A VPN device communication method and device, electronic equipment and storage medium

By adding VPN device clusters to logical communication domains and automatically generating communication policies, the problems of low communication configuration efficiency and high security risks of VPN devices are solved, enabling flexible network management and efficient topology adjustment.

CN121367645BActive Publication Date: 2026-06-02WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)
Filing Date
2025-12-22
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

Existing VPN device communication configuration methods are inefficient and pose high security risks, mainly due to the complexity of configuration and frequent configuration errors caused by reliance on manual operation.

Method used

Multiple VPN device clusters can be added to a pre-created logical communication domain. The logical communication domain describes the interoperability requirements between devices and configures the network structure. The system automatically generates communication policies. Administrators only need to define the network topology, and the system automatically generates specific policies that can be recognized by the devices. It supports network topology adjustment and expansion.

Benefits of technology

It improves configuration efficiency, reduces the risk of human error, ensures the logical consistency of policies and the reliability of the network, and supports flexible network changes and expansions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121367645B_ABST
    Figure CN121367645B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of computer network communication, and specifically discloses a VPN device communication method and device, an electronic device and a storage medium, the method comprising the following steps: adding a plurality of pre-established VPN device clusters into a pre-created logical communication domain; configuring a network structure of the logical communication domain; generating a communication strategy based on the network structure; and establishing bidirectional communication between the plurality of pre-established VPN device clusters based on the communication strategy. The method can greatly reduce configuration complexity and workload, improve configuration efficiency, improve network reliability, and reduce security risks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of computer network communication technology, and more specifically, relates to a VPN device communication method, apparatus, electronic device and storage medium. Background Technology

[0002] In modern enterprise network environments, Virtual Private Network (VPN) technology has become a critical infrastructure for secure interconnection between different geographical sites. As enterprises expand and network topologies become increasingly complex, traditional VPN network management solutions heavily rely on manual operations by network administrators. This process is cumbersome and requires a high level of expertise. Changes in network topology can lead to numerous complex configuration challenges and even security risks, as detailed below:

[0003] 1. Complex policy configuration management: Administrators need to write policies for each pair of devices one by one, which is tedious, time-consuming and prone to configuration errors, leading to network connectivity problems;

[0004] 2. Communication policies are difficult to maintain: When the network topology needs to be changed, such as adding a new site, the administrator must perform a lot of repetitive manual policy adjustments. The response speed is slow and the operation and maintenance efficiency is low. Once a configuration error occurs, it may lead to security risks such as unauthorized access.

[0005] In summary, existing VPN device communication configuration methods suffer from low efficiency and high security risks. Summary of the Invention

[0006] In view of the shortcomings of the prior art, the purpose of this application is to provide a VPN device communication method, apparatus, electronic device and storage medium, which aims to solve the problems of low efficiency and high security risks caused by manual operation in the existing VPN device communication configuration methods.

[0007] To achieve the above objectives, in a first aspect, this application provides a VPN device communication method, comprising:

[0008] Add multiple pre-established VPN device clusters to a pre-created logical communication domain;

[0009] Configure the network structure of the logical communication domain;

[0010] Based on the network structure, a communication strategy is generated;

[0011] Based on the communication strategy, bidirectional communication is established between the multiple pre-established VPN device clusters.

[0012] This application adds VPN device clusters to pre-created logical communication domains. These logical communication domains describe the communication needs between VPN network devices and configure the network structure within them. The system automatically generates communication policies and establishes communication for VPN network devices added to the logical communication domain. Administrators only need to define the network topology of the logical communication domain through a visual interface, and the system automatically generates all underlying, device-recognizable specific communication policies. When the network topology needs adjustment, administrators only need to modify the network topology definition of the logical communication domain and edit the members within the domain; the system can then automatically regenerate the synchronization policy. This makes network changes flexible, fast, and easily scalable, greatly reducing configuration complexity and workload, improving configuration efficiency, and avoiding human errors that may result from manual configuration by automatically generating policies. This ensures the logical consistency and correctness of policies, improves network reliability, and reduces security risks.

