Service access method and equipment

By including the business identity identifier (ID) in the message, the problem of existing network security policies being unable to associate with business information is solved, enabling more efficient network security policy configuration and management, and improving network security and IP address utilization efficiency.

CN121940145APending Publication Date: 2026-04-28PETAL CLOUD TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
PETAL CLOUD TECH CO LTD
Filing Date
2024-10-25
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing network security strategies based on the five-tuple of business information cannot be associated with business information, which poses security risks and is complex to configure, resulting in insufficient network security and complicated management.

Method used

By carrying a service identity identifier (ID) in the message, network elements can directly associate with service information, thereby configuring network security policies based on the service information and improving network security.

Benefits of technology

It enables network security policy configuration based on business information, reduces management complexity, improves network security, and allows for flexible allocation of IP network segments during business expansion, reducing IP address waste.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121940145A_ABST
    Figure CN121940145A_ABST
Patent Text Reader

Abstract

The invention provides a service access method and equipment. The method is applied to a first device, and the method comprises the following steps: obtaining a first corresponding relationship between a plurality of service names and a plurality of service identities (ID); a first service ID corresponding to the first service name is determined according to the first corresponding relation, and the first service name comprises the service name of the source service and / or the service name of the target service; and sending a first message to a second device where the target service is located, wherein the first message comprises the first service ID. In the technical scheme, when service access is carried out, service information can be directly associated by carrying the service ID in the first message, so that a manager can configure a network security policy based on the service information, and a source service or a target service of service access can be limited to improve network security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cybersecurity, and more specifically, to a method and apparatus for business access. Background Technology

[0002] To mitigate the risk of security attacks, network security policies need to be configured for business access. Current network security policies typically involve configuring network access control lists or network security groups based on the five-tuple of business information, or configuring whitelists or blacklists. However, security policies based on the five-tuple of business information cannot be linked to business information, posing certain security risks, and the configuration process and maintenance of security policies are relatively complex. Summary of the Invention

[0003] This application provides a method and apparatus for service access. In this technical solution, by carrying a service identity identifier (ID) in the message during service access, the message can be directly associated with service information. This facilitates administrators in configuring network security policies based on service information, thereby improving network security.

[0004] In a first aspect, a method for accessing services is provided, applied to a first device. The method includes: obtaining a first correspondence between multiple service names and multiple service identity IDs, wherein the multiple service names and multiple service identity IDs correspond one-to-one; determining a first service ID corresponding to a first service name based on the first correspondence, wherein the first service name includes the service name of the source service that triggered the generation of the first message, and / or the service name of the destination service that the source service needs to access; and sending a first message to a second device where the destination service is located, wherein the first message includes the first service ID.

[0005] It should be understood that the identity ID can also be an identifier, identifier, identity information, identification information, identification number, identity number, serial number, etc., and this application does not limit it in this way.

[0006] For example, the first device can be a terminal device or a business server.

[0007] Optionally, before the second device where the target service to be accessed is located sends the first message, the method further includes: generating the first message.

[0008] It should be understood that when the first device sends the first message to the second device, the first message may be forwarded by multiple network elements within the data center before finally reaching the second device. For example, the path of the first message may be first device-fourth device-second device, or it may be first device-fourth device-fifth device-second device.

[0009] It should also be understood that if the first packet does not conform to the network security policy configured in the network element, the network element may also discard the first packet. In this case, the first packet will not be able to reach the second device.

[0010] Based on the embodiments of this application, the first device can obtain multiple service IDs corresponding to multiple service names, thereby determining the unique service ID corresponding to each service name, and sending a first message carrying the aforementioned service ID to the second device where the target service to be accessed is located.

[0011] In this way, the first message can be directly associated with business information. After receiving the first message, the network elements in the data center can directly determine the relevant business information and match the network security policy based on the business ID to determine whether to forward the first message. This can restrict the source business and / or destination business access to improve network security.

[0012] In some implementations, the first service ID is carried in the extended header field of the first message.

[0013] For example, the extended header field can be a destination option extended header field. In other examples, the header field may also be carried in other extended header fields, which is not limited in this embodiment.

[0014] In some implementations, obtaining the first correspondence between multiple service names and multiple service IDs includes: sending a first resolution request to a third device, the first resolution request being used to obtain the first correspondence.

[0015] In this way, the first device can obtain the first correspondence between the service name and the service ID from the third device, thereby determining the unique service ID corresponding to the service name.

[0016] Optionally, a first parsing request is sent to the third device, including:

[0017] After a preset interval, the first parsing request is resent to the third device.

[0018] For example, the preset duration can be 600s or 500s, etc., and the specific value of the preset duration is not limited in this application embodiment.

[0019] Based on the embodiments of this application, the first device needs to resend the first parsing request to the third device at preset time intervals to obtain the latest first correspondence. In this way, the first correspondence in the third device can change dynamically, and the first device can dynamically obtain the first correspondence, thereby ensuring network security.

[0020] In some implementations, the first message includes a 5-tuple, which includes the protocol number, the service ID of the source service, the source port number, the destination port number, and the service ID of the destination service.

[0021] Based on the embodiments of this application, the five-tuple information of the first message carries business information (such as the ID of the source service and the ID of the destination service), so the first message can be directly associated with business information, which is beneficial for managers to configure network security policies based on business information and can reduce the workload of managers in configuring network security policies.

[0022] Secondly, a method for accessing services is provided, applied to a fourth device. The method includes: obtaining a second correspondence between multiple service names and multiple service identity IDs included in a configured network security policy, wherein the multiple service names and multiple service IDs correspond one-to-one; receiving a first message sent by a first device, the first message including a first service ID, wherein the first service name corresponding to the first service ID includes the service name of the source service that triggered the generation of the first message, and / or the service name of the destination service accessed by the source service; determining the first service name corresponding to the first service ID according to the second correspondence; and determining whether to forward the first message according to the network security policy and the first service name.

[0023] For example, the fourth device can be a network element such as an Elastic Load Balancer (ELB), a Virtual Private Cloud (VPC), or an egress gateway.

[0024] Based on the embodiments of this application, the fourth device can obtain the correspondence between multiple service names and multiple service IDs included in the network security policy. After receiving the first message sent by the first device, since the first message carries a service ID, the first device can determine the service name corresponding to the service ID carried in the first message based on the obtained correspondence between multiple service names and multiple service IDs; and match the service name with the network security policy to determine whether to forward the first message.

[0025] In this way, the fourth device can restrict the source and / or destination services accessed by the service, thereby improving network security. Furthermore, configuring network security policies based on service names simplifies configuration. Moreover, this technical solution ensures that the IP network segments corresponding to service names are contiguous, eliminating IP address waste and allowing for on-demand allocation. When service expansion is needed, new network segments can be flexibly allocated.

[0026] In some implementations, the decision to forward the first packet is based on the configured network security policy and the first service name. This includes: forwarding the first packet if the first service name conforms to the security rules in the network security policy; or discarding the first packet if the first service name does not conform to the security rules in the network security policy.

[0027] Based on the embodiments of this application, the fourth device can match the first service name based on the configured network security policy, and forward the first message to the next node if it meets the security rules, and directly discard the first message if it does not meet the security rules.

[0028] In this way, the fourth device can filter received packets based on the configured network security policy to ensure network security.

[0029] In some implementations, the network security policy includes a whitelist and a blacklist of business names. Determining whether a first business name conforms to the security rules in the network security policy includes: determining whether the first business name conforms to the security rules in the network security policy when it is in the whitelist; or determining whether the first business name does not conform to the security rules in the network security policy includes: determining whether the first business name does not conform to the security rules in the network security policy when it is in the blacklist.

