Dynamic interconnection and intercommunication method and system in heterogeneous network environment

By deploying gateways and broker clusters in a heterogeneous network environment, and using the RSocket protocol and the national cryptographic SM2 certificate for identity authentication and port mapping, the efficiency and security issues of cross-domain exchange in heterogeneous networks are solved, achieving efficient and secure dynamic interconnection and interoperability, reducing transformation costs and improving system performance.

CN121000451APending Publication Date: 2025-11-21DIGITAL CHINA INFORMATION SYST
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511168328.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-20
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

In heterogeneous network environments, cross-domain exchange cannot simultaneously meet the requirements of autonomy and controllability, security and reliability, and dynamic real-time efficiency. In particular, in cross-domain exchange scenarios involving sensitive data, traditional methods cannot guarantee the efficiency and security of data exchange.

Method used

Deploy gateways at the edge of each security domain to provide conversion from HTTP/gRPC protocol to RSocket protocol, establish a Broker cluster based on RSocket protocol, perform identity authentication through national cryptographic SM2 certificate and device fingerprint, create proxy tunnels, and use security isolation gateways for port mapping and encrypted data stream transmission to achieve long connection and back pressure control.

Benefits of technology

It enables efficient, secure, and autonomously controllable dynamic interconnection in heterogeneous network environments, reduces development and modification costs, improves the real-time performance of data exchange and system performance, simplifies inter-service calls, and enhances system docking efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000451A_ABST
    Figure CN121000451A_ABST
Patent Text Reader

Abstract

The invention provides a dynamic interconnection and intercommunication method and system in a heterogeneous network environment, and relates to the technical field of information technology application innovation, and the method comprises the steps: deploying a gateway at the edge of each security domain; a Broker cluster based on the RSocket protocol is established, and persistent connection is established between each cluster node and one security domain; a cluster node a connected with the security domain A submits a cryptographic SM2 certificate and a device fingerprint to a security isolation gatekeeper between the cluster node a and the security domain B based on an access request of a service end, and identity authentication is passed; the security isolation gatekeeper creates a proxy tunnel, and maps a random high-order port of the security domain A to a temporary open port at the security domain B side; and the security isolation gatekeeper sends an authorization connection certificate to the cluster node a, and the cluster node a transmits the encrypted framing RSocket data stream to the cluster node b connected with the security domain B to obtain a response result. According to the invention, the problems of dynamic interconnection and intercommunication and data exchange in a heterogeneous environment are solved, and the system docking efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information technology application innovation technology, and in particular to a dynamic interconnection method and system in a heterogeneous network environment. Background Technology

[0002] With the continuous advancement of information technology application innovation, domestically developed cloud computing, with its independent controllability, security, and reliability, has been widely used in key industries such as government, finance, and energy. However, in practical applications, heterogeneous scenarios often face the challenge of cross-domain exchange.

[0003] On the one hand, different heterogeneous platforms may be built on different hardware (such as domestically produced chips like Kunpeng and Phytium), operating systems (such as Kylin and Tongxin), and middleware, resulting in technological heterogeneity among the platforms. Inconsistent data formats and communication protocols increase the difficulty of cross-domain exchange and dynamic real-time interconnection. For example, business systems developed based on different operating systems have significantly different data storage structures and transmission interfaces, making it difficult to directly exchange data between different platforms.

[0004] On the other hand, for security reasons, strict access control policies and security protection mechanisms are often set up between different security domains. Traditional cross-domain exchange methods struggle to meet strict security requirements while ensuring efficient data exchange and smooth service calls. For example, in some cross-domain exchange scenarios involving sensitive data, complex encryption and authentication mechanisms are typically used to ensure data security, which can lead to high processing latency and affect the real-time performance of business operations.

