Cross-border control system, method and product

By leveraging the collaborative work of the domestic smart gateway and the cross-border service subsystem through the cross-border control system, the problems of low efficiency and resource utilization in cross-border access have been solved, achieving efficient, secure, and stable cross-border access and load balancing.

CN121728151APending Publication Date: 2026-03-24CHINA TELECOM CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-24
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In existing cross-border access methods, as the number of users increases, the efficiency of cross-border access for cross-border gateway devices decreases, resource utilization is reduced, log tracking is insufficient, and security and load balancing are difficult to guarantee.

Method used

The system employs a cross-border control system, which forwards overseas access requests to the domestic cross-border gateway via a domestic smart gateway device. The cross-border service subsystem makes decisions and generates response instructions, and the domestic cross-border gateway executes forwarding or rejection. The system includes cross-border request identification, load calculation, and log modules to achieve intelligent load balancing and long-term log storage.

Benefits of technology

It improves the efficiency and security of cross-border business configuration distribution, realizes intelligent load balancing, long log storage and tracking, enhances cross-border access efficiency and system stability, and reduces energy consumption and system complexity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121728151A_ABST
    Figure CN121728151A_ABST
Patent Text Reader

Abstract

The invention provides a cross-border control system, method and product, and belongs to the technical field of cross-border access. In the system, domestic intelligent gateway equipment forwards an overseas access request of a user to a registered domestic cross-border gateway; the domestic cross-border gateway bypasses and forwards the overseas access request to the cross-border service subsystem, and receives a response instruction corresponding to the overseas access request returned by the cross-border service subsystem; when the response instruction is a forwarding instruction, forwarding the overseas access request; after receiving the overseas access request, the cross-border service subsystem determines whether the overseas access request is allowed to be forwarded; and when forwarding is allowed, determining a target overseas cross-border gateway and a routing forwarding strategy corresponding to the overseas access request, generating a response instruction corresponding to the overseas access request, and sending the response instruction to the overseas cross-border gateway. The invention aims to improve the cross-border access efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of cross-border access, and more specifically, to a cross-border control system, method, and product. Background Technology

[0002] With the continuous development of SD-WAN (software-defined networking in a wide area network) technology, the demand for edge smart gateway devices (Customer Premises Equipment, CPE) is also increasing, especially with the growing demand for cross-border access for smart gateway devices, and the requirements for the security, efficiency and load balancing of cross-border control are also becoming higher.

[0003] In the current common cross-border access methods, operators build cross-border gateways domestically and internationally based on their business layout. Then, users' CPEs are connected to specific cross-border gateways according to the customer's business needs to enable cross-border access for CPEs. Furthermore, cross-border business control for users is achieved by configuring whitelists for different users on the cross-border gateway. However, in the current cross-border access method, due to the limited performance of the cross-border gateway, the cross-border access efficiency of the cross-border gateway device will decrease significantly as the number of users accessing cross-border services increases rapidly. Summary of the Invention

[0004] This application provides a cross-border control system, method, and product designed to improve the efficiency of cross-border access.

[0005] In a first aspect, embodiments of this application provide a cross-border control system, the system comprising domestic smart gateway devices corresponding to each user, multiple domestic cross-border gateways, multiple overseas cross-border gateways, and a cross-border service subsystem, wherein: The domestic smart gateway device corresponding to any user is used to forward the user's overseas access requests to the registered domestic cross-border gateway. The domestic cross-border gateway is used to bypass and forward the received overseas access request to the cross-border service subsystem, and receive the response instruction corresponding to the overseas access request returned by the cross-border service subsystem; when the response instruction is a forwarding instruction, the overseas access request is forwarded according to the forwarding instruction; when the response instruction is a rejection forwarding instruction, a rejection forwarding response corresponding to the overseas access request is returned to the domestic smart gateway device. The cross-border service subsystem is used to determine whether to allow the overseas access request to be forwarded after receiving the overseas access request; when the overseas access request is allowed to be forwarded, it determines the target overseas cross-border gateway and routing forwarding policy corresponding to the overseas access request, generates a response instruction corresponding to the overseas access request and sends it to the domestic cross-border gateway.

[0006] Optionally, the domestic smart gateway device is used for: Upon receiving the user's overseas access request, basic verification is performed on the overseas access request based on the status of the user's cross-border switch and the user's cross-border whitelist configuration. When the basic verification is successful, the overseas access request is forwarded to the domestic cross-border gateway; When the basic verification fails, a rejection response is returned to the user, which includes information on the reason for refusing to forward the message.

[0007] Optionally, when the cross-border switch is in the open state and the target address of the overseas access request is in the cross-border whitelist configuration, the basic verification is passed; The basic verification fails when the cross-border switch is in the off state, or when the target address of the overseas access request is not in the cross-border whitelist configuration.

[0008] Optionally, the cross-border service subsystem includes a cross-border request authentication module, used for: Based on the user's preset cross-border business configuration, the received overseas access request is subjected to security audit and compliance verification, and an authentication result is generated. The authentication result is used to indicate whether the overseas access request is allowed to be forwarded. When the authentication result is authentication failure, a rejection forwarding instruction will be sent to the domestic cross-border gateway as the response instruction corresponding to the overseas access request.

