A network adaptive configuration system and method supporting secure resource access
Patent Information
- Application Number
- CN202611031838.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-13
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2046-07-13
AI Technical Summary
[0004]针对现有技术的不足,本发明提供一种支持资源安全接入的网络自适应配置系统及方法,解决了现有组网技术中配置流程繁琐、资源与网络调度脱节、中心化拓扑延迟高以及复杂网络环境下穿透能力不足的问题
本发明整合了控制层、网关层与数据传输层,系统构建了从盲状态到全网状智能互联的全生命周期闭环,利用网络端点地址动态感知和全网状拓扑协商机制,消除了传统中心化网关的流量中转瓶颈及单点故障风险,系统基于底层探针的综合负载风险模型、端到端时延评估以及单位字节加密开销模型,实现了网络路由动态切换与终端硬件资源健康状态的底层级深度耦合,结合跨操作系统平台的自适应网卡生成、动态载荷调优及基于载荷的会话密钥轮换机制,解决了传统异地组网技术中配置繁琐、资源与网络调度脱节、异构硬件兼容性差的问题。本发明为复杂异构网络提供了高吞吐、低延迟、前向保密的智能化通信基础设施。
Smart Images

Figure CN122533878B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to a network adaptive configuration system and method that supports secure access to resources, belonging to the field of computer network technology. Background Technology
[0002] Data centers need to frequently exchange large-scale data, access remote services, and collaborate with nodes in research institutions, enterprises, and universities. Existing networking technologies and terminal configuration schemes have shortcomings in practical applications. Network configuration is complex and deployment efficiency is low. Traditional methods require manual configuration of a large number of routing policies, keys, and firewall rules. This approach lacks automated management methods, resulting in long deployment cycles, difficulty in meeting the demand for rapid access, and a disconnect between computing resources and network scheduling.
[0003] The network layer cannot perceive the terminal hardware status in real time, and task distribution and resource scheduling cannot be dynamically optimized according to the terminal load. This can easily lead to uneven resource allocation or overload risks. The topology architecture has limited performance and high latency. The centralized architecture has single point of failure and bandwidth loss problems. Encrypted communication has high computational overhead on low-power edge devices, making it difficult to maintain low latency in high-bandwidth scenarios. The penetration capability is insufficient in complex network environments. Nodes in different regions and service providers are often restricted by firewalls and NAT. Although existing relay technologies can ensure connectivity, they sacrifice bandwidth and increase link complexity. There is a lack of efficient point-to-point adaptive negotiation mechanisms. The field needs a heterogeneous terminal networking solution that can automatically configure, perceive hardware status in real time, and has point-to-point direct connection capabilities. Summary of the Invention
[0004] To address the shortcomings of existing technologies, this invention provides a network adaptive configuration system and method that supports secure resource access, solving the problems of cumbersome configuration processes, disconnect between resource and network scheduling, high latency in centralized topologies, and insufficient penetration capability in complex network environments in existing networking technologies.
[0005] The technical solution of the present invention is as follows: A network adaptive configuration system supporting secure resource access includes a control layer, a gateway layer, and a data transmission layer, wherein: The control layer is used for centralized management of global network node registration status maintenance, key pair generation and distribution, and dynamic synchronization of routing policies; The gateway layer, deployed on the network terminal, integrates a network configuration client and a system probe to execute configuration commands and monitor the hardware operating status of the terminal in real time. The data transmission layer establishes encrypted transmission tunnels between terminals via the VPN protocol. The data transmission layer, in conjunction with the application gateway component, enables the conversion of private service protocols and remote access.
[0006] According to a preferred embodiment of the present invention, the control layer is deployed on a cloud server with a static public IP address, serving as the network management hub. The control layer includes a controller core built based on an interface and message transmission mechanism, a domain name resolution module, a reverse proxy component, and a message middleware that supports bidirectional communication protocols. The controller core is responsible for maintaining the global node registration status, generating and distributing key pairs, and dynamically synchronizing routing policies. The domain name resolution module provides private domain name resolution for each network node within the virtual network. The reverse proxy component serves as a secure access point, handling the secure isolation of management backend access, interface calls, and message transmission. The message middleware is used to perform heartbeat monitoring between the client and the server and to distribute configurations in real time.
[0007] According to a preferred embodiment of the present invention, the gateway layer adopts a terminal with heterogeneous access, the hardware of which includes an embedded network device or a physical node with general computing capabilities. An automated configuration client and a system probe are deployed inside the terminal. The automated configuration client is responsible for acquiring network parameters and automatically creating logical network card interfaces. The system probe collects resource load indicators such as processor utilization and storage occupancy, as well as environmental indicators such as hardware temperature, in real time according to a preset period. The system probe provides decision data support for network and resource coordination through a preset health evaluation model.
[0008] According to a preferred embodiment of the present invention, a sensing component is integrated into the terminal and coordinated with the control layer scheduling strategy to achieve deep coupling between hardware and network status. The adaptive mapping and remote management process is as follows: ① Real-time perception of multi-dimensional underlying resources; An internal background system sensing component runs on the terminal. This component resides at the operating system kernel boundary as a low-level probe, continuously monitoring the terminal's hardware resource status. The system probe polls the underlying hardware at preset time intervals, collecting multi-dimensional physical indicators in real time, including processor real-time utilization, memory load ratio, disk space remaining, and device core temperature. This forms a basic data set of the terminal's operating status, constructing a comprehensive load risk model to quantify the real-time operating pressure of network nodes. A unified assessment of the network node's operating status is then performed using multi-dimensional resource indicators, resulting in a node comprehensive load risk value R. load Satisfy the following formula:
[0009] Where e is the natural constant, serving as the base of the exponential function to amplify the sensitivity to load changes; U cpu Represents processor utilization; U mem Represents storage memory load; T curr This refers to the current core temperature of the equipment; T maxThe upper limit of the safe temperature for the equipment is designed; λ1, λ2 and λ3 represent the risk penalty coefficients of various physical indicators. Specifically, the risk penalty coefficients satisfy the normalization constraint (i.e. λ1+λ2+λ3=1), and the control layer performs dynamic adjustment according to the business attributes carried by the current terminal: for computing-intensive business, the system increases λ1 and decreases λ2; for data storage business, the system increases λ2 and decreases λ1; thereby realizing the adaptive coupling between the risk assessment model and the actual business scenario. This model amplifies the risk warning value under high load and high temperature conditions by introducing exponential and square operations. By R load The network node status is evaluated by comparing it in real time with a preset security threshold: when R load When the preset threshold is exceeded, the control layer determines that the network node has an operational risk and automatically triggers an adaptive scheduling strategy. This strategy reduces the network access route weight of the network node or performs request redirection to achieve dynamic load balancing of computing resources. ② Encrypted reporting and dynamic mapping of node operating status; The system dynamically associates the physical hardware operating status with the virtual network topology. The terminal-side sensing component serializes and encapsulates the collected physical indicator data. The sensing component securely reports the encapsulated telemetry data to the cloud control platform through an encrypted communication tunnel to prevent intermediate nodes from eavesdropping on or tampering with the terminal status information. After receiving the data, the cloud control platform parses and processes it. The platform establishes a mapping relationship between the hardware operating status of the underlying physical nodes and the corresponding virtual network nodes. The monitoring interface dynamically displays the distribution of the operating status of all physical nodes in the network. When the monitoring module detects that the risk value of a network node exceeds the preset security threshold, the control layer automatically triggers an adaptive scheduling strategy. The control layer dynamically lowers the network access routing weight of the network node and redirects new service access requests to adjacent network nodes with higher health, thereby achieving dynamic load balancing of computing resources and ensuring operational stability. ③ Remote proxy conversion under a clientless architecture; It supports clientless remote operation and maintenance of underlying physical nodes isolated within a virtual network. This mechanism relies on the application layer backend proxy module deployed in the cloud. The proxy module acts as an intermediary component between the front-end user and the underlying physical node, establishing a connection with the target physical node within the virtual network that includes underlying operation and maintenance protocols such as character terminal control protocol and encrypted file transfer protocol. During the conversion process, the proxy module acts as an intermediate component to perform bidirectional conversion on the data stream, capturing the original character stream and terminal escape sequence output by the network node in real time, serializing them and encapsulating them into a full-duplex WebSocket communication frame, thereby achieving transparent conversion from the underlying protocol to a web-compatible protocol; at the same time, it accurately maps the user commands returned by the browser frontend to the control codes of the underlying operation and maintenance protocol, and pushes the processed data stream to the user's standard browser frontend in real time through a secure communication channel, realizing remote operation and maintenance access capabilities without deploying additional client programs on the terminal; ④ Seamless connection guarantee in dynamic network environments; In complex network environments, the mapped addresses of network terminals may change dynamically. The proxy module keeps the state synchronized with the underlying virtual network control plane. When the virtual logical address of the underlying node drifts due to adaptive configuration, the internal domain name resolution module executes an automated update process. Specifically, the node-side client synchronously reports the latest address information to the control layer. Based on this, the resolution module dynamically corrects the device identifier-virtual address mapping record in the internal database. Subsequently, the proxy module, by monitoring changes in the addressing record, maintains the active state of the full-duplex communication session at the web frontend while seamlessly redirecting the backend connection to the new address after the drift. Even if the transmission path of the underlying virtual network undergoes adaptive switching, the user's browser access session remains connected, achieving complete transparency of underlying network state changes to upper-layer applications and ensuring seamless remote operation and maintenance of underlying hardware resources.