[0005] Current cross-domain switching solutions are difficult to meet the requirements of autonomous control, security and reliability, and dynamic, real-time and efficient switching in heterogeneous environments. There is an urgent need for a new cross-domain switching method to solve the above problems. Summary of the Invention

[0006] To address the aforementioned issues, this invention provides a dynamic interconnection and interoperability method and system in a heterogeneous network environment. This overcomes the problems of technological heterogeneity and difficulty in balancing security and efficiency in existing technologies, enabling efficient, secure, autonomous, and controllable dynamic interconnection and interoperability of data and services between different security domains and platforms, as well as cross-domain exchange. This reduces development and modification costs and improves the real-time performance of data exchange.

[0007] To achieve the above objectives, the present invention provides a dynamic interconnection method in a heterogeneous network environment, comprising:

[0008] Gateways are deployed at the edge of each security domain, and these gateways provide conversion from the HTTP / gRPC protocol to the RSocket protocol;

[0009] Establish a Broker cluster based on the RSocket protocol, with each cluster node establishing a persistent connection with a security domain;

[0010] Cluster node a connected to security domain A submits a national cryptographic SM2 certificate and device fingerprint to the security isolation gateway between security domain B based on the access request from the business end to pass identity authentication;

[0011] The security isolation gateway creates a proxy tunnel and temporarily opens a port on the security domain B side, mapping a random high-level port of security domain A to the temporarily opened port on the security domain B side;

[0012] The security isolation gateway sends an authorization connection credential to cluster node a, and cluster node a transmits an encrypted framed RSocket data stream to cluster node b connected to security domain B.

[0013] Cluster node b forwards the encrypted framed RSocket data stream to the target service terminal in security domain B, and the target service terminal returns a response stream.

[0014] Cluster node b transmits the response stream to cluster node a, and cluster node a delivers the response result to the service terminal of security domain A.

[0015] As a further improvement of the present invention, cluster node a connected to security domain A submits a national cryptographic SM2 certificate and device fingerprint to the security isolation gateway between security domain B for identity authentication based on the access request from the service terminal; including:

[0016] The cluster node a connected to security domain A initiates a cross-domain handshake to the security isolation gateway between security domain B based on the access request from the business end.

[0017] The security isolation gateway returns a whitelist verification request to cluster node a;

[0018] The cluster node a submits the national cryptographic SM2 certificate and device fingerprint to the security isolation gateway to complete identity authentication and simultaneously achieve hardware-level trusted verification.

[0019] As a further improvement of the present invention, the security isolation gateway is equipped with a gateway preset rule that only allows binary frames containing a specific signature to pass through.

[0020] As a further improvement of the present invention, after the security isolation gateway maps the random high-order port of security domain A to the temporary open port on the side of security domain B, the cluster node b returns the tunnel ID to the security isolation gateway.

[0021] As a further improvement of the present invention, cluster node b forwards the encrypted framed RSocket data stream to the target service terminal of security domain B, including:

[0022] The cluster node b splits the data into 128KB binary frames, and each frame in the encrypted framed RSocket data stream carries the tunnel ID.

[0023] As a further improvement of the present invention, the security isolation gateway sends authorized connection credentials to cluster node a, including:

[0024] The security isolation gateway issues a session token to cluster node A, generating a one-time token as an authorized connection credential.

[0025] As a further improvement of the present invention, a network outage self-healing mechanism is provided. When data transmission is interrupted, the security domain service terminal that initiated the access request automatically retransmits the lost frame based on the network outage self-healing mechanism.

[0026] As a further improvement of the present invention, each cluster node carries and manages the connection between the two security domain service terminals, maintains long-lived connections, and processes multiplexed request and response streams on the connection.

[0027] As a further improvement of the present invention, the cluster node provides a back pressure control mechanism. The security domain B service terminal restricts the flow to input from the source through the credit value declaration processing capability, monitors the load in real time, and makes access requests queued in an orderly manner on the cluster node.

