VPN access method and device, electronic equipment and storage medium

By introducing a hook plug-in mechanism in the VPN gateway and configuring a customized hook plug-in by the administrator, the problem of non-customizability of the VPN access process is solved, and the administrator can independently control the VPN access process and improve security.

CN120692113APending Publication Date: 2025-09-23TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410339607.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-22
Publication Date
2025-09-23

AI Technical Summary

Technical Problem

In the existing technology, the process of VPN client accessing the gateway is fixed and cannot be modified, lacks customization capabilities, and the management party cannot intervene or perform necessary approval and blocking operations, which poses a security risk.

Method used

The hook plug-in mechanism is introduced. By configuring the administrator's customized hook plug-in in the VPN gateway, the corresponding plug-in is called according to the VPN access stage to execute the administrator's pre-configured operations, thereby realizing a customized VPN access process.

Benefits of technology

It enables the administrator to independently control the VPN access process, improves security and flexibility, meets the personalized demands of different administrators, and avoids security risks caused by uploading sensitive data to the cloud.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120692113A_ABST
    Figure CN120692113A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a VPN access method and device, electronic equipment and a computer readable storage medium, and relates to the technical field of cloud. The method is applied to a VPN gateway and comprises the following steps: receiving a request related to access to a VPN, and determining a VPN access stage in which a VPN client is currently located according to the request and a current state node of a state machine; if it is determined that the target hook plug-in corresponding to the target VPN access stage is started, calling the target hook plug-in to process the request, and updating a state node of a state machine according to an obtained calling result; a management party related to a VPN client pre-configures a reference hook plug-in corresponding to at least one VPN access stage in a VPN access process in a VPN gateway; and each reference hook plug-in is used for executing operation related to the corresponding VPN access phase. According to the embodiment of the invention, a customized VPN access process can be realized, and personalized demands of different managers on the access process can be met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of cloud technology, and more specifically, to a VPN access method, device, electronic device, computer-readable storage medium, and computer program product. Background Art

[0002] With the rise of mobile office, there has been an increasing demand for accessing cloud VPC resources through mobile devices in recent years. Users use OpenVPN clients to establish secure encrypted tunnels with OpenVPN-based cloud gateways.

[0003] In related technologies, VPN clients access gateways to establish tunnels to access private resources, but the access process is fixed and cannot be modified, lacking customization capabilities. VPN client administrators cannot intervene or perform necessary approvals, blocking, and other operations. Summary of the Invention

[0004] The embodiments of the present application provide a VPN access method, apparatus, electronic device, computer-readable storage medium, and computer program product, which can implement a customized VPN access process and address the personalized access process requirements of different management parties.

[0005] In a first aspect, an embodiment of the present application provides a VPN access method, applied to a VPN gateway, the method comprising:

[0006] receiving a request related to accessing a VPN, and determining a current VPN access stage of the VPN client based on the request and a current state node of the state machine;

[0007] If it is determined to enable the target hook plug-in corresponding to the current VPN access stage, calling the target hook plug-in to process the request, and updating the state node of the state machine according to the obtained calling result;

[0008] The state node of the state machine is used to record the state of the security link corresponding to the VPN client;

[0009] The VPN client-related management party pre-configures a reference hook plug-in corresponding to at least one VPN access stage in the VPN access process in the VPN gateway;

[0010] Each reference hook plug-in is used to perform operations related to a corresponding VPN access phase, and the target hook plug-in belongs to the reference hook plug-in.

[0011] In a second aspect, an embodiment of the present application provides a VPN access device, which is applied to a VPN gateway. The device includes:

[0012] a stage determination module configured to receive a request related to VPN access and determine the VPN access stage currently in which the VPN client is located based on the request and a current state node of a state machine; the state node of the state machine is configured to record the state of a security link corresponding to the VPN client;

[0013] A plug-in calling module is configured to, if it is determined that a target hook plug-in corresponding to the current VPN access stage is enabled, call the target hook plug-in to process the request, and update the state node of the state machine according to the obtained call result;

[0014] The VPN client-related management party pre-configures a reference hook plug-in corresponding to at least one VPN access stage in the VPN access process in the VPN gateway;

[0015] Each reference hook plug-in is used to perform operations related to a corresponding VPN access phase, and the target hook plug-in belongs to the reference hook plug-in.

[0016] As an optional implementation, the VPN access phase in the VPN access process includes:

[0017] The secure link establishment phase refers to the phase of establishing a secure link between the VPN client and the VPN gateway;

[0018] The identity authentication phase refers to the phase of authenticating the user of the VPN client;

[0019] The security link control phase refers to the phase of controlling the security link;

[0020] The state nodes of the state machine in the VPN access process include:

[0021] A first status node is used to indicate that a secure link between the VPN client and the VPN gateway is not established;

[0022] A second status node is used to indicate that a secure link between the VPN client and the VPN gateway has been established;

[0023] The third status node is used to indicate that the user of the VPN client has passed authentication.

[0024] As an optional implementation, each reference hook plug-in includes a corresponding cloud function, where the cloud function is used to describe the execution logic of the target cloud service;

[0025] The reference hook plug-in performs operations related to the corresponding VPN access phase, including: interacting with the corresponding target cloud service according to the execution logic described by the cloud function;

[0026] The target cloud service is a cloud service configured by the management party in a trusted environment outside the gateway and related to the corresponding VPN stage.

[0027] As an optional implementation, each reference hook plug-in further includes a corresponding console API interface, VPN controller, and API call instance;

[0028] The console API interface is used to receive the parameters of the cloud function configured by the management party and edit the cloud function according to the parameters;

[0029] The VPN controller is configured to, when determining to enable a target hook plug-in corresponding to the current VPN access stage, call a cloud function corresponding to the target hook plug-in;

[0030] The API call instance is used to indicate a method for calling the cloud function corresponding to the target hook plug-in.

[0031] As an optional implementation, the stage determination module is specifically configured to:

[0032] receiving a security negotiation request sent by a VPN client, wherein the security negotiation request is used to request establishment of a secure link, and the security negotiation request includes a handshake packet to be authenticated;

[0033] According to the current state node being the first state node and the security negotiation request including the handshake packet, determining that the current VPN access phase is the secure link establishment phase;

[0034] Among them, the target hook plug-in corresponding to the secure link establishment phase is the first hook plug-in, which is used to call the link establishment service pre-built by the management party outside the VPN gateway, and establish a secure link between the VPN client and the gateway according to the handshake packet.