[0030] Based on the embodiments of this application, when the configured network security policy includes a whitelist and a blacklist, the fourth device can determine whether the first service name conforms to security rules based on whether it is in the whitelist or the blacklist. In this way, the fourth device can conveniently determine whether the first service name conforms to security rules.

[0031] In some implementations, the network security policy includes a whitelist or blacklist of business names. Determining whether a first business name complies with the security rules in the network security policy includes: determining whether the first business name complies with the security rules in the network security policy if the first business name is not in the blacklist; or determining whether the first business name does not comply with the requirements in the network security policy includes: determining whether the first business name does not comply with the security rules in the network security policy if the first business name is not in the whitelist or blacklist.

[0032] Based on the embodiments of this application, when the configured network security policy includes a whitelist or a blacklist, the fourth device can determine whether the first service name conforms to security rules based on whether it is in the whitelist or blacklist. In this way, the fourth device can conveniently determine whether the first service name conforms to security rules.

[0033] In some implementations, the network security policy includes a network access control list (ACL) or a network security group. The ACL or network security group includes access information for multiple service names. Determining whether a first service name conforms to the security rules in the network security policy includes: determining that the first service name conforms to the security rules in the network security policy when the first service name matches the access information in the network ACL or network security group; or determining whether the first service name does not conform to the security rules in the network security policy includes: determining that the first service name does not conform to the security rules in the network security policy when the first service name does not match the access information in the network ACL or network security group.

[0034] Based on the embodiments of this application, the fourth device can conveniently determine whether the first service name complies with security rules.

[0035] In some implementations, the first service ID is carried in the extended header field of the first message.

[0036] For example, the extended header field can be a destination option extended header field. In other examples, the header field may also be carried in other extended header fields, which is not limited in this embodiment.

[0037] In some implementations, a second mapping relationship between multiple service names and multiple service IDs included in the configured network security policy is obtained, including:

[0038] A second parsing request is sent to the third device. The second parsing request is used to obtain the second correspondence.

[0039] In this way, the fourth device can obtain the second correspondence between the service name and the service ID from the third device, thereby determining the unique service ID corresponding to the service name included in the network security policy.

[0040] In some implementations, a second parsing request is sent to a third device, including:

[0041] After a preset interval, a second parsing request is sent again to the third device.

[0042] In this way, the first correspondence in the third device can change dynamically, and the fourth device can dynamically obtain the second correspondence, thereby ensuring network security.

[0043] In some implementations, the first message includes a 5-tuple, which includes the protocol number, the service ID of the source service, the source port number, the destination port number, and the service ID of the destination service.

[0044] Based on the embodiments of this application, the five-tuple information of the first message carries business information (such as the business ID of the source business and the business ID of the destination business), so the first message can be directly associated with business information, which is beneficial for managers to configure network security policies based on business information and can reduce the workload of managers in configuring network security policies.

[0045] Thirdly, an apparatus is provided, comprising: one or more processors; one or more memories; wherein the one or more memories store one or more programs that, when executed by the one or more processors, cause the methods described in the first to second aspects and any possible implementation thereof to be performed.

[0046] Fourthly, a chip is provided, the chip including a processor and a communication interface for receiving signals and transmitting signals to the processor, the processor processing the signals such that the methods described in the first to second aspects and any possible implementation thereof are executed.

[0047] Fifthly, a readable storage medium is provided that stores instructions which, when executed on a device, cause the methods described in the first to second aspects and any possible implementation thereof to be performed.

[0048] A sixth aspect provides a program product comprising program code that, when run on a device, causes the methods described in the first to second aspects and any possible implementation thereof to be executed. Attached Figure Description

[0049] Figure 1 This is a schematic diagram illustrating a scenario to which the embodiments of this application can be applied.

[0050] Figure 2 This is a schematic diagram of a service access method provided in an embodiment of this application.

[0051] Figure 3 This is a schematic diagram of an IPv6 packet structure provided in an embodiment of this application.

[0052] Figure 4 This is a schematic diagram of the structure of a destination option extension header field provided in an embodiment of this application.

[0053] Figure 5 This is a schematic diagram illustrating another type of service access provided in an embodiment of this application.

[0054] Figure 6 This is a schematic diagram illustrating another type of service access provided in an embodiment of this application.

[0055] Figure 7This is a schematic flowchart illustrating a business access method provided in an embodiment of this application.

[0056] Figure 8 This is an illustrative flowchart of another service access provided in an embodiment of this application.

[0057] Figure 9 This is a schematic block diagram of a device provided in an embodiment of this application. Detailed Implementation

[0058] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0059] Before introducing the technical solution of this application, the following is a brief introduction to some of the technical terms that may be involved in this application.

[0060] Virtual Private Cloud (VPC): An isolated network environment created within a public cloud. Users can deploy and manage their own computing resources (such as virtual machines, storage, databases, etc.) and control network traffic and access permissions by configuring network policies (such as subnets, routing tables, security groups, etc.). VPCs provide network isolation and security similar to traditional physical data centers, but with the flexibility and scalability of cloud computing.

[0061] Elastic load balancing (ELB) is used to automatically distribute incoming network traffic to multiple backend servers (such as Elastic Compute Cloud EC2 instances, containers, etc.) to improve application availability and fault tolerance. ELB can dynamically adjust traffic distribution based on traffic patterns and health check results to ensure that applications always have high performance and high availability.

[0062] Global Name Service (GNS): A server used to manage, distribute, and resolve global names and Internet Protocol (IP) addresses. GNS servers are primarily used in distributed systems and cloud computing environments, providing unified naming and resolution services to computers, devices, and users in different locations and topologies.

[0063] Network Address Translation (NAT): This is used to translate IP addresses in a private network into IP addresses in a public network, enabling communication between the private network and the internet. NAT can hide the internal network structure, enhance network security, and conserve public IP addresses. NAT is commonly used in routers, firewalls, and cloud services to allow resources in a private subnet to access the internet.

[0064] Application-aware networking (APN) utilizes the extended header space of Internet Protocol version 6 (IPv6) to carry application information into the network, including application identity (APN ID) and application requirement parameter information (APN parameters), thereby providing service providers with refined network services and precise network operation and maintenance.

[0065] A quintuple is a set of five basic attributes of a network data packet, including the source IP address, destination IP address, source port number, destination port number, and transport protocol.

[0066] Source IP address: The IP address of the device that sent the data packet, used to identify the source of the data packet.

[0067] Destination IP address: The IP address of the device receiving the data packet, used to determine the destination of the data packet.

[0068] Source port number: The port number used by the device sending the data packet, indicating which application the data packet was sent from.

[0069] Destination port number: The port number used by the device receiving the data packet, indicating which application should handle the data packet.

[0070] Transport protocol: The protocol used to send data packets, such as Transmission Control Protocol (TCP) and User Datagram Protocol (UDP).

[0071] To mitigate the risk of security attacks, network security policies need to be configured for business access. Current network security policies typically involve configuring network access control lists or network security groups based on the five-tuple of business information, or configuring whitelists and blacklists. However, security policies based on the five-tuple of business information cannot be linked to business information, posing certain security risks, and the configuration process and maintenance of these policies are relatively complex. The following section will combine... Figure 1 Describe the process of accessing services.

