor.

[0071] That is, after the requesting device logs in to the front-end processor (FEP) via the intranet switch, it enters the target URL into the FEP to form an access request. This triggers the FEP to execute step 303, triggering the routing policy to select a network interface card (NIC). In this scenario, the first internal NIC is selected, and the access request is sent to the VPN device. This process is typically performed automatically by the FEP's operating system based on a pre-set routing table, requiring no manual intervention. Upon receiving the access request, the operating system resolves the target address and matches the corresponding egress NIC based on the routing policy, thereby implementing intelligent control of the communication path.

[0072] The routing strategy is determined by the target URL obtained by the front-end. The routing strategy can be: route add aax3 mask 255.255.255.255 bbcb; route add aax4 mask 255.255.255.255 bbcb; route add aax255 mask 255.255.255.255 bbcb; route add aax1-aax255 mask 255.255.255.255 aax255.

[0073] It should be noted that "route add" is a command that specifies the next jump address in the external network address or internal network address range. Here, aax3 and aax4 are the IP addresses of the financial metropolitan area network, and aax255 is the IP address of the external system. Obviously, the IP addresses of the financial metropolitan area network and the external system both fall within the internal network address range aax1-aax255. Therefore, if the target address is any of aax3, aax4, or aax255, the first internal network card should be used as the target network card according to the routing policy. If the target address is not aax3, aax4, or aax255, but falls within the internal network address range aax1-aax255, the second internal network card should be used as the target network card. This prevents IP address conflicts between the target network card and the external system. This fine-grained routing policy configuration enables precise control of different network addresses, ensuring that access requests are always transmitted through compliant paths, thereby meeting access control requirements in high-security scenarios.

[0074] Furthermore, bbcb represents the IP addresses of the master and slave servers. In the routing logic, this essentially indicates the next-hop network address to the front-end processor based on the target address of the access request. Because the next-hop network address is connected to the first internal network card and matches the routing prefix of the first internal network card, it is undoubtedly confirmed that the aforementioned external network address is associated with the first internal network card.

[0075] In step 304a, if there are no faults, the VPN device's access switch passes the access request to the Master. "No faults" refers to the controller's operational status. A heartbeat mechanism is configured between the Master and Slave. The Master periodically provides operational status feedback to the Slave. If the Master fails to send heartbeat information to the Slave on time, it indicates a fault. The Master will then control the access switch to execute step 304b. In the event of a fault, the access request will be passed to the Slave to ensure normal maintenance and forwarding of the access request. This master-slave switching mechanism is one of the key technologies for ensuring network service continuity. The heartbeat mechanism monitors the status of the primary controller in real time. Once an anomaly is detected, the system can quickly switch to the backup controller, avoiding service interruption. This mechanism is of great significance in scenarios such as finance and government affairs where service availability is extremely high.

[0076] Furthermore, when there is no fault, step 305a is executed, and the Master transmits the access request to the dedicated line switch; when there is a fault, step 305b is executed, and the Slave transmits the access request to the dedicated line switch.

[0077] Furthermore, in step 307, the request is transmitted to the Financial Metropolitan Area Network (FIN) via a dedicated VPN tunnel. As a highly secure network built specifically for the financial industry, the FIN is typically accessed by multiple financial institutions and regulatory agencies, forming a unified network communication platform. This network has strict access control mechanisms and policies, requiring all access requests to pass security authentication to ensure the authenticity of both communicating parties and the integrity of their data.

[0078] It should be noted that the external network address that the requesting subject can access is the external network address that establishes a dedicated VPN channel with the internal network system, including the IP address of the external network system and the IP address of the security authentication network.

[0079] Security authentication networks such as financial metropolitan area networks contain a registered address library and a security access authentication component. In step 307, the front-end centralized security plug-in captures the network information in the intranet system, forms and synchronizes a message to the financial metropolitan area network. The message includes at least the system information of the front-end, hardware information (including the front-end identifier), the IP address information of the first internal network card, and other contents. The system information may be, for example, the Windows system, etc., which will not be repeated here. The security access authentication component traverses each registered IP address in the registered address library based on the front-end identifier associated with the access request. If there is an IP address corresponding to the front-end identifier, it means that the identity of the request subject associated with the access request is legal, and an access certificate is issued to it, indicating that its access validity is valid and it can access the target address. Then, step 308 is executed. When the access validity is valid, the access subject is allowed to access the external system.

[0080] Specifically, determine whether the network address in the message is recorded in the registered address library of the security authentication network; and if the network address is recorded in the registered address library, determine that the access validity of the source address is valid; or, if the network address is not recorded in the registered address library, determine that the access validity of the source address is invalid.

[0081] In some implementations, a persistent flag is configured for a routing policy, wherein the routing policy with the persistent flag remains valid after the front-end processor running the routing policy is restarted.

[0082] This feature is implemented by adding the "-p" parameter to the routing command, ensuring that the front-end can retain and automatically restore key routing configurations after a restart. This effectively improves the stability and continuity of network policies and avoids access interruptions or policy failures caused by device restarts.