[0035] As an optional implementation manner, the plug-in calling module calls the target hook plug-in to process the request, including:

[0036] Calling the first hook plug-in to transparently transmit the handshake packet to the link establishment service to establish a secure link between the VPN client and the VPN gateway;

[0037] The first hook plug-in is called to receive a result indicating that the secure link establishment is complete, which is returned by the link establishment service, and the result is transparently transmitted to the VPN client.

[0038] As an optional implementation, the stage determination module is specifically configured to:

[0039] receiving an authentication request sent by the VPN client, the authentication request being used to request authentication of a user of the VPN end, the authentication request including user information to be authenticated;

[0040] According to the current state node being the second state node and receiving the authentication request, determining that the current VPN access phase is a VPN authentication phase;

[0041] The target hook plug-in corresponding to the VPN authentication stage is a second hook plug-in, and the second hook plug-in is used to call the authentication service pre-built by the management party and determine whether the VPN client passes the VPN authentication according to the user information.

[0042] As an optional implementation, the stage determination module is specifically configured to:

[0043] receiving a re-access request sent by the management party, wherein the re-access request is used to request reconnection of a secure link established by the VPN client or re-authentication of user information of the client;

[0044] According to the current state node being the third state node and receiving the re-access request, determining that the current VPN access phase is a secure link control phase;

[0045] The target hook plug-in corresponding to the secure link control phase is the third hook plug-in, and the third hook plug-in is used to call the link control service pre-built by the management room to control the connected secure link.

[0046] In a third aspect, an embodiment of the present application provides an electronic device, which includes a memory, a processor, and a computer program stored in the memory, and the processor executes the computer program to implement the above-mentioned VPN access method.

[0047] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which implements the above-mentioned VPN access method when the computer program is executed by a processor.

[0048] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which implements the above-mentioned VPN access method when executed by a processor.

[0049] In the embodiment of the present application, the administrator pre-configures a reference hook plug-in in the VPN gateway, and the administrator also independently decides whether to enable it. The reference hook plug-in is used to perform operations related to the corresponding VPN access stage. If it is determined to enable the target hook plug-in corresponding to the current VPN access stage, the target hook plug-in is called to perform the operations pre-configured by the administrator, thereby enabling the administrator to independently control the VPN access process. In the embodiment of the present application, by setting the correspondence between the VPN access stage and the hook plug-in, since the hook plug-in is independently configured by the administrator of the VPN client, by defining the VPN access stage, a customized VPN access process can be implemented to meet the personalized demands of different administrators for the access process. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 Schematic diagram of the system architecture for implementing VPN access provided in an embodiment of the present application;

[0051] Figure 2 A schematic diagram of the overall concept of a VPN access method provided in an embodiment of the present application;

[0052] Figure 3 A flowchart of a VPN access method provided in an embodiment of the present application;

[0053] Figure 4 A schematic diagram of the relationship between a state machine and a VPN access phase provided in an embodiment of the present application;

[0054] Figure 5 An architectural diagram of a hook plug-in provided in an embodiment of the present application;

[0055] Figure 6A Interaction diagrams for establishing secure links for related technologies;

[0056] Figure 6B Interactive diagram for establishing a secure link provided in an embodiment of the present application

[0057] Figure 7A A schematic diagram of a process flow for establishing a secure link provided in an embodiment of the present application;

[0058] Figure 7B A schematic diagram of a process flow for establishing a secure link provided in an embodiment of the present application;

[0059] Figure 7C A schematic diagram of a process flow for establishing a secure link provided in an embodiment of the present application;

[0060] Figure 8 A schematic diagram of the structure of a VPN access device provided in an embodiment of the present application;

[0061] Figure 9 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0062] The following describes the embodiments of the present application in conjunction with the drawings in the present application.

[0063] Those skilled in the art will understand that, unless otherwise stated, the singular forms "a", "an" and "the" used herein may also include plural forms. It should be further understood that the terms "including" and "comprising" used in the embodiments of the present application mean that the corresponding features can be implemented as the presented features, information, data, steps, operations, elements and / or components, but do not exclude implementation as other features, information, data, steps, operations, elements, components and / or combinations thereof supported by the present technical field. It should be understood that when we say that an element is "connected" or "coupled" to another element, the element can be directly connected or coupled to the other element, or it can refer to that the element and the other element establish a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used here can include wireless connection or wireless coupling. The term "and / or" used here indicates at least one of the items defined by the term, for example, "A and / or B" can be implemented as "A", or as "B", or as "A and B".

[0064] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0065] First, several terms involved in this application are introduced and explained:

[0066] 1) Virtual Private Network (VPN)

[0067] VPNs establish a secure, encrypted connection over public networks, allowing users to access the internet securely and privately. A VPN encrypts user data transmission, making it difficult to eavesdrop on even unsecured public Wi-Fi networks. VPNs can also be used to hide a user's true IP address, providing anonymity and enabling them to bypass geographic restrictions or access restricted websites. VPNs are often used to protect personal privacy, strengthen network security, and enable remote access to internal network resources.

[0068] 2) VPN instance

[0069] An OpenVPN server process or container running on a Linux host.

[0070] 3) VPN Terminal

[0071] A hardware or software device that runs an OpenVPN Client process or container, used to connect to a VPN cluster and establish a VPN virtual private tunnel.

[0072] 4) Secure Sockets Layer (SSL)

[0073] It is a commonly used encryption protocol for secure communications on computer networks. SSL establishes a secure, encrypted connection between two communicating parties, ensuring that data cannot be eavesdropped or tampered with during transmission. The SSL protocol is commonly used to protect data transmission on websites, such as in online shopping and online banking, where confidentiality and integrity are crucial. SSL has been superseded by its upgraded version, Transport Layer Security (TLS), and is therefore often referred to as TLS.

[0074] 5) Hook Functions are predefined functions in software development that can be extended or modified by users. These functions are typically associated with specific events or conditions. When these events or conditions occur, the system automatically calls the corresponding hook plugin, allowing users to insert customized logic or processing at specific points in time. Hook plugins are commonly used in various programming languages ​​and frameworks, such as front-end and back-end frameworks in web development and version control systems.

[0075] 6) Callback points are typically defined within software design, allowing users to register and invoke custom callback functions at specific times or under specific conditions. When program execution reaches these callback points, the corresponding callback functions are triggered, implementing the user-defined logic. Callback points are commonly used in event-driven programming models, such as graphical user interfaces (GUIs), network communications, and asynchronous operations.

[0076] Hook plug-ins and callback points are mechanisms used to implement customized logic and functionality in software development. They provide users with flexibility and scalability, allowing the system to be customized according to specific needs.