[0013] According to a VPN device communication method provided in this application, configuring the network structure of the logical communication domain includes:

[0014] Configure the network structure of the logical communication domain as a mesh structure; or,

[0015] Configure the network structure of the logical communication domain as a star topology.

[0016] According to a VPN device communication method provided in this application, the step of generating a communication strategy based on the location information of the VPN device cluster in the logical communication domain and the network structure includes:

[0017] If the network structure of the logical communication domain is a mesh structure, a first communication strategy is generated, which is: to establish bidirectional communication between any two nodes within the logical communication domain; or...

[0018] If the network structure of the logical communication domain is a star structure, a second communication strategy is generated. The second communication strategy is to establish bidirectional communication between the preset central node and all remote nodes in the logical communication domain.

[0019] This application configures the logical communication domain's network structure as a mesh structure, enabling direct communication between nodes. This avoids the latency caused by all traffic rerouting around the central node, resulting in optimal path optimization. There are no single points of failure in the network. Even if any link or node fails, data packets can still reach their destination via other paths, demonstrating strong network self-healing capabilities. Configuring the logical communication domain's network structure as a star structure reduces the number of communication links required, lowering management and maintenance costs. All traffic passes through the central node, facilitating the implementation of unified security policies, traffic monitoring, data auditing, and access control. The network structure is clear, and troubleshooting is relatively simple. When adding a remote node, only a link between that node and the central node needs to be established; no changes to the configuration of existing nodes are required, resulting in strong scalability.

[0020] According to the VPN device communication method provided in this application, if the network structure of the logical communication domain is a star topology, the method further includes:

[0021] Different business systems are assigned to multiple preset central nodes;

[0022] When a remote node accesses the first business system, it prioritizes establishing a secure channel through a preset central node where the first business system is located. The first business system can be any of the different business systems.

[0023] This application achieves business-based traffic splitting by assigning different business systems to multiple preset central nodes, ensuring the performance of critical businesses. It can select the optimal path for each business system, improve resource utilization, allow multiple central nodes to carry business traffic simultaneously, and has a clear mapping relationship between business and path, which facilitates fault location and performance optimization. Adding a remote node only requires adding it to the logical communication domain, without further configuration.

[0024] According to the VPN device communication method provided in this application, if the network structure of the logical communication domain is a star topology, the method further includes:

[0025] Assign different preset center nodes to different remote nodes;

[0026] When remote nodes access data on the central side, they prioritize establishing a secure channel through the assigned preset central node.

[0027] This application achieves path-based traffic splitting by assigning different central nodes as the preferred paths to different remote nodes, which greatly reduces the complexity of operation and maintenance. The network structure is stable, the path strategy does not change with the changes in business, and it is easy to expand. When the number of remote nodes increases, the addition of a new central node is only related to the addition of a new remote node and has no impact on the original structure.

[0028] Secondly, this application provides a VPN device communication apparatus, comprising:

[0029] The join module is used to join multiple pre-established VPN device clusters into a pre-created logical communication domain;

[0030] The configuration module is used to configure the network structure of the logical communication domain;

[0031] A generation module is used to generate a communication strategy based on the network structure.

[0032] A communication establishment module is used to establish bidirectional communication between the plurality of pre-established VPN device clusters based on the communication strategy.

[0033] Thirdly, this application provides an electronic device, comprising: at least one memory for storing a program; and at least one processor for executing the program stored in the memory, wherein when the program stored in the memory is executed, the processor is configured to execute the VPN device communication method described in the first aspect or any possible implementation thereof.

[0034] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when run on a processor, causes the processor to perform the VPN device communication method described in the first aspect or any possible implementation thereof.

[0035] Fifthly, this application provides a computer program product that, when run on a processor, causes the processor to execute the VPN device communication method described in the first aspect or any possible implementation of the first aspect.

