Quasi-two-layer transmission method and system based on SD-WAN network

By employing a dynamic authentication mechanism that combines identity and application traffic context in the SD-WAN network, the problems of excessive trust and rigid permissions in the SD-WAN security model are resolved. This achieves a dynamic and continuous secure transmission system, ensuring effective response to internal threats and closed-loop management of security resources.

CN121887462APending Publication Date: 2026-04-17SUNSHINE GOLD NETWORK (BEIJING) COMMUNICATIONS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SUNSHINE GOLD NETWORK (BEIJING) COMMUNICATIONS CO LTD
Filing Date
2025-12-23
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing SD-WAN technology relies on a static, IP address-based trust mechanism in its security model, leading to excessive trust in cross-domain traffic, rigid permissions, lack of real-time authentication and encrypted isolation, and difficulty in dealing with internal threats and advanced persistent attacks.

Method used

A dynamic verification mechanism based on identity and application traffic context is adopted. Real-time authentication and encrypted tunnel establishment are performed through a zero-trust controller. Combined with continuous monitoring and dynamic policy management, the security and least privilege access of each transmission are ensured.

Benefits of technology

It achieves identity-centric security control, dynamic real-time authentication and on-demand encryption, addresses internal threats and achieves a security closed loop through automatic policy destruction, thus building a dynamic and continuous next-generation secure transmission system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121887462A_ABST
    Figure CN121887462A_ABST
Patent Text Reader

Abstract

The invention discloses a quasi-two-layer transmission method based on an SD-WAN network, and belongs to the field of information transmission, the quasi-two-layer transmission method based on the SD-WAN network comprises the following steps: collecting application traffic data of a sending end in the SD-WAN network, and extracting an identity label and application traffic context information of the sending end; two items of verification are synchronously carried out based on the identity label of the sending end and application flow context information, and the method has the advantages that the security problem that a traditional SD-WAN is statically extensive is fundamentally solved, IP-based trust is replaced by identity and application binding, and identity-centered security control is achieved; through dynamic real-time authentication and on-demand tunnel encryption, minimum permission access is implemented, and verification and encryption of each transmission are ensured; internal threats and behavior anomalies are continuously monitored and coped with by means of sessions; and finally, realizing a safe closed loop through automatic strategy destruction. And a new-generation secure transmission system is constructed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information transmission, and particularly relates to a pseudo-Layer 2 transmission method and system based on SD-WAN network. Background Technology

[0002] SD-WAN is a wide area network built on software-defined networking technology. It can centrally manage multiple network links and intelligently select the best path according to application needs to optimize performance and reduce leased line costs.

[0003] Existing SD-WAN technology enables centralized management and intelligent routing of wide area networks, but its security model is typically based on static, coarse-grained trust centered on network location (such as IP address and VLAN). This leads to security risks such as over-trust, rigid permissions, lack of real-time authentication and encrypted isolation during cross-domain traffic transmission, making it difficult to cope with internal threats and advanced persistent attacks, and thus requires improvement. Summary of the Invention

[0004] Therefore, it is necessary to provide a pseudo-Layer 2 transmission method and system based on SD-WAN network to address the above-mentioned problems.

[0005] The present invention is implemented as follows: a pseudo-Layer 2 transmission method based on an SD-WAN network includes the following steps:

[0006] Collect application traffic data from the sender in the SD-WAN network, and extract the sender's identity (device fingerprint, user identity, etc.) and application traffic context information (application traffic type, security status, etc.).

[0007] Based on the sender's identity and application traffic context information, two verifications are performed simultaneously: first, it is determined whether the sender and receiver have matching transport domain permissions; second, the zero-trust controller authenticates the sender's identity and confirms that the sender has obtained precise access authorization for the target application. When both verifications pass, a pseudo-Layer 2 line is established between the WAN interfaces with matching permissions, and an encrypted tunnel (such as using IP security protocol or transport layer security protocol) is superimposed on the pseudo-Layer 2 line to form a secure pseudo-Layer 2 encrypted transmission line.

[0008] After application traffic data is transmitted to the receiving end through a pseudo-Layer 2 encrypted transmission line, the zero-trust gateway controlling the receiving end decrypts and performs compliance checks on the traffic according to dynamic policies to ensure that the traffic complies with the current authorized scope of data transmission. The zero-trust controller continuously monitors the behavior of both communicating parties, the security status of devices, and the network environment. If any abnormality is detected, the access permissions of the pseudo-Layer 2 encrypted transmission line are interrupted or restricted in real time.