[0077] 7) Cloud technology: A general term for network technology, information technology, integration technology, management platform technology, and application technology based on the cloud computing business model. This technology forms a resource pool, enabling flexible and convenient on-demand access. Cloud computing technology will become a crucial support. Backend services for technical network systems, such as those for video sites, image sites, and more portals, require significant computing and storage resources. With the rapid development and application of the internet industry, every item will likely have its own unique identifier, requiring transmission to backend systems for logical processing. Data of varying levels will be processed separately, requiring robust system support across all industries, a reality only possible through cloud computing.

[0078] In existing implementations, tenant administrators must escrow their authentication certificates and keys with a cloud gateway. This sensitive data migration to the cloud poses serious security risks, such as data leakage. Furthermore, if an enterprise employee using VPN to access a private VPC experiences a security vulnerability on their terminal or account, the tenant administrator cannot reauthenticate their client. For enterprise tenants with high security requirements, current VPN gateway products struggle to meet their demands.

[0079] The embodiment of the present application introduces a callback hook plug-in-based identity authentication framework (Hook-based Authentication Framework, HAF security framework) to enable VPN to be integrated into the tenant's global security solution, to meet the above security demands, and to enhance customer security confidence. By providing a custom callback hook plug-in, at key nodes in the VPN life cycle, based on the hook mechanism, it supports tenant custom processes. When the security situation of the enterprise employee terminal or account changes, the tenant can re-initiate authentication for the client; decouple the authentication process, support tenant sensitive data not to be uploaded to the cloud, and provide fully customized authentication authorization.

[0080] The VPN access method, apparatus, electronic device, computer-readable storage medium, and computer program product provided in this application are intended to solve the above technical problems in the prior art.

[0081] The following describes several exemplary embodiments to illustrate the technical solutions of the embodiments of the present application and the technical effects produced by the technical solutions of the present application. It should be noted that the following embodiments can refer to, draw on, or combine with each other, and the same terms, similar features, and similar implementation steps in different embodiments will not be repeated.

[0082] Figure 1 A schematic diagram of a system architecture for implementing VPN access provided in an embodiment of the present application, wherein the system architecture includes a client 110, a VPN gateway server 120, a private cloud server 130, and an authentication server 140.

[0083] In the embodiments of the present application, client 110 includes, but is not limited to, mobile phones, tablets, laptops, desktop computers, intelligent voice interaction devices, in-vehicle terminals, and other devices with display capabilities. A VPN application can be installed on client 110. This VPN application can be either client software or browser software. The target user accesses private cloud server 130 by entering their account and password in the VPN application installed on client 110. VPN gateway server 120 is a server dedicated to VPN access. Private cloud server 130 can be built from multiple servers. Verification server 150 includes cloud services customized by VPN tenants and related to the corresponding VPN phase.

[0084] The above-mentioned types of servers can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), as well as big data and artificial intelligence platforms.

[0085] The VPN access method in the embodiment of the present application can be performed by Figure 1 The client 110, VPN gateway server 120, and verification server 140 in the example above are jointly executed. In specific implementations, when a target user accesses resources on private cloud server 130 through client 110, they enter the VPN account and password for accessing private cloud server 130 on client 110 and send a request to VPN gateway server 120 via the internet. VPN gateway server 120, following a pre-configured protocol, encapsulates the VPN account, password, and request into a message and sends it to verification server 140. Upon receiving the message, verification server 140 performs VPN access based on the pre-configured cloud service.

[0086] It should be noted that Figure 1 The figures are only examples. In fact, the number of clients and servers is not limited and is not specifically limited in the embodiments of this application.

[0087] Figure 2A schematic diagram of the overall concept of the VPN access method provided in an embodiment of the present application. As shown in the figure, the gateway of the embodiment of the present application provides multiple hook plug-ins customized by the administrator of the VPN client. These hook plug-ins correspond to multiple key stages in the VPN access process - the pre-authentication stage, the mid-authentication stage and the post-authentication stage. In the embodiment of the present application, the administrator independently decides whether to enable the hook plug-in for each stage. When the VPN end enters any stage where a hook plug-in is defined, it will determine whether the corresponding hook plug-in is enabled. If so, the corresponding hook plug-in is called to execute the operation customized by the administrator. If not, the default operation is executed. Among them, the pre-authentication stage is also the secure link establishment stage, which is Refers to the stage of establishing a secure link between the VPN client and the gateway. After this stage is completed, it naturally enters the identity authentication stage, which is to authenticate the VPN client, that is, to determine whether the identity of the user of the VPN client is appropriate. If the authentication is passed, the post-identity authentication stage, if the corresponding hook plug-in is not enabled in this stage, enters the secure link control stage, the VPN client can access the VPN network normally through the secure link, the gateway can control the secure link according to the preset control rules, if the corresponding hook plug-in is enabled, then through the corresponding hook plug-in, the management party uses the customized control method to control the life cycle of the secure link, such as disconnecting the secure link, reconnecting the secure link or re-authenticating. The VPN access method of the embodiment of the present application is aimed at

[0088] The present application provides a VPN access method, such as Figure 3 As shown, the method includes:

[0089] S101: Receive a request related to accessing a VPN, and determine the VPN access phase currently in which the VPN client is located based on the request and a current state node of a state machine.

[0090] When performing VPN access, the embodiment of the present application continuously determines the VPN access stage that the VPN client is currently in. The embodiment of the present application can divide the VPN access process into three stages, namely, the secure link establishment stage, the identity authentication stage, and the secure link control stage. The secure link establishment stage refers to the stage of establishing a secure link between the VPN client and the gateway. When the secure link establishment stage is completed, it is considered to enter the identity authentication stage. The identity authentication stage refers to the stage of authenticating the user of the VPN client. A common method is to perform identity authentication through facial recognition. After the identity authentication is successful, it is considered to enter the secure link control stage. In this stage, the secure link can be maintained or closed.

[0091] In some embodiments, embodiments of the present application pre-set a state machine within the gateway. The state machine includes multiple state nodes, each of which is used to record different states of the secure link corresponding to the VPN client, such as disconnected state, connected state, etc. The state machine of embodiments of the present application is updated after the target hook plug-in corresponding to each VPN access stage processes a request. The updated state node is related to the VPN access stage of the VPN client after executing the request.

[0092] In the embodiment of the present application, when determining the current VPN access stage of the VPN client, the determination is made based on the currently received request related to VPN access and the current state node of the state machine. Determining the current VPN access stage based on information from two dimensions can improve the accuracy of VPN access processing.