[0036] It is understood that the beneficial effects of the second to fifth aspects mentioned above can be found in the relevant descriptions in the first aspect mentioned above, and will not be repeated here.

[0037] Overall, the technical solutions conceived in this application have the following beneficial effects compared with the prior art:

[0038] This application adds VPN device clusters to pre-created logical communication domains. These logical communication domains describe the communication needs between VPN network devices and configure the network structure within them. The system automatically generates communication policies and establishes communication for VPN network devices added to the logical communication domain. Administrators only need to define the network topology of the logical communication domain through a visual interface, and the system automatically generates all underlying, device-recognizable specific communication policies. When the network topology needs adjustment, administrators only need to modify the network topology definition of the logical communication domain and edit the members within the domain; the system can then automatically regenerate the synchronization policy. This makes network changes flexible, fast, and easily scalable, greatly reducing configuration complexity and workload, improving configuration efficiency, and avoiding human errors that may result from manual configuration by automatically generating policies. This ensures the logical consistency and correctness of policies, improves network reliability, and reduces security risks. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1This is a flowchart illustrating the VPN device communication method provided in an embodiment of this application;

[0041] Figure 2 This is a flowchart of the communication strategy generation process provided in an embodiment of this application;

[0042] Figure 3 This is a schematic diagram of the network structure provided in an embodiment of this application;

[0043] Figure 4 This is a schematic diagram of the automatic adjustment process of the communication strategy provided in the embodiments of this application;

[0044] Figure 5 This is a schematic diagram of traffic splitting by service provided in an embodiment of this application;

[0045] Figure 6 This is a schematic diagram of path-based traffic splitting provided in an embodiment of this application;

[0046] Figure 7 This is a schematic diagram of the structure of the VPN device communication apparatus provided in the embodiments of this application;

[0047] Figure 8 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0048] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0049] In this article, the term "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The symbol " / " in this article indicates that the related objects are in an "or" relationship; for example, A / B means A or B.

[0050] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0051] In the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more, for example, multiple processing units means two or more processing units, multiple elements means two or more elements, etc.

[0052] Next, combined Figures 1-6 The VPN device communication method provided in the embodiments of this application is described.

[0053] Figure 1 This is a flowchart illustrating the VPN device communication method provided in an embodiment of this application, as shown below. Figure 1 As shown, the method includes the following steps:

[0054] Step S1: Add multiple pre-established VPN device clusters to a pre-created logical communication domain;

[0055] Optionally, physical or virtual devices that need to be added to the VPN network can be registered in the management center and a device cluster can be established. A cluster can contain one or more devices.

[0056] Optionally, a logical communication domain can be created, which defines the boundary scope in which the policy takes effect.

[0057] Optionally, the VPN device cluster can be added to a logical communication domain, becoming a member of the logical communication domain.

[0058] Step S2: Configure the network structure of the logical communication domain;

[0059] Optionally, the network structure of the logical communication domain is used to define the network topology of each node in the logical communication domain.

[0060] Optionally, the network architecture can be configured according to requirements.

[0061] Alternatively, network administrators can define the network topology of logical communication domains through a visual interface.

[0062] Step S3: Generate a communication strategy based on the network structure;

[0063] Once the network structure is configured, all underlying, device-recognizable specific communication policies can be automatically generated.

[0064] Figure 2 This is a flowchart of the communication strategy generation process provided in the embodiments of this application, such as... Figure 2 As shown in one embodiment of this application, the automatic communication policy generation process includes three steps: node creation, logical communication domain creation, and communication policy configuration, as detailed below:

[0065] 1a. Node creation: Register device information in the management center and manage the devices in clusters. Each cluster must contain at least one device, and a cluster is considered a node.

[0066] 2a. Logical communication domain creation: Register logical communication domain information in the management center, configure the logical communication domain network topology, add nodes to the logical communication domain, and if the logical communication domain is a star network, specify at least one central node for the logical communication domain.

[0067] 3a. Communication policy configuration: The management center automatically creates communication policies for nodes in the domain based on the logical communication domain network topology and node information within the domain, and generates communication policies for each device in the domain accordingly, and distributes them to the devices.