[0028] The present invention also provides a dynamic interconnection system in a heterogeneous network environment, comprising: an application deployment module, a communication connection module, an access request module, an interface call module, and a result return module;

[0029] The application deployment module is used for:

[0030] Establish a Broker cluster based on the RSocket protocol, with each cluster node establishing a persistent connection with a security domain;

[0031] Cluster node a connected to security domain A submits a national cryptographic SM2 certificate and device fingerprint to the security isolation gateway between security domain B based on the access request from the business end to pass identity authentication;

[0032] The communication connection module is used for:

[0033] The security isolation gateway is controlled to create a proxy tunnel and temporarily open a port on the security domain B side, mapping a random high-level port of security domain A to a temporarily open port on the security domain B side;

[0034] The security isolation gateway is controlled to send an authorized connection credential to cluster node a;

[0035] Control cluster node a to transmit encrypted framed RSocket data streams to cluster node b connected to security domain B;

[0036] The access request module is used for:

[0037] When a service terminal in security domain A / B calls a service terminal in security domain B / A, the calling terminal sends the service access request to the called terminal based on the connection established by the communication connection module.

[0038] The interface calling module is used for:

[0039] In security domains A and B, the business service interface is called to obtain the business request result;

[0040] The result return module is used for:

[0041] The service terminals of security domains A and B return the service request result to the requesting terminal through the connection established by the communication connection module.

[0042] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0043] This invention achieves "protocol penetration" by setting up a gateway to provide HTTP / gRPC protocol to RSocket conversion, solving application layer protocol compatibility issues. Cluster nodes achieve "network penetration," resolving data transmission in physically isolated environments. Simultaneously, long connections are established through cluster nodes, enabling dynamic interconnection in heterogeneous scenarios. Only an outbound security policy needs to be enabled to achieve synchronous response to external application requests. This solves the problem of penetrating physical isolation without compromising security, and achieving both high performance and heterogeneity compatibility in heterogeneous cross-domain scenarios. It significantly reduces the modification costs for external units to access and develop systems, improves system integration efficiency, and plays a crucial role in integration with the domestic ecosystem, security compliance, and performance optimization.

[0044] Compared with existing technologies, this invention achieves high real-time bidirectional interaction and connection reuse, and its performance (including the throughput, latency and other indicators of the entire system) far exceeds that of existing technologies. At the same time, it monitors the application service load and implements functions such as "circuit breaking" and "degradation" in bidirectional access applications to avoid excessive load on the business end in the security domain.

[0045] This invention addresses network boundary issues and simplifies inter-service calls based on Brokers. Brokers enable single nodes to handle massive connections and multiplexed streams, reducing connection overhead. Brokers also provide unified management of connection lifecycles, service routing, load balancing, and failover. Furthermore, Brokers eliminate the need for clients and servers to be aware of each other's specific locations and network topology. In high-concurrency scenarios, Broker node clusters leverage the protocol's inherent advantages such as long connections, multiplexing, and backpressure to achieve non-blocking, highly scalable network communication for business access requests, resulting in significantly improved performance and stability. Attached Figure Description

[0046] Figure 1 This is a flowchart of a dynamic interconnection method in a heterogeneous network environment disclosed in one embodiment of the present invention;

[0047] Figure 2 This is a schematic diagram illustrating the process of a business system in external unit domain A initiating a business request to a system in domain B, as disclosed in one embodiment of the present invention.

[0048] Figure 3 This is a schematic diagram illustrating the interconnection requirements in a heterogeneous network environment as disclosed in one embodiment of the present invention. Detailed Implementation

[0049] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0050] The present invention will now be described in further detail with reference to the accompanying drawings:

[0051] like Figure 1 , 2 As shown, this invention provides a dynamic interconnection method in a heterogeneous network environment, which utilizes penetration to solve the efficiency and security problems of "firewall restriction" penetration in heterogeneous cross-domain scenarios, including:

[0052] S1. Deploy gateways at the edge of each security domain. The gateways provide the conversion from HTTP / gRPC protocol to RSocket protocol.

[0053] S2. Establish a Broker cluster based on the RSocket protocol, with each cluster node establishing a persistent connection with a security domain.

[0054] in,

[0055] Broker clusters act as communication bridges between different network domains. They function as cross-domain relay hubs, resolving issues such as network limitations (firewalls, high latency, instability) and service discovery difficulties that may arise from direct cross-domain connections.