[0010] A network adaptive configuration method supporting secure resource access includes the following steps: (1) The terminal initiates registration with the control layer through the automated configuration client. The control layer automatically distributes network interface parameters and encryption keys to realize the automatic access of the terminal in the virtual network. (2) The system probe collects the computing resource load and environmental indicators of the terminal and associates them with the network scheduling strategy; (3) Establish point-to-point direct connection tunnels between each network node to construct a full mesh logical topology; (4) Configure multi-level encryption and decryption parameters for different terminals and complete data encapsulation in kernel mode to ensure efficient and secure communication between terminals.
[0011] According to a preferred embodiment of the present invention, in step (1), specifically: (11) Control layer environment initialization and global policy preset; Before system startup, the network infrastructure logic of the control layer is defined through configuration files, including preset management parameters, configuration of communication ports, and construction of a key derivation security model. The system pre-sets the static network address and management domain name of the controller, generates a master control key for identity authentication, and provides basic support for the operation of the control layer. Access control rules are configured on the control layer server. Through source IP whitelisting, device digital certificate verification, and protocol behavior filtering, the management interface and data interface are securely isolated. The system allows the ports required for management interface and domain name resolution service, and reserves dynamically allocated port ranges for subsequent data transmission. The system uses a key derivation mechanism to generate session keys for communication between network nodes based on the master control key, ensuring the randomness of key generation and communication security. (12) Adaptive access and interface construction for business nodes; When a terminal accesses the network, it executes an automated configuration process. The terminal initiates automated registration through an internally deployed automated configuration client. The terminal submits an access request to the control layer using authentication credentials. After receiving and verifying the authentication credentials, the control layer allocates a virtual network address to the terminal according to the global resource table. The virtual network address does not conflict with the terminal's local network. At the same time, the control layer issues the corresponding security parameters. After receiving the configuration, the terminal client automatically creates a logical network card interface in the operating system kernel mode. The terminal configures the maximum transmission unit and activates the encrypted communication link to achieve automatic access for the terminal.
[0012] According to a preferred embodiment of the present invention, in step (2), the system probe periodically collects multi-dimensional hardware indicators, and the system introduces a health evaluation model to achieve the coupling of network scheduling and hardware status. The functional expression of the health evaluation model is as follows:
[0013] Among them, U cpu Represents the real-time utilization of the processor; U mem T represents the utilization rate of storage resources. curr This indicates that the hardware is monitoring the temperature in real time; T limit This indicates the preset temperature tolerance limit for this type of equipment; w1, w2, and w3 represent weighting coefficients for various indicators. Specifically, the weighting coefficients satisfy the normalization constraint w1+w2+w3=1. The control layer establishes an adaptive mapping relationship between business scenarios and weighting coefficients: for compute-intensive businesses, the system increases w1 to enhance its sensitivity to processor load; for storage-intensive businesses, the system increases w2 to ensure high-concurrency read / write security; for high-temperature and harsh physical environments, the system increases w3 to achieve rapid temperature warning and traffic redirection. The system probe acquires and calculates the various indicators in the formula, and the health indicator H... nThe message middleware provides real-time feedback to the control layer, which uses it as a dynamic decision-making basis for network path selection and business task distribution. Specifically, the control layer uses the H of each network node... n The system dynamically adjusts its routing weight in the network topology to guide traffic away from low-health nodes; simultaneously, it employs a weighted load balancing strategy to prioritize the distribution of business tasks to H. n Nodes with high health values are selected, and service redirection is triggered when a node's health falls below a safety threshold, ensuring the stability of the entire network.
[0014] According to a preferred embodiment of the present invention, in step (3), a point-to-point direct connection tunnel is constructed between terminals through UDP hole punching and signaling coordination logic to eliminate the relay delay caused by the centralized architecture. Each terminal obtains the public network mapping address in the current network environment through the detection service. The public network mapping address serves as the network endpoint for communication. The control layer collects the endpoint address information of all network nodes and broadcasts it to the relevant terminals. After receiving the information, the terminal triggers address negotiation and establishes a direct connection tunnel.
[0015] According to a further preferred embodiment of the present invention, the specific process in step (3) is as follows: (31) Network endpoint address detection and dynamic sensing; After accessing the virtual network, each terminal performs an address probing process. The terminal sends protocol messages to a pre-set probing server to obtain its mapping information in the external network. The server returns mapping information including the public physical address and the corresponding source port, which together constitute the terminal's network endpoint address. Subsequently, a multi-point probing response mechanism identifies the NAT (Network Address Translation) type of the terminal. Specifically, the terminal sends multiple probing messages to different IP addresses or ports of the probing server. If the mapping port remains unchanged, it is identified as Cone NAT; if it changes with the target address, it is identified as Symmetric NAT. Simultaneously, the server attempts to send back messages to probe inbound filtering characteristics, determining whether it is loose or restricted filtering, and based on this, queries the pre-set NAT settings. The feasibility of establishing a point-to-point direct connection is assessed by traversing the combination matrix: if both ends are cone NATs, it is determined to be highly feasible and hole punching is initiated directly; if one end is a symmetric NAT, it is determined to be of medium feasibility and the port prediction mechanism is triggered; if both ends are symmetric NATs, it is determined to be of low feasibility and a gateway transit path is selected as an alternative. After obtaining the network endpoint address, the terminal reports the information to the control layer through an encrypted control channel, so that the control layer can grasp the network location of all network nodes in real time. (32) Adaptive negotiation and synchronization of topology information; The control layer, acting as the signaling hub, is responsible for distributing and coordinating network topology information. It aggregates network endpoint address information reported by each network node and generates a full routing map. This full routing map is then broadcast to all relevant terminals. Upon receiving network endpoint addresses from other network nodes, each terminal proactively sends an encrypted probe packet to the target address according to a point-to-point handshake logic. When the firewall policy between two network nodes allows the packet to pass, a direct tunnel is established. To evaluate the success probability of tunnel construction, a hole-punching success rate model is introduced. The probability of successful direct tunnel construction, P... succ The following relationship must be satisfied:
[0016] Among them, T nat1 and T nat2 These represent the network address translation type characteristic parameters of the two communication nodes; △t represents the time difference between the two network nodes initiating probe requests. The preset NAT traversal success rate evaluation function is used to characterize the nonlinear mapping relationship between node feature parameters and time difference on the probability of successful tunnel construction. By issuing synchronous triggering instructions with preset execution timestamps through the control layer, the real-time delivery capability of the message middleware is used to coordinate the two ends to initiate probes at the same time point, so that Δt tends to be minimized and the success rate of establishing point-to-point communication is improved. (33) Direct connection verification mechanism based on hop count and latency; The effectiveness of the direct tunnel is verified by multi-dimensional indicators to ensure that the communication link does not pass through third-party nodes. The routing tracing command is run regularly through the logical hop count verification mechanism to monitor the network transmission path between nodes. When the logical hop count between nodes is detected to be one hop, it is determined that the two nodes have achieved a direct connection at the underlying protocol level. Establish a total latency evaluation benchmark for end-to-end communication, and use the measured communication latency D obtained from real-time detection. real Compared with the total delay reference value D total Compare the values, set a deviation threshold σ, and when the measured delay... Compared with the total delay reference value D total When the proportion exceeds (1+σ), the control layer determines that the performance of the direct link is degraded or there is an abnormal relay. It automatically increases the weight of the direct link in the global routing table and reduces its priority as the preferred transmission path. Conversely, if the measured value continues to approach and stabilize within the total delay baseline value, the routing weight is gradually reduced through the attenuation algorithm to restore the priority of the efficient path. The routing weight of the direct link is dynamically adjusted to continuously optimize the communication path between network nodes. (34) Adaptive switching and optimization of local area network endpoints; For terminals located within the same physical local area network (LAN), adaptive optimization of the transmission path is supported. LAN detection identifies peer devices with the same physical network prefix. When the target terminal is detected to be on the local network, the communication target address is automatically switched from a public IP address to a private intranet address. This reduces latency and bandwidth limitations caused by public network links. In intranet direct connection mode, throughput optimization is further performed by adaptively adjusting the maximum transmission unit (MTU) of the virtual network interface card to improve link transmission efficiency. The adjusted virtual interface payload is 1 MTU. virt :
[0017] Among them, MTU phys The maximum transmission unit (MTU) of a physical link; L header This represents the fixed-length overhead of the encryption protocol encapsulation header. This model avoids data packet fragmentation and improves the link throughput in high-bandwidth intranet scenarios. When a terminal needs to access a physical network segment not covered by the virtual network, an adaptive forwarding strategy is executed, and the health of each network node is evaluated. n And network connectivity, specifically, calculating a comprehensive score for each potential exit node. ; Among them, D link The link latency from the network node to the target physical network segment is defined by α and β, which are preset weight coefficients that satisfy the normalization constraint α + β = 1. The control layer adaptively adjusts the allocation ratio of α and β based on the latency sensitivity of the service to be forwarded: For high-latency sensitive services (such as real-time audio / video and interactive control commands), the system increases the link latency weight β to ensure that the service flows out from the node with the fastest network path first; for high-throughput or non-real-time services (such as background data synchronization and batch file downloads), the system increases the node health weight α to prioritize nodes with low hardware load and good heat dissipation, ensuring continuous high bandwidth output from the nodes. The network node with the highest comprehensive score S is selected as the preferred exit gateway for the current service, thus achieving the lowest cross-network segment access latency while ensuring node load balancing. Routing and address masquerading rules are configured on this network node. To avoid packet fragmentation caused by encryption encapsulation, a pre-reservation strategy is adopted at the virtual network card layer. Since the encryption protocol adds extra header overhead to the original data packet, if the original data packet length has reached the physical link MTU... At the limit, the encapsulated data packet will be forcibly fragmented by the physical network due to exceeding the limit. By actively reducing the maximum transmission unit (MTU) at the virtual interface, the total length of the original data plus the encrypted header is always less than or equal to the maximum transmission unit (MTU) of the physical link. phys This ensures that data packets can be transmitted in one go without secondary fragmentation at the physical layer, and dynamically calculates the optimal payload (MTU) of the virtual interface based on the maximum transmission unit of the physical link.virt This computational model ensures transmission efficiency in large-scale data exchange scenarios.
[0018] According to a preferred embodiment of the present invention, in step (3), during the construction of the full mesh topology, the system calculates the total end-to-end communication delay to evaluate transmission performance and optimize the direct connection paths between network nodes. The total delay D total The formula is:
[0019] Among them, D path Represents the physical transmission delay of the link; D enc D represents the computational delay caused by the symmetric encryption algorithm. stack This represents the processing latency of the protocol stack in kernel mode. The system continuously monitors the total latency and evaluates it in conjunction with the logical hop count. When the logical hop count is one and the total latency meets the condition, i.e., D... total If the latency is lower than the preset business communication latency threshold and the measured value is less than the path latency via the centralized gateway, the system confirms that the optimal direct connection path has been successfully constructed.
[0020] According to a preferred embodiment of the present invention, in step (4), an adaptive security encryption and cross-platform compatibility mechanism is designed to address the differences in terminal hardware architecture and the diversity of operating systems. Specifically: (41) Hardware resource awareness and adaptive encryption strategy; The terminal devices in the network encompass a variety of forms, ranging from high-performance servers to low-power edge gateways. The optimal encryption algorithm is adaptively allocated based on the terminal's underlying hardware capabilities. Before a terminal connects to the network, a system probe automatically detects whether the processor has a built-in hardware acceleration instruction set for a specific encryption algorithm. The system probe then evaluates the encryption and decryption performance based on this information. To quantify the encryption overhead across different hardware platforms, a unit-byte encryption overhead evaluation model is introduced, setting the terminal's unit-byte encryption overhead to E. cost It satisfies the following formula:
[0021] Among them, W ops This represents the number of instruction cycles required by the selected encryption algorithm to process a unit of data block. This represents the hardware acceleration gain coefficient; when the terminal does not have a relevant hardware acceleration module, ;F cpu Representing the processor's real-time operating frequency, for embedded network devices with limited computing resources and no hardware-accelerated instruction sets, adaptively selecting one with W... ops Smaller stream cipher algorithms replace traditional block cipher algorithms, reducing E without compromising data confidentiality. cost This enables faster symmetric encryption speeds and lower processing latency. (42) Keep-alive and compatible deployment of multiple operating systems; To address cross-platform deployment requirements, differentiated client lifecycle management and network scheduling are implemented across different underlying operating systems. In the first type of desktop-oriented graphical operating system, the network configuration client is deployed in a protected system storage space. The client registers as a daemon service for the system through the underlying application programming interface, ensuring that the client automatically and silently loads when the system boots up, achieving continuous keep-alive operation and automatic restart in case of failure. In the second type of server-oriented open-source operating system, the client program registers as a background daemon process, automatically identifies the network protection environment at the operating system level, injects dynamic traffic allowance rules into the kernel packet filtering module, and the rules accurately match the adaptively allocated transmission ports and generated logical network cards, ensuring that the data frames of the encrypted communication tunnel are not blocked by the system's native firewall. (43) Dynamic key rotation and forward security; To prevent key leakage and replay attacks during massive business data interaction, a payload-based dynamic key rotation mechanism is established at the cross-platform transport layer. This mechanism continuously monitors the running time and cumulative transmission traffic of each direct-connection tunnel and determines the effective lifespan T of the secure session key according to the following formula. rot :
[0022] Among them, T max V represents the system's preset absolute key lifespan threshold. max v(x) represents the maximum amount of data that can be encrypted using a single session key, and v(x) represents the network transmission rate at time x. After calculating T rot Then, it is set as the trigger threshold for the dynamic renegotiation timer. Specifically, a key status monitoring task is started in the background, and the timer is triggered when it enters the preset pre-negotiation window (e.g., the remaining time is less than...). When the actual data transmission volume of the direct tunnel reaches 10%, the control layer, without interrupting the existing service flow, pre-issues the next-generation key parameters through the control channel and establishes a dual-key coexistence buffer. max Or the continuous running time reaches T max At this time, the control layer automatically triggers the key renegotiation command, and without interrupting the existing network connection, it seamlessly distributes and applies the new generation key parameters through the control channel to achieve forward confidentiality and high-strength security for business data transmission.