[0068] Step S4: Based on the communication strategy, establish bidirectional communication between multiple pre-established VPN device clusters.

[0069] Optionally, the automatically generated communication policy can be decomposed into specific devices and translated into specific configuration instructions that can be recognized and executed by the network devices, and then sent to the corresponding devices to establish bidirectional communication between devices.

[0070] The VPN device communication method provided in this application adds a cluster of VPN devices to a pre-created logical communication domain. The logical communication domain describes the interoperability requirements between VPN network devices and configures the network structure within it. It automatically generates communication policies and establishes communication for VPN network devices added to the logical communication domain. Administrators only need to define the network topology of the logical communication domain through a visual interface, and the system automatically generates all underlying, device-identifiable specific communication policies. When the network topology needs adjustment, administrators only need to modify the network topology definition of the logical communication domain and edit the members within the domain; the system can then automatically regenerate the synchronization policy. This makes network changes flexible, fast, and easily scalable, greatly reducing configuration complexity and workload, improving configuration efficiency, and avoiding human errors that may result from manual configuration by automatically generating policies. This ensures the logical consistency and correctness of policies, improves network reliability, and reduces security risks.

[0071] In some embodiments, step S2 specifically includes:

[0072] Configure the network structure of the logical communication domain as a mesh structure; or,

[0073] Configure the network structure of the logical communication domain as a star topology.

[0074] Figure 3 This is a schematic diagram of the network structure provided in the embodiments of this application, such as... Figure 3As shown, in one embodiment of this application, star network and mesh network are two important network structure templates. They serve different network application scenarios and design goals and are complementary. The network structure is: to establish bidirectional communication between any two nodes in the logical communication domain. The star structure is: to designate a central node in the logical communication domain, and the nodes other than the central node are remote nodes, and to establish bidirectional communication between the central node and all remote nodes.

[0075] In some embodiments, step S3 is specifically used for:

[0076] If the network structure of the logical communication domain is a mesh structure, a first communication strategy is generated, which is: to establish bidirectional communication between any two nodes within the logical communication domain; or...

[0077] If the network structure of the logical communication domain is a star structure, a second communication strategy is generated. The second communication strategy is to establish bidirectional communication between the preset central node and all remote nodes in the logical communication domain.

[0078] If the network structure of the logical communication domain is a mesh structure, the first communication strategy is automatically generated: establish bidirectional communication between any two nodes in the logical communication domain. If the network structure of the logical communication domain is a star structure, the second communication strategy is automatically generated: establish bidirectional communication between the preset central node and all remote nodes in the logical communication domain.

[0079] The advantages of a mesh structure are:

[0080] 1b. Extremely low latency and high performance: Direct communication between nodes avoids the latency caused by all traffic going around the central node, resulting in the optimal path;

[0081] 2b. Extremely high reliability and redundancy: There are no single points of failure in the network. Even if any link or node fails, data packets can still reach their destination through other paths, demonstrating strong self-healing capabilities.

[0082] Typical applications of mesh structures include:

[0083] 1c. Applications with extremely high real-time requirements: such as high-frequency trading systems in the financial industry, online game server clusters, real-time video rendering clusters, etc., where extremely low point-to-point latency is required between nodes;

[0084] 2c. Interconnection of core nodes of critical infrastructure: For example, establishing a full mesh connection between several core data centers in different regions to ensure that core business can continue uninterrupted in the event of any single point of failure;

[0085] 3c. Enterprise Core Campus Network: Connect key nodes such as core switches, data centers, and egress gateways to build a highly reliable enterprise network backbone.

[0086] In simple terms, mesh networks are suitable for core network scenarios with extremely high requirements for performance and reliability, and a relatively small number of nodes.