[0093] The request related to accessing VPN in the embodiment of the present application can be a request for requesting to establish a secure connection, a request for requesting to authenticate a VPN client, or a request for disconnecting a secure connection, etc., which is not specifically limited in the embodiment of the present application.

[0094] S102: If it is determined to enable the target hook plug-in corresponding to the current VPN access stage, the target hook plug-in is called to process the request, and the state node of the state machine is updated according to the obtained call result.

[0095] In order to solve the problem in the related art that the administrator cannot intervene in or customize the VPN access process, in the embodiment of the present application, the administrator pre-configures a reference hook plug-in in the VPN gateway, and the administrator also has the autonomy to decide whether to enable it. The reference hook plug-in is used to perform operations related to the corresponding VPN access stage. If it is determined to enable the target hook plug-in corresponding to the current VPN access stage, the target hook plug-in is called to perform the operations pre-configured by the administrator, thereby enabling the administrator to independently control the VPN access process. By setting the corresponding relationship between the VPN access stage and the hook plug-in, the embodiment of the present application, since the hook plug-in is independently configured by the administrator of the VPN client, can achieve a customized VPN access process by defining the VPN access stage and responding to the personalized demands of different administrators for the access process.

[0096] Based on the above embodiments, as an optional embodiment, the VPN access phase in the VPN access process includes:

[0097] The secure link establishment phase refers to the phase of establishing a secure link between the VPN client and the VPN gateway;

[0098] The identity authentication phase refers to the phase of authenticating the user of the VPN client;

[0099] The security link control phase refers to the phase for controlling the security link.

[0100] The state nodes of the state machine in the embodiment of the present application include:

[0101] A first status node is used to indicate that a secure link between the VPN client and the VPN gateway is not established;

[0102] A second status node is used to indicate that a secure link between the VPN client and the VPN gateway has been established;

[0103] The third status node is used to indicate that the user of the VPN client has passed authentication.

[0104] See Figure 4 , which exemplarily shows a schematic diagram of the relationship between the state machine and the VPN access stage of an embodiment of the present application. As shown in the figure, when the state machine is in the first state node, it means that a secure link has not been established between the VPN client and the VPN gateway at this time. After entering the secure link establishment stage, if the secure link is successfully established, the state machine is updated to the second state node. After entering the identity authentication stage, if the identity authentication is successful, the VPN client can access the VPN normally, and the state machine is updated to the third state node. After entering the secure link control stage, the VPN client may be required to re-establish the secure link or may be required to re-authenticate. Therefore, according to different situations, the state machine will be updated to the first state node or the second state node. Similarly, the VPN access stage will also be updated to the secure link stage or the identity authentication stage.

[0105] Based on the above embodiments, as an optional embodiment, each reference hook plug-in includes a corresponding cloud function, and the cloud function is used to describe the execution logic of the target cloud service.

[0106] Each reference hook plug-in in the embodiment of the present application includes a corresponding cloud function. There is a corresponding relationship between the cloud function and the cloud service. Taking into account the possible security risks caused by hosting sensitive information related to establishing a secure link on the gateway side, the management party of the embodiment of the present application configures at least one cloud service in a trusted environment outside the gateway, which solves the above problem and also facilitates the management party to manage the cloud service.

[0107] It should be understood that each cloud service in the embodiments of the present application corresponds to a VPN phase. Furthermore, since the reference hook plugin also corresponds to a VPN phase, the cloud functions included in each reference hook plugin are used to describe the cloud services associated with the corresponding VPN phase. For example, if there are three VPN access phases, VPN phases 1 to 3, then VPN phase 1 corresponds to target cloud service 1, VPN phase 2 corresponds to target cloud service 2, and VPN phase 3 corresponds to target cloud service 3.

[0108] Based on the above embodiments, as an optional embodiment, each reference hook plug-in further includes a corresponding console API interface, a VPN controller, and an API call instance.

[0109] The console API interface is used to receive the parameters of the cloud function configured by the management party and edit the cloud function according to the parameters.

[0110] The embodiment of the present application can provide the administrator with a front-end interface for configuring cloud functions. The administrator configures the parameters of the cloud function on the front-end interface. The configured parameters will be received by the console API interface, and the cloud function will be edited by the console API interface.

[0111] The VPN controller is configured to, upon determining to enable a target hook plug-in corresponding to the current VPN access stage, call a cloud function corresponding to the target hook plug-in. The VPN gateway is located within the VPN intranet, and upon determining to call the target hook function, transparently transmits a message to the VPN controller and calls the cloud function.

[0112] The API call instance is used to indicate the method of calling the cloud function corresponding to the target hook plug-in. The VPN gateway does not call the cloud function directly, but calls the cloud function corresponding to the target hook plug-in through the API call instance.

[0113] See Figure 5 , which exemplarily shows the architecture diagram of the hook plug-in provided in an embodiment of the present application. As shown in the figure, when the VPN gateway receives a request, the VPN gateway determines the current VPN access stage and the corresponding target hook plug-in based on the request and the current state node of the state machine. If the management party enables the corresponding target hook plug-in through the console API interface, the VPN controller of the target hook plug-in obtains the method of calling the cloud function corresponding to the target hook plug-in from the API call instance, calls the cloud function of the target hook plug-in based on this method, and calls the corresponding target cloud service based on the execution logic described by the cloud function.

[0114] See Figure 6AThe figure illustrates an interactive diagram of establishing a secure link using related technologies. As shown in the figure, before establishing a secure tunnel, the gateway and the client exchange handshake messages, authenticate each other, and then negotiate to establish a secure link. Because the certificates, secret keys, and other information required for authentication in related technologies are stored on the VPN gateway side, during the handshake, the VPN gateway sends the certificate to the VPN client. The VPN client verifies the certificate using its local private key. If the verification passes, the client's certificate is sent to the VPN gateway. The gateway then verifies the client's certificate using its local private key. If the verification passes, a secure link is established, and the client can subsequently conduct encrypted communications through this secure link.

[0115] Based on the above embodiments, as an optional embodiment, the embodiment of the present application receives a request related to accessing a VPN, and determines the current VPN access stage of the VPN client based on the request and the current state node of the state machine, including:

[0116] receiving a security negotiation request sent by a VPN client, wherein the security negotiation request is used to request establishment of a secure link, and the security negotiation request includes a handshake packet to be authenticated;

[0117] According to the fact that the current state node is the first state node and the security negotiation request includes a handshake packet, it is determined that the current VPN access phase is the SSL secure link establishment phase.