[0009] When the application traffic data transmission is completed or the session times out, the pseudo-Layer 2 encrypted transmission line is terminated. The access authorization granted this time is actively revoked through the zero trust controller, and the temporary security assets generated by both ends of the communication for building and maintaining the pseudo-Layer 2 encrypted transmission line (mainly the session key and related policy entries corresponding to the pseudo-Layer 2 encrypted transmission line) are cleared, thereby completing the recovery and closed-loop management of security resources.

[0010] In one embodiment, the present invention provides a pseudo-Layer 2 transport method based on an SD-WAN network, further comprising:

[0011] Zero-trust proxy gateways are deployed at the network edge where unidentified devices (such as non-standard devices and dumb terminals) are located to achieve agentless secure access. The zero-trust proxy gateway registers a proxy identity for the unidentified device in the zero-trust controller based on the inherent attributes of the unidentified device (such as fixed MAC address, serial number, dedicated certificate) or physical port information, and collects the application traffic data of the unidentified device on its behalf, while attaching the proxy identity and application traffic context information. Then, the zero-trust proxy gateway acts as the sending proxy.

[0012] In one embodiment, the present invention provides a pseudo-Layer 2 transport method based on an SD-WAN network, further comprising:

[0013] Multiple zero-trust proxy gateways are deployed using a load-balanced and highly available cluster architecture. The zero-trust controller dynamically assigns access ownership to devices without identity verification and synchronizes proxy identity registration information and security policy status in real time. When a single gateway fails, the zero-trust controller switches the traffic of the affected devices to other healthy gateways in the cluster, ensuring scalability, high availability, and process continuity for large-scale access by devices without identity verification.

[0014] In one embodiment, the present invention provides a pseudo-Layer 2 transport method based on an SD-WAN network, further comprising:

[0015] The zero-trust controller determines the session type based on application traffic context information, historical session behavior patterns, and a preset business session feature library. If the session type is a long-term / intermittent session (normal sessions are standard sessions, while long-term sessions have a longer duration than standard sessions), an intelligent session lifecycle management mechanism is enabled. This mechanism maintains the active state of intermittent sessions by injecting low-overhead keep-alive probe packets and dynamically adjusts the session timeout threshold to accommodate long-term sessions.

[0016] In one embodiment, the present invention provides a pseudo-Layer 2 transport method based on an SD-WAN network, further comprising:

[0017] A trusted learning and correction mechanism for session type recognition is introduced. The zero-trust controller continuously records the recognition process, decision basis, and actual traffic behavior of all sessions. Through trusted baseline comparison and administrator feedback, misjudged sessions are marked and corrected in real time. The business session feature library and judgment logic are dynamically optimized to ensure the accuracy of session type recognition and the reliability of policy execution.

[0018] In one embodiment, the present invention provides a pseudo-Layer 2 transport system based on an SD-WAN network, comprising:

[0019] The information acquisition module is used to collect application traffic data from the sending end in the SD-WAN network and extract the identity identifier (device fingerprint, user identity, etc.) and application traffic context information (application traffic type, security status, etc.) of the sending end.

[0020] The pseudo-Layer 2 line construction module is used to simultaneously perform two verifications based on the sender's identity and application traffic context information: first, it determines whether the sender and receiver have matching transport domain permissions; second, the zero-trust controller authenticates the sender's identity and confirms that the sender has obtained precise access authorization for the target application. When both verifications pass, a pseudo-Layer 2 line is established between the WAN interfaces with matching permissions, and an encrypted tunnel (such as using IP security protocol or transport layer security protocol) is superimposed on the pseudo-Layer 2 line to form a secure pseudo-Layer 2 encrypted transmission line.

[0021] The data transmission verification module is used to control the zero-trust gateway at the receiving end to decrypt and perform compliance checks on the traffic according to dynamic policies after the application traffic data is transmitted to the receiving end through the pseudo-layer 2 encrypted transmission line. This ensures that the traffic complies with the authorized scope of the current data transmission. The zero-trust controller continuously monitors the behavior of both communicating parties, the security status of the devices, and the network environment. If any abnormality is detected, the access permissions of the pseudo-layer 2 encrypted transmission line will be interrupted or restricted in real time.

[0022] The pseudo-Layer 2 line termination module is used to trigger the termination of the pseudo-Layer 2 encrypted transmission line when the application traffic data transmission is completed or the session times out. It actively revokes the access authorization granted in this session through the zero trust controller and clears the temporary security assets (mainly the session key and related policy entries corresponding to the pseudo-Layer 2 encrypted transmission line) generated by both ends of the communication to build and maintain the pseudo-Layer 2 encrypted transmission line, thereby completing the recovery and closed-loop management of security resources.