[0009] Optionally, the cross-border service subsystem includes: The load calculation module is used to determine the load usage corresponding to the overseas access request when the authentication result is successful. The load scheduling module is used to determine the target overseas cross-border gateway and routing forwarding strategy corresponding to the overseas access request based on the load usage corresponding to the overseas access request.

[0010] Optionally, the load calculation module is used for: Based on the unique identifier of the local area network where the domestic smart gateway device corresponding to the overseas access request is located, the target address of the overseas access request, the cross-border tunnel information, the real-time performance information of each domestic and overseas cross-border gateway, and the current load status of the cross-border service subsystem, the priority weighting result of multiple overseas cross-border gateways is determined. The real-time performance information of each domestic and overseas cross-border gateway includes the real-time resource utilization rate of each domestic and overseas cross-border gateway, the current network quality, and the estimated time consumption of any request forwarding destination. The multiple overseas cross-border gateways are sorted according to the priority weighting results, and this sorting is used as the load usage corresponding to the overseas access requests.

[0011] Optionally, the load scheduling module is used to: Based on the load usage corresponding to the overseas access request, determine the target overseas cross-border gateway and routing forwarding strategy corresponding to the overseas access request; The forwarding instruction is sent to the domestic cross-border gateway as a response instruction corresponding to the overseas access request. The forwarding instruction includes the target overseas cross-border gateway and the routing forwarding policy corresponding to the overseas access request.

[0012] Optionally, the cross-border service subsystem further includes a resource alarm module, used for: Real-time monitoring of resource utilization rates for each domestic and overseas cross-border gateway; When the resource utilization rate of any domestic cross-border gateway or any overseas cross-border gateway exceeds the preset resource limit threshold, a resource shortage alarm will be sent to the administrator. When the resource utilization rate of any domestic or overseas cross-border gateway is less than the preset lower limit threshold, a resource redundancy alarm is sent to the administrator.

[0013] Optionally, the cross-border service subsystem further includes a security alarm module, used for: Real-time monitoring of access volume for each domestic and overseas cross-border gateway within a target unit of time. When the number of accesses to any domestic or overseas cross-border gateway exceeds the preset security access threshold within a target unit of time, a security alert is sent to the administrator.

[0014] Optionally, the cross-border service subsystem further includes a logging module, used for: Upon receiving any cross-border access request, the cross-border access request will be logged. The authentication results of the cross-border access request are recorded; Record the target overseas cross-border gateway and routing forwarding policy corresponding to the overseas access request.

[0015] Optionally, the system further includes an operation and maintenance management platform for: Obtain the user's login request and authenticate it. The login request includes the user's account, password, and verification code. Once the login request is successfully authenticated, the user's cross-border business configuration is obtained. The cross-border business configuration includes cross-border interconnection configuration, cross-border control configuration, and cross-border whitelist configuration.

[0016] Optionally, the operation and maintenance management platform is used to respond to the user's cross-border business configuration request, obtain the user's cross-border business configuration, the cross-border business configuration includes a target cross-border tunnel, register the user's corresponding domestic smart gateway device to the domestic cross-border gateway corresponding to the target cross-border tunnel, so as to establish a mutual trust mechanism between the domestic smart gateway device and the domestic cross-border gateway, and forward the cross-border business configuration request to the cross-border service subsystem; The cross-border service subsystem is used to classify the cross-border business configuration requests and store them in the business database, and then return a configuration completion response to the operation and maintenance management platform.

[0017] Secondly, embodiments of this application provide a cross-border control method, the method being applied to the cross-border control system as described in the first aspect of the embodiments, the method comprising: The domestic smart gateway device corresponding to any user will forward the user's overseas access request to the registered domestic cross-border gateway. The domestic cross-border gateway will bypass and forward the received overseas access requests to the cross-border service subsystem; Upon receiving the overseas access request, the cross-border service subsystem determines whether to allow the overseas access request to be forwarded. When the overseas access request is allowed to be forwarded, the subsystem determines the target overseas cross-border gateway and routing policy corresponding to the overseas access request, generates a response instruction corresponding to the overseas access request, and sends it to the domestic cross-border gateway. The domestic cross-border gateway receives the response instruction corresponding to the overseas access request returned by the cross-border service subsystem; when the response instruction is a forwarding instruction, it forwards the overseas access request according to the forwarding instruction; when the response instruction is a reject forwarding instruction, it returns a reject forwarding response corresponding to the overseas access request to the domestic smart gateway device.

[0018] Thirdly, embodiments of this application provide a readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the cross-border control method as described in the second aspect of the embodiments.

[0019] Fourthly, embodiments of this application provide a computer program product, including a computer program / instructions, which, when executed by a processor, implement the cross-border control method described in the second aspect of the embodiments.