[0056] The Broker cluster provides single-node support for long-lived connections. That is, a single node can carry and manage a large number of continuous client and server connections, maintain these long-lived connections, process multiplexed request / response streams on the connections, and realize the core capabilities of connection management.

[0057] It provides access control based on national cryptographic certificates, uses SM2 certificates to replace account passwords to make identities trustworthy, uses SM4 end-to-end encryption to prevent theft, and implements minimal authorization through a dynamic policy engine to achieve core security capabilities.

[0058] It provides back pressure control to prevent low-configuration servers from overloading. The server declares its processing capacity through credit value, restricts traffic input from the source, monitors the load in real time, and queues access requests in an orderly manner at the Broker layer, realizing the core capability of traffic governance.

[0059] Provides session recovery capabilities, enabling session reconstruction within 5ms after a network outage;

[0060] The national cryptographic security gateway integrates hardware-level encryption to achieve compliance protection and follows the GM / T 0024 SSL VPN specification.

[0061] S3, such as Figure 1 As shown, cluster node a connected to security domain A submits a national cryptographic SM2 certificate and device fingerprint to the security isolation gateway between security domain B based on the access request from the business end to pass identity authentication;

[0062] in,

[0063] Cluster node a connected to security domain A initiates a cross-domain handshake to the security isolation gateway between security domain B based on the access request from the business end.

[0064] The security isolation gateway returns a whitelist verification request to cluster node a;

[0065] Cluster node a submits the national cryptographic SM2 certificate and device fingerprint to the security isolation gateway to complete identity authentication and achieve hardware-level trusted verification.

[0066] Furthermore,

[0067] The security isolation gateway has preset rules that allow only binary frames with specific signatures to pass through.

[0068] Specifically,

[0069] Perform connection initialization and device authentication: Clients in domain A authenticate their identity using the national cryptographic SM2 certificate (issued by the CA), and simultaneously implement hardware-level trusted verification; implement a network gateway whitelist mechanism, set network gateway preset rules, and only allow binary frames containing specific signatures to pass through (filtering non-protocol traffic).

[0070] S4. The security isolation gateway creates a proxy tunnel and temporarily opens a port on the security domain B side, mapping a random high-level port of security domain A to a temporarily opened port on the security domain B side.

[0071] in,

[0072] After the security isolation gateway maps a random high-order port of security domain A to a temporarily open port on the side of security domain B, cluster node b returns the tunnel ID to the security isolation gateway.

[0073] Specifically,

[0074] Establish a communication tunnel to achieve dynamic port mapping. The network gateway temporarily opens ports on the domain B side and completes the mapping of random high-order ports (such as 30000) to avoid the risk of fixed ports being exposed.

[0075] S5. The security isolation gateway sends an authorization connection credential to cluster node a, and cluster node a transmits encrypted framed RSocket data streams to cluster node b connected to security domain B.

[0076] in,

[0077] The security isolation gateway issues a session token to cluster node A, generating a one-time token (SM3 signature) with a validity period of 60 seconds, which serves as an authorized connection credential for subsequent data stream verification;

[0078] S6. Cluster node b forwards the encrypted framed RSocket data stream to the target service terminal in security domain B, and the target service terminal returns a response stream.

[0079] in,

[0080] Cluster node b splits the data into 128KB binary frames, and each frame in the encrypted RSocket data stream carries a tunnel ID.

[0081] S7. Cluster node b transmits the response stream to cluster node a, and cluster node a delivers the response result to the service terminal of security domain A.

[0082] This invention also includes a network outage self-healing mechanism. When data transmission is interrupted, the security domain service that initiated the access request automatically retransmits the lost frame (not a full reconnection) based on the network outage self-healing mechanism.

[0083] In this invention, each cluster node carries and manages the connection between the two security domain service terminals, maintains long-lived connections, and processes multiplexed request and response streams on the connection.

[0084] The present invention provides a back pressure control mechanism for cluster nodes. The security domain B service end restricts the flow to input from the source through credit value declaration processing capability, monitors the load in real time, and makes access requests queued in an orderly manner on the cluster nodes.