[0023] In one embodiment, the present invention provides a pseudo-Layer 2 transport system based on an SD-WAN network, further comprising:

[0024] The unidentified access module is used to deploy a zero-trust proxy gateway at the network edge where unidentified devices (such as non-standard devices and dumb terminals) are located to achieve agentless secure access. The zero-trust proxy gateway registers a proxy identity for the unidentified device in the zero-trust controller based on the inherent attributes of the unidentified device (such as fixed MAC address, serial number, and dedicated certificate) or physical port information, and collects application traffic data of the unidentified device on its behalf, while attaching the proxy identity and application traffic context information. Then, the zero-trust proxy gateway acts as the sending proxy.

[0025] In one embodiment, the present invention provides a pseudo-Layer 2 transport system based on an SD-WAN network, further comprising:

[0026] The gateway failover module is used to deploy multiple zero-trust proxy gateways using a load-balanced and high-availability cluster architecture. It dynamically assigns access ownership to unidentified devices through the zero-trust controller and synchronizes proxy identity registration information and security policy status in real time. When a single gateway fails, the zero-trust controller switches the traffic of the affected devices to other healthy gateways in the cluster, ensuring scalability, high availability, and process continuity for large-scale access by unidentified devices.

[0027] In one embodiment, the present invention provides a pseudo-Layer 2 transport system based on an SD-WAN network, further comprising:

[0028] The session type determination and management module is used to determine the session type based on application traffic context information, historical session behavior patterns and preset business session feature library through the zero trust controller. If the session type is a long-term / intermittent session (normal is a regular standard session, and long-term sessions have a longer cycle than standard sessions), the intelligent session lifecycle management mechanism is enabled. The intermittent session is kept active by injecting low-overhead keep-alive probe packets, and the session timeout threshold is dynamically adjusted to adapt to long-term sessions.

[0029] In one embodiment, the present invention provides a pseudo-Layer 2 transport system based on an SD-WAN network, further comprising:

[0030] The session type identification and correction module introduces a trusted learning and correction mechanism for session type identification. Through a zero-trust controller, it continuously records the identification process, decision basis, and actual traffic behavior of all sessions. Through trusted baseline comparison and administrator feedback, it marks and corrects misjudged sessions in real time and dynamically optimizes the business session feature library and judgment logic to ensure the accuracy of session type identification and the reliability of policy execution.

[0031] Compared with existing technologies, the beneficial effects of this invention are as follows: This invention fundamentally solves the static and coarse security problem of traditional SD-WAN, replacing IP-based trust with identity and application binding to achieve identity-centric security control; it implements least privilege access through dynamic real-time authentication and on-demand encrypted tunnels, ensuring that every transmission is verified and encrypted; it addresses internal threats and abnormal behavior through continuous session monitoring; and finally, it achieves a security closed loop through automatic policy destruction; the entire process deeply integrates zero trust into SD-WAN, constructing a dynamic, continuous, and closed-loop next-generation secure transmission system. Attached Figure Description

[0032] Figure 1 This is a schematic diagram of the first part of a pseudo-Layer 2 transmission method based on an SD-WAN network provided in an embodiment of the present invention.

[0033] Figure 2 This is a schematic diagram of the second part of a pseudo-Layer 2 transmission method based on an SD-WAN network provided in an embodiment of the present invention.

[0034] Figure 3 This is a schematic diagram of the third part of a pseudo-Layer 2 transmission method based on an SD-WAN network provided in an embodiment of the present invention.

[0035] Figure 4 This is a schematic diagram of the fourth part of a pseudo-Layer 2 transmission method based on an SD-WAN network provided in an embodiment of the present invention.

[0036] Figure 5 This is a schematic diagram of the fifth part of a pseudo-Layer 2 transmission method based on an SD-WAN network provided in an embodiment of the present invention.

[0037] Figure 6 This is a schematic diagram of the first part of a pseudo-Layer 2 transmission system based on an SD-WAN network, provided as an embodiment of the present invention.

[0038] Figure 7 This is a schematic diagram of the second part of a pseudo-Layer 2 transmission system based on an SD-WAN network, provided as an embodiment of the present invention.

[0039] Figure 8 This is a schematic diagram of the third part of a pseudo-Layer 2 transmission system based on an SD-WAN network, provided as an embodiment of the present invention.

[0040] Figure 9 This is a schematic diagram of the fourth part of a pseudo-Layer 2 transmission system based on an SD-WAN network, provided as an embodiment of the present invention.

[0041] Figure 10This is a schematic diagram of the fifth part of a pseudo-Layer 2 transmission system based on an SD-WAN network, provided as an embodiment of the present invention. Detailed Implementation

[0042] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0043] In one embodiment, such as Figure 1 As shown, a pseudo-Layer 2 transport method based on an SD-WAN network includes the following steps:

[0044] Step S1: Collect application traffic data from the sending end in the SD-WAN network, and extract the identity identifier (device fingerprint, user identity, etc.) and application traffic context information (application traffic type, security status, etc.) of the sending end.