[0118] When the VPN client of the embodiment of the present application intends to access the VPN, it will send a security negotiation request to the VPN gateway. The request is used to request the VPN gateway to establish a secure link. The secure link of the embodiment of the present application can be an SSL secure link or a TSL secure link. The secure write request includes a handshake packet to be authenticated. The handshake packet can include information about the user of the VPN client, etc. The VPN gateway determines that the current VPN access stage is the secure link establishment stage based on the handshake packet included in the received request and the current state node of the state machine is the first state node.

[0119] The BIO (BIO I / O Abstraction) mechanism in OpenSSL is an I / O abstraction layer used to handle data input and output operations. BIO provides a unified interface that allows developers to use the same code to handle different types of data sources, such as files, sockets, and memory.

[0120] The BIO mechanism simplifies reading and writing data streams and provides support for encryption and compression. Through BIO, developers can easily implement data transmission, encryption and decryption, compression and decompression, etc., without having to directly handle the underlying data stream.

[0121] In OpenSSL, BIO can be used to build secure communication channels, perform encrypted communications, and process certificates. Developers can use the BIO interface to manage different types of data streams, thereby implementing flexible and secure data processing capabilities. OpenSSL's BIO mechanism provides a convenient and scalable way to handle various data input and output operations and is an important and powerful functional module in OpenSSL. The embodiments of the present application can intercept handshake packets based on the BIO mechanism.

[0122] In the embodiment of the present application, the target hook plug-in corresponding to the secure link establishment phase is the first hook plug-in. The first hook plug-in is used to call the link establishment service pre-built by the management party and establish a secure link between the VPN client and the gateway according to the SSL data packet. In other words, when establishing a secure link, the first hook plug-in in the embodiment of the present application calls the service built by the management party outside the VPN gateway, specifically the link establishment service, through which the secure link between the VPN client and the gateway is established according to the handshake packet. By building a link establishment service that the management party can trust outside the gateway, on the one hand, the security of network access can be improved, and on the other hand, the specific operation of the link establishment service can be completely configured by the management party, which improves flexibility.

[0123] Based on the above embodiments, as an optional embodiment, calling the target hook plug-in to process the request includes:

[0124] Calling the first hook plug-in to transparently transmit the handshake packet to the link establishment service to establish a secure link between the VPN client and the VPN gateway;

[0125] The first hook plug-in is called to receive a result indicating that the secure link establishment is complete, which is returned by the link establishment service, and transparently transmit the result to the VPN client.

[0126] See Figure 6B, the interactive diagram of establishing a secure link provided by the embodiment of the present application is as shown in the figure. First, the client and the gateway establish a link of unknown security. The client sends a security negotiation request to the gateway. The gateway calls the first hook plug-in and transmits the handshake packet to the link establishment service. The link establishment service pre-stores the secret key, certificate and other information configured by the management party. The link establishment service transmits the server's certificate to the VPN client through the VPN gateway. The client verifies the server's certificate according to the client's private key. After the verification is successful, the VPN client sends the client's certificate to the gateway. The gateway transmits the certificate to the link establishment service. The link establishment service verifies the client's certificate according to the server's private key. If the verification is successful, a secure link is established between the client and the gateway. The link establishment service returns the verification result to the grid. Subsequently, the client and the gateway send

[0127] The embodiment of the present application can meet the VPN client manager's demand for not uploading sensitive data to the cloud. Sensitive data is stored in a database trusted by the manager himself, avoiding security leaks on the cloud. When establishing a secure link, the gateway forwards the data between the link establishment service and the client through the first hook plug-in. The gateway only performs forwarding processing throughout the process and does not participate in specific verification steps, thereby improving the manager's security trust.

[0128] It should be understood that when the gateway calls the first hook plug-in and calls the link establishment service to complete the establishment of the secure link, the gateway updates the state node in the state machine to the second state node.

[0129] See Figure 7A , which exemplarily shows a flow chart of the secure link establishment phase of an embodiment of the present application, as shown in the figure, including:

[0130] The administrator configures a trusted link establishment service outside the gateway. The link establishment service is a service that establishes a secure link between the VPN client and the VPN gateway. In addition, the administrator configures a first hook plug-in on the front end, for example, configures the parameters of the first cloud function on the front end, and the console API edits the first cloud function based on the parameters. The first cloud function describes the execution logic of the link establishment service.

[0131] The administrator enables the first hook plug-in through the VPN controller.

[0132] The gateway receives a security negotiation request sent by the VPN client, where the security negotiation request is used to request establishment of a secure link, and the security negotiation request includes a handshake packet to be authenticated;

[0133] The gateway determines that the current VPN access phase is the secure link establishment phase and the hook plug-in for the secure link establishment phase is the first hook plug-in based on the current state node being the first state node and the security negotiation request including the handshake packet.

[0134] Since the management party has pre-set the first hook plug-in to enable, the first hook plug-in can be called to process the security negotiation request. Specifically, the VPN controller calls the first cloud function according to the method of calling the first cloud function indicated by the API call instance, and interacts with the link establishment service according to the execution logic described by the first cloud function.

[0135] When the gateway receives the result indicating that the secure link establishment is complete returned by the link establishment service, the gateway transparently transmits the result to the VPN client and updates the state node of the state machine to the second state node.

[0136] Based on the above embodiments, as an optional embodiment, receiving a request related to accessing a VPN, and determining the current VPN access stage of the VPN client based on the request and a current state node of a state machine includes:

[0137] receiving an authentication request sent by the VPN client, the authentication request being used to request authentication of a user of the VPN end, the authentication request including user information to be authenticated;

[0138] According to the current state node being the second state node and receiving the authentication request, it is determined that the current VPN access phase is the VPN authentication phase.

[0139] In an embodiment of the present application, after the complete link is created, the embodiment of the present application can also configure a user authentication link, that is, only when the user of the VPN client passes the user authentication can he access the VPN normally. The user authentication of the embodiment of the present application can be based on facial information, fingerprint information, iris information, etc., and the embodiment of the present application does not impose any specific restrictions.

[0140] In an embodiment of the present application, a VPN client sends an authentication request to a gateway. The authentication request is used to request authentication of a user of the VPN end. The authentication request includes information of the user to be authenticated. When the gateway receives the authentication request and determines that the current state node is the second state node, it determines that the VPN access stage currently in which the VPN client is located is the VPN authentication stage.

[0141] The target hook plug-in corresponding to the VPN authentication stage is the second hook plug-in, which is used to call the authentication service pre-built by the management party and determine whether the VPN client passes the VPN authentication according to the user information.