[0085] This invention also provides a dynamic interconnection system in a heterogeneous network environment, achieving, for example... Figure 3 The cross-domain interconnection and interoperability in the heterogeneous environment shown includes: application deployment module, communication connection module, access request module, interface call module, and result return module;

[0086] The application deployment module is used for:

[0087] Establish a Broker cluster based on the RSocket protocol, with each cluster node establishing a persistent connection with a security domain;

[0088] Cluster node a connected to security domain A submits a national cryptographic SM2 certificate and device fingerprint to the security isolation gateway between security domain B based on the access request from the business end to pass identity authentication;

[0089] Communication connection module, used for:

[0090] Control the security isolation gateway to create a proxy tunnel and temporarily open a port on the security domain B side, mapping a random high-level port of security domain A to a temporarily opened port on the security domain B side;

[0091] Control the security isolation gateway to send authorized connection credentials to cluster node a;

[0092] Control cluster node a to transmit encrypted framed RSocket data streams to cluster node b connected to security domain B;

[0093] The access request module is used for:

[0094] When a business terminal in security domain A / B calls a business terminal in security domain B / A, the calling terminal sends the business access request to the called terminal based on the connection established by the communication connection module.

[0095] The interface call module is used for:

[0096] In security domains A and B, the business service interface is called to obtain the business request result;

[0097] The result return module is used for:

[0098] The business terminals of security domains A and B return the results of their business requests to the requesting terminal through the connection established by the communication connection module.

[0099] Advantages of this invention:

[0100] This invention achieves "protocol penetration" by setting up a gateway to provide HTTP / gRPC protocol to RSocket conversion, solving application layer protocol compatibility issues. Cluster nodes achieve "network penetration," resolving data transmission in physically isolated environments. Simultaneously, long connections are established through cluster nodes, enabling dynamic interconnection in heterogeneous scenarios. Only an outbound security policy needs to be enabled to achieve synchronous response to external application requests. This solves the problem of penetrating physical isolation without compromising security, and achieving both high performance and heterogeneity compatibility in heterogeneous cross-domain scenarios. It significantly reduces the modification costs for external units to access and develop systems, improves system integration efficiency, and plays a crucial role in integration with the domestic ecosystem, security compliance, and performance optimization.

[0101] Compared with existing technologies, this invention achieves high real-time bidirectional interaction and connection reuse, and its performance (including the throughput, latency and other indicators of the entire system) far exceeds that of existing technologies. At the same time, it monitors the application service load and implements functions such as "circuit breaking" and "degradation" in bidirectional access applications to avoid excessive load on the business end in the security domain.

[0102] This invention addresses network boundary issues and simplifies inter-service calls based on Brokers. Brokers enable single nodes to handle massive connections and multiplexed streams, reducing connection overhead. Brokers also provide unified management of connection lifecycles, service routing, load balancing, and failover. Furthermore, Brokers eliminate the need for clients and servers to be aware of each other's specific locations and network topology. In high-concurrency scenarios, Broker node clusters leverage the protocol's inherent advantages such as long connections, multiplexing, and backpressure to achieve non-blocking, highly scalable network communication for business access requests, resulting in significantly improved performance and stability.

[0103] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for dynamic interconnection and interoperability in a heterogeneous network environment, characterized in that, include: Gateways are deployed at the edge of each security domain, and these gateways provide conversion from the HTTP / gRPC protocol to the RSocket protocol; Establish a Broker cluster based on the RSocket protocol, with each cluster node establishing a persistent connection with a security domain; Cluster node a connected to security domain A submits a national cryptographic SM2 certificate and device fingerprint to the security isolation gateway between security domain B based on the access request from the business end to pass identity authentication; The security isolation gateway creates a proxy tunnel and temporarily opens a port on the security domain B side, mapping a random high-level port of security domain A to the temporarily opened port on the security domain B side; The security isolation gateway sends an authorization connection credential to cluster node a, and cluster node a transmits an encrypted framed RSocket data stream to cluster node b connected to security domain B. Cluster node b forwards the encrypted framed RSocket data stream to the target service terminal in security domain B, and the target service terminal returns a response stream. Cluster node b transmits the response stream to cluster node a, and cluster node a delivers the response result to the service terminal of security domain A.