[0045] Step S2: Based on the sender's identity and application traffic context information, two verifications are performed simultaneously: first, it is determined whether the sender and receiver have matching transport domain permissions; second, the zero-trust controller authenticates the sender's identity and confirms that the sender has obtained precise access authorization for the target application. When both verifications pass, a pseudo-Layer 2 line is established between the WAN interfaces with matching permissions, and an encrypted tunnel (such as using IP security protocol or transport layer security protocol) is superimposed on the pseudo-Layer 2 line to form a secure pseudo-Layer 2 encrypted transmission line.

[0046] Step S3: After the application traffic data is transmitted to the receiving end through the pseudo-Layer 2 encrypted transmission line, the zero-trust gateway at the receiving end decrypts and performs compliance checks on the traffic according to the dynamic policy to ensure that the traffic complies with the authorized scope of the current data transmission. The zero-trust controller continuously monitors the behavior of the two communicating parties, the security status of the devices, and the network environment. If any abnormality is found, the access permissions of the pseudo-Layer 2 encrypted transmission line are interrupted or restricted in real time.

[0047] Step S4: When the application traffic data transmission is completed or the session times out, the pseudo-Layer 2 encrypted transmission line is terminated. The access authorization granted this time is actively revoked through the zero trust controller, and the temporary security assets generated by both ends of the communication for building and maintaining the pseudo-Layer 2 encrypted transmission line (mainly the session key and related policy entries corresponding to the pseudo-Layer 2 encrypted transmission line) are cleared, thereby completing the recycling and closed-loop management of security resources.

[0048] Traditional Software-Defined Wide Area Networks (SD-WANs) primarily rely on network layer VLANs or transport domain permissions for traffic isolation, lacking continuous verification of visitor identity and intent. This leads to security risks such as lateral movement of internal threats and permission generalization. Steps S1 to S4 are designed to build an enhanced security architecture driven by identity, with dynamic verification and closed-loop management. Step S1 collects identity identifiers and application traffic context information, transforming the anchor point of security policies from IP addresses to unique identities. Step S2 uses dual verification of transport domain permissions and zero-trust authorization to ensure that only legitimate identities access designated applications with minimal privileges and establishes a quasi-Layer 2 encrypted transmission line, providing connectivity while ensuring transmission security. Step S3 introduces continuous monitoring and dynamic policy enforcement, shifting from "one-time authentication" to "continuous trust assessment" to address runtime risks such as session hijacking and device compromise. Step S4 proactively revokes permissions after session termination through proactive security asset cleanup, preventing permission remnants and key leaks.

[0049] In one embodiment, such as Figure 2 As shown, a pseudo-Layer 2 transmission method based on an SD-WAN network further includes:

[0050] Step S5: Deploy a zero-trust proxy gateway at the network edge where unidentified devices (such as non-standard devices and dumb terminals) are located to achieve agentless secure access. The zero-trust proxy gateway registers a proxy identity for the unidentified device in the zero-trust controller based on the inherent attributes of the unidentified device (such as fixed MAC address, serial number, dedicated certificate) or physical port information, and collects application traffic data of the unidentified device on its behalf, while attaching the proxy identity identifier and application traffic context information. Then, the zero-trust proxy gateway is used as the sending proxy.

[0051] In real-world networks, numerous industrial control devices, IoT terminals, and traditional printers exist that lack identity verification capabilities, such as those that cannot install proxy software or extract modern identity identifiers. This prevents their identities from being effectively collected in step S1, thus hindering the zero-trust authentication and authorization process in step S2 and creating a blind spot for secure access. Therefore, step S5 is designed to deploy a zero-trust proxy gateway at the network edge, providing these devices with proxy identity registration and traffic management capabilities. This ensures that devices without native identity verification capabilities can still obtain secure access based on identity and continuous authentication through a quasi-Layer 2 encrypted transmission line.

[0052] In one embodiment, such as Figure 3 As shown, a pseudo-Layer 2 transmission method based on an SD-WAN network further includes:

[0053] Step S6 involves deploying multiple zero-trust proxy gateways using a load balancing and high-availability cluster architecture. The zero-trust controller dynamically assigns access ownership to devices without identities and synchronizes proxy identity registration information and security policy status in real time. When a single gateway fails, the zero-trust controller switches the traffic of the affected devices to other healthy gateways within the cluster, ensuring the scalability, high availability, and process continuity of large-scale access for devices without identities.