[0020] Beneficial effects: In this system, the domestic smart gateway device corresponding to any user forwards the user's overseas access request to the registered domestic cross-border gateway. The domestic cross-border gateway then bypasses and forwards the received overseas access request to the cross-border service subsystem. The cross-border service subsystem determines whether to allow the overseas access request to be forwarded. If the overseas access request is allowed to be forwarded, it can also determine the target overseas cross-border gateway and routing forwarding policy corresponding to the overseas access request, and generate a response instruction corresponding to the overseas access request and send it to the domestic cross-border gateway. When the domestic cross-border gateway receives a forwarding instruction, it forwards the overseas access request according to the forwarding instruction. When it receives a rejection instruction, it returns a rejection response corresponding to the overseas access request to the domestic smart gateway device.

[0021] In this system, the domestic smart gateway device focuses on the forwarding process of overseas access requests. The cross-border service subsystem executes the decision-making process of whether to allow the forwarding of overseas access requests, as well as the decision-making process of the target overseas cross-border gateway and routing forwarding policy corresponding to the overseas access requests. Compared with the cross-border access method where the decision is made by the cross-border gateway, this system can improve the efficiency of cross-border access and can ensure high efficiency even when the number of cross-border access users increases rapidly. Attached Figure Description

[0022] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a schematic diagram of the architecture of a cross-border control system proposed in an embodiment of this application; Figure 2 This is a schematic diagram of the architecture of a cross-border control system proposed in an embodiment of this application; Figure 3 This is a login flowchart of an operation and maintenance management platform provided in one embodiment of this application; Figure 4 This is a flowchart of the steps of a cross-border control method proposed in an embodiment of this application; Figure 5 This is a schematic diagram of an electronic device provided in an embodiment of this application; Figure 6This is a schematic diagram of a readable storage medium proposed in an embodiment of this application; Figure 7 This is a schematic diagram of a computer program product proposed in an embodiment of this application. Detailed Implementation

[0024] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0025] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0026] CPE: Customer Premises Equipment, refers to a smart gateway device that receives 5G or 4G signals and converts them into Wi-Fi signals; SD-WAN, or Software-defined Networking in a Wide Area Network, is a service that applies Software-Defined Networking (SDN) technology to the management of Wide Area Networks (WANs). This service connects enterprise networks, data centers, internet applications, and cloud services across a wide geographical area. A key characteristic of this service is the "cloudification" of network control capabilities through software, supporting application-aware network capability exposure. SD-WAN simplifies network management and deployment, effectively reducing equipment and personnel costs. It offers advantages such as eliminating the need for dedicated networks or public IP addresses, thus addressing many pain points of traditional network technologies.

[0027] With the continuous development of SD-WAN network technology, the demand for edge smart gateway devices (CPEs) is also increasing, especially as the demand for cross-border access of smart gateway devices is growing, and the requirements for the security, efficiency and load balancing of cross-border control are also becoming higher.

[0028] In actual business operations, operators typically build cross-border gateways both domestically and internationally based on their business layout. Then, users' CPEs are connected to specific cross-border gateways according to the customer's business needs to enable cross-border access for CPEs. Furthermore, by issuing specified whitelist configurations to different users on the cross-border gateways, control over users' cross-border business can be achieved.

[0029] However, this current method of cross-border access has the following key problems: 1. As the number of users increases, the efficiency of cross-border configuration distribution, cross-border business access efficiency, and business security will gradually decrease.

[0030] In actual business operations, as the number of users increases, the number of configuration files for cross-border access, cross-border whitelist control, and other services issued to cross-border gateway devices will also increase. In the actual configuration issuance process, this will not only reduce the efficiency and security of configuration issuance, but also reduce the actual efficiency of users' cross-border access.

[0031] 2. With the increase in cross-border users, resource and energy consumption gradually increases, and resource utilization gradually decreases.

[0032] In the actual business expansion process, as the number of users increases, it is necessary to add more cross-border gateway devices to meet the increase in cross-border business and improve cross-border access efficiency. However, as the number of cross-border gateway devices increases, their equipment procurement costs and resource energy consumption costs also gradually increase. Furthermore, different users have different usage frequencies, and their resource idle rate will also increase with the increase of resources, while the resource utilization rate will gradually decrease, making it difficult to achieve efficient load balancing.

[0033] 3. The access tracking time is too short, making it impossible to achieve more efficient and long-term log tracking and analysis, resulting in lower security.

[0034] In actual business operations, the storage resources of cross-border gateway devices are limited and valuable. The amount of transit logs that can be stored is limited. Moreover, traditional log tracing is highly specialized and has a high professional threshold, making it difficult to improve log utilization. Similarly, traditional log storage cannot achieve efficient log tracing and security analysis, nor can it improve the load balancing of cross-border gateway devices through log analysis.

[0035] 4. The efficiency of cross-border business forwarding is easily affected.

[0036] In actual business operations, the storage resources of cross-border gateway devices are very precious and the computing power is limited. When there are too many configurations involving cross-border gateways and too many requests, the computing decision-making ability of cross-border gateways will seriously affect the efficiency of cross-border business forwarding. Currently, the business needs are met by increasing resources. However, increasing hardware gateway resources will inevitably increase the system's energy consumption and increase the system's operating costs.