[0083] In Windows, the default persistence flag is "-p". Other systems can use other persistence flags without any restrictions. After adding the persistence flag, if the front-end is restarted, the routing policy configured for it will still be valid and can be used. After adding the persistence flag to the routing policy, it will be displayed as follows: route add -p aax3 mask 255.255.255.255 bbcb; route add -p aax4 mask 255.255.255.255 bbcb; route add -p aax255 mask 255.255.255.255 bbcb; route add -p aax1-aax255 mask 255.255.255.255 aax255.

[0084] This solution configures precise routing strategies for the request subject and combines it with the dual network card architecture of the front-end machine to achieve intelligent selection and management of internal and external network access paths, ensuring that each access request can be sent through the most appropriate network card, avoiding security authentication failures caused by address conflicts or NAT conversion, and greatly enhancing the security and compliance of the system. Secondly, the application of persistent routing strategies in this solution allows key routing configurations to be automatically restored even after the front-end machine is restarted, effectively avoiding access interruptions or policy failures caused by device restarts, and ensuring the continuity and stability of network services. In addition, the security plug-in integrated in the front-end machine can not only dynamically capture and synchronize the network information of the intranet system during the access process to form messages containing important information such as the source address, but also seamlessly connect with the security authentication mechanism of the external system to achieve real-time verification and control of access requests, further strengthening the security of the communication process. Furthermore, by setting the network address of the first internal network card and the address of the external system or financial metropolitan area network as different routing prefixes, this solution cleverly avoids address conflicts, simplifies the complexity of hardware deployment, and eliminates the need for additional configuration of NAT conversion modules, thereby reducing the complexity and maintenance costs of the network structure, which is of great significance for improving the overall performance and security of the enterprise network environment.

[0085] Figure 4 Schematic diagram of the composition of the access device according to the embodiment of the present disclosure. Figure 4 As shown, the access device 400 proposed in the present disclosure includes a front-end 410 and an electronic device 420 .

[0086] The front-end processor 410 is configured with a first internal network card and a second internal network card. The first internal network card is a network interface for data interaction between the requesting entity and the external network address. The routing prefix of the network address of the first internal network card is different from the routing prefix of the external network address. The second internal network card provides a network interface for data interaction for any internal network address that is in the internal network address range and does not belong to the external network address; and an electronic device 420, which is used for the access method of any of the above embodiments to select the internal network card suitable for the target address in the front-end processor 410.

[0087] Figure 5 : is a schematic block diagram of the structure of the access device according to the embodiment of the present disclosure. Figure 5 As shown, the present disclosure proposes an access device 500, including: a policy configuration module 510, used to configure a routing policy for an external network address accessible to a requesting subject, wherein the routing policy represents the association between the external network address and the internal network card of the requesting subject; a network card selection module 520, used to respond to the requesting subject's access request to the target address, and determine a target network card suitable for the target address according to the routing policy; and an execution module 530, used to access the target address using the network address of the target network card as the source address of the requesting subject.

[0088] The access device 500 of the present disclosure may be in the form of computer software, and each module of the access device 500 may be in the form of a computer software module.

[0089] The various modules of the access device 500 disclosed in the present invention are configured to implement various steps of the access method. The execution principles and steps thereof may be referred to above and will not be described in detail here.

[0090] Figure 6 FIG. 1 is a schematic block diagram of an electronic device according to an embodiment of the present disclosure. Figure 6 As shown, the present disclosure further provides an electronic device 1000, including: a processor 1200 and a memory 1300, wherein the memory 1300 stores execution instructions; the processor 1200 executes the execution instructions stored in the memory 1300, so that the processor 1200 performs the access method. The electronic device may be the electronic device 420 in the access device 400.

[0091] The hardware structure of the electronic device 1000 can be implemented using a bus architecture. The bus architecture can include any number of interconnecting buses and bridges, depending on the specific application and overall design constraints of the hardware. The bus 1100 connects various circuits including one or more processors 1200, memory 1300, and / or hardware modules. The bus 1100 can also connect various other circuits 1400 such as peripheral devices, voltage regulators, power management circuits, external antennas, etc.

[0092] Bus 1100 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Component Architecture (EISA) bus. Buses can be classified as address buses, data buses, control buses, and the like. For ease of illustration, this figure shows only one connecting line, but this does not imply that there is only one bus or only one type of bus.

[0093] The present disclosure also provides a readable storage medium having a computer program stored therein, which is used to implement the above-mentioned method when the computer program is executed by a processor. "Readable storage medium" can be any device that can contain, store, communicate, propagate or transmit a program for use in an instruction execution system, device or equipment or in combination with these instruction execution systems, devices or equipment. More specific examples of readable storage media include the following: an electrical connection portion with one or more wirings (electronic device), a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and editable read-only memory (EPROM or flash memory), an optical fiber device, and a portable read-only memory (CDROM), etc.

[0094] The present disclosure also provides a computer program product. The method of the present disclosure can be implemented in whole or in part using software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed, the process or function of the present disclosure is performed in whole or in part.