[0054] After step S5 is implemented, as the number of unidentified devices connected increases, a single zero-trust proxy gateway can easily become a performance bottleneck and a single point of failure, potentially causing a large number of devices to be unable to connect or existing connections to be interrupted, severely damaging the reliability and scalability of the network. Therefore, step S6 is designed to deploy multiple proxy gateways through load balancing and a high-availability cluster architecture, with intelligent scheduling and state synchronization performed by a zero-trust controller. This ensures the elastic scaling of proxy service capabilities and enables seamless traffic switching in the event of a single node failure, thereby guaranteeing business continuity and high service availability for large-scale, critical IoT and industrial network access.

[0055] In one embodiment, such as Figure 4 As shown, a pseudo-Layer 2 transmission method based on an SD-WAN network further includes:

[0056] Step S7: The zero-trust controller determines the session type based on application traffic context information, historical session behavior patterns, and a preset business session feature library. If the session type is a long-term / intermittent session (normal is a regular standard session, and long-term sessions have a longer cycle than standard sessions), the intelligent session lifecycle management mechanism is enabled. The intermittent session is kept active by injecting a low-overhead keep-alive probe packet, and the session timeout threshold is dynamically adjusted to adapt to long-term sessions.

[0057] The fixed-timeout session termination mechanism in step S4 can cause unnecessary interruptions to critical business sessions that are active for long periods or intermittently, such as long-lived database connections, video surveillance streams, and industrial telemetry, affecting normal business operations. Therefore, step S7 is designed to use an intelligent session lifecycle management mechanism to identify such special sessions and adopt flexible management strategies such as keep-alive detection and dynamic timeout adjustment. This effectively maintains the necessary active state while preserving security monitoring capabilities, achieving a precise balance between security control and business continuity.

[0058] In one embodiment, such as Figure 5 As shown, a pseudo-Layer 2 transmission method based on an SD-WAN network further includes:

[0059] Step S8 introduces a trusted learning and correction mechanism for session type recognition. The zero-trust controller continuously records the recognition process, decision basis, and actual traffic behavior of all sessions. Through trusted baseline comparison and administrator feedback, misjudged sessions are marked and corrected in real time. The business session feature library and judgment logic are dynamically optimized to ensure the accuracy of session type recognition and the reliability of policy execution.

[0060] The automatic session type identification mechanism relied upon in step S7 may misjudge in complex traffic environments due to an incomplete policy library or variable behavior patterns. For example, it may misidentify aggressive long connections as legitimate business or misjudge new legitimate business as abnormal, leading to security vulnerabilities or business interruptions. Therefore, step S8 is designed to introduce a trusted learning and correction mechanism. Through continuous behavior analysis, baseline comparison, and administrator feedback, the identification results are optimized in a closed loop and dynamically corrected to continuously improve the accuracy of the business session feature library. This enables the intelligent management mechanism to have self-evolution capabilities, ensuring the reliability and adaptability of its decisions.

[0061] In one embodiment, such as Figure 6 As shown, a pseudo-Layer 2 transmission system based on an SD-WAN network includes:

[0062] Information acquisition module 1 is used to collect application traffic data from the sending end in the SD-WAN network and extract the identity identifier (device fingerprint, user identity, etc.) and application traffic context information (application traffic type, security status, etc.) of the sending end.

[0063] The pseudo-Layer 2 line construction module 2 is used to simultaneously perform two verifications based on the sender's identity and application traffic context information: first, to determine whether the sender and receiver have matching transport domain permissions; second, the zero-trust controller authenticates the sender's identity and confirms that the sender has obtained precise access authorization for the target application. When both verifications pass, a pseudo-Layer 2 line is established between the WAN interfaces with matching permissions, and an encrypted tunnel (such as using IP security protocol or transport layer security protocol) is superimposed on the pseudo-Layer 2 line to form a secure pseudo-Layer 2 encrypted transmission line.

[0064] The data transmission verification module 3 is used to control the zero-trust gateway at the receiving end to decrypt and check the traffic according to dynamic policies after the application traffic data is transmitted to the receiving end through the pseudo-layer 2 encrypted transmission line. This ensures that the traffic complies with the authorized scope of the current data transmission. The zero-trust controller continuously monitors the behavior of both communicating parties, the security status of the devices, and the network environment. If any abnormality is found, the access permissions of the pseudo-layer 2 encrypted transmission line are interrupted or restricted in real time.

[0065] The pseudo-Layer 2 line termination module 4 is used to trigger the termination of the pseudo-Layer 2 encrypted transmission line when the current application traffic data transmission is completed or the session times out. It actively revokes the access authorization granted in this session through the zero trust controller and clears the temporary security assets (mainly the session key and related policy entries corresponding to the pseudo-Layer 2 encrypted transmission line) generated by both ends of the communication for building and maintaining the pseudo-Layer 2 encrypted transmission line, thereby completing the recycling and closed-loop management of security resources.