[0037] Therefore, this application provides a cross-border control system that is more efficient, convenient, safe, and has better load balancing.

[0038] The following description, in conjunction with the accompanying drawings, details a cross-border control system provided in this application through specific embodiments and application scenarios.

[0039] Reference Figure 1 This illustration shows a schematic diagram of the architecture of a cross-border control system provided in an embodiment of this application. The system includes domestic smart gateway devices corresponding to each user, multiple domestic cross-border gateways, multiple overseas cross-border gateways, and a cross-border service subsystem, wherein: The domestic smart gateway device corresponding to any user is used to forward the user's overseas access requests to the registered domestic cross-border gateway.

[0040] The domestic cross-border gateway is used to bypass and forward the received overseas access request to the cross-border service subsystem, and receive the response instruction corresponding to the overseas access request returned by the cross-border service subsystem; when the response instruction is a forwarding instruction, the overseas access request is forwarded according to the forwarding instruction; when the response instruction is a rejection forwarding instruction, a rejection forwarding response corresponding to the overseas access request is returned to the domestic smart gateway device.

[0041] The cross-border service subsystem is used to determine whether to allow the overseas access request to be forwarded after receiving the overseas access request; when the overseas access request is allowed to be forwarded, it determines the target overseas cross-border gateway and routing forwarding policy corresponding to the overseas access request, generates a response instruction corresponding to the overseas access request and sends it to the domestic cross-border gateway.

[0042] Reference Figure 2 The diagram illustrates the architecture of a cross-border control system provided in an embodiment of this application. In one feasible implementation, the system may further include an operation and maintenance management platform, domestic smart gateway devices corresponding to each user, multiple domestic cross-border gateways, multiple overseas cross-border gateways, and a cross-border service subsystem.

[0043] The operation and maintenance management platform can be a visualized SD-WAN intelligent operation and maintenance platform. Users can log in to the operation and maintenance management platform and issue cross-border business configurations according to actual business needs.

[0044] Reference Figure 3 The diagram illustrates the login process of the operation and maintenance management platform provided in this application embodiment. During the user login process, the operation and maintenance management platform obtains the user's login request, which includes the user's account, password, and verification code.

[0045] The operation and maintenance management platform uses two-factor authentication for users' accounts, passwords, and verification codes, ensuring the security of users' accounts by authenticating them based on both passwords and verification codes.

[0046] For example, after a user enters their account and password on the login interface of the operation and maintenance management platform, the system first performs the first authentication based on the account and password. Then, a verification code is randomly generated and sent to the user via SMS. After obtaining the verification code entered by the user, the system performs the second authentication based on the verification code.

[0047] After successful authentication, the operation and maintenance management platform generates a session and an authentication token. The validity periods of the session and the authentication token can be set according to the actual application requirements, such as setting the session validity period to 60 minutes and the authentication token validity period to 10 minutes. The operation and maintenance management platform stores the session and authentication token on the Redis service and returns the authentication token and authentication result to the front end of the operation and maintenance management platform.

[0048] In practice, the authentication results of each user's login to the operation and maintenance management platform can be logged.

[0049] Once the login request is successfully authenticated, the operation and maintenance management platform can obtain the user's cross-border business configuration, which includes cross-border interconnection configuration, cross-border control configuration, and cross-border whitelist configuration.

[0050] In one feasible implementation, a user initiates a cross-border business configuration request on the operation and maintenance management platform. The operation and maintenance management platform responds to the user's cross-border business configuration request and obtains the user's cross-border business configuration, which includes a target cross-border tunnel.

[0051] Then, the operation and maintenance management platform registers the domestic smart gateway device corresponding to the user to the domestic cross-border gateway corresponding to the target cross-border tunnel.

[0052] For example, after receiving a cross-border business configuration request, the operation and maintenance management platform will register the unique identifier serial-number of the user's domestic smart gateway device with the domestic cross-border gateway of the target cross-border tunnel instance selected by the user, so as to establish a mutual trust mechanism between the domestic smart gateway device and the domestic cross-border gateway. The mutual trust mechanism between the two gateways mainly achieves trust establishment and data interoperability between different networks through technical means such as protocol conversion, address conversion, security policies and rule adaptation.

[0053] Next, the operation and maintenance management platform forwards the cross-border business configuration request to the cross-border service subsystem. The cross-border service subsystem is used to classify the cross-border business configuration of the cross-border business configuration request and store it in the business database, and then return a configuration completion response to the operation and maintenance management platform.

[0054] For example, after receiving a cross-border business configuration request, the cross-border service subsystem processes the cross-border business configuration in the request according to business categories such as interconnection, control, and whitelisting. It then stores the cross-border business configuration data model in the business database of the cross-border service subsystem, maps and associates the bandwidth limit of the cross-border business with the bandwidth limit configuration of the domestic cross-border gateway, and finally sends a configuration completion response to the operation and maintenance management platform and logs the current cross-border business configuration request.