[0023] The beneficial effects of this invention are as follows: This invention integrates the control layer, gateway layer, and data transmission layer, constructing a closed-loop system that spans the entire lifecycle from blind operation to full mesh intelligent interconnection. Utilizing dynamic network endpoint address awareness and a full mesh topology negotiation mechanism, it eliminates the traffic relay bottlenecks and single-point-of-failure risks of traditional centralized gateways. Based on a comprehensive load risk model using low-level probes, end-to-end latency assessment, and a unit-byte encryption overhead model, the system achieves deep coupling at the low-level between dynamic network routing switching and terminal hardware resource health status. Combined with cross-operating system platform adaptive NIC generation, dynamic load optimization, and a load-based session key rotation mechanism, it solves the problems of cumbersome configuration, disconnect between resource and network scheduling, and poor compatibility with heterogeneous hardware in traditional geographically dispersed networking technologies. This invention provides a high-throughput, low-latency, forward-secure intelligent communication infrastructure for complex heterogeneous networks. Attached Figure Description
[0024] Figure 1 This is a system architecture diagram of the present invention; Figure 2 This is a flowchart of the method of the present invention; Figure 3 This is a schematic diagram of the full mesh logic topology construction and communication of the present invention; Figure 4 This is a schematic diagram of the adaptive mapping and remote management process of the present invention. Detailed Implementation
[0025] like Figure 1 As shown, this embodiment provides a network adaptive configuration system that supports secure resource access, including a control layer, a gateway layer, and a data transmission layer, wherein: The control layer is used for centralized management of global network node registration status maintenance, key pair generation and distribution, and dynamic synchronization of routing policies; The gateway layer, deployed on the network terminal, integrates a network configuration client and a system probe to execute configuration commands and monitor the hardware operating status of the terminal in real time. The data transmission layer establishes encrypted transmission tunnels between terminals via the VPN protocol. The data transmission layer, in conjunction with the application gateway component, enables the conversion of private service protocols and remote access.
[0026] The data transmission layer is responsible for establishing logical encrypted tunnels between terminals. The transmission protocol runs in the operating system kernel space, avoiding the performance loss caused by memory copying. In the encryption algorithm combination, key exchange, symmetric encryption and data verification respectively adopt encryption algorithm suites and follow an adaptive encryption and decryption calculation model. The transmission port is dynamically allocated within the preset protocol port range to achieve traffic isolation between virtual networks.
[0027] The control layer is deployed on a cloud server with a static public IP address. As the network management hub, the control layer includes a controller core built on an interface and message transmission mechanism, a domain name resolution module, a reverse proxy component, and a message middleware that supports bidirectional communication protocols. The controller core is responsible for maintaining the global node registration status, generating and distributing key pairs, and dynamically synchronizing routing policies. The domain name resolution module provides private domain name resolution for each network node in the virtual network. The reverse proxy component serves as a secure access point, handling the secure isolation of management backend access, interface calls, and message transmission. The message middleware is used to perform heartbeat monitoring between the client and the server and to distribute configurations in real time.
[0028] The gateway layer uses terminals with heterogeneous access, whose hardware forms include embedded network devices or physical nodes with general computing capabilities. The terminals deploy automated configuration clients and system probes. The automated configuration clients are responsible for acquiring network parameters and automatically creating logical network card interfaces. The system probes collect resource load indicators such as processor utilization and storage occupancy, as well as environmental indicators such as hardware temperature, in real time according to a preset period. The system probes provide decision data support for network and resource coordination through a preset health evaluation model.
[0029] By integrating sensing components into the terminal and coordinating with control layer scheduling strategies, deep coupling between hardware and network status is achieved, enabling adaptive mapping and remote management processes such as... Figure 4 As shown, it is: ① Real-time perception of multi-dimensional underlying resources; An internal background system sensing component runs on the terminal. This component resides at the operating system kernel boundary as a low-level probe, continuously monitoring the terminal's hardware resource status. The system probe polls the underlying hardware at preset time intervals, collecting multi-dimensional physical indicators in real time, including processor real-time utilization, memory load ratio, disk space remaining, and device core temperature. This forms a basic data set of the terminal's operating status, constructing a comprehensive load risk model to quantify the real-time operating pressure of network nodes. A unified assessment of the network node's operating status is then performed using multi-dimensional resource indicators, resulting in a node comprehensive load risk value R. load Satisfy the following formula:
[0030] Where e is the natural constant, serving as the base of the exponential function to amplify the sensitivity to load changes; U cpu Represents processor utilization; U mem Represents storage memory load; T curr This refers to the current core temperature of the equipment; T max The upper limit of safe temperature for equipment design; λ1, λ2 and λ3 represent the risk penalty coefficients of various physical indicators. By introducing exponential and square operations, the risk warning value under high load and high temperature conditions is amplified. By R load The network node status is evaluated by comparing it in real time with a preset security threshold: when R load When the preset threshold is exceeded, the control layer determines that the network node has an operational risk and automatically triggers an adaptive scheduling strategy. This strategy reduces the network access route weight of the network node or performs request redirection to achieve dynamic load balancing of computing resources. ② Encrypted reporting and dynamic mapping of node operating status; The system dynamically associates the physical hardware operating status with the virtual network topology. The terminal-side sensing component serializes and encapsulates the collected physical indicator data. The sensing component securely reports the encapsulated telemetry data to the cloud control platform through an encrypted communication tunnel to prevent intermediate nodes from eavesdropping on or tampering with the terminal status information. After receiving the data, the cloud control platform parses and processes it. The platform establishes a mapping relationship between the hardware operating status of the underlying physical nodes and the corresponding virtual network nodes. The monitoring interface dynamically displays the distribution of the operating status of all physical nodes in the network. When the monitoring module detects that the risk value of a network node exceeds the preset security threshold, the control layer automatically triggers an adaptive scheduling strategy. The control layer dynamically lowers the network access routing weight of the network node and redirects new service access requests to adjacent network nodes with higher health, thereby achieving dynamic load balancing of computing resources and ensuring operational stability. ③ Remote proxy conversion under a clientless architecture; It supports clientless remote operation and maintenance of underlying physical nodes isolated within a virtual network. This mechanism relies on the application layer backend proxy module deployed in the cloud. The proxy module acts as an intermediary component between the front-end user and the underlying physical node, establishing a connection with the target physical node within the virtual network that includes underlying operation and maintenance protocols such as character terminal control protocol and encrypted file transfer protocol. During the conversion process, the proxy module acts as an intermediate component to perform bidirectional conversion on the data stream, capturing the original character stream and terminal escape sequence output by the network node in real time, serializing them and encapsulating them into a full-duplex WebSocket communication frame, thereby achieving transparent conversion from the underlying protocol to a web-compatible protocol; at the same time, it accurately maps the user commands returned by the browser frontend to the control codes of the underlying operation and maintenance protocol, and pushes the processed data stream to the user's standard browser frontend in real time through a secure communication channel, realizing remote operation and maintenance access capabilities without deploying additional client programs on the terminal; ④ Seamless connection guarantee in dynamic network environments; In complex network environments, the mapped addresses of network terminals may change dynamically. The proxy module keeps the state synchronized with the underlying virtual network control plane. When the virtual logical address of the underlying node drifts due to adaptive configuration, the internal domain name resolution module executes an automated update process. Specifically, the node-side client synchronously reports the latest address information to the control layer. Based on this, the resolution module dynamically corrects the device identifier-virtual address mapping record in the internal database. Subsequently, the proxy module, by monitoring changes in the addressing record, maintains the active state of the full-duplex communication session at the web frontend while seamlessly redirecting the backend connection to the new address after the drift. Even if the transmission path of the underlying virtual network undergoes adaptive switching, the user's browser access session remains connected, achieving complete transparency of underlying network state changes to upper-layer applications and ensuring seamless remote operation and maintenance of underlying hardware resources.
[0031] Example 2: like Figure 2 As shown, this embodiment provides a network adaptive configuration method for supporting secure resource access in the system of embodiment 1. The steps are as follows: (1) The terminal initiates registration with the control layer through the automated configuration client. The control layer automatically distributes network interface parameters and encryption keys to realize the automatic access of the terminal in the virtual network. (2) The system probe collects the computing resource load and environmental indicators of the terminal and associates them with the network scheduling strategy; (3) Establish point-to-point direct connection tunnels between each network node to construct a full mesh logical topology, such as Figure 3 As shown; (4) Configure multi-level encryption and decryption parameters for different terminals and complete data encapsulation in kernel mode to ensure efficient and secure communication between terminals.