[0087] The advantages of a star-shaped structure are:

[0088] 1d. High cost-effectiveness: Minimal number of communication links required, low management and maintenance costs;

[0089] 2d. Easy to manage and centrally control: All traffic passes through the central node, facilitating the implementation of unified security policies, traffic monitoring, data auditing, and access control. The network structure is clear, and troubleshooting is relatively simple.

[0090] 3D, highly scalable: When adding a new remote node, only the link between that node and the central node needs to be established, without changing the configuration of other existing nodes.

[0091] Typical applications of star-shaped structures include:

[0092] 1e. Headquarters-Branch Architecture: This is the most classic application scenario. For example, the interconnection between a bank's headquarters data center (Hub) and various branches / sub-branches (Spokes). All communication between branches must go through headquarters to meet management and security requirements;

[0093] 2e. Data Center Interconnection: In a hybrid cloud architecture, the public cloud virtual network is connected as a branch (radius) to the local data center (Hub) to achieve interconnection between the cloud and on-premises environments;

[0094] 3e. Internet of Things (IoT): The IoT platform acts as a central node, receiving data from a massive number of distributed IoT devices (terminal nodes).

[0095] In simple terms, star networks are suitable for scenarios with obvious central radiation characteristics and an emphasis on centralized management and cost control.

[0096] Figure 4 This is a schematic diagram of the automatic adjustment process of the communication strategy provided in the embodiments of this application, such as... Figure 4 As shown, in one embodiment of this application, the automatic adjustment of the communication strategy includes four cases: topology change, node addition, node deletion, and central node adjustment, wherein:

[0097] Topology Change: When the topology is changed from star to mesh or from mesh to star, all communication policies within the domain are cleared, new communication policies are created based on the changed topology, and the communication policy configurations for all devices within the domain are updated.

[0098] Node addition: For a mesh-structured logical communication domain, add a bidirectional communication strategy between the new node and all existing nodes, issue communication strategies to devices within the new node, and update communication strategies for other devices within the domain; For a star-structured logical communication domain (considering the addition of remote nodes here, the addition of the central node is considered a central node adjustment), add a bidirectional communication strategy between the new node and the central node, issue communication strategies to devices within the new node, and update communication strategies for devices within all central nodes.

[0099] Node deletion: For a mesh logical communication domain, delete the communication policies between all remaining nodes and the deleted node, and update the communication policies for all devices in the domain; for a star logical communication domain, issue communication policies to devices within newly added nodes, update the communication policies for devices within the central node, delete the communication policies between all central nodes and the deleted node, and update the communication policies for devices within all central nodes.

[0100] Central node change: Delete the communication policy between the original central node (if any) and all remote nodes, add the communication policy between the new central node (if any) and all remote devices, and update the communication policy configuration for all devices in the domain.

[0101] In some embodiments, if the network structure of the logical communication domain is a star topology, the method further includes:

[0102] Different business systems are assigned to multiple preset central nodes;

[0103] When a remote node accesses the first business system, it prioritizes establishing a secure channel through the preset central node where the first business system is located. The first business system can be any business system among different business systems.

[0104] In core networks of financial institutions, government agencies, and large enterprises, a highly available multi-center network architecture has become a rigid requirement. This involves configuring multiple VPN devices in the data center to form multiple central nodes, with communication policies established between remote nodes and these central nodes. Simultaneously, dynamic routing protocols automatically calculate and select paths to achieve multi-path load balancing. However, core networks typically require firewalls to ensure network security. Firewalls generally operate based on stateful monitoring mechanisms, which have strict requirements for session consistency. Specifically, for any Transmission Control Protocol (TCP), User Datagram Protocol (UDP), or Internet Control Message Protocol (ICMP) session, all request and response packets must pass through the same firewall without exception (i.e., "returning along the original path"). Dynamic routing mechanisms make routing decisions based on instantaneous network conditions such as link cost and load, making it difficult to guarantee the return of session data along the original path. Business data may be intercepted by the firewall, severely impacting network availability.