[0066] The proposed Layer 2 network construction module 2 design incorporates two verification measures to achieve dual security assurance: basic network layer compliance and dynamic authorization at the application layer. Transport domain permission matching is a prerequisite, ensuring device access conforms to network architecture and physical boundary policies, preventing unauthorized network access. Zero-trust authentication and precise authorization are the core, implementing least-privilege access control based on identity and context, dynamically responding to security threats such as identity spoofing and privilege abuse. Both are indispensable: the former constructs a basic network isolation defense, while the latter provides an adaptive business security boundary, fundamentally addressing the security shortcomings of traditional networks that rely solely on a single layer of verification.

[0067] In one embodiment, such as Figure 7 As shown, a pseudo-Layer 2 transmission system based on an SD-WAN network also includes:

[0068] The unidentified access module 5 is used to deploy a zero-trust proxy gateway at the network edge where unidentified devices (such as non-standard devices and dumb terminals) are located to achieve agentless secure access. The zero-trust proxy gateway registers a proxy identity for the unidentified device in the zero-trust controller based on the inherent attributes of the unidentified device (such as fixed MAC address, serial number, and dedicated certificate) or physical port information, and collects application traffic data of the unidentified device on behalf of it. At the same time, it attaches the proxy identity and application traffic context information, and then uses the zero-trust proxy gateway as the sending proxy.

[0069] Taking an industrial camera as an example, it only has basic network functions. The zero-trust proxy gateway discovers the device through the switch port it is connected to, reads its fixed MAC address and manufacturer OUI information, and combines them to generate a unique device identifier "CAM-PlantA-Port7-MAC:00:1A:2B:3C:4D:5E". This identifier is then registered in the zero-trust controller as the proxy identity "Factory Area A-Monitoring Camera-001", with the device type marked as "Video Surveillance". When the camera generates a video stream, the proxy gateway collects this raw traffic and appends the aforementioned proxy identity identifier to each data packet. Simultaneously, it labels the application traffic context information as "Real-time Video Stream (H.264)" based on traffic characteristics, thereby completing the secure access and data standardization processing of devices without identifiers.

[0070] In one embodiment, such as Figure 8 As shown, a pseudo-Layer 2 transmission system based on an SD-WAN network also includes:

[0071] Gateway failover module 6 is used to deploy multiple zero-trust proxy gateways using a load balancing and high-availability cluster architecture. It dynamically allocates access ownership for unidentified devices through the zero-trust controller and synchronizes proxy identity registration information and security policy status in real time. When a single gateway fails, the zero-trust controller switches the traffic of the affected devices to other healthy gateways in the cluster, ensuring the scalability, high availability, and process continuity of large-scale unidentified device access.

[0072] In Gateway Failover Module 6, the real-time performance and consistency of state synchronization require close attention. The agent registration information, session states, and security policies among nodes within the zero-trust proxy gateway cluster must be strongly synchronized through the zero-trust controller. Any delay or deviation may lead to identity recognition errors, session interruptions, or incorrect policy execution after failover. An efficient and reliable consistency synchronization protocol (such as Raft or Paxos) must be adopted, along with a graceful failover mechanism to avoid secondary authentication storms or service interruptions caused by state loss.

[0073] In one embodiment, such as Figure 9 As shown, a pseudo-Layer 2 transmission system based on an SD-WAN network also includes:

[0074] The session type determination and management module 7 is used to determine the session type based on application traffic context information, historical session behavior patterns and preset business session feature library through the zero trust controller. If the session type is a long-term / intermittent session (normal is a regular standard session, and long-term sessions have a longer cycle than standard sessions), the intelligent session lifecycle management mechanism is enabled. The intermittent session is kept active by injecting low-overhead keep-alive probe packets, and the session timeout threshold is dynamically adjusted to adapt to long-term sessions.

[0075] Taking a long-lived connection of an enterprise core database's application programming interface (API) as an example, its session characteristics are continuous openness and intermittent query execution. When the zero-trust controller identifies this as a "long-lived / intermittent session" through collected application traffic context information (such as application port and protocol characteristics) and historical patterns (such as session duration of several hours), it activates the session type judgment and management module 7 mechanism. This mechanism first dynamically extends the default 30-minute Transport Layer Security (TLS) session timeout threshold to several hours; simultaneously, during periods of no business data interaction, the controller injects a lightweight keep-alive probe packet bidirectionally to both the database server and the client every 5 minutes, simulating a heartbeat to maintain the TLS connection and network path status. In this way, it avoids unexpected transaction interruptions caused by default connection recycling of network devices, and ensures that the session is still under security monitoring during periods of continuous no actual traffic, achieving a unity of business continuity and security management.