[0072] For example, Figure 1 This is a schematic diagram illustrating a scenario to which the embodiments of this application can be applied. For example... Figure 1 As shown, a Virtual Private Cloud (VPC) 150 can include at least multiple subnets (such as subnet 1, subnet 2, and subnet 3), an egress gateway 151, and a virtual router (not shown in the figure).

[0073] Subnet 1 may include Elastic Load Balancer ELB1 and Service Server 1; Subnet 2 may include ELB2 and Service Server 2; Subnet 3 may include ELB3 and Service Server 3.

[0074] In this embodiment, the business server can be a server used to host and process business applications. The business server is primarily used to store and process large amounts of data, while also supporting the operation of business application software. For example, the business server can be an account server, a game server, an application market server, etc.

[0075] This egress gateway 151 can also be a NAT gateway.

[0076] It should be understood that the VPC150 and the egress gateway 151 can form a data center.

[0077] Before business access, developers or site reliability engineers (SREs) have configured network security policies for the aforementioned network elements such as VPC150, ELB1, ELB2, ELB3, business server 1, business server 2, business server 3, and egress gateway 151.

[0078] For example, SREs can configure network access control lists (ACLs) and network security groups on a VPC150 based on the five-tuple of a service (source IP address, destination IP address, source port number, destination port number, and transport protocol). For instance, Table 1 shows an example of a configured network ACL.

[0079] Table 1

[0080]

[0081] For example, Table 2 is an example of configuring a network security group.

[0082] Table 2

[0083]

[0084]

[0085] For example, SRE can configure whitelists, blacklists, etc. on ELB based on the five-tuple of a service. Traffic from services in the whitelist is allowed to be forwarded, while traffic from services in the blacklist is not allowed to be forwarded and will be dropped.

[0086] In this application embodiment, the scenarios for service access can include the following three types.

[0087] Scenario 1: Terminal device 100 (such as smartphone, tablet, etc.) accesses the business server in the data center.

[0088] Scenario 2: Business servers within a data center accessing each other.

[0089] Scenario 3: Business servers within the data center access third-party servers.

[0090] See Figure 1 For scenario one, we will take the example of terminal device 100 accessing business server 1 in subnet 1 for explanation.

[0091] The service message 1 in terminal device 100 will pass through ELB1 and VPC150 and finally reach service server 1.

[0092] Since network security policies have been configured on ELB1 and VPC150, ELB1 and VPC can decide whether to forward or drop packet 1 based on the network security policies. However, the network security policies mentioned above are not associated with business information, which poses certain risks.

[0093] Furthermore, when the IP network segment required by the business needs to be expanded, the network ACL and security group need to be modified. Otherwise, network request failures and service interruptions will occur, placing an additional burden on SRE. Moreover, if the expanded IP network segment includes multiple non-contiguous segments, it will increase the number of network ACL and security group configurations, making the rules cumbersome and subsequent maintenance complex.

[0094] For scenario two, we will take the mutual access between business server 1 and business server 2 as an example for explanation.

[0095] For example, business server 1 may include business software. When message 2 from the business software accesses business server 2, VPC150, upon receiving message 2, will determine whether to discard or forward message 2 based on the configured network security policy. However, since the aforementioned network security policy is not associated with business information, it poses a certain risk.

[0096] For scenario three, we will take the example of business server 3 accessing a third-party server to illustrate the concept.

[0097] Business server 3 may include business software. When the business software's message 3 needs to access a third-party server outbound, the message 3 also needs to be forwarded through VPC150 and egress gateway 151 before it can access the third-party server.

[0098] Upon receiving message 3, VPC150 will determine whether to discard or forward it to the egress gateway based on its configured network security policy. Similarly, upon receiving message 3, egress gateway 151 will determine whether to discard or forward it based on its configured network security policy (such as a whitelist or blacklist). However, since these network security policies are not associated with business information, they pose a certain risk.

[0099] To enable the network to be aware of service information, APN6 utilizes the programmable space of IPv6 or segmented routing based on the IPv6 forwarding plane to carry service IDs into the network, allowing the network to be aware of applications and their requirements. For example, in multi-service scenarios, by carrying the destination service ID, different network paths can be planned to improve the service access experience.

[0100] However, APN6 carries the destination service ID, and the network cannot know what the source service is, which also carries certain risks.

[0101] In view of this, embodiments of this application provide a method and device for service access. In this technical solution, users can configure the mapping between service names and service IDs in a unified server (such as GNS), and configure network security policies based on service names in network elements. Network elements can resolve the mapping between service names and service IDs from this unified server. Subsequently, during service access, by carrying the service ID in the extended header field of the service message, each network element can determine whether the received message conforms to the network security policy according to the configured network security policy, thereby improving network security. Furthermore, configuring network security policies based on service names simplifies the configuration scheme. Moreover, the IP network segments corresponding to service names are contiguous, with no wasted IP addresses, allowing for on-demand application and flexible allocation of new network segments when service expansion is needed.

[0102] The following will combine Figures 2-6 This application introduces the technical solutions for service access in its embodiments.

[0103] For example, Figure 2 This is a schematic diagram illustrating a service access method provided in an embodiment of this application. For example... Figure 2 As shown, the example of terminal device 200 accessing service server 1 in subnet 1 will be used for illustration.

[0104] It should be understood that before business access, the SRE first needs to configure the mapping relationship between business name and business ID on the global (or global) name service GNS server, and configure network security policies on ELB1 and VPC.

[0105] For example, SRE can configure the mapping between business names and business IDs on the Global Name Service (GNS) server.

[0106] For example, the Huawei App Market includes a business name of "search-drcn.appstore.huawei" with a corresponding business ID of "0x0123", and the Huawei account includes a business name of "hwid-drcn.platform.huawei" with a corresponding business ID of "0x0456".

[0107] Furthermore, SRE can further configure the mapping relationship between service names and IP addresses, and time to live (TTL). Table 3 shows the configuration table of the mapping relationship between service names and service IDs.

[0108] Table 3

[0109]

[0110] In some alternative implementations, the service IDs in Table 3 can change dynamically. For example, the service ID can change once every preset time interval, or the service IDs in Table 3 can be updated by SRE triggering, thereby increasing security and reducing the risk of impersonation and malicious tampering.

[0111] In some implementations, the service name can also support multi-level configuration, enabling precise or fuzzy matching. For example, the service name ".platform.huawei" can include multiple second-level service names and their corresponding service IDs. When other services request the service name ".platform.huawei", GNS can return all the second-level service names and their corresponding service IDs included under that service name, thereby reducing the workload of SRE configuration and lowering the complexity of parsing service names and service IDs in batch requests from other services.

[0112] For example, SREs can configure network security policies in ELB1 and VPC.

[0113] When configuring network security policies on ELB1, SREs can configure whitelists and / or blacklists for source services. Packets from source services in the whitelist are allowed to be forwarded, while packets from source services in the blacklist are not allowed to be forwarded.

[0114] In one implementation, the SRE can configure a whitelist of source services on ELB1. For example, the whitelist can include service name 1 to service name n.

[0115] In another implementation, the SRE can also configure a blacklist of source services on ELB1. For example, this blacklist can include service names p1 to pn.

[0116] In other examples, the SRE can further configure whitelists and / or blacklists for the target business on ELB1, and the process is similar.