[0032] In step (1), specifically: (11) Control layer environment initialization and global policy preset; Before system startup, the network infrastructure logic of the control layer is defined through configuration files, including preset management parameters, configuration of communication ports, and construction of a key derivation security model. The system pre-sets the static network address and management domain name of the controller, generates a master control key for identity authentication, and provides basic support for the operation of the control layer. Access control rules are configured on the control layer server. Through source IP whitelisting, device digital certificate verification, and protocol behavior filtering, the management interface and data interface are securely isolated. The system allows the ports required for management interface and domain name resolution service, and reserves dynamically allocated port ranges for subsequent data transmission. The system uses a key derivation mechanism to generate session keys for communication between network nodes based on the master control key, ensuring the randomness of key generation and communication security. (12) Adaptive access and interface construction for business nodes; When a terminal accesses the network, it executes an automated configuration process. The terminal initiates automated registration through an internally deployed automated configuration client. The terminal submits an access request to the control layer using authentication credentials. After receiving and verifying the authentication credentials, the control layer allocates a virtual network address to the terminal according to the global resource table. The virtual network address does not conflict with the terminal's local network. At the same time, the control layer issues the corresponding security parameters. After receiving the configuration, the terminal client automatically creates a logical network card interface in the operating system kernel mode. The terminal configures the maximum transmission unit and activates the encrypted communication link to achieve automatic access for the terminal.
[0033] In step (2), the system probe collects multi-dimensional hardware indicators periodically. The system introduces a health evaluation model to couple network scheduling with hardware status. The function expression of the health evaluation model is as follows:
[0034] Among them, U cpu Represents the real-time utilization of the processor; U mem T represents the utilization rate of storage resources. curr This indicates that the hardware is monitoring the temperature in real time; T limit This indicates the preset temperature tolerance limit for this type of equipment; w1, w2, and w3 represent the weighting coefficients for each indicator. The system probe acquires each indicator in the formula and completes the calculation. The health indicator H... n The message middleware provides real-time feedback to the control layer, which uses it as a dynamic decision-making basis for network path selection and business task distribution. Specifically, the control layer uses the H of each network node... n The system dynamically adjusts its routing weight in the network topology to guide traffic away from low-health nodes; simultaneously, it employs a weighted load balancing strategy to prioritize the distribution of business tasks to H. n Nodes with high health values are selected, and service redirection is triggered when a node's health falls below a safety threshold, ensuring the stability of the entire network.
[0035] In step (3), a point-to-point direct connection tunnel is built between terminals through UDP hole punching and signaling coordination logic to eliminate the relay delay caused by the centralized architecture. Each terminal obtains the public network mapping address in the current network environment through the probe service. The public network mapping address serves as the network endpoint for communication. The control layer collects the endpoint address information of all network nodes and broadcasts it to the relevant terminals. After receiving the information, the terminal triggers address negotiation and establishes a direct connection tunnel.
[0036] The specific process is as follows: (31) Network endpoint address detection and dynamic sensing; After accessing the virtual network, each terminal performs an address probing process. The terminal sends protocol messages to a pre-set probing server to obtain its mapping information in the external network. The server returns mapping information including the public physical address and the corresponding source port, which together constitute the terminal's network endpoint address. Subsequently, a multi-point probing response mechanism identifies the NAT (Network Address Translation) type of the terminal. Specifically, the terminal sends multiple probing messages to different IP addresses or ports of the probing server. If the mapping port remains unchanged, it is identified as Cone NAT; if it changes with the target address, it is identified as Symmetric NAT. Simultaneously, the server attempts to send back messages to probe inbound filtering characteristics, determining whether it is loose or restricted filtering, and based on this, queries the pre-set NAT settings. The feasibility of establishing a point-to-point direct connection is assessed by traversing the combination matrix: if both ends are cone NATs, it is determined to be highly feasible and hole punching is initiated directly; if one end is a symmetric NAT, it is determined to be of medium feasibility and the port prediction mechanism is triggered; if both ends are symmetric NATs, it is determined to be of low feasibility and a gateway transit path is selected as an alternative. After obtaining the network endpoint address, the terminal reports the information to the control layer through an encrypted control channel, so that the control layer can grasp the network location of all network nodes in real time. (32) Adaptive negotiation and synchronization of topology information; The control layer, acting as the signaling hub, is responsible for distributing and coordinating network topology information. It aggregates network endpoint address information reported by each network node and generates a full routing map. This full routing map is then broadcast to all relevant terminals. Upon receiving network endpoint addresses from other network nodes, each terminal proactively sends an encrypted probe packet to the target address according to a point-to-point handshake logic. When the firewall policy between two network nodes allows the packet to pass, a direct tunnel is established. To evaluate the success probability of tunnel construction, a hole-punching success rate model is introduced. The probability of successful direct tunnel construction, P... succ The following relationship must be satisfied:
[0037] Among them, T nat1 and T nat2 These represent the network address translation type characteristic parameters of the two communication nodes respectively; △t represents the time difference between the two network nodes initiating the probe request. By issuing a synchronous trigger command with a preset execution timestamp through the control layer, the real-time delivery capability of the message middleware is used to coordinate the two ends to initiate probes at the same time point, so that △t tends to be minimized and the success rate of establishing point-to-point communication is improved. (33) Direct connection verification mechanism based on hop count and latency; The effectiveness of the direct tunnel is verified by multi-dimensional indicators to ensure that the communication link does not pass through third-party nodes. The routing tracing command is run regularly through the logical hop count verification mechanism to monitor the network transmission path between nodes. When the logical hop count between nodes is detected to be one hop, it is determined that the two nodes have achieved a direct connection at the underlying protocol level. Establish a total latency evaluation benchmark for end-to-end communication, and use the measured communication latency D obtained from real-time detection. real Compared with the total delay reference value D total Compare the values, set a deviation threshold σ, and when the measured delay... Compared with the total delay reference value D total When the proportion exceeds (1+σ), the control layer determines that the performance of the direct link is degraded or there is an abnormal relay. It automatically increases the weight of the direct link in the global routing table and reduces its priority as the preferred transmission path. Conversely, if the measured value continues to approach and stabilize within the total delay baseline value, the routing weight is gradually reduced through the attenuation algorithm to restore the priority of the efficient path. The routing weight of the direct link is dynamically adjusted to continuously optimize the communication path between network nodes. (34) Adaptive switching and optimization of local area network endpoints; For terminals located within the same physical local area network (LAN), adaptive optimization of the transmission path is supported. LAN detection identifies peer devices with the same physical network prefix. When the target terminal is detected to be on the local network, the communication target address is automatically switched from a public IP address to a private intranet address. This reduces latency and bandwidth limitations caused by public network links. In intranet direct connection mode, throughput optimization is further performed by adaptively adjusting the maximum transmission unit (MTU) of the virtual network interface card to improve link transmission efficiency. The adjusted virtual interface payload is 1 MTU. virt :
[0038] Among them, MTU phys The maximum transmission unit (MTU) of a physical link; L header This represents the fixed-length overhead of the encryption protocol encapsulation header. This model avoids data packet fragmentation and improves the link throughput in high-bandwidth intranet scenarios. When a terminal needs to access a physical network segment not covered by the virtual network, an adaptive forwarding strategy is executed, and the health of each network node is evaluated. n And network connectivity, specifically, calculating a comprehensive score for each potential exit node. ; Among them, D linkThe link latency from the network node to the target physical network segment is defined by α and β, which are preset weighting coefficients. The network node with the highest comprehensive score S is selected as the preferred egress gateway for the current service, thereby ensuring node load balancing while achieving the lowest cross-network segment access latency. Routing and address masquerading rules are configured on this network node. To avoid packet fragmentation caused by encryption encapsulation, a pre-reservation strategy is adopted at the virtual network interface layer. Since the encryption protocol adds extra header overhead to the original data packet, if the length of the original data packet has reached the physical link MTU limit, the encapsulated data packet will be forcibly fragmented by the physical network due to exceeding the limit. By actively reducing the maximum transmission unit on the virtual interface, the total length of the original data plus the encrypted header is always less than or equal to the physical link's maximum transmission unit (MTU). phys This ensures that data packets can be transmitted in one go without secondary fragmentation at the physical layer, and dynamically calculates the optimal payload (MTU) of the virtual interface based on the maximum transmission unit of the physical link. virt This computational model ensures transmission efficiency in large-scale data exchange scenarios.