[0142] See Figure 7B , which exemplarily shows a flow chart of the secure link establishment phase of an embodiment of the present application, as shown in the figure, including:

[0143] The administrator configures a trusted authentication service outside the gateway. The authentication service is a service that authenticates the current user of the VPN client. In addition, the administrator configures a second hook plug-in on the front end. For example, the administrator configures the parameters of the second cloud function on the front end. The console API edits the second cloud function based on the parameters. The second cloud function describes the execution logic of the authentication service.

[0144] The administrator enables the second hook plug-in through the VPN controller.

[0145] The gateway receives an authentication request sent by the VPN client, the authentication request being used to request authentication of the user of the VPN end, the authentication request including user information to be authenticated;

[0146] The gateway determines that the current VPN access phase is the VPN authentication phase and the hook plug-in for the VPN authentication phase is the second hook plug-in based on the current state node being the second state node and receiving the authentication request.

[0147] Since the management party has pre-set up the second hook plug-in to enable it, the second hook plug-in can be called to process the authentication request. Specifically, the VPN controller calls the second cloud function according to the method of calling the second cloud function indicated by the API call instance, and interacts with the authentication service according to the execution logic described by the second cloud function.

[0148] When the gateway receives the authentication result returned by the authentication service, the gateway transparently transmits the result to the VPN client and updates the state node of the state machine to the third state node.

[0149] Based on the above embodiments, as an optional embodiment, the authentication service of the embodiment of the present application is specifically used for any one of the following:

[0150] Sending an instruction to allow the VPN client to access VPN data;

[0151] Sending an instruction to deny the VPN client access to VPN data;

[0152] Perform multi-factor authentication (MFA) on user information.

[0153] That is, the authentication service of the embodiment of the present application can directly return a release indication or a rejection indication in response to the authentication request sent by the VPN client. Alternatively, the authentication service can first perform MFA authentication on the user information in the authentication request and then return a release or rejection indication based on the authentication result. It should be understood that if the authentication service returns a release indication, it means that the VPN client can subsequently access the VPN through the secure link. Conversely, if the authentication service returns a rejection indication, it means that the VPN client cannot subsequently access the VPN through the secure link.

[0154] Based on the above embodiments, as an optional embodiment, receiving a request related to accessing a VPN, and determining the current VPN access stage of the VPN client based on the request and a current state node of a state machine includes:

[0155] receiving a re-access request sent by the management party, wherein the re-access request is used to request reconnection of a secure link established by the VPN client or re-authentication of user information of the client;

[0156] According to the current state node being the third state node and receiving the re-access request, determining that the current VPN access phase is a secure link control phase;

[0157] The target hook plug-in corresponding to the secure link control phase is the third hook plug-in, and the third hook plug-in is used to call the link control service pre-built by the management room to control the connected secure link.

[0158] In an embodiment of the present application, when the VPN client passes the authentication, it means that the VPN client can normally access the VPN through the secure link. During the access period, the embodiment of the present application supports the management party to trigger the management of the secure link at any time through the third hook plug-in, such as instructing the VPN client to reconnect the secure link or reauthenticate the user of the VPN client.

[0159] The management party sends a re-access request to the gateway through a preset terminal. The re-access request is used to request reconnection of the secure link established by the VPN client or re-authentication of the user information of the VPN client. If it is determined that the current state node is the third state node and the re-access request is received, it is determined that the current VPN access stage is the secure link control stage.

[0160] In an embodiment of the present application, the target hook plug-in corresponding to the security link control stage is the third hook plug-in, and the third hook plug-in is used to call the link control service pre-built by the management room to control the connected security link.

[0161] See Figure 7C , which exemplarily shows a flow chart of the secure link establishment phase of an embodiment of the present application, as shown in the figure, including:

[0162] The management party configures a trusted link control service outside the gateway. The link control service is a service that controls the connected security link. In addition, the management party configures a third hook plug-in on the front end, for example, configures the parameters of the third cloud function on the front end, and the console API edits the third cloud function according to the parameters. The third cloud function describes the execution logic of the link control service.

[0163] The administrator enables the third hook plug-in through the VPN controller.

[0164] The gateway receives a re-access request sent by the VPN client, where the re-access request is used to request reconnection of the secure link established by the VPN client or re-authentication of user information of the VPN client;

[0165] The gateway determines that the current VPN access phase is the secure link control phase and the hook plug-in for the secure link control phase is the third hook plug-in based on the current state node being the third state node and receiving the re-access request.

[0166] Since the management party has pre-set the third hook plug-in to enable, the third hook plug-in can be called to process the re-access request. Specifically, the VPN controller calls the third cloud function according to the method of calling the third cloud function indicated by the API call instance, and interacts with the link control service according to the execution logic described by the third cloud function.

[0167] When the gateway receives the result of interrupting the secure link returned by the link control service, the gateway transmits the result to the VPN client so that the VPN client resends the security negotiation request, and the gateway updates the state node of the state machine to the first state node; or when the gateway receives the result of triggering re-authentication returned by the link control service, the gateway transmits the result to the VPN client so that the VPN client resends the authentication request, and the gateway updates the state node of the state machine to the second state node.

[0168] The embodiment of the present application supports that when the security status of an enterprise employee terminal or account changes, the administrator of the VPN client can re-authenticate the client and obtain more security control over the link.

[0169] The embodiment of the present application provides a VPN access device, which is applied to a VPN gateway, such as Figure 8 As shown, the VPN access device may include: a phase determination module 801 and a plug-in calling module 802, wherein:

[0170] Phase determination module 801 is configured to receive a request related to VPN access and determine the current VPN access phase of the VPN client based on the request and a current state node of a state machine; the state node of the state machine is configured to record the state of a security link corresponding to the VPN client;

[0171] The plug-in calling module 802 is configured to, if it is determined that the target hook plug-in corresponding to the current VPN access stage is enabled, call the target hook plug-in to process the request, and update the state node of the state machine according to the obtained call result;

[0172] The VPN client-related management party pre-configures a reference hook plug-in corresponding to at least one VPN access stage in the VPN access process in the VPN gateway;

[0173] Each reference hook plug-in is used to perform operations related to a corresponding VPN access phase, and the target hook plug-in belongs to the reference hook plug-in.

[0174] The device of the embodiment of the present application can execute the method provided by the embodiment of the present application, and its implementation principle is similar. The actions performed by each module in the device of each embodiment of the present application correspond to the steps in the method of each embodiment of the present application. For the detailed functional description of each module of the device, please refer to the description in the corresponding method shown in the previous text, and will not be repeated here.