[0105] This application targets multi-center high-availability network application scenarios. In this scenario, the logical communication domain is configured as a star network and multiple central nodes are configured. Priorities are assigned to communication policies according to service traffic distribution, thereby establishing multiple communication policies with clear priorities between remote nodes and central nodes. This guides the VPN to select deterministic paths, achieving deterministic routing and load distribution of service data.

[0106] The business-based traffic routing model uses the business system as the core for path planning. By binding specific business subnets to designated central nodes, it achieves fine-grained traffic scheduling based on destination addresses. The main advantages of this model include:

[0107] 1f. Ensure the performance of critical business operations by selecting the optimal path for each business system;

[0108] 2f. Improve resource utilization and allow multiple central nodes to simultaneously handle business traffic;

[0109] 3f. The mapping relationship between business and path is clear, which facilitates fault location and performance optimization;

[0110] 4f. Remote nodes are easily expandable. Adding a new remote node only requires adding it to the logical communication domain, without any further configuration.

[0111] The business-based traffic splitting model is suitable for the following typical scenarios:

[0112] Scenario 1: A network environment with clearly defined geographical deployment of business systems. When business systems are deployed in different data centers based on their geographical distribution, a traffic splitting model is suitable. For example, business systems in the northern region are deployed in the Beijing data center, while business systems in the southern region are deployed in the Guangzhou data center. In this case, the traffic splitting model can direct traffic from branches in different regions to the northern business center to the Beijing center, and traffic to the southern business center to the Guangzhou center, ensuring that business traffic always follows the optimal path.

[0113] Scenario 2: Applications with special performance requirements, such as video conferencing, real-time transactions, and telemedicine, which are highly sensitive to network latency and jitter, should adopt a traffic offloading model. By assigning dedicated paths to these critical services, they avoid competing for network resources with other service traffic, thereby ensuring the stability and reliability of the service experience.

[0114] Scenario 3: In a network architecture with heterogeneous central node resources, when the services or resources provided by the primary and backup central nodes differ, a business traffic splitting model must be adopted. For example, the primary central node connects to the core database cluster, while the backup central node only provides internet access services. In this case, database access traffic needs to be directed to the primary central node, and internet access traffic needs to be directed to the backup central node, based on the business type.

[0115] Figure 5 This is a schematic diagram of service-based traffic splitting provided in the embodiments of this application, such as... Figure 5 As shown, in one embodiment of this application, assuming two central nodes are A and B, the application systems in the network are divided into two groups, A and B, according to the service traffic splitting mode, and assigned to two central nodes A and B respectively. A protection subnet is configured for central node A, covering the entire central-side network segment of the application systems in group A. Similarly, a protection subnet is configured for central node B, covering the entire central-side network segment of the application systems in group B. When a remote node accesses the application systems in group A, it first establishes a secure channel through central node A. If this cannot be established due to network failure or other reasons, it then establishes a secure channel through central node B. When a remote node accesses the application systems in group B, it first establishes a secure channel through central node B. If this cannot be established due to network failure or other reasons, it then establishes a secure channel through central node A. Figure 5As shown, assuming the remote node is C, two communication strategies are established between the central node A and the remote node C, and between the central node B and the remote node C, respectively. This results in four communication strategies being configured for the remote node C: C (remote protection subnet) <—> A (Group A protection subnet), C (remote protection subnet) <—> B (Group A protection subnet), C (remote protection subnet) <—> B (Group B protection subnet), and C (remote protection subnet) <—> A (Group B protection subnet). When a remote user accesses the central A group business system through the remote node C, the available communication strategies are C (remote protection subnet) <—> A (Group A protection subnet) and C (remote protection subnet) <—> B (Group A protection subnet), with the former having higher priority. Similarly, when a remote user accesses the central B group business system through the remote node C, the available communication strategies are C (remote protection subnet) <—> B (B group protection subnet) and C (remote protection subnet) <—> A (B group protection subnet), with the former having higher priority.

[0116] In some embodiments, if the network structure of the logical communication domain is a star topology, the method further includes:

[0117] Assign different preset center nodes to different remote nodes;

[0118] When remote nodes access data on the central side, they prioritize establishing a secure channel through the assigned preset central node.