[0117] When configuring network security policies on a VPC, the SRE can configure network ACLs and / or network security groups. The VPC can form a new 5-tuple based on the source service name, source port number, destination service name, destination port number, and transport protocol, and configure network security policies based on this new 5-tuple, such as binding subnets, virtual machines, containers, and container sets (e.g., pods) to restrict packet requests at service egress and ingress points. It's understood that the 5-tuple in the packets received by the VPC includes the source service ID, source port number, destination service ID, destination port number, and transport protocol. However, since the VPC can obtain the mapping between service names and service IDs from the GNS, the VPC can determine the service name corresponding to the service ID in the packet.

[0118] For example, the configuration table for network security policies on a VPC can be found in Table 4.

[0119] Table 4

[0120]

[0121] The terminal device 200 may include an IPv6 network software development kit (SDK). The SDK can periodically send a service name resolution request to the Global Name Service (GNS) server. This resolution request is used to request the correspondence between the service name and the service ID in order to determine the service ID corresponding to the service name.

[0122] It should be understood that the number of service names can be multiple. In this case, the resolution request is used to request the mapping relationship between multiple service names and multiple service IDs, and there is a one-to-one correspondence between the service names and service IDs.

[0123] In some examples, the SRE can also set a Time-to-Live (TTL). After the timeout, the terminal device 200 resends the resolution request to the GNS server to obtain the latest service ID corresponding to the service name, thereby improving security.

[0124] For example, the TTL may be 600 seconds or 500 seconds, etc., which is not limited in the embodiments of this application.

[0125] Similarly, ELB1 can send a service name resolution request to the GNS server based on the service names in the whitelist and blacklist of the configured network security policy to obtain the service ID corresponding to the service name. In this way, ELB1 can determine what the service ID is for the service name in the whitelist and blacklist, which is beneficial for subsequent packet forwarding or dropping.

[0126] In some examples, the SRE can also set a Time-to-Live (TTL). After the timeout, ELB1 resends the resolution request to the GNS server to obtain the latest service ID corresponding to the service name, thereby improving security.

[0127] Similarly, VPC can send a service name resolution request to the GNS server based on the network ACL in the configured network security policy and the service name in the network security group to obtain the service ID corresponding to the service name. In this way, VPC can determine the service ID of the service name in the network security policy, which is beneficial for subsequent packet forwarding or dropping.

[0128] In some examples, the SRE can also set a Time-to-Live (TTL). After the timeout, the VPC resends the resolution request to the GNS server to obtain the latest service ID corresponding to the service name, thereby improving security.

[0129] It should be understood that the SRE can configure network security policies in the same way for ELBs and service servers in other subnets.

[0130] In this embodiment of the application, when a service in the terminal device 200 needs to access the service server 1, the access path is ELB1-VPC-service server 1. The corresponding steps may include steps 210 to 230.

[0131] 210. Terminal device 200 sends message A to ELB1, where message A includes the source service ID.

[0132] In some examples, packet A is an IPv6 packet, and terminal device 200 can carry the source service ID in the destination options header field of packet A. The source service is the service that terminal device 200 needs to access service server 1.

[0133] In other examples, terminal device 200 may carry the service ID of the source service and the service ID of the destination service in the destination option extension header field of message A. For example, the service ID of the destination service defaults to 0x0000 or 0xFFFF.

[0134] For example, see Figure 3 , Figure 3 This is a schematic diagram of an IPv6 packet structure provided in an embodiment of this application. For example... Figure 3 As shown, the message may include a basic message header, an extended message header, and a payload.

[0135] The fields in the basic message header may include vision, traffic class, flow label, payload length, next header, hop limit, source address, and destination address.

[0136] The version field is 4 bits long. A value of "4" indicates IPv4, and a value of "6" indicates IPv6.

[0137] The Traffic Category field is 8 bits long and is used to distinguish the Service Code Point (SCOP) marking of an IPv6 packet, thereby indicating how the packet should be handled.

[0138] The flow label field is 20 bits long and is used to mark a flow of IP packets. The current standard does not define the details of how to manage and process flow labels.

[0139] The payload length field is used to indicate the length of the payload, which refers to the data packet that immediately follows the IPv6 base header and includes the IPv6 extension header.

[0140] The next header field is 8 bits long and is used to specify the information type of the extended header that follows the IPv6 basic header.

[0141] The jump limit field is 8 bits long and is used to define the maximum number of hops that an IPv6 packet can take. This field is very similar to the TTL field in IPv4.

[0142] The source address field is 128 bits long and is used to indicate the source address from which the message was sent.

[0143] The destination address field is 128 bits long and is used to indicate the destination address for receiving the message.

[0144] Fields in the extended header can include hop-by-hop options extended header, destination options extended header, route extended header, etc.

[0145] The value of the hop-by-hop option extended header field is 0, and it is used to define the next header field in the IPv6 header.

[0146] The routing extension header field is used for source routing options and mobile IPv6.

[0147] In this embodiment of the application, the service ID of the source service can be carried in the target option extension header field.

[0148] For example, see Figure 4 , Figure 4 This is a schematic diagram of the structure of a destination option extension header field provided in an embodiment of this application. The destination option extension header field of this message may include the type of APN-ID, reserved bits, the type of APN network performance requirement parameter (APN-Para), APN-ID, intent (optional), and APN network performance requirement parameter (optional).

[0149] The APN-ID type field indicates the type of the APN-ID. A value of "1" indicates a length of 32 bits; a value of "2" indicates a length of 64 bits; a value of "3" indicates a length of 128 bits; and a value of "4" indicates a length of 64 bits, comprising a 32-bit service ID and a 32-bit destination service ID. In this embodiment, the APN-ID type field in the destination option extension header of message A is set to "4".

[0150] The type field of APN-Para indicates which network performance requirements are included in the APN-Para field. For example, this parameter may include bandwidth, latency, jitter, packet loss rate, etc.

[0151] The intent field is used to represent a set of intent requests made to the network.

[0152] The APN-Para field is used to represent the specific content information of network performance requirement parameters. Each parameter uses 4 bytes, and the parameters included are determined by the type of APN-Para.

[0153] The APN-ID may include the source service ID and / or the destination service ID.

[0154] In some examples, if the APN-ID carries the source service ID but not the destination service ID, then the APN-ID includes a 32-bit source service ID and the other 32-bit destination service ID has a value of either all 0 or all 1.

[0155] In some examples, if the APN-ID carries the destination service ID but not the source service ID, then the APN-ID includes a 32-bit destination service ID and the other 32-bit source service ID, which are all 0 or all 1.

[0156] In some examples, if the APN-ID carries a source service ID and a destination service ID, then the APN-ID includes a 32-bit source service ID and a 32-bit destination service ID.

[0157] It should be understood that the service that initiates the service access in the terminal device 200 is the source service, and the service that is accessed in the service server 1 is the destination service.

[0158] In this embodiment, when terminal device 200 sends message A, the destination option extension header field in message A carries the source service ID. During the transmission of message A, by default, intermediate network elements (such as ELB1, VPC) will not modify the destination option extension header field when forwarding message A. This ensures compatibility with existing IPv6 standards.

[0159] 220. When ELB1 determines that message A meets the forwarding requirements, it sends message A to the VPC.

[0160] Since network security policies have been configured in ELB1, and ELB1 periodically sends resolution requests to the GNS server to obtain the service IDs corresponding to the service names in the configured whitelist and / or blacklist.

[0161] In some implementations, message A carries a source service ID. When ELB1 receives message A, the rules for determining whether to forward the source service ID are as follows.

[0162] a1: If a whitelist and blacklist are configured, and the service name corresponding to the source service ID is in the whitelist, then forwarding of message A is allowed.