[0076] In one embodiment, such as Figure 10 As shown, a pseudo-Layer 2 transmission system based on an SD-WAN network also includes:

[0077] The Session Type Recognition and Correction Module 8 is used to introduce a trusted learning and correction mechanism for session type recognition. Through a zero-trust controller, it continuously records the recognition process, decision basis, and actual traffic behavior of all sessions. Through trusted baseline comparison and administrator feedback, it marks and corrects misjudged sessions in real time and dynamically optimizes the business session feature library and judgment logic to ensure the accuracy of session type recognition and the reliability of policy execution.

[0078] The Session Type Identification and Correction Module 8 primarily relies on historical data and feedback for optimization, which is somewhat passive. It can enhance the traffic awareness and analysis engine of the Zero Trust Controller, enabling it to proactively identify and label "unknown session types" that do not conform to the existing feature library but exhibit regular behavioral patterns, and prompt administrators for collaborative analysis and classification. These confirmed new patterns can be quickly converted into policy templates for direct use by similar services, thereby upgrading the identification and correction mechanism from "post-event optimization" to "in-process collaborative discovery," accelerating the system's adaptation to emerging services.

[0079] It should be understood that although the steps in the flowcharts of the various embodiments of the present invention are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the various embodiments may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least a portion of the sub-steps or stages of other steps.

[0080] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0081] The embodiments described above are merely illustrative of several implementations of the present invention, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the present invention, and these modifications and improvements all fall within the scope of protection of the present invention. Therefore, the scope of protection of this patent should be determined by the appended claims.

[0082] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

[0083] Furthermore, it should be understood that although this specification describes embodiments, not every embodiment contains only one independent technical solution. This narrative style is merely for clarity. Those skilled in the art should consider the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.

Claims

1. A pseudo-Layer 2 transmission method based on SD-WAN network, characterized in that, The pseudo-Layer 2 transport method based on SD-WAN network includes the following steps: Collect application traffic data from the sender in the SD-WAN network and extract the sender's identity and application traffic context information; Based on the sender's identity and application traffic context information, two verifications are performed simultaneously: first, it is determined whether the sender and receiver have matching transmission domain permissions; second, the zero-trust controller authenticates the sender's identity and confirms that the sender has obtained precise access authorization for the target application. When both verifications pass, a pseudo-Layer 2 line is established between the WAN interfaces with matching permissions, and an encrypted tunnel is superimposed on the pseudo-Layer 2 line to form a secure pseudo-Layer 2 encrypted transmission line. After application traffic data is transmitted to the receiving end through a pseudo-Layer 2 encrypted transmission line, the zero-trust gateway controlling the receiving end decrypts and performs compliance checks on the traffic according to dynamic policies to ensure that the traffic complies with the current authorized scope of data transmission. The zero-trust controller continuously monitors the behavior of both communicating parties, the security status of devices, and the network environment. If any abnormality is detected, the access permissions of the pseudo-Layer 2 encrypted transmission line are interrupted or restricted in real time. Once the application traffic data transmission is completed or the session times out, the pseudo-Layer 2 encrypted transmission line is terminated. The zero-trust controller actively revokes the access authorization granted this time and clears the temporary security assets generated by both ends of the communication to build and maintain the pseudo-Layer 2 encrypted transmission line, thereby completing the recovery and closed-loop management of security resources.

2. The pseudo-Layer 2 transmission method based on SD-WAN network according to claim 1, characterized in that, Also includes: Zero-trust proxy gateways are deployed at the network edge where unidentified devices are located to achieve agentless secure access. The zero-trust proxy gateway registers a proxy identity for the unidentified device in the zero-trust controller based on the inherent attributes or physical port information of the unidentified device, and collects the application traffic data of the unidentified device on its behalf, while attaching the proxy identity and application traffic context information. Then, the zero-trust proxy gateway acts as the sending proxy.

3. The pseudo-Layer 2 transmission method based on SD-WAN network according to claim 2, characterized in that, Also includes: Multiple zero-trust proxy gateways are deployed using a load balancing and high-availability cluster architecture. The zero-trust controller dynamically allocates access to devices without identity verification and synchronizes proxy identity registration information and security policy status in real time. When a single gateway fails, the zero-trust controller switches the traffic of affected devices to other healthy gateways within the cluster, ensuring scalability, high availability, and process continuity for large-scale access by unidentified devices.