2. The dynamic interconnection method in a heterogeneous network environment according to claim 1, characterized in that: Cluster node a connected to security domain A submits its national cryptographic SM2 certificate and device fingerprint to the security isolation gateway between security domain B based on the access request from the business terminal to achieve identity authentication; including: Cluster node a connected to security domain A initiates a cross-domain handshake to the security isolation gateway between security domain B based on the access request from the business end. The security isolation gateway returns a whitelist verification request to cluster node a; The cluster node a submits the national cryptographic SM2 certificate and device fingerprint to the security isolation gateway to complete identity authentication and simultaneously achieve hardware-level trusted verification.

3. The dynamic interconnection method in a heterogeneous network environment according to claim 2, characterized in that: The security isolation gateway has preset rules that allow only binary frames with specific signatures to pass through.

4. The dynamic interconnection method in a heterogeneous network environment according to claim 1, characterized in that: After the security isolation gateway maps a random high-order port of security domain A to a temporarily open port on the side of security domain B, cluster node b returns the tunnel ID to the security isolation gateway.

5. The dynamic interconnection method in a heterogeneous network environment according to claim 4, characterized in that: Cluster node b forwards the encrypted framed RSocket data stream to the target service terminal in security domain B, including: The cluster node b splits the data into 128KB binary frames, and each frame in the encrypted framed RSocket data stream carries the tunnel ID.

6. The dynamic interconnection method in a heterogeneous network environment according to claim 1, characterized in that: The security isolation gateway sends authorized connection credentials to cluster node a, including: The security isolation gateway issues a session token to cluster node A, generating a one-time token as an authorized connection credential.

7. The dynamic interconnection method in a heterogeneous network environment according to claim 1, characterized in that: A network outage self-healing mechanism is provided. When data transmission is interrupted, the security domain service terminal that initiated the access request automatically retransmits the lost frame based on the network outage self-healing mechanism.

8. The dynamic interconnection and interoperability method in a heterogeneous network environment according to claim 1, characterized in that: Each cluster node carries and manages the connection between the two security domain service terminals, maintains long-lived connections, and processes multiplexed request and response streams on the connection.

9. The dynamic interconnection method in a heterogeneous network environment according to claim 1, characterized in that: The cluster nodes provide a backpressure control mechanism. The security domain B business end restricts the flow to input from the source through credit value declaration processing capabilities, monitors the load in real time, and ensures that access requests are queued in an orderly manner on the cluster nodes.

10. A dynamic interconnection system in a heterogeneous network environment, used to implement the dynamic interconnection method in a heterogeneous network environment as described in any one of claims 1 to 9, characterized in that: include: Application deployment module, communication connection module, access request module, interface call module, and result return module; The application deployment module is used for: Establish a Broker cluster based on the RSocket protocol, with each cluster node establishing a persistent connection with a security domain; Cluster node a connected to security domain A submits a national cryptographic SM2 certificate and device fingerprint to the security isolation gateway between security domain B based on the access request from the business end to pass identity authentication; The communication connection module is used for: The security isolation gateway is controlled to create a proxy tunnel and temporarily open a port on the security domain B side, mapping a random high-level port of security domain A to a temporarily open port on the security domain B side; The security isolation gateway is controlled to send an authorization connection credential to cluster node a; Control cluster node a to transmit encrypted framed RSocket data streams to cluster node b connected to security domain B; The access request module is used for: When a service terminal in security domain A / B calls a service terminal in security domain B / A, the calling terminal sends the service access request to the called terminal based on the connection established by the communication connection module. The interface call module is used for: In security domains A and B, the business service interface is called to obtain the business request result; The result return module is used for: The service terminals of security domains A and B return the service request result to the requesting terminal through the connection established by the communication connection module.