[0055] After a user completes the configuration for cross-border business, they can initiate an overseas access request. Specifically, when a user needs to access a cross-border service, they can initiate an overseas access request. Upon receiving the user's overseas access request, the domestic smart gateway device first decomposes the overseas access request and performs basic verification.

[0056] In one feasible implementation, the domestic smart gateway device is used to perform basic verification on the overseas access request based on the status of the cross-border switch corresponding to the user and the cross-border whitelist configuration corresponding to the user.

[0057] Specifically, when the cross-border switch is in the "on" state and the target address of the overseas access request is in the cross-border whitelist configuration, the basic verification is passed, and the domestic smart gateway device can forward the overseas access request to the domestic cross-border gateway.

[0058] When the cross-border switch is in the off state, or when the target address of the overseas access request is not in the cross-border whitelist configuration, the basic verification fails, and the domestic smart gateway device can return a rejection response to the user, which includes the reason information for the rejection.

[0059] A cross-border switch can be used to control each user's cross-border access. For example, when a user's cross-border service is in arrears, the cross-border switch corresponding to that user can be set to the off state, and when the user's cross-border service is not in arrears, the cross-border switch corresponding to that user can be set to the on state. In actual implementation, the state of the cross-border switch can be set according to the actual application requirements. For example, if the current operator suspends cross-border services, the cross-border switch of each user can be set to the off state. This application embodiment does not impose any restrictions.

[0060] The cross-border whitelist configuration is determined by the cross-border business configuration pre-issued by the user. The cross-border whitelist configuration can include multiple access addresses pre-configured by the user according to business needs. If the target address of the user's current overseas access request is not in the cross-border whitelist configuration, the user cannot access the target address.

[0061] After receiving the overseas access request sent by the domestic smart gateway device, the domestic cross-border gateway first forwards the received overseas access request to the cross-border service subsystem, which then determines whether to allow the overseas access request to be forwarded. If the overseas access request is allowed to be forwarded, the domestic cross-border gateway determines the target overseas cross-border gateway and routing forwarding policy corresponding to the overseas access request, and generates a response instruction corresponding to the overseas access request and sends it to the domestic cross-border gateway.

[0062] In one feasible implementation, the cross-border service subsystem further includes a cross-border request authentication module, a load calculation module, a load scheduling module, and a log module.

[0063] When the cross-border service subsystem receives an overseas access request sent by the domestic cross-border gateway, the log module first analyzes the information content of the overseas access request and records it in the log. The log module is used to store any log in the log database of the cross-border service subsystem.

[0064] Then, the cross-border request authentication module performs security audit and compliance verification on the received overseas access request according to the user's preset cross-border business configuration, and generates an authentication result. The authentication result is used to indicate whether the overseas access request is allowed to be forwarded.

[0065] When the authentication result is authentication failure, a rejection forwarding instruction is sent to the domestic cross-border gateway as the response instruction corresponding to the overseas access request. The domestic cross-border gateway returns a rejection forwarding response corresponding to the overseas access request to the domestic smart gateway device based on the received rejection forwarding instruction. In actual implementation, the rejection forwarding response may also include the reason for rejection forwarding, such as the overseas access request not conforming to the cross-border business configuration.

[0066] When the authentication result is successful, the load calculation module can further determine the load usage corresponding to the overseas access request.

[0067] In practice, the log module is also used to record the authentication results of the cross-border access requests.

[0068] Specifically, the load calculation module can determine the priority weighting result of multiple overseas cross-border gateways based on the unique identifier of the local area network where the domestic smart gateway device corresponding to the overseas access request is located (such as the ID, VRF information and VIN information of the SD-WAN instance where the domestic smart gateway device is located), the target address of the overseas access request, cross-border tunnel information, real-time performance information of each domestic cross-border gateway and overseas cross-border gateway, and the current load status of the cross-border service subsystem.

[0069] The real-time performance information of each domestic and overseas cross-border gateway includes the real-time resource utilization rate, current network quality, and estimated time consumption for any request forwarding destination.

[0070] Then, according to the priority weighting result, the multiple overseas cross-border gateways are sorted and used as the load usage corresponding to the overseas access requests.

[0071] The load scheduling module is used to determine the target overseas cross-border gateway and routing forwarding strategy corresponding to the overseas access request based on the load usage corresponding to the overseas access request.

[0072] Specifically, the load scheduling module can determine the target overseas cross-border gateway and routing forwarding strategy corresponding to the overseas access request based on the load usage corresponding to the overseas access request; then, it sends a forwarding instruction as a response instruction corresponding to the overseas access request to the domestic cross-border gateway, wherein the forwarding instruction includes the target overseas cross-border gateway and routing forwarding strategy corresponding to the overseas access request.

[0073] For example, after sorting multiple overseas cross-border gateways according to priority weighting results, the overseas cross-border gateway with the best performance can be selected as the target overseas cross-border gateway.

[0074] The routing and forwarding strategy includes the target domestic cross-border gateway and the target overseas cross-border gateway for forwarding overseas access requests.