[0175] As an optional implementation, the VPN access phase in the VPN access process includes:

[0176] The secure link establishment phase refers to the phase of establishing a secure link between the VPN client and the VPN gateway;

[0177] The identity authentication phase refers to the phase of authenticating the user of the VPN client;

[0178] The security link control phase refers to the phase of controlling the security link;

[0179] The state nodes of the state machine in the VPN access process include:

[0180] A first status node is used to indicate that a secure link between the VPN client and the VPN gateway is not established;

[0181] A second status node is used to indicate that a secure link between the VPN client and the VPN gateway has been established;

[0182] The third status node is used to indicate that the user of the VPN client has passed authentication.

[0183] As an optional implementation, each reference hook plug-in includes a corresponding cloud function, where the cloud function is used to describe the execution logic of the target cloud service;

[0184] The reference hook plug-in performs operations related to the corresponding VPN access phase, including: interacting with the corresponding target cloud service according to the execution logic described by the cloud function;

[0185] The target cloud service is a cloud service configured by the management party in a trusted environment outside the gateway and related to the corresponding VPN stage.

[0186] As an optional implementation, each reference hook plug-in further includes a corresponding console API interface, VPN controller, and API call instance;

[0187] The console API interface is used to receive the parameters of the cloud function configured by the management party and edit the cloud function according to the parameters;

[0188] The VPN controller is configured to, when determining to enable a target hook plug-in corresponding to the current VPN access stage, call a cloud function corresponding to the target hook plug-in;

[0189] The API call instance is used to indicate a method for calling the cloud function corresponding to the target hook plug-in.

[0190] As an optional implementation, the stage determination module is specifically configured to:

[0191] receiving a security negotiation request sent by a VPN client, wherein the security negotiation request is used to request establishment of a secure link, and the security negotiation request includes a handshake packet to be authenticated;

[0192] According to the current state node being the first state node and the security negotiation request including the handshake packet, determining that the current VPN access phase is the secure link establishment phase;

[0193] Among them, the target hook plug-in corresponding to the secure link establishment phase is the first hook plug-in, which is used to call the link establishment service pre-built by the management party outside the VPN gateway, and establish a secure link between the VPN client and the gateway according to the handshake packet.

[0194] As an optional implementation manner, the plug-in calling module calls the target hook plug-in to process the request, including:

[0195] Calling the first hook plug-in to transparently transmit the handshake packet to the link establishment service to establish a secure link between the VPN client and the VPN gateway;

[0196] The first hook plug-in is called to receive a result indicating that the secure link establishment is complete, which is returned by the link establishment service, and the result is transparently transmitted to the VPN client.

[0197] As an optional implementation, the stage determination module is specifically configured to:

[0198] receiving an authentication request sent by the VPN client, the authentication request being used to request authentication of a user of the VPN end, the authentication request including user information to be authenticated;

[0199] According to the current state node being the second state node and receiving the authentication request, determining that the current VPN access phase is a VPN authentication phase;

[0200] The target hook plug-in corresponding to the VPN authentication stage is a second hook plug-in, and the second hook plug-in is used to call the authentication service pre-built by the management party and determine whether the VPN client passes the VPN authentication according to the user information.

[0201] As an optional implementation, the stage determination module is specifically configured to:

[0202] receiving a re-access request sent by the management party, wherein the re-access request is used to request reconnection of a secure link established by the VPN client or re-authentication of user information of the client;

[0203] According to the current state node being the third state node and receiving the re-access request, determining that the current VPN access phase is a secure link control phase;

[0204] The target hook plug-in corresponding to the secure link control phase is the third hook plug-in, and the third hook plug-in is used to call the link control service pre-built by the management room to control the connected secure link.

[0205] In an embodiment of the present application, an electronic device is provided, comprising a memory, a processor, and a computer program stored on the memory, wherein the processor executes the above-mentioned computer program to implement the steps of the VPN access method. Compared with the related art, the following can be achieved: In an embodiment of the present application, the administrator pre-configures a reference hook plug-in in the VPN gateway, and the administrator also independently decides whether to enable it. The reference hook plug-in is used to perform operations related to the corresponding VPN access stage. If it is determined to enable the target hook plug-in corresponding to the current VPN access stage, the target hook plug-in is called to execute the operations pre-configured by the administrator, thereby enabling the administrator to autonomously control the VPN access process. In an embodiment of the present application, by setting the corresponding relationship between the VPN access stage and the hook plug-in, since the hook plug-in is autonomously configured by the administrator of the VPN client, by defining the VPN access stage, a customized VPN access process can be implemented to meet the personalized demands of different administrators for the access process.

[0206] In an alternative embodiment, an electronic device is provided, such as Figure 9 As shown, Figure 9 The electronic device 4000 shown includes: a processor 4001 and a memory 4003. The processor 4001 and the memory 4003 are connected, for example, via a bus 4002. Optionally, the electronic device 4000 may further include a transceiver 4004, which may be used for data exchange between the electronic device and other electronic devices, such as data transmission and / or data reception. It should be noted that in actual applications, the number of transceivers 4004 is not limited to one, and the structure of the electronic device 4000 does not constitute a limitation on the embodiments of the present application.

[0207] Processor 4001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 4001 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.

[0208] Bus 4002 may include a path for transmitting information between the aforementioned components. Bus 4002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, for example. Bus 4002 may be divided into an address bus, a data bus, a control bus, and so on. For ease of illustration, bus 4002 is represented by a single thick line in the figure, but this does not indicate that there is only one bus or only one type of bus.

[0209] The memory 4003 can be a ROM (Read Only Memory) or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory) or other types of dynamic storage devices that can store information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, optical disk storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, other magnetic storage devices, or any other medium that can be used to carry or store computer programs and can be read by a computer, without limitation here.

[0210] The memory 4003 is used to store the computer program for executing the embodiment of the present application, and the execution is controlled by the processor 4001. The processor 4001 is used to execute the computer program stored in the memory 4003 to implement the steps shown in the above method embodiment.

[0211] An embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps and corresponding contents of the aforementioned method embodiment can be implemented.

[0212] An embodiment of the present application also provides a computer program product, including a computer program, which can implement the steps and corresponding contents of the aforementioned method embodiment when executed by a processor.

[0213] The terms "first," "second," "third," "fourth," "1," "2," and the like (if any) in the specification and claims of this application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequential sequence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the application described herein can be implemented in an order other than that shown or described in the drawings.