[0163] a2: If a whitelist and a blacklist are configured, and the service name corresponding to the source service ID is in the blacklist, then the packet A will be discarded.

[0164] a3: When only a whitelist is configured, all packets with service names not on the whitelist will be discarded. That is, if the service name corresponding to the source service ID is on the whitelist, then packet A is allowed to be forwarded; if it is not on the whitelist, then packet A will be discarded.

[0165] a4: When only a blacklist is configured, packets with service names not in the blacklist are allowed to be forwarded. That is, if the service name corresponding to the source service ID is in the blacklist, then packet A is discarded; if it is not in the blacklist, then packet A is allowed to be forwarded.

[0166] A5: Supports fuzzy matching; "*" represents matching all. For example, the business name "*.ads.huawei" can match businesses such as "api.adas.hauwei", "open.ads.huawei", and "platform.ads.huawei".

[0167] a6: Modification of information in the Destination Options Extension Header field of an IPv6 packet is not allowed.

[0168] It should be understood that if message A carries a destination service ID, the whitelist, blacklist, and destination service ID can be matched to determine whether to allow forwarding of message A.

[0169] Understandably, when ELB1 determines that message A does not meet the forwarding requirements, it can directly discard message A.

[0170] In some implementations, ELB1 may include a central processing unit (CPU) and a network processor (NP). When the CPU determines that packet A is the first packet of the service, it can generate a forwarding table and send it to the forwarding chip (such as the NP). The NP can then determine whether to forward packet A according to the rules described above.

[0171] For example, if the CPU determines that the service ID carried by message A is appearing for the first time, it can determine that message A has been received for the first time.

[0172] 230. When VPC determines that message A meets the forwarding requirements, it sends message A to business server 1.

[0173] Since network security policies have been configured in the VPC, and the VPC periodically sends resolution requests to the GNS server to obtain the service ID corresponding to the service name in the configured network ACL and / or network security group.

[0174] In some implementations, message A carries the source service ID. When the VPC receives message A, the rules for determining whether to forward message A are as follows.

[0175] b1: Supports fuzzy matching, where "*" represents matching all. For example, the business name "*.ads.huawei" can match businesses such as "api.adas.hauwei", "open.ads.huawei", and "platform.ads.huawei".

[0176] b2: Modification of information in the Destination Options Extension Header field of an IPv6 packet is not allowed.

[0177] b3: Match each rule sequentially according to its order and priority, based on the network ACL and / or network security group rules. For example, a VPC can match packet A against the rules in Table 4 to determine whether to forward packet A.

[0178] For rule b1 above, if the service ID carried in message A is the ID corresponding to ".ads.huawei", then all secondary services under the service name ".ads.huawei" can be matched.

[0179] In some implementations, if the VPC includes a CPU and an NP, the CPU can generate a forwarding table based on the new 5-tuple and send it to the NP. The NP can then determine whether to forward the message A based on the rules described above.

[0180] In other examples, message A may also carry a destination service ID. In this case, the description of whether message A conforms to the forwarding rules is the same as the description of message A carrying the source service ID mentioned earlier, and will not be repeated here. The destination service is the service of service server 1 that message A needs to access.

[0181] If message A meets the forwarding requirements, the VPC can send message A to service server 1 to enable service access. If message A does not meet the forwarding requirements, the VPC can discard message A.

[0182] Based on the embodiments of this application, SRE can configure network security policies based on service names without mapping service names to IP network segments, making the configuration method convenient and simple.

[0183] In this way, the IP network segments corresponding to the service names are contiguous, with no wasted IP addresses. Applications can be made on demand, and new network segments can be flexibly allocated when service needs expansion. Furthermore, the IP network segments corresponding to the service can be released at any time when the service is not in use.

[0184] Furthermore, when terminal devices access business servers within the data center, network elements along the access path can determine whether the packet meets the forwarding requirements based on the configured network security policies. Since the packet carries a business ID that includes at least the source business ID, the source of the business access can be controlled, thereby improving network security.

[0185] For example, Figure 5 This is a schematic diagram illustrating another service access method provided in an embodiment of this application. For example... Figure 5 As shown, the example of business access to business server 2 in business server 1 will be used for illustration.

[0186] It should be understood that a network security policy has already been configured in the VPC before any business access from business server 1 goes to business server 2. Refer to the relevant descriptions above for instructions on configuring the network security policy.

[0187] Similarly, the SRE has already configured the mapping between service names and service IDs on the GNS server, as detailed above. Figure 2As described in the documentation, Business Server 1, VPC, and Business Server 2 can periodically send resolution requests to the GNS server to obtain the mapping between business names and business IDs.

[0188] For example, the service server 1 may include an SDK, which sends a service message B to access the service server 2. The path for the service in service server 1 to access service server 2 is VPC-service server 2. The message B first arrives at the VPC, and the VPC decides whether to forward the message B to the service server 2. The steps corresponding to this access process may include steps 310 to 320.

[0189] 310. Service server 1 sends message B to VPC, where message B includes source service ID 2. Correspondingly, VPC receives message B.

[0190] It should be understood that the data structure of message B can be the same as that of message A. For example, business server 1 can carry the service ID2 of the source service in the destination option extension header field of message B. The source service is the service in business server 1 that needs to access business server 2.

[0191] In other examples, message B may also carry the destination service ID, for example, see [link to example]. Figure 4 Furthermore, the destination option extension header field of message B can also include the destination service ID. This allows administrators to implement bidirectional control over the source and destination of service access when configuring network security policies, thereby enhancing network security for communication between service servers within the data center.

[0192] 320. When VPC determines that message B meets the forwarding requirements, it sends message B to business server 2.

[0193] For example, after receiving packet B, the VPC can determine whether packet B meets the forwarding requirements according to the configured network security policy. If packet B meets the forwarding requirements, it can send packet B to service server 2 to complete the service access. If the VPC determines that packet B does not meet the forwarding requirements according to the network security policy, it can directly discard packet B.

[0194] It should be understood that when the VPC determines that packet B does not meet the forwarding requirements according to the network security policy, it means that packet B does not comply with the network security policy configured by the administrator, and therefore packet B is discarded to ensure network security.

[0195] In some implementations, message B carries the source service ID2. When the VPC receives message B, the rules for determining whether to forward message A are as follows.

[0196] b1: Supports fuzzy matching, where "*" represents matching all. For example, the business name "*.ads.huawei" can match businesses such as "api.adas.hauwei", "open.ads.huawei", and "platform.ads.huawei".

[0197] b2: Modification of information in the Destination Options Extension Header field of an IPv6 packet is not allowed.

[0198] b3: Match each rule sequentially according to its order and priority, based on the rules in the network ACL and / or network security group. For example, the VPC can match packet B according to the rules in Table 4 to determine whether to forward packet B.

[0199] In some implementations, the VPC includes a CPU and an NP. The CPU can generate a forwarding table based on the new 5-tuple and send it to the NP. The NP can determine whether to forward the message B based on the above rules.

[0200] Optionally, for business servers 1 accessing other business servers within the data center, please refer to the above description.

[0201] Based on the embodiments of this application, SRE can configure network security policies based on service names without mapping service names to IP network segments, making the configuration method convenient and simple.

[0202] In this way, the IP network segments corresponding to the service names are contiguous, with no wasted IP addresses. Applications can be made on demand, and new network segments can be flexibly allocated when service needs expansion. Furthermore, the IP network segments corresponding to the service can be released at any time when the service is not in use.