[0075] For example, if the domestic cross-border gateway that initially receives the overseas access request has good performance, such as low load or high network quality, the overseas access request can be used as the target domestic cross-border gateway for forwarding the overseas access request, and the overseas access request can be forwarded to the target overseas cross-border gateway.

[0076] If the performance of the domestic cross-border gateway that initially receives the overseas access request is poor, such as due to excessive load or low network quality, the best-performing domestic cross-border gateway can be selected from other domestic cross-border gateways registered by the user as the target domestic cross-border gateway for forwarding the overseas access request. After receiving the forwarding instruction, the domestic cross-border gateway that initially receives the overseas access request can first forward the overseas access request to the target domestic cross-border gateway according to the routing and forwarding strategy in the forwarding instruction, and then the target domestic cross-border gateway can forward the overseas access request to the target overseas cross-border gateway.

[0077] Once the target domestic cross-border gateway forwards the overseas access request to the target overseas cross-border gateway, the target overseas cross-border gateway forwards the overseas access request from the domestic smart gateway device to the overseas destination, and finally returns the cross-border completion response result to the cross-border service subsystem.

[0078] In actual implementation, the log module is also used to record the target overseas cross-border gateway, routing and forwarding policy, and cross-border completion response results corresponding to the overseas access request.

[0079] In actual implementation, the log module can first log the priority weighting results of each overseas cross-border gateway. The load scheduling module can call the priority weighting results of each overseas cross-border gateway in the log module, and then, combined with the target address of the current overseas access request, select the optimal overseas cross-border gateway as the target overseas cross-border gateway. At the same time, the selection result of the target overseas cross-border gateway is reported to the log module for recording, and the performance weight of the target overseas cross-border gateway is modified. At the same time, a new round of resource and service status inspection of this system is started.

[0080] In one feasible implementation, the cross-border service subsystem further includes a resource alarm module for real-time monitoring of the resource utilization rates of each domestic cross-border gateway and each overseas cross-border gateway.

[0081] When the resource utilization rate of any domestic or overseas cross-border gateway exceeds the preset resource limit threshold, a resource shortage alarm will be sent to the administrator. For example, resource shortage alarms can be continuously sent to the administrator via SMS and email, allowing the system administrator to decide whether to expand resources and allocate more cross-border gateway resources as soon as possible to ensure that the system can continuously provide efficient cross-border services to customers.

[0082] When the resource utilization rate of any domestic or overseas cross-border gateway is less than the preset lower limit threshold, a resource redundancy alarm is sent to the administrator. For example, resource redundancy alarms can be continuously sent to the administrator via SMS and email, allowing the system administrator to decide whether to take temporary shutdown measures for cross-border gateway devices with low resource utilization to ensure that the system can provide cross-border services normally under high efficiency and low energy consumption conditions.

[0083] In one feasible implementation, the cross-border service subsystem further includes a security alarm module for real-time monitoring of the access volume of each domestic cross-border gateway and each overseas cross-border gateway within a target unit of time.

[0084] When the number of accesses to any domestic or overseas cross-border gateway exceeds the preset security access threshold within a target unit of time, a security alert is sent to the administrator. This allows the system administrator to be notified promptly via email or SMS when any domestic or overseas cross-border gateway experiences abnormal access, enabling the administrator to intervene and investigate, thus ensuring the secure operation of the system and greatly improving the system's security and self-defense capabilities.

[0085] The cross-border control system provided in this application has at least the following beneficial effects: 1. Improve the efficiency, security, and stability of cross-border business configuration distribution.

[0086] The current practice of storing cross-border business configurations on the cross-border gateway device has been improved by storing them in the business database of the cross-border service subsystem. This simplifies the interaction between cross-border business configurations and the hardware of the cross-border gateway device, and improves the efficiency of cross-border business configuration distribution. At the same time, by digitizing and modeling the cross-border business configurations, the risks associated with modifying the hardware configuration of the cross-border gateway device are reduced, and the security of cross-border business configuration and operation is improved. In the process of reducing interaction with hardware, the stability of the product is greatly enhanced, the system complexity of the cross-border gateway device is reduced, and thus the performance of the cross-border gateway device is improved.

[0087] 2. Achieve intelligent load balancing and improve resource utilization.

[0088] By sorting the actual usage of each overseas cross-border gateway, balanced scheduling and allocation can be carried out, so that the resource utilization rate within the system increases with the increase in the number of users, achieving a high utilization and low energy consumption operation mode. Furthermore, through the coordinated operation of the resource alarm module, the utilization rate is improved while the energy consumption of resources is reduced, realizing a green and low-carbon environmentally friendly operation mode.

[0089] 3. Long-term log storage and tracing improve system stability and security.

[0090] Continuously generating logs for cross-border business configurations and overseas access requests and storing these logs in the log database of the cross-border service subsystem provides longer-term log storage and tracing capabilities. In practice, this allows for the visualization and searching of logs related to cross-border business configurations and overseas access requests, improving the efficiency of problem tracking and troubleshooting. Furthermore, the security alert module enhances the system's predictive and defensive capabilities, strengthening the security and stability of cross-border business operations.