4. The pseudo-Layer 2 transmission method based on SD-WAN network according to claim 1, characterized in that, Also includes: The zero-trust controller determines the session type based on application traffic context information, historical session behavior patterns, and a preset business session feature library. If the session type is a long-term / intermittent session, an intelligent session lifecycle management mechanism is enabled. This mechanism maintains the active state of intermittent sessions by injecting low-overhead keep-alive probe packets and dynamically adjusts the session timeout threshold to accommodate long-term sessions.

5. The pseudo-Layer 2 transmission method based on SD-WAN network according to claim 4, characterized in that, Also includes: A trusted learning and correction mechanism for session type recognition is introduced. The zero-trust controller continuously records the recognition process, decision basis, and actual traffic behavior of all sessions. Through trusted baseline comparison and administrator feedback, misjudged sessions are marked and corrected in real time. The business session feature library and judgment logic are dynamically optimized to ensure the accuracy of session type recognition and the reliability of policy execution.

6. A pseudo-Layer 2 transmission system based on an SD-WAN network, characterized in that, include: The information acquisition module is used to collect application traffic data from the sending end in the SD-WAN network and extract the identity and application traffic context information of the sending end. The proposed Layer 2 line construction module is used to perform two simultaneous verifications based on the sender's identity and application traffic context information: first, to determine whether the sender and receiver have matching transmission domain permissions; Second, the zero-trust controller authenticates the sender's identity and confirms that the sender has obtained precise access authorization for the target application. When both verifications pass, a pseudo-Layer 2 line is established between the WAN interfaces with matching permissions, and an encrypted tunnel is superimposed on the pseudo-Layer 2 line to form a secure pseudo-Layer 2 encrypted transmission line. The data transmission verification module is used to control the zero-trust gateway at the receiving end to decrypt and perform compliance checks on the traffic according to dynamic policies after the application traffic data is transmitted to the receiving end through the pseudo-layer 2 encrypted transmission line. This ensures that the traffic complies with the authorized scope of the current data transmission. The zero-trust controller continuously monitors the behavior of both communicating parties, the security status of the devices, and the network environment. If any abnormality is detected, the access permissions of the pseudo-layer 2 encrypted transmission line will be interrupted or restricted in real time. The pseudo-Layer 2 line termination module is used to trigger the termination of the pseudo-Layer 2 encrypted transmission line when the application traffic data transmission is completed or the session times out. It actively revokes the access authorization granted in this session through the zero trust controller and clears the temporary security assets generated by both ends of the communication to build and maintain the pseudo-Layer 2 encrypted transmission line, thereby completing the recovery and closed-loop management of security resources.

7. The pseudo-Layer 2 transmission system based on SD-WAN network according to claim 6, characterized in that, Also includes: The unidentified access module is used to deploy a zero-trust proxy gateway at the network edge where the unidentified device is located to achieve agentless secure access. The zero-trust proxy gateway registers a proxy identity for the unidentified device in the zero-trust controller based on the inherent attributes or physical port information of the unidentified device, and collects the application traffic data of the unidentified device on its behalf, while attaching the proxy identity and application traffic context information. Then, the zero-trust proxy gateway acts as the sending proxy.

8. The pseudo-Layer 2 transmission system based on SD-WAN network according to claim 7, characterized in that, Also includes: The gateway failover module is used to deploy multiple zero-trust proxy gateways using a load balancing and high-availability cluster architecture. It dynamically allocates access ownership to devices without identity verification through the zero-trust controller and synchronizes proxy identity registration information and security policy status in real time. When a single gateway fails, the zero-trust controller switches the traffic of affected devices to other healthy gateways within the cluster, ensuring scalability, high availability, and process continuity for large-scale access by unidentified devices.

9. The pseudo-Layer 2 transmission system based on SD-WAN network according to claim 6, characterized in that, Also includes: The session type determination and management module is used to determine the session type based on application traffic context information, historical session behavior patterns and preset business session feature library through the zero trust controller. If the session type is a long-term / intermittent session, the intelligent session lifecycle management mechanism is enabled. The intermittent session is kept active by injecting low-overhead keep-alive probe packets, and the session timeout threshold is dynamically adjusted to adapt to long-term sessions.

10. The pseudo-Layer 2 transmission system based on SD-WAN network according to claim 9, characterized in that, Also includes: The session type identification and correction module introduces a trusted learning and correction mechanism for session type identification. Through a zero-trust controller, it continuously records the identification process, decision basis, and actual traffic behavior of all sessions. Through trusted baseline comparison and administrator feedback, it marks and corrects misjudged sessions in real time and dynamically optimizes the business session feature library and judgment logic to ensure the accuracy of session type identification and the reliability of policy execution.