[0203] Furthermore, when business access occurs between business servers, network elements in the access path can determine whether the packet meets the forwarding requirements based on the configured network security policy. Since the packet carries a business ID that includes at least the source business ID, the source of the business access can be controlled, thus improving network security.

[0204] For example, Figure 6 This is a schematic diagram illustrating another service access method provided in an embodiment of this application. For example... Figure 6 As shown, the example of a business server 1 accessing a third-party server outside the data center will be used for illustration.

[0205] As mentioned earlier, the SRE first configures the mapping between service names and service IDs on the GNS server. This process can be found in the previous text. Figure 2 For the sake of brevity, the description will not be repeated here.

[0206] Similarly, SREs configure network security policies on VPCs and egress gateways; see the previous text for details. Figure 2 The description in the text.

[0207] The business server 1 may include an SDK. When accessing a third-party server through the SDK, the access path for the business message C is: VPC - egress gateway - third-party server. The corresponding steps may include steps 410 to 430.

[0208] 410. Service server 1 sends message C to VPC, where message C includes source service ID 3.

[0209] For example, the Destination Options extension header field in message C carries the source service ID3.

[0210] In other examples, message C includes the destination service ID.

[0211] In other examples, message C includes both the source service ID and the destination service ID.

[0212] 420. When the VPC determines that message C meets the forwarding requirements, it sends message C to the egress gateway. The egress gateway then receives message C.

[0213] For example, after receiving packet C, the VPC can determine whether packet C meets the forwarding requirements according to the configured network security policy. If packet C meets the forwarding requirements, it can send packet C to the egress gateway to complete the service access. If the VPC determines that packet C does not meet the forwarding requirements according to the network security policy, it can directly discard packet C.

[0214] It should be understood that when VPC determines that packet C does not meet the forwarding requirements according to the network security policy, it means that packet C does not comply with the network security policy configured by the administrator, and its business traffic is not allowed to access the third-party server. In this case, VPC can directly discard packet C to ensure network security.

[0215] It is understandable that the rules by which VPC determines whether packet C meets the forwarding requirements can be found in the previous description, and will not be repeated here.

[0216] 430. When the egress gateway determines that message C meets the forwarding requirements, it sends message C to the third-party server.

[0217] For example, after receiving packet C, the egress gateway can determine whether packet C meets the forwarding requirements according to the configured network security policy. If packet C meets the forwarding requirements, it can send packet C to the third-party server to complete the service access. If the egress gateway determines that packet C does not meet the forwarding requirements according to the network security policy, it can directly discard packet C.

[0218] It should be understood that when the egress gateway determines that packet C does not meet the forwarding requirements according to the network security policy, it means that packet C does not comply with the network security policy configured by the administrator, and its business traffic is not allowed to access the third-party server. In this case, the egress gateway can directly discard packet C to ensure network security.

[0219] In some implementations, message C carries source service ID3. When the egress gateway receives message A, the rules for determining whether to forward the source service ID are as follows.

[0220] c1: If a whitelist and blacklist are configured, and the service name corresponding to the source service ID3 is in the whitelist, then forwarding of the message C is allowed.

[0221] c2: If a whitelist and blacklist are configured, and the service name corresponding to the source service ID3 is in the blacklist, then the packet C will be discarded.

[0222] c3: When only a whitelist is configured, all packets with service names not in the whitelist are discarded. That is, if the service name corresponding to the source service ID3 is in the whitelist, then packet C is allowed to be forwarded; if it is not in the whitelist, then packet C is discarded.

[0223] c4: When only a blacklist is configured, packets with service names not in the blacklist are allowed to be forwarded. That is, if the service name corresponding to the source service ID3 is in the blacklist, then packet C is discarded; if it is not in the blacklist, then packet C is allowed to be forwarded.

[0224] c5: Supports fuzzy matching; "*" represents matching all. For example, the business name "*.ads.huawei" can match businesses such as "api.adas.hauwei", "open.ads.huawei", and "platform.ads.huawei".

[0225] c6: Modification of information in the Destination Options Extension Header field of an IPv6 packet is not allowed.

[0226] In this way, VPC and egress gateway can match the source service ID3 carried in message C to control the source of service access, so that only qualified service sources can access third-party servers, thereby improving network security.

[0227] It should be understood that if message C carries a destination service ID, the egress gateway can match the whitelist, blacklist, and destination service ID to determine whether to allow forwarding of message C.

[0228] In this way, VPCs and egress gateways can match the destination service ID carried in message C to control the destination service accessed by the service, so that qualified service traffic can access third-party servers, thereby improving network security.

[0229] In some examples, message C may include either the source service ID3 or the destination service ID. The process for determining whether it meets the forwarding requirements is similar and will not be described in detail here.

[0230] In some implementations, the egress gateway includes a CPU and an NP. The CPU can generate a forwarding table based on the new 5-tuple and send it to the NP. The NP can determine whether to forward the message C based on the above rules.

[0231] Based on the embodiments of this application, SRE can configure network security policies based on service names without mapping service names to IP network segments, making the configuration method convenient and simple.

[0232] In this way, when allocating network segments for services, the IP addresses they occupy are continuous, with no wasted IP addresses. Applications can be made on demand, and new network segments can be flexibly allocated when services need to be expanded. Furthermore, the IP network segment corresponding to the service can be released at any time when the service is not in operation.

[0233] Based on the embodiments of this application, when a business server in a data center needs to access a third-party server, the network elements in the access path can determine whether the packet meets the forwarding requirements based on the configured network security policy. Since the packet carries a business ID that includes at least the source business ID, the source of the business access can be controlled, thereby improving network security.

[0234] Optionally, the process of accessing third-party servers from other business servers within the data center can be found in the above description.

[0235] Figure 7 This is a schematic flowchart illustrating a service access method provided in an embodiment of this application. For example... Figure 7 As shown, the method 700 can be applied to a first device, and the method 700 may include steps 710 to 730.

[0236] 710, The first device obtains the first correspondence between multiple service names and multiple service identity IDs, and the multiple service names correspond one-to-one with the multiple service IDs.

[0237] It should be understood that the identity ID can also be an identifier, identifier, identity information, identification information, identification number, identity number, serial number, etc., and this application does not limit it in this way.

[0238] For example, the first mapping relationship can be presented in tabular form or in a key-value pair format. For instance, the first mapping relationship can be stored in a table, and the first device can directly access the table to obtain the mapping relationship between multiple service names and multiple service IDs.

[0239] The correspondence between multiple business names and multiple business IDs can be understood as each business name uniquely corresponding to one business ID.

[0240] In some implementations, the first correspondence can be configured in a third device (such as a GNS), and the first device can send a first parsing request to the third device to obtain the first correspondence.

[0241] In some implementations, to enhance network security, the first device can also dynamically obtain the first correspondence. For example, the first correspondence in the third device can change dynamically, and the first device repeatedly sends a first parsing request to the third device at preset time intervals to obtain the latest first correspondence.

[0242] For example, the preset duration can be 600s or 500s, etc., and the specific value of the preset duration is not limited in this application embodiment.

[0243] Based on the embodiments of this application, the first device needs to resend the first parsing request to the third device at preset time intervals to obtain the latest first correspondence. In this way, the first correspondence in the third device can change dynamically, and the first device can dynamically obtain the first correspondence, thereby ensuring network security.

[0244] 720. The first device determines the first service ID corresponding to the first service name according to the first correspondence relationship, wherein the first service name includes the service name of the source service that triggered the generation of the first message, and / or the service name of the destination service that the source service needs to access.