[0039] According to a preferred embodiment of the present invention, in step (3), during the construction of the full mesh topology, the system calculates the total end-to-end communication delay to evaluate transmission performance and optimize the direct connection paths between network nodes. The total delay D total The formula is:
[0040] Among them, D path Represents the physical transmission delay of the link; D enc D represents the computational delay caused by the symmetric encryption algorithm. stack This represents the processing latency of the protocol stack in kernel mode. The system continuously monitors the total latency and evaluates it in conjunction with the logical hop count. When the logical hop count is one and the total latency meets the condition, i.e., D... total If the latency is lower than the preset business communication latency threshold and the measured value is less than the path latency via the centralized gateway, the system confirms that the optimal direct connection path has been successfully constructed.
[0041] According to a preferred embodiment of the present invention, in step (4), an adaptive security encryption and cross-platform compatibility mechanism is designed to address the differences in terminal hardware architecture and the diversity of operating systems. Specifically: (41) Hardware resource awareness and adaptive encryption strategy; The terminal devices in the network encompass a variety of forms, ranging from high-performance servers to low-power edge gateways. The optimal encryption algorithm is adaptively allocated based on the terminal's underlying hardware capabilities. Before a terminal connects to the network, a system probe automatically detects whether the processor has a built-in hardware acceleration instruction set for a specific encryption algorithm. The system probe then evaluates the encryption and decryption performance based on this information. To quantify the encryption overhead across different hardware platforms, a unit-byte encryption overhead evaluation model is introduced, setting the terminal's unit-byte encryption overhead to E. cost It satisfies the following formula:
[0042] Among them, W ops This represents the number of instruction cycles required by the selected encryption algorithm to process a unit of data block. This represents the hardware acceleration gain coefficient; when the terminal does not have a relevant hardware acceleration module, ;F cpu Representing the processor's real-time operating frequency, for embedded network devices with limited computing resources and no hardware-accelerated instruction sets, adaptively selecting one with W... ops Smaller stream cipher algorithms replace traditional block cipher algorithms, reducing E without compromising data confidentiality. cost This enables faster symmetric encryption speeds and lower processing latency. (42) Keep-alive and compatible deployment of multiple operating systems; To address cross-platform deployment requirements, differentiated client lifecycle management and network scheduling are implemented across different underlying operating systems. In the first type of desktop-oriented graphical operating system, the network configuration client is deployed in a protected system storage space. The client registers as a daemon service for the system through the underlying application programming interface, ensuring that the client automatically and silently loads when the system boots up, achieving continuous keep-alive operation and automatic restart in case of failure. In the second type of server-oriented open-source operating system, the client program registers as a background daemon process, automatically identifies the network protection environment at the operating system level, injects dynamic traffic allowance rules into the kernel packet filtering module, and the rules accurately match the adaptively allocated transmission ports and generated logical network cards, ensuring that the data frames of the encrypted communication tunnel are not blocked by the system's native firewall. (43) Dynamic key rotation and forward security; To prevent key leakage and replay attacks during massive business data interaction, a payload-based dynamic key rotation mechanism is established at the cross-platform transport layer. This mechanism continuously monitors the running time and cumulative transmission traffic of each direct-connection tunnel and determines the effective lifespan T of the secure session key according to the following formula. rot :
[0043] Among them, T maxV represents the system's preset absolute key lifespan threshold. max v(x) represents the maximum amount of data that can be encrypted using a single session key, and v(x) represents the network transmission rate at time x. After calculating T rot Then, it is set as the trigger threshold for the dynamic renegotiation timer. Specifically, a key status monitoring task is started in the background, and the timer is triggered when it enters the preset pre-negotiation window (e.g., the remaining time is less than...). When the actual data transmission volume of the direct tunnel reaches 10%, the control layer, without interrupting the existing service flow, pre-issues the next-generation key parameters through the control channel and establishes a dual-key coexistence buffer. max Or the continuous running time reaches T max At this time, the control layer automatically triggers the key renegotiation command, and without interrupting the existing network connection, it seamlessly distributes and applies the new generation key parameters through the control channel to achieve forward confidentiality and high-strength security for business data transmission.
Claims
1. A network adaptive configuration system supporting secure resource access, characterized in that, It includes a control layer, a gateway layer, and a data transmission layer, among which: The control layer is used for centralized management of global network node registration status maintenance, key pair generation and distribution, and dynamic synchronization of routing policies; The control layer is deployed on a cloud server with a static public IP address. As the network management hub, the control layer includes a controller core built on an interface and message transmission mechanism, a domain name resolution module, a reverse proxy component, and a message middleware that supports bidirectional communication protocols. The controller core is responsible for maintaining the global node registration status, generating and distributing key pairs, and dynamically synchronizing routing policies. The domain name resolution module provides private domain name resolution for each network node in the virtual network. The reverse proxy component serves as a secure access point, handling the secure isolation of management backend access, interface calls, and message transmission. The message middleware is used to perform heartbeat monitoring between the client and the server and to distribute configurations in real time. The gateway layer, deployed on the network terminal, integrates a network configuration client and a system probe to execute configuration commands and monitor the hardware operating status of the terminal in real time. The gateway layer uses terminals with heterogeneous access, whose hardware forms include embedded network devices or physical nodes with general computing capabilities. The terminals deploy automated configuration clients and system probes. The automated configuration clients are responsible for acquiring network parameters and automatically creating logical network card interfaces. The system probes collect resource load indicators and environmental indicators in real time according to a preset period. The system probes provide decision data support for network and resource coordination through a preset health evaluation model. The data transmission layer establishes an encrypted transmission tunnel between terminals via the VPN protocol. The data transmission layer, in conjunction with the application gateway component, enables the conversion of private service protocols and remote access. By integrating sensing components into the terminal and linking them with control layer scheduling strategies, deep coupling between hardware and network status is achieved. The adaptive mapping and remote management process is as follows: ① Real-time perception of multi-dimensional underlying resources; An internal background system sensing component runs on the terminal. This component resides at the operating system kernel boundary as a low-level probe, continuously monitoring the terminal's hardware resource status. The system probe polls the underlying hardware at preset time intervals, collecting multi-dimensional physical indicators in real time, including processor real-time utilization, memory load ratio, disk space remaining, and device core temperature. This forms a basic data set of the terminal's operating status, constructing a comprehensive load risk model to quantify the real-time operating pressure of network nodes. A unified assessment of the network node's operating status is then performed using multi-dimensional resource indicators, resulting in a node comprehensive load risk value R. load Satisfy the following formula: ; Where e is the natural constant, serving as the base of the exponential function to amplify the sensitivity to load changes; U cpu Represents processor utilization; U mem Represents storage memory load; T curr This refers to the current core temperature of the equipment; T max The upper limit of safe temperature for equipment design; λ1, λ2 and λ3 represent the risk penalty coefficients of various physical indicators. By introducing exponential and square operations, the risk warning value under high load and high temperature conditions is amplified. By R