[0091] 4. By making software-based decisions through the cross-border service subsystem, the gateway device focuses on request forwarding, thereby improving the efficiency of cross-border access.

[0092] By using the cross-border service subsystem for software computation and decision-making, while the gateway device focuses solely on request forwarding, the strengths of both software and hardware can be leveraged. Furthermore, the software computation and decision-making of the cross-border service subsystem can improve the computational decision-making process before forwarding cross-border tasks, thereby enhancing decision-making efficiency. By eliminating the decision-making computation of the gateway device and retaining only the ability to forward cross-border requests, the forwarding efficiency of the cross-border gateway can be improved, achieving a 1+1 greater than 2 effect. This can improve cross-border access efficiency and maintain high cross-border access efficiency even when the number of users accessing cross-border services increases rapidly.

[0093] Reference Figure 4 This document illustrates a flowchart of a cross-border control method provided in an embodiment of this application. The method is applied to the cross-border control system described in this embodiment and may specifically include the following steps: S101: Any domestic smart gateway device corresponding to a user will forward the user's overseas access request to the registered domestic cross-border gateway.

[0094] S102: The domestic cross-border gateway will bypass and forward the received overseas access request to the cross-border service subsystem.

[0095] S103: After receiving the overseas access request, the cross-border service subsystem determines whether to allow the overseas access request to be forwarded; when the overseas access request is allowed to be forwarded, it determines the target overseas cross-border gateway and routing forwarding policy corresponding to the overseas access request, generates a response instruction corresponding to the overseas access request, and sends it to the domestic cross-border gateway.

[0096] S104: The domestic cross-border gateway receives the response instruction corresponding to the overseas access request returned by the cross-border service subsystem; when the response instruction is a forwarding instruction, the overseas access request is forwarded according to the forwarding instruction; when the response instruction is a reject forwarding instruction, a reject forwarding response corresponding to the overseas access request is returned to the domestic smart gateway device.

[0097] This method can achieve the same technical effects as the cross-border control system described above when executed, and will not be elaborated further here.

[0098] Reference Figure 5 The diagram illustrates an electronic device according to an embodiment of this application. The electronic device includes a processor, a memory, and a program or instructions stored in the memory and executable on the processor. When the program or instructions are executed by the processor, they implement the cross-border control method described above and achieve the same technical effect.

[0099] It should be noted that the electronic devices in the embodiments of this application include the mobile electronic devices and non-mobile electronic devices described above.

[0100] Reference Figure 6 The diagram illustrates a readable storage medium provided in an embodiment of this application. The readable storage medium stores a program or instructions, which, when executed by a processor, implement the cross-border control method described above and achieve the same technical effect.

[0101] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0102] Reference Figure 7 The diagram illustrates a computer program product provided in an embodiment of this application, including a computer program / instruction. When the computer program / instruction is executed by a processor, it implements the cross-border control method described above and achieves the same technical effect.

[0103] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0104] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0105] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. The description of the embodiments above is only for the purpose of helping to understand the method and core idea of ​​this application. Those skilled in the art can make many forms under the guidance of this application without departing from the spirit and scope of protection of the claims, and all of these are within the protection scope of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation and application scope based on the idea of ​​this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A cross-border control system, characterized in that, The system includes domestic smart gateway devices for each user, multiple domestic cross-border gateways, multiple overseas cross-border gateways, and a cross-border service subsystem, wherein: The domestic smart gateway device corresponding to any user is used to forward the user's overseas access requests to the registered domestic cross-border gateway. The domestic cross-border gateway is used to bypass and forward the received overseas access request to the cross-border service subsystem, and receive the response instruction corresponding to the overseas access request returned by the cross-border service subsystem; when the response instruction is a forwarding instruction, the overseas access request is forwarded according to the forwarding instruction; when the response instruction is a rejection forwarding instruction, a rejection forwarding response corresponding to the overseas access request is returned to the domestic smart gateway device. The cross-border service subsystem is used to determine whether to allow the overseas access request to be forwarded after receiving the overseas access request; when the overseas access request is allowed to be forwarded, it determines the target overseas cross-border gateway and routing forwarding policy corresponding to the overseas access request, generates a response instruction corresponding to the overseas access request and sends it to the domestic cross-border gateway.

2. The system according to claim 1, characterized in that, The domestic smart gateway device is used for: Upon receiving the user's overseas access request, basic verification is performed on the overseas access request based on the status of the user's cross-border switch and the user's cross-border whitelist configuration. When the basic verification is successful, the overseas access request is forwarded to the domestic cross-border gateway; When the basic verification fails, a rejection response is returned to the user, which includes information on the reason for refusing to forward the message.

3. The system according to claim 2, characterized in that, The basic verification is successful when the cross-border switch is in the "on" state and the target address of the overseas access request is in the cross-border whitelist configuration. The basic verification fails when the cross-border switch is in the off state, or when the target address of the overseas access request is not in the cross-border whitelist configuration.