[0245] The first device may include multiple service names for multiple services. After obtaining the first correspondence, the first device can determine the first service ID corresponding to the first service name associated with the first message. For example, the first service name may include the service name of the source service and / or the service name of the destination service.

[0246] 730, the first device sends a first message to the second device where the destination service is located. The first message includes the first service ID.

[0247] For example, the first device can be a terminal device or a business server.

[0248] Optionally, before the second device where the target service to be accessed is located sends the first message, the method 700 further includes: generating the first message.

[0249] It should be understood that when the first device sends the first message to the second device, the first message may be forwarded by multiple network elements within the data center before finally reaching the second device. For example, the path of the first message may be first device-fourth device-second device, or it may be first device-fourth device-fifth device-second device.

[0250] It should also be understood that if the first packet does not conform to the network security policy configured in the network element, the network element may also discard the first packet. In this case, the first packet will not be able to reach the second device.

[0251] Based on the embodiments of this application, the first device can obtain multiple service IDs corresponding to multiple service names, thereby determining the unique service ID corresponding to each service name, and sending a first message carrying the aforementioned service ID to the second device where the target service to be accessed is located.

[0252] In this way, the first message can be directly associated with business information. After receiving the first message, the network elements in the data center can directly determine the relevant business information and match the network security policy based on the business ID to determine whether to forward the first message. This can restrict the source business and / or destination business access to improve network security.

[0253] In some implementations, the first service ID is carried in the extended header field of the first message.

[0254] For example, the extended header field can be a destination option extended header field. In other examples, the header field may also be carried in other extended header fields, which is not limited in this embodiment.

[0255] In some implementations, the first message includes a 5-tuple, which includes the protocol number, the service ID of the source service, the source port number, the destination port number, and the service ID of the destination service.

[0256] Based on the embodiments of this application, the five-tuple information of the first message carries business information (such as the business ID of the source business and the business ID of the destination business), so that the first message can be directly associated with business information, which is beneficial for managers to consider business factors when configuring network security policies and can reduce the workload of managers in configuring network security policies.

[0257] Figure 8 This is an illustrative flowchart illustrating another service access method provided in an embodiment of this application. For example... Figure 8 As shown, the method 800 can be applied to a fourth device, and the method 800 may include steps 810 to 840.

[0258] 810, The fourth device obtains the second correspondence between multiple service names and multiple service identity IDs included in the configured network security policy, and the multiple service names correspond one-to-one with the multiple service IDs.

[0259] For example, the fourth device can be a network element such as an Elastic Load Balancer (ELB), a Virtual Private Cloud (VPC), or an egress gateway.

[0260] For example, the SRE can configure network security policies on a fourth device. For instance, the SRE can configure network security policies based on service names.

[0261] The fourth device can obtain a second mapping relationship between multiple service IDs and the multiple service names included in the configured network security policy.

[0262] For example, a fourth device can send a second resolution request to a third device (such as GNS) to obtain the second mapping.

[0263] Optionally, to enhance network security, the fourth device may resend the second parsing request to the third device at preset intervals.

[0264] Optionally, when the fourth device obtains the second correspondence, it may also obtain the business ID corresponding to a business name other than the business name included in the network security policy.

[0265] For example, the GNS stores a table containing a first number of service names and their corresponding service IDs. The fourth device retrieves this table from the GNS. In addition to the multiple service names and their corresponding service IDs in the network security policy configured by the fourth device, the table also includes other service names and their corresponding service IDs.

[0266] 820, the fourth device receives the first message sent by the first device. The first message includes a first service ID, wherein the first service name corresponding to the first service ID includes the service name of the source service that triggered the generation of the first message, and / or the service name of the destination service accessed by the source service.

[0267] For example, the first message may be a message sent by the first device. For instance, when the first device sends the first message to the second device, the first message needs to be forwarded by a fourth or more devices in the network before it can reach the second device.

[0268] 830, the fourth device determines the first service name corresponding to the first service ID based on the second correspondence.

[0269] Since the fourth device has obtained the second correspondence between the service name and the service ID in the network security policy, after receiving the first message, the fourth device can determine that the service name corresponding to the first service ID displayed in the first message is the first service name.

[0270] 840. The fourth device determines whether to forward the first message based on the network security policy and the first service name.

[0271] In some implementations, when the fourth device determines that the first service name conforms to the security rules, it may forward the first message to the next node. Alternatively, when the fourth device determines that the first service name does not conform to the security rules, it may discard the first message.

[0272] Based on the embodiments of this application, the fourth device can obtain the correspondence between multiple service names and multiple service IDs included in the network security policy. After receiving the first message sent by the first device, since the first message carries a service ID, the first device can determine the service name corresponding to the service ID carried in the first message based on the obtained correspondence between multiple service names and multiple service IDs; and match the service name with the network security policy to determine whether to forward the first message.

[0273] In this way, the fourth device can restrict the source and / or destination services accessed by the service, thereby improving network security. Furthermore, configuring network security policies based on service names simplifies configuration. Moreover, this technical solution ensures that the IP network segments corresponding to service names are contiguous, eliminating IP address waste and allowing for on-demand allocation. When service expansion is needed, new network segments can be flexibly allocated.

[0274] In some implementations, the decision to forward the first packet is based on the configured network security policy and the first service name. This includes: forwarding the first packet if the first service name conforms to the security rules in the network security policy; or discarding the first packet if the first service name does not conform to the security rules in the network security policy.

[0275] For example, see Figure 2 The fourth device is ELB1. If the fourth device determines to forward the first message, it can forward the first message to the VPC.

[0276] For example, see Figure 5 The fourth device is a VPC. If the fourth device determines to forward the first message, it can forward the first message to the service server 2.

[0277] Based on the embodiments of this application, the fourth device can match the first service name based on the configured network security policy, and forward the first message to the next node if it meets the security rules, and directly discard the first message if it does not meet the security rules.

[0278] In this way, the fourth device can filter received packets based on the configured network security policy to ensure network security.

[0279] In some implementations, network security policies include whitelists and blacklists for business names, determining whether the first business name conforms to the security rules in the network security policy, including:

[0280] If the first business name is in the whitelist, it is determined that the first business name complies with the security rules in the network security policy.

[0281] Alternatively, determine that the first business name does not comply with the security rules in the network security policy, including: when the first business name is in the blacklist, determine that the first business name does not comply with the security rules in the network security policy.

[0282] Based on the embodiments of this application, when the configured network security policy includes a whitelist and a blacklist, the fourth device can determine whether the first service name conforms to security rules based on whether it is in the whitelist or the blacklist. In this way, the fourth device can conveniently determine whether the first service name conforms to security rules.

[0283] In some implementations, network security policies include whitelists or blacklists of business names, determining whether a primary business name conforms to the security rules in the network security policy, including:

[0284] If the first business name is not in the blacklist, it is determined that the first business name complies with the security rules in the network security policy.

[0285] Alternatively, determine that the first business name does not comply with the requirements of the network security policy, including: when the first business name is not in the blacklist or whitelist, determine that the first business name does not comply with the security rules in the network security policy.

[0286] Based on the embodiments of this application, when the configured network security policy includes a whitelist or a blacklist, the fourth device can determine whether the first service name conforms to security rules based on whether it is in the whitelist or blacklist. In this way, the fourth device can conveniently determine whether the first service name conforms to security rules.