load The network node status is evaluated by comparing it in real time with a preset security threshold: when R load When the preset threshold is exceeded, the control layer determines that the network node has an operational risk and automatically triggers an adaptive scheduling strategy. This strategy reduces the network access route weight of the network node or performs request redirection to achieve dynamic load balancing of computing resources. ② Encrypted reporting and dynamic mapping of node operating status; The system dynamically associates the physical hardware operating status with the virtual network topology. The terminal-side sensing component serializes and encapsulates the collected physical indicator data. The sensing component securely reports the encapsulated telemetry data to the cloud control platform through an encrypted communication tunnel. After receiving the data, the cloud control platform parses and processes it. The platform establishes a mapping relationship between the hardware operating status of the underlying physical nodes and the corresponding virtual network nodes. The monitoring interface dynamically displays the operating status distribution of all physical nodes in the network. When the monitoring module detects that the risk value of a network node exceeds the preset safety threshold, the control layer automatically triggers an adaptive scheduling strategy. The control layer dynamically lowers the network access routing weight of the network node and redirects new service access requests to adjacent network nodes with higher health, thereby achieving dynamic load balancing of computing resources and ensuring operational stability. ③ Remote proxy conversion under a clientless architecture; It supports clientless remote operation and maintenance of underlying physical nodes isolated within a virtual network. This mechanism relies on the application layer backend proxy module deployed in the cloud. The proxy module acts as an intermediary component between the front-end user and the underlying physical node, establishing a connection with the target physical node within the virtual network that includes underlying operation and maintenance protocols such as character terminal control protocol and encrypted file transfer protocol. During the conversion process, the proxy module acts as an intermediate component to perform bidirectional conversion on the data stream, capturing the original character stream and terminal escape sequence output by the network node in real time, serializing them and encapsulating them into a full-duplex WebSocket communication frame, thereby achieving transparent conversion from the underlying protocol to a web-compatible protocol; at the same time, it accurately maps the user commands returned by the browser frontend to the control codes of the underlying operation and maintenance protocol, and pushes the processed data stream to the user's standard browser frontend in real time through a secure communication channel, realizing remote operation and maintenance access capabilities without deploying additional client programs on the terminal; ④ Seamless connection guarantee in dynamic network environments; In complex network environments, the mapped addresses of network terminals may change dynamically. The proxy module keeps the state synchronized with the underlying virtual network control plane. When the virtual logical address of the underlying node drifts due to adaptive configuration, the internal domain name resolution module executes an automated update process. Specifically, the node-side client synchronously reports the latest address information to the control layer. Based on this, the resolution module dynamically corrects the mapping record of device identifier-virtual address in the internal database. Subsequently, the proxy module, by monitoring the changes in the addressing record, maintains the active state of the full-duplex communication session of the web page front-end while seamlessly redirecting the back-end connection to the new address after the drift. Even if the transmission path of the underlying virtual network undergoes adaptive switching, the browser access session of the user's front-end remains connected, achieving complete transparency of the underlying network state changes to the upper-layer application and ensuring seamless remote operation and maintenance of the underlying hardware resources.
2. A network adaptive configuration method supporting secure resource access, applied to the network adaptive configuration system supporting secure resource access as described in claim 1, characterized in that, The steps are as follows: (1) The terminal initiates registration with the control layer through the automated configuration client. The control layer automatically distributes network interface parameters and encryption keys to realize the automatic access of the terminal in the virtual network. (2) The system probe collects the computing resource load and environmental indicators of the terminal and associates them with the network scheduling strategy; (3) Establish point-to-point direct connection tunnels between each network node to construct a full mesh logical topology; (4) Configure multi-level encryption and decryption parameters for different terminals and complete data encapsulation in kernel mode to ensure efficient and secure communication between terminals.
3. The network adaptive configuration method supporting secure resource access as described in claim 2, characterized in that, In step (1), specifically: (11) Control layer environment initialization and global policy preset; Before system startup, the network infrastructure logic of the control layer is defined through configuration files, including preset management parameters, configuration of communication ports, and construction of a key derivation security model. The system pre-sets the static network address and management domain name of the controller, generates a master control key for identity authentication, and provides basic support for the operation of the control layer. Access control rules are configured on the control layer server. Through source IP whitelist, device digital certificate verification, and protocol behavior filtering, the system allows the ports required for management interfaces and domain name resolution services, and reserves dynamically allocated port ranges for subsequent data transmission. The system uses a key derivation mechanism to generate session keys for communication between network nodes based on the master control key. (12) Adaptive access and interface construction for business nodes; When a terminal accesses the network, it executes an automated configuration process. The terminal initiates automated registration through an internally deployed automated configuration client. The terminal submits an access request to the control layer using authentication credentials. After receiving and verifying the authentication credentials, the control layer allocates a virtual network address to the terminal according to the global resource table. The virtual network address does not conflict with the terminal's local network. At the same time, the control layer issues the corresponding security parameters. After receiving the configuration, the terminal client automatically creates a logical network card interface in the operating system kernel mode. The terminal configures the maximum transmission unit and activates the encrypted communication link to achieve automatic access for the terminal.
4. The network adaptive configuration method supporting secure resource access as described in claim 3, characterized in that, In step (2), the system probe collects multi-dimensional hardware indicators periodically. The system introduces a health evaluation model to couple network scheduling with hardware status. The function expression of the health evaluation model is as follows: ; Among them, U cpu Represents the real-time utilization of the processor; U mem T represents the utilization rate of storage resources. curr This indicates that the hardware is monitoring the temperature in real time; T limit This indicates the preset temperature tolerance limit of the equipment; w1, w2, and w3 represent the weighting coefficients of each indicator. The system probe acquires each indicator in the formula and completes the calculation. The health indicator H... n The message middleware provides real-time feedback to the control layer, which uses it as a dynamic decision-making basis for network path selection and business task distribution. Specifically, the control layer uses the H of each network node... n The system dynamically adjusts its routing weight in the network topology to guide traffic away from low-health nodes; simultaneously, it employs a weighted load balancing strategy to prioritize the distribution of business tasks to H. n Nodes with high health values are selected, and service redirection is triggered when a node's health falls below a safety threshold, ensuring the stability of the entire network.
5. The network adaptive configuration method supporting secure resource access as described in claim 4, characterized in that, In step (3), a point-to-point direct connection tunnel is built between terminals through UDP hole punching and signaling coordination logic to eliminate the relay delay caused by the centralized architecture. Each terminal obtains the public network mapping address in the current network environment through the probe service. The public network mapping address serves as the network endpoint for communication. The control layer collects the endpoint address information of all network nodes and broadcasts it to the relevant terminals. After receiving the information, the terminal triggers address negotiation and establishes a direct connection tunnel.