[0119] This application targets multi-center high-availability network application scenarios. In this scenario, the logical communication domain is configured as a star network and multiple central nodes are configured. The communication policies are assigned priorities according to the path, thereby establishing multiple communication policies with clear priorities between remote nodes and central nodes. This guides the VPN to select deterministic paths, achieving deterministic routing and load balancing of business data.

[0120] The path-based traffic splitting model uses network nodes as the core for path planning. By grouping remote nodes and assigning them to different central nodes, it achieves simplified traffic scheduling based on source addresses. The main advantages of this model include:

[0121] 1g, simple and clear configuration, greatly reducing the complexity of operation and maintenance;

[0122] 2G network structure is stable, and path strategy does not change with changes in business;

[0123] 3G, easy to expand, after the number of remote nodes increases, the newly added central node is only related to the newly added remote node and has no impact on the original structure.

[0124] The path-based traffic splitting mode is suitable for the following typical scenarios:

[0125] Scenario 1: Organizational networks with clear hierarchical structures, such as enterprise networks with branches established according to administrative divisions or organizational structures, are suitable for a path-based routing model. For example, in a banking system, provincial branches are under the jurisdiction of the head office data center, while city branches are under the jurisdiction of the provincial branch data center. In this model, path allocation is consistent with the administrative management structure, facilitating maintenance and management.

[0126] Scenario 2: For large-scale networks prioritizing operational efficiency, when the network size is large and operational resources are limited, a path-based traffic splitting model is recommended. This model configures only one master center for each remote node, minimizing the number of policies and simplifying the logic. It significantly reduces the workload and error probability of daily operations and maintenance, making it particularly suitable for industries with numerous branch offices, such as retail and logistics.

[0127] Scenario 3: In a dual-center homogeneous environment with balanced network quality, when the primary and backup centers are roughly equivalent in terms of resource configuration, service capabilities, and network quality, a path-based traffic splitting model can be adopted. Clear traffic scheduling can be achieved through simple source address partitioning, ensuring both business continuity and architectural simplicity.

[0128] Figure 6 This is a schematic diagram of path-based traffic splitting provided in an embodiment of this application, such as... Figure 6 As shown in one embodiment of this application, assuming two central nodes are A and B, in a path-based traffic splitting mode, remote nodes in the network are divided into two groups. One group prioritizes accessing the central network through central node A, with one of the remote nodes being C. The other group prioritizes accessing the central network through central node B, with one of the remote nodes being D. As shown in the figure, remote node C establishes communication policies with both central nodes A and B, with the communication policy between C and A having a higher priority. That is, when a remote user accesses central data through node C, a secure channel is first established through central node A. If the establishment fails due to network failure or other reasons, a secure channel is established through central node B. Similarly, remote node D establishes policies with both central nodes A and B, but the communication policy between D and B has a higher priority. That is, when a remote user accesses central data through node D, a secure channel is first established through central node B. If the establishment fails due to network failure or other reasons, a secure channel is established through central node A.

[0129] Alternatively, in actual deployment, the two modes can be used in combination. For example, a path-based traffic splitting mode can be used for general office tasks to simplify operations and maintenance, while a business-based traffic splitting mode can be used for core business systems to ensure performance. This hybrid mode maintains ease of management while ensuring the service quality of critical business processes.

[0130] The VPN device communication apparatus provided in this application is described below. The VPN device communication apparatus described below can be referred to in correspondence with the VPN device communication method described above.

[0131] Figure 7 This is a schematic diagram of the structure of a VPN device communication apparatus provided in an embodiment of this application, as shown below. Figure 7 As shown, the device 700 includes:

[0132] Add module 710, used to add multiple pre-established VPN device clusters to a pre-created logical communication domain;

[0133] Configuration module 720 is used to configure the network structure of the logical communication domain;

[0134] Generation module 730 is used to generate communication strategies based on network structure;

[0135] The communication establishment module 740 is used to establish bidirectional communication between multiple pre-established VPN device clusters based on a communication policy.