[0287] In some implementations, the network security policy includes a network access control list (ACL) or a network security group. The ACL or network security group includes access information for multiple service names. The system determines that the first service name conforms to the security rules in the network security policy, including:

[0288] When the first service name matches the access information in the network ACL or network security group, it is determined that the first service name conforms to the security rules in the network security policy.

[0289] Alternatively, determine that the first service name does not comply with the security rules in the network security policy, including: when the first service name does not match the access information in the network ACL or network security group, determine that the first service name does not comply with the security rules in the network security policy.

[0290] Based on the embodiments of this application, the fourth device can conveniently determine whether the first service name complies with security rules.

[0291] In some implementations, the first service ID is carried in the extended header field of the first message.

[0292] For example, the extended header field can be a destination option extended header field. In other examples, the header field may also be carried in other extended header fields, which is not limited in this embodiment.

[0293] In some implementations, the first message includes a 5-tuple, which includes the protocol number, the ID of the source service, the source port number, the destination port number, and the ID of the destination service.

[0294] Based on the embodiments of this application, the five-tuple information of the first message carries business information (such as the ID of the source service and the ID of the destination service), so the first message can be directly associated with business information, which is beneficial for managers to configure network security policies based on business information and can reduce the workload of managers in configuring network security policies.

[0295] Figure 9 This is a schematic block diagram of a device provided in an embodiment of this application. Figure 9 As shown, the device 900 includes one or more processors 910; one or more memories 920; the one or more memories 920 storing one or more instructions that, when executed by one or more processors 910, cause the service access method as described in any of the possible implementations above to be executed.

[0296] For example, the device 900 can be the terminal device 200, ELB, VPC, egress gateway, service server, first device, second device, third device, fourth device, etc. mentioned above. The device 900 can be used to execute the methods 700, 800, etc. mentioned above.

[0297] This application also provides an apparatus including a processor and a communication interface. The communication interface is used to receive signals and transmit the signals to the processor. The processor processes the signals so that the service access method described in any of the possible implementations above is executed.

[0298] The device can be a chip. For example, the chip can be a chip system or a standalone chip.

[0299] This application also provides a readable storage medium (also known as a computer-readable storage medium) storing a program that, when run on a device, causes the device to execute the aforementioned method steps to implement the service access method described in the above embodiments.

[0300] This application also provides a program product (also known as a computer program product) that, when run on a device, causes the device to perform the aforementioned steps to implement the service access method described in the above embodiments.

[0301] This application also provides an apparatus including a module for implementing the service access method as described in any of the foregoing embodiments.

[0302] In addition, embodiments of this application also provide an apparatus, which may specifically be a chip, component, or module. The apparatus may include a connected processor and a memory; wherein the memory is used to store instructions, and when the apparatus is running, the processor may execute the instructions stored in the memory to cause the apparatus to perform the service access methods in the above-described method embodiments.

[0303] In this embodiment, the device, readable storage medium, program product or apparatus are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects of the corresponding methods provided above, and will not be repeated here.

[0304] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0305] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0306] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed.

[0307] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0308] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0309] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory, random access memory, magnetic disks, or optical disks.

[0310] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A method for accessing services, characterized in that, The method is applied to a first device, and the method includes: Obtain a first correspondence between multiple business names and multiple business identity IDs, wherein the multiple business names correspond one-to-one with the multiple business IDs; The first service ID corresponding to the first service name is determined according to the first correspondence, wherein the first service name includes the service name of the source service that triggers the generation of the first message, and / or the service name of the destination service that the source service needs to access; The first message is sent to the second device where the target service is located, and the first message includes the first service ID.

2. The method according to claim 1, characterized in that, The first service ID is carried in the extended header field of the first message.

3. The method according to claim 1 or 2, characterized in that, The step of obtaining the first correspondence between multiple service names and multiple service IDs includes: A first parsing request is sent to a third device, the first parsing request being used to obtain the first correspondence.

4. The method according to any one of claims 1-3, characterized in that, The first message includes a five-tuple, which includes the protocol number, the service ID of the source service, the source port number, the destination port number, and the service ID of the destination service.

5. A method for accessing services, characterized in that, The method is applied to a fourth device, and the method includes: Obtain the second correspondence between multiple service names and multiple service identity IDs included in the configured network security policy, wherein the multiple service names and the multiple service IDs correspond one-to-one; Receive a first message sent by a first device, the first message including a first service ID, wherein the first service name corresponding to the first service ID includes the service name of the source service that triggered the generation of the first message, and / or the service name of the destination service accessed by the source service; The first service name corresponding to the first service ID is determined according to the second correspondence relationship; Whether to forward the first message is determined based on the network security policy and the first service name.

6. The method according to claim 5, characterized in that, The step of determining whether to forward the first packet based on the configured network security policy and the first service name includes: If the first service name is determined to conform to the security rules in the network security policy, the first packet is forwarded; or, If the first service name is determined to be inconsistent with the security rules in the network security policy, the first packet is discarded.

7. The method according to claim 6, characterized in that, The network security policy includes a whitelist and a blacklist of business names. Determining that the first service name conforms to the security rules in the network security policy includes: If the first service name is in the whitelist, it is determined that the first service name conforms to the security rules in the network security policy. Alternatively, determining that the first service name does not conform to the security rules in the network security policy includes: If the first service name is in the blacklist, it is determined that the first service name does not comply with the security rules in the network security policy.

8. The method according to claim 6, characterized in that, The network security policy includes a whitelist or blacklist of business names. Determining that the first service name conforms to the security rules in the network security policy includes: If the first service name is not in the blacklist, it is determined that the first service name conforms to the security rules in the network security policy; or... The determination that the first service name does not meet the requirements of the network security policy includes: If the first service name is not in the blacklist or whitelist, it is determined that the first service name does not comply with the security rules in the network security policy.

9. The method according to claim 6, characterized in that, The network security policy includes network access control lists (ACLs) or network security groups, which contain access information for multiple service names. Determining that the first service name conforms to the security rules in the network security policy includes: When the first service name matches the access information in the network ACL or network security group, it is determined that the first service name conforms to the security rules in the network security policy; or... The step of determining that the first service name does not conform to the security rules in the network security policy includes: When the first service name does not match the access information in the network ACL or network security group, it is determined that the first service name does not comply with the security rules in the network security policy.

10. The method according to any one of claims 5-9, characterized in that, The first service ID is carried in the extended header field of the first message.

11. The method according to any one of claims 5-10, characterized in that, The second correspondence between multiple service names and multiple service IDs included in the obtained network security policy configuration includes: A second parsing request is sent to a third device, the second parsing request being used to obtain the second correspondence.

12. The method according to claim 11, characterized in that, Sending the second parsing request to the third device includes: After a preset time interval, the second parsing request is resent to the third device.

13. The method according to any one of claims 5-12, characterized in that, The first message includes a five-tuple, which includes the protocol number, the service ID of the source service, the source port number, the destination port number, and the service ID of the destination service.

14. A device, characterized in that, include: One or more processors; One or more memories; the one or more memories storing one or more programs that, when executed by one or more processors, cause the method as described in any one of claims 1-13 to be performed.

15. A chip, characterized in that, The chip includes a processor and a communication interface, the communication interface being used to receive signals and transmit the signals to the processor, the processor processing the signals such that the method as described in any one of claims 1-13 is executed.

16. A readable storage medium, characterized in that, The readable storage medium stores instructions that, when executed on the device, cause the method as described in any one of claims 1-13 to be performed.

17. A program product, characterized in that, The program product includes program code that, when run on a device, causes the method as described in any one of claims 1-13 to be executed.