6. The network adaptive configuration method supporting secure resource access as described in claim 5, characterized in that, The specific process in step (3) is as follows: (31) Network endpoint address detection and dynamic sensing; After accessing the virtual network, each terminal performs an address probing process. The terminal sends protocol messages to a preset probing server to obtain its own mapping information in the external network. The mapping information returned by the server includes the public physical address and the corresponding mapping source port. The two together constitute the terminal's network endpoint address. Subsequently, a multi-point probing response mechanism is used to identify the NAT type of the terminal. Specifically, the terminal sends multiple probing messages to different IP addresses or ports of the probing server. If the mapping port remains unchanged, it is identified as a cone NAT; if it changes with the target address, it is identified as a symmetric NAT. At the same time, the server attempts to send back messages to probe the inbound filtering characteristics and determine whether it is loose filtering or restricted filtering. Based on this, it queries a preset NAT traversal combination matrix to evaluate the feasibility of establishing a point-to-point direct connection: if both ends are cone NATs, it is determined to be highly feasible and hole punching is initiated directly; if one end is a symmetric NAT, it is determined to be of medium feasibility and a port prediction mechanism is triggered; if both ends are symmetric NATs, it is determined to be of low feasibility and a gateway transit path is selected as an alternative. After obtaining the network endpoint address, the terminal reports this information to the control layer through an encrypted control channel, enabling the control layer to monitor the network location of all nodes in the network in real time. (32) Adaptive negotiation and synchronization of topology information; The control layer, acting as the signaling hub, is responsible for distributing and coordinating network topology information. It aggregates network endpoint address information reported by each network node and generates a full routing map. This full routing map is then broadcast to all relevant terminals. Upon receiving network endpoint addresses from other network nodes, each terminal proactively sends an encrypted probe packet to the target address according to a point-to-point handshake logic. When the firewall policy between two network nodes allows the packet to pass, a direct tunnel is established. To evaluate the success probability of tunnel construction, a hole-punching success rate model is introduced. The probability of successful direct tunnel construction, P... succ The following relationship must be satisfied: ; Among them, T nat1 and T nat2 These represent the network address translation type characteristic parameters of the two communication nodes; △t represents the time difference between the two network nodes initiating the probe request. The preset NAT traversal success rate evaluation function is used to characterize the nonlinear mapping relationship between node feature parameters and time difference on the probability of successful tunnel construction. By issuing synchronous triggering instructions with preset execution timestamps through the control layer, the real-time delivery capability of the message middleware is used to coordinate the two ends to initiate probes at the same time point, so that Δt tends to be minimized and the success rate of establishing point-to-point communication is improved. (33) Direct connection verification mechanism based on hop count and latency; The effectiveness of the direct tunnel is verified by multi-dimensional indicators to ensure that the communication link does not pass through third-party nodes. The routing tracing command is run regularly through the logical hop count verification mechanism to monitor the network transmission path between nodes. When the logical hop count between nodes is detected to be one hop, it is determined that the two nodes have achieved a direct connection at the underlying protocol level. Establish a total latency evaluation benchmark for end-to-end communication, and use the measured communication latency D obtained from real-time detection. real Compared with the total delay reference value D total Compare the values, set a deviation threshold σ, and when the measured delay... Compared with the total delay reference value D total When the proportion exceeds (1+σ), the control layer determines that the performance of the direct link is degraded or there is an abnormal relay. It automatically increases the weight value of the direct link in the global routing table and reduces its priority as the preferred transmission path. Conversely, if the measured value continues to approach and stabilize within the total delay baseline value, the routing weight is gradually reduced through the attenuation algorithm to restore the priority of the efficient path. The routing weight of the direct link is dynamically adjusted to continuously optimize the communication path between network nodes. (34) Adaptive switching and optimization of local area network endpoints; For terminals located within the same physical local area network (LAN), adaptive optimization of the transmission path is supported. LAN detection identifies peer devices with the same physical network prefix. When the target terminal is detected to be on the local network, the communication target address is automatically switched from a public IP address to a private intranet address. In intranet direct connection mode, throughput optimization is further performed, adaptively adjusting the maximum transmission unit (MTU) of the virtual network interface card to improve link transmission efficiency. The adjusted virtual interface payload is denoted by MTU. virt : ; Among them, MTU phys L is the maximum transmission unit of a physical link; header This represents the fixed-length overhead of the encryption protocol encapsulation header. This model avoids data packet fragmentation and improves the link throughput in high-bandwidth intranet scenarios. When a terminal needs to access a physical network segment not covered by the virtual network, an adaptive forwarding strategy is executed, and the health of each network node is evaluated. n And network connectivity, specifically, calculating a comprehensive score for each potential exit node. ; Among them, D link The link latency from the network node to the target physical network segment is defined by α and β, which are preset weighting coefficients. The network node with the highest comprehensive score S is selected as the preferred egress gateway for the current service. Routing and address masquerading rules are configured on this network node. To avoid packet fragmentation caused by encryption encapsulation, a pre-reservation strategy is adopted at the virtual network interface card layer. Since the encryption protocol adds extra header overhead to the original data packet, if the length of the original data packet has reached the physical link MTU limit, the encapsulated data packet will be forcibly fragmented by the physical network due to exceeding the limit. By actively reducing the maximum transmission unit on the virtual interface, the total length of the original data plus the encrypted header is always less than or equal to the maximum transmission unit (MTU) of the physical link. phys The optimal payload MTU of the virtual interface is dynamically calculated based on the maximum transmission unit of the physical link. virt This computational model ensures transmission efficiency in large-scale data exchange scenarios.
7. The network adaptive configuration method supporting secure resource access as described in claim 6, characterized in that, In step (3), during the construction of the full mesh topology, the system calculates the total end-to-end communication latency to evaluate transmission performance and optimize direct connection paths between network nodes. The total latency D total The formula is: ; Among them, D path Represents the physical transmission delay of the link; D enc D represents the computational delay caused by the symmetric encryption algorithm. stack This represents the processing latency of the protocol stack in kernel mode. The system continuously monitors the total latency and evaluates it in conjunction with the logical hop count. When the logical hop count is one and the total latency meets the condition, i.e., D... total If the latency is lower than the preset business communication latency threshold and the measured value is less than the path latency via the centralized gateway, the system confirms that the optimal direct connection path has been successfully constructed.
8. The network adaptive configuration method supporting secure resource access as described in claim 7, characterized in that, In step (4), an adaptive security encryption and cross-platform compatibility mechanism is designed to address the differences in terminal hardware architecture and the diversity of operating systems. Specifically: (41) Hardware resource awareness and adaptive encryption strategy; The terminal devices in the network encompass a variety of forms, ranging from high-performance servers to low-power edge gateways. The optimal encryption algorithm is adaptively allocated based on the terminal's underlying hardware capabilities. Before a terminal connects to the network, a system probe automatically detects whether the processor has a built-in hardware acceleration instruction set for a specific encryption algorithm. The system probe then evaluates the encryption and decryption performance based on this information. To quantify the encryption overhead across different hardware platforms, a unit-byte encryption overhead evaluation model is introduced, setting the terminal's unit-byte encryption overhead to E. cost It satisfies the following formula: ; Among them, W ops This represents the number of instruction cycles required by the selected encryption algorithm to process a unit of data block. This represents the hardware acceleration gain coefficient; when the terminal does not have a relevant hardware acceleration module, ;F cpu Representing the processor's real-time operating frequency, for embedded network devices with limited computing resources and no hardware-accelerated instruction sets, adaptively selecting one with W... ops Smaller stream cipher algorithms can replace block cipher algorithms, reducing E without compromising data confidentiality. cost This enables faster symmetric encryption speeds and lower processing latency. (42) Keep-alive and compatible deployment of multiple operating systems; To address cross-platform deployment requirements, differentiated client lifecycle management and network scheduling are implemented across different underlying operating systems. In the first type of desktop-oriented graphical operating system, the network configuration client is deployed in a protected system storage space. The client registers as a daemon service for the system through the underlying application programming interface, ensuring that the client automatically and silently loads when the system boots up, achieving continuous keep-alive operation and automatic restart in case of failure. In the second type of server-oriented open-source operating system, the client program registers as a background daemon process, automatically identifies the network protection environment at the operating system level, injects dynamic traffic allowance rules into the kernel packet filtering module, and the rules accurately match the adaptively allocated transmission ports and generated logical network cards, ensuring that the data frames of the encrypted communication tunnel are not blocked by the system's native firewall. (43) Dynamic key rotation and forward security; To prevent key leakage and replay attacks during massive business data interaction, a payload-based dynamic key rotation mechanism is established at the cross-platform transport layer. This mechanism continuously monitors the running time and cumulative transmission traffic of each direct-connection tunnel and determines the effective lifespan T of the secure session key according to the following formula. rot : ; Among them, T max V represents the system's preset absolute key lifespan threshold. max v(x) represents the maximum amount of data that can be encrypted with a single session key, and v(x) represents the network transmission rate at time x. After calculating T rot Then, it is set as the trigger threshold for the dynamic renegotiation timer. Specifically, a key status monitoring task is started in the background. When the timer enters the preset pre-negotiation window, the control layer, without interrupting the existing service flow, pre-issues the next-generation key parameters through the control channel and establishes a dual-key coexistence buffer. When the actual transmission data volume of the direct tunnel reaches V... max Or the continuous running time reaches T max At this time, the control layer automatically triggers the key renegotiation command, and without interrupting the existing network connection, it seamlessly distributes and applies the new generation key parameters through the control channel to achieve forward confidentiality and high-strength security for business data transmission.
Citation Information
Patent Citations
Infrastructure processing unit
CN116018795A
Method for realizing Kubernetes cluster service public network access through P2P network and gateway
CN119544340A