[0214] It should be understood that, although each operation step is indicated by arrows in the flowchart of the embodiment of the present application, the order of implementation of these steps is not limited to the order indicated by the arrows. Unless otherwise clearly stated herein, in some implementation scenarios of the embodiment of the present application, the implementation steps in each flowchart can be performed in other orders according to demand. In addition, some or all of the steps in each flowchart can include multiple sub-steps or multiple stages based on actual implementation scenarios. Some or all of these sub-steps or stages can be executed at the same time, and each sub-step or stage in these sub-steps or stages can also be executed at different times respectively. Under different scenarios at the execution time, the execution order of these sub-steps or stages can be flexibly configured according to demand, and the embodiment of the present application does not limit this.

[0215] The above description is only an optional implementation method for some implementation scenarios of this application. It should be pointed out that for ordinary technicians in this technical field, without departing from the technical concept of the solution of this application, the use of other similar implementation methods based on the technical ideas of this application also falls within the protection scope of the embodiments of this application.

Claims

1. A virtual private network VPN access method, characterized in that: Applied to a VPN gateway, the method includes: receiving a request related to accessing a VPN, and determining a current VPN access phase of the VPN client based on the request and a current state node of a state machine, wherein the state node of the state machine is used to record a state of a security link corresponding to the VPN client; If it is determined to enable the target hook plug-in corresponding to the current VPN access stage, calling the target hook plug-in to process the request, and updating the state node of the state machine according to the obtained calling result; The VPN client manager pre-configures a reference hook plug-in corresponding to at least one VPN access stage in the VPN access process in the VPN gateway; Each reference hook plug-in is used to perform operations related to a corresponding VPN access phase, and the target hook plug-in belongs to the reference hook plug-in.

2. The method according to claim 1, characterized in that The VPN access phase in the VPN access process includes: The secure link establishment phase refers to the phase of establishing a secure link between the VPN client and the VPN gateway; The identity authentication phase refers to the phase of authenticating the user of the VPN client; The security link control phase refers to the phase of controlling the security link; The state nodes of the state machine in the VPN access process include: A first status node is used to indicate that a secure link between the VPN client and the VPN gateway is not established; A second status node is used to indicate that a secure link between the VPN client and the VPN gateway has been established; The third status node is used to indicate that the user of the VPN client has passed authentication.

3. The method according to claim 2, characterized in that Each reference hook plugin includes a corresponding cloud function, which is used to describe the execution logic of the target cloud service; The reference hook plugin performs operations related to the corresponding VPN access phase, including: interacting with the corresponding target cloud service according to the execution logic described by the cloud function; The target cloud service is a cloud service configured by the management party in a trusted environment outside the gateway and related to the corresponding VPN stage.

4. The method according to claim 3, characterized in that Each reference hook plugin also includes the corresponding console API interface, VPN controller, and API call examples; The console API interface is used to receive the parameters of the cloud function configured by the management party and edit the cloud function according to the parameters; The VPN controller is configured to, when determining to enable a target hook plug-in corresponding to the current VPN access stage, call a cloud function corresponding to the target hook plug-in; The API call instance is used to indicate a method for calling the cloud function corresponding to the target hook plug-in.

5. The method according to any one of claims 2 to 4, characterized in that: The receiving a request related to accessing the VPN and determining the VPN access stage currently in which the VPN client is located based on the request and a current state node of the state machine includes: receiving a security negotiation request sent by a VPN client, wherein the security negotiation request is used to request establishment of a secure link, and the security negotiation request includes a handshake packet to be authenticated; According to the current state node being the first state node and the security negotiation request including the handshake packet, determining that the current VPN access phase is the secure link establishment phase; Among them, the target hook plug-in corresponding to the secure link establishment phase is the first hook plug-in, which is used to call the link establishment service pre-built by the management party outside the VPN gateway, and establish a secure link between the VPN client and the gateway according to the handshake packet.

6. The method according to claim 5, characterized in that The calling of the target hook plug-in to process the request includes: Calling the first hook plug-in to transparently transmit the handshake packet to the link establishment service to establish a secure link between the VPN client and the VPN gateway; The first hook plug-in is called to receive a result indicating that the secure link establishment is complete, which is returned by the link establishment service, and the result is transparently transmitted to the VPN client.

7. The method according to any one of claims 2 to 4, characterized in that: The receiving a request related to accessing the VPN and determining the VPN access stage currently in which the VPN client is located based on the request and a current state node of the state machine includes: receiving an authentication request sent by the VPN client, the authentication request being used to request authentication of a user of the VPN end, the authentication request including user information to be authenticated; According to the current state node being the second state node and receiving the authentication request, determining that the current VPN access phase is a VPN authentication phase; The target hook plug-in corresponding to the VPN authentication stage is a second hook plug-in, and the second hook plug-in is used to call the authentication service pre-built by the management party and determine whether the VPN client passes the VPN authentication according to the user information.

8. The method according to any one of claims 2 to 4, characterized in that: The receiving a request related to accessing the VPN and determining the VPN access stage currently in which the VPN client is located based on the request and a current state node of the state machine includes: receiving a re-access request sent by the management party, wherein the re-access request is used to request reconnection of a secure link established by the VPN client or re-authentication of user information of the VPN client; According to the current state node being the third state node and receiving the re-access request, determining that the current VPN access phase is a secure link control phase; The target hook plug-in corresponding to the secure link control phase is the third hook plug-in, and the third hook plug-in is used to call the link control service pre-built by the management room to control the connected secure link.

9. A VPN access device, characterized in that: Applied to a VPN gateway, the device includes: a stage determination module configured to receive a request related to VPN access and determine the VPN access stage currently in which the VPN client is located based on the request and a current state node of a state machine; the state node of the state machine is configured to record the state of a security link corresponding to the VPN client; A plug-in calling module is configured to, if it is determined that a target hook plug-in corresponding to the current VPN access stage is enabled, call the target hook plug-in to process the request, and update the state node of the state machine according to the obtained call result; The VPN client-related management party pre-configures a reference hook plug-in corresponding to at least one VPN access stage in the VPN access process in the VPN gateway; Each reference hook plug-in is used to perform operations related to a corresponding VPN access phase, and the target hook plug-in belongs to the reference hook plug-in.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory, wherein: The processor executes the computer program to implement the VPN access method according to any one of claims 1 to 9.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the VPN access method according to any one of claims 1 to 9 is implemented.

12. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the VPN access method according to any one of claims 1 to 9 is implemented.