[0136] It should be understood that the above-described device is used to execute the methods in the above embodiments. The implementation principle and technical effect of the corresponding program modules in the device are similar to those described in the above methods. The working process of the device can be referred to the corresponding process in the above methods, and will not be repeated here.

[0137] Based on the methods in the above embodiments, Figure 8 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 8 As shown in the illustration, this application provides an electronic device that may include a processor 810, a communications interface 820, a memory 830, and a communication bus 840. The processor 810, communications interface 820, and memory 830 communicate with each other via the communication bus 840. The processor 810 can call logical instructions stored in the memory 830 to execute the VPN device communication method described in the above embodiment.

[0138] Furthermore, the logical instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the VPN device communication method described in the various embodiments of this application.

[0139] Based on the methods in the above embodiments, this application provides a computer-readable storage medium storing a computer program that, when run on a processor, causes the processor to execute the VPN device communication method in the above embodiments.

[0140] Based on the methods in the above embodiments, this application provides a computer program product that, when run on a processor, causes the processor to execute the VPN device communication method in the above embodiments.

[0141] It is understood that the processor in the embodiments of this application can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor can be a microprocessor or any conventional processor.

[0142] The method steps in this application embodiment can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can reside in an ASIC.

[0143] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0144] It is understood that the various numerical designations used in the embodiments of this application are merely for the convenience of description and are not intended to limit the scope of the embodiments of this application.

[0145] Those skilled in the art will readily understand that the above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A VPN device communication method, characterized in that, include: Add multiple pre-established VPN device clusters to a pre-created logical communication domain; Configure the network structure of the logical communication domain; Based on the network structure, a communication strategy is generated; Based on the communication strategy, bidirectional communication is established between the multiple pre-established VPN device clusters; The network structure configured for the logical communication domain includes: Configure the network structure of the logical communication domain as a star topology; The generation of communication strategies based on the network structure includes: A communication strategy is generated, wherein the communication strategy is to establish bidirectional communication between a preset central node and all remote nodes within the logical communication domain; The method further includes: Different business systems are assigned to multiple preset central nodes; When a remote node accesses the first business system, it prioritizes establishing a secure channel through a preset central node where the first business system resides. The first business system can be any of the different business systems mentioned; or... The method further includes: Assign different preset center nodes to different remote nodes; When remote nodes access data on the central side, they prioritize establishing a secure channel through the assigned preset central node.

2. A VPN device communication apparatus, characterized in that, include: The join module is used to join multiple pre-established VPN device clusters into a pre-created logical communication domain; The configuration module is used to configure the network structure of the logical communication domain; A generation module is used to generate a communication strategy based on the network structure. A communication establishment module is used to establish bidirectional communication between the multiple pre-established VPN device clusters based on the communication strategy. The configuration module is specifically used for: Configure the network structure of the logical communication domain as a star topology; The generation module is specifically used for: A communication strategy is generated, wherein the communication strategy is to establish bidirectional communication between a preset central node and all remote nodes within the logical communication domain; The device further includes: The first allocation module is used to allocate different business systems to multiple preset central nodes; When a remote node accesses the first business system, it prioritizes establishing a secure channel through a preset central node where the first business system resides. The first business system can be any of the different business systems mentioned; or... The device further includes: The second allocation module is used to allocate different preset center nodes to different remote nodes; When remote nodes access data on the central side, they prioritize establishing a secure channel through the assigned preset central node.

3. An electronic device, characterized in that, include: At least one memory for storing computer programs; At least one processor is configured to execute a program stored in the memory, wherein when the program stored in the memory is executed, the processor is configured to perform the VPN device communication method as described in claim 1.

4. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is run on the processor, it causes the processor to perform the VPN device communication method as described in claim 1.

5. A computer program product, characterized in that, When the computer program product is run on the processor, the processor performs the VPN device communication method as described in claim 1.