[0095] A computer program or instruction can be stored in a readable storage medium or transferred from one readable storage medium to another. For example, the computer program or instruction can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The readable storage medium can be any accessible medium or a data storage device such as a server or data center that integrates one or more accessible media. The accessible medium can be a magnetic medium such as a floppy disk, hard disk, or magnetic tape; an optical medium such as a digital video disk; or a semiconductor medium such as a solid-state drive. The computer-readable storage medium can be a volatile or non-volatile storage medium, or can include both volatile and non-volatile types of storage media.

[0096] Those skilled in the art will appreciate that embodiments of the present disclosure may be provided as methods, electronic devices, readable storage media, or computer program products. Therefore, the present disclosure may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present disclosure may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0097] The present disclosure is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present disclosure. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0098] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0099] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0100] In the description of this specification, the description with reference to the terms "one embodiment / method", "some embodiments / methods", "example", "specific example", or "some examples" means that the specific features, structures, or characteristics described in conjunction with the embodiment / method or example are included in at least one embodiment / method or example of the present disclosure. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiment / method or example. Moreover, the specific features, structures, or characteristics described may be combined in a suitable manner in any one or more embodiments / methods or examples. In addition, those skilled in the art may combine and combine different embodiments / methods or examples described in this specification and the features of different embodiments / methods or examples, unless they are contradictory.

[0101] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one such feature. Throughout the present disclosure, "plurality" means at least two, such as two, three, etc., unless otherwise specifically defined.

[0102] Those skilled in the art will appreciate that the above embodiments are merely intended to clearly illustrate the present disclosure and are not intended to limit the scope of the present disclosure. Other changes or modifications may be made based on the above disclosure, and such changes or modifications are still within the scope of the present disclosure.

Claims

1. An access method, characterized in that: include: Configuring a routing policy for an external network address accessible to the requesting subject, wherein the routing policy represents an association between the external network address and the internal network card of the requesting subject; In response to the access request of the request subject to the target address, determining a target network card suitable for the target address according to the routing policy; as well as The target address is accessed by using the network address of the target network card as the source address of the request body.

2. The access method according to claim 1, wherein: Configure routing policies for external addresses accessible to the request subject, including: Determining a first routing policy associated with the external network address and a first internal network card, wherein the first internal network card is a network interface for the requesting subject to exchange data with the external network address, and a routing prefix of the network address of the first internal network card is different from a routing prefix of the external network address; and A second routing policy is determined that is associated between the intranet address interval of the request subject and a second internal network card, wherein the second internal network card provides a network interface for data interaction for any network address that is in the intranet address interval and different from an external network address.

3. The access method according to claim 2, wherein: In response to the access request of the request subject to the target address, determining a target network card suitable for the target address according to the routing policy, including: Based on the routing policy, when the target address is the external network address, using the first internal network card as the target network card; and When the target address is within the intranet address range and does not belong to any intranet address of the external network address, the second internal network card is used as the target network card.

4. The access method according to claim 1 or 2, characterized in that: After configuring routing policies for external addresses accessible to the request subject, also include: A persistence flag is configured for the routing policy, wherein the routing policy with the persistence flag is in a valid state after the front-end processor running the routing policy is restarted.

5. The access method according to claim 1, wherein: Also includes: The security plug-in of the front-end processor triggered by the access request reads network information of the network system where the front-end processor is located, and generates a message including the network address of the target network card.

6. The access method according to claim 5, characterized in that After accessing the target address using the network address of the target network card as the source address of the request subject, the method includes: The message is verified by the security authentication network corresponding to the target address to determine the access validity of the source address.

7. The access method according to claim 6, characterized in that: The security authentication network corresponding to the target address verifies the message to determine the access validity of the source address, including: Determining whether the network address in the message is recorded in the registered address database of the security authentication network; and If the network address is recorded in the registered address library, the access validity of the source address is determined to be valid; or if the network address is not recorded in the registered address library, the access validity of the source address is determined to be invalid.

8. An access device, characterized in that: include: A front-end processor, wherein the front-end processor is configured with a first internal network card and a second internal network card, wherein the first internal network card is a network interface for data exchange between a requesting entity and an external network address, the routing prefix of the network address of the first internal network card is different from the routing prefix of the external network address, and the second internal network card provides a network interface for data exchange for any internal network address that is within the internal network address range and does not belong to the external network address; as well as An electronic device, configured to execute the access method according to any one of claims 1 to 7, so as to select an internal network card in the front-end processor that is adapted to the target address.

9. An electronic device, characterized in that: include: a memory storing execution instructions; as well as A processor, wherein the processor executes the execution instruction stored in the memory, so that the processor executes the access method according to any one of claims 1 to 7.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the access method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Method and device for automatically solving IP network segment conflict

    CN105577853A

  • Communication method and electronic equipment

    CN110572817A

  • Network access method and device

    CN114363031A

  • Service routing method and device

    CN115250289A

  • Terminal external connection detection method and device, electronic equipment and storage medium

    CN116155549A