4. The system according to claim 1, characterized in that, The cross-border service subsystem includes a cross-border request authentication module, used for: Based on the user's preset cross-border business configuration, the received overseas access request is subjected to security audit and compliance verification, and an authentication result is generated. The authentication result is used to indicate whether the overseas access request is allowed to be forwarded. When the authentication result is authentication failure, a rejection forwarding instruction will be sent to the domestic cross-border gateway as the response instruction corresponding to the overseas access request.

5. The system according to claim 4, characterized in that, The cross-border service subsystem includes: The load calculation module is used to determine the load usage corresponding to the overseas access request when the authentication result is successful. The load scheduling module is used to determine the target overseas cross-border gateway and routing forwarding strategy corresponding to the overseas access request based on the load usage corresponding to the overseas access request.

6. The system according to claim 5, characterized in that, The load calculation module is used for: Based on the unique identifier of the local area network where the domestic smart gateway device corresponding to the overseas access request is located, the target address of the overseas access request, the cross-border tunnel information, the real-time performance information of each domestic and overseas cross-border gateway, and the current load status of the cross-border service subsystem, the priority weighting result of multiple overseas cross-border gateways is determined. The real-time performance information of each domestic and overseas cross-border gateway includes the real-time resource utilization rate of each domestic and overseas cross-border gateway, the current network quality, and the estimated time consumption for any request forwarding destination. Based on the priority weighting result, the multiple overseas cross-border gateways are sorted and used as the load usage corresponding to the overseas access requests.

7. The system according to claim 6, characterized in that, The load scheduling module is used for: Based on the load usage corresponding to the overseas access request, determine the target overseas cross-border gateway and routing forwarding strategy corresponding to the overseas access request; The forwarding instruction is sent to the domestic cross-border gateway as a response instruction corresponding to the overseas access request. The forwarding instruction includes the target overseas cross-border gateway and the routing forwarding policy corresponding to the overseas access request.

8. The system according to claim 7, characterized in that, The cross-border service subsystem also includes a resource alarm module, used for: Real-time monitoring of resource utilization rates for each domestic and overseas cross-border gateway; When the resource utilization rate of any domestic cross-border gateway or any overseas cross-border gateway exceeds the preset resource limit threshold, a resource shortage alarm will be sent to the administrator. When the resource utilization rate of any domestic or overseas cross-border gateway is less than the preset lower limit threshold, a resource redundancy alarm will be sent to the administrator.

9. The system according to claim 8, characterized in that, The cross-border service subsystem also includes a security alert module for: Real-time monitoring of access volume for each domestic and overseas cross-border gateway within a target unit of time. When the number of accesses to any domestic or overseas cross-border gateway exceeds the preset security access threshold within a target unit of time, a security alert is sent to the administrator.

10. The system according to claim 9, characterized in that, The cross-border service subsystem also includes a log module, used for: Upon receiving any cross-border access request, the cross-border access request will be logged. The authentication results of the cross-border access request are recorded; Record the target overseas cross-border gateway and routing forwarding policy corresponding to the overseas access request.

11. The system according to claim 1, characterized in that, The system also includes an operation and maintenance management platform, used for: Obtain the user's login request and authenticate it. The login request includes the user's account, password, and verification code. Once the login request is successfully authenticated, the user's cross-border business configuration is obtained. The cross-border business configuration includes cross-border interconnection configuration, cross-border control configuration, and cross-border whitelist configuration.

12. The system according to claim 11, characterized in that, The operation and maintenance management platform is used to respond to the user's cross-border business configuration request, obtain the user's cross-border business configuration, which includes a target cross-border tunnel, and register the user's corresponding domestic smart gateway device to the domestic cross-border gateway corresponding to the target cross-border tunnel to establish a mutual trust mechanism between the domestic smart gateway device and the domestic cross-border gateway, and forward the cross-border business configuration request to the cross-border service subsystem. The cross-border service subsystem is used to classify the cross-border business configuration requests and store them in the business database, and then return a configuration completion response to the operation and maintenance management platform.

13. A method for cross-border control, characterized in that, The method is applied to the cross-border control system as described in any one of claims 1-12, the method comprising: The domestic smart gateway device corresponding to any user will forward the user's overseas access request to the registered domestic cross-border gateway. The domestic cross-border gateway will bypass and forward the received overseas access requests to the cross-border service subsystem; Upon receiving the overseas access request, the cross-border service subsystem determines whether to allow the overseas access request to be forwarded. When the overseas access request is allowed to be forwarded, the subsystem determines the target overseas cross-border gateway and routing policy corresponding to the overseas access request, generates a response instruction corresponding to the overseas access request, and sends it to the domestic cross-border gateway. The domestic cross-border gateway receives the response instruction corresponding to the overseas access request returned by the cross-border service subsystem; when the response instruction is a forwarding instruction, it forwards the overseas access request according to the forwarding instruction; when the response instruction is a reject forwarding instruction, it returns a reject forwarding response corresponding to the overseas access request to the domestic smart gateway device.

14. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed by a processor, implement the cross-border control method as described in claim 13.

15. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the cross-border control method of claim 13.