A communication method, device, equipment, medium and product of a polymerization link environment

CN122534005APending Publication Date: 2026-08-07NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
Filing Date
2026-04-16
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0004]本发明旨在提供一种聚合链路环境的通信方法、装置、设备、介质及产品,以解决在聚合链路环境下安全设备较多时,通信部署难度大和部署成本高的问题

Benefits of technology

[0015]第五方面,本申请提供一种计算机程序产品,该计算机程序产品包括计算机程序,当计算机程序在电子设备上运行时,使得电子设备执行上述第一方面的方法。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122534005A_ABST
    Figure CN122534005A_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of communication, and provides a communication method, device, equipment, medium and product in an aggregated link environment, which are used for reducing the deployment difficulty and cost. The method is based on a secure network node capable of realizing the function of forwarding data, acquires a target access request sent by a client and used for indicating that the client accesses communication data of a target secure node, and forwards the target access request to the target secure node based on attribute information of the target secure node, so as to reduce the deployment difficulty and cost.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication technology, and more specifically, to a communication method, apparatus, device, medium, and product for an aggregated link environment. Background Technology

[0002] Link aggregation communication can quickly switch to other communication lines according to the aggregation link rules when one communication line fails, ensuring secure and reliable data transmission. In a link aggregation communication environment, there are numerous secure network nodes such as VPNs (Virtual Private Networks) and security gateways.

[0003] When enabling client applications to access secure network nodes, aggregation link rules may switch between different communication links, preventing clients from accessing secure nodes outside the communication link. Therefore, related solutions often involve extending a separate network cable from the service port to the outside of the aggregation link network to enable client-secure node access. However, this solution increases deployment difficulty and cost when there are many secure nodes associated with the security device. Summary of the Invention

[0004] The present invention aims to provide a communication method, apparatus, device, medium and product for an aggregated link environment, in order to solve the problems of high difficulty and high cost of communication deployment when there are many security devices in an aggregated link environment.

[0005] In a first aspect, the present invention provides a communication method for an aggregated link environment, comprising: Obtain the target access request sent by the client; wherein, the target access request is used to instruct the client on communication data to the target security node; Based on the attribute information of the target security node, the target access request is forwarded to the target security node; whereby the attribute information is used to indicate the target identity and target policy label of the target security node.

[0006] The technical solution provided in this application offers at least the following advantages: Based on a secure network node capable of forwarding data, it acquires a target access request sent by a client, instructing the client to communicate with a target secure node. Based on the attribute information of the target secure node, it forwards the target access request to the target secure node. Thus, by using a secure network node capable of forwarding data, combined with the target identity and target policy tag of the target secure node, the target access request is automatically forwarded to the target secure node. This adapts to the same business and management scenarios without requiring a large number of new hardware devices, thereby reducing deployment difficulty and cost.

[0007] One possible implementation involves obtaining the target access request sent by the client, including: obtaining the target access request through a switch in an aggregated link environment; The target access request includes at least the attribute information and communication data of the target security node, and the communication data is used to indicate the business and management information for interconnection of the security node; The target identity identifier is used to describe the location of the target security node in the aggregated link environment, and the target policy label is used to describe the communication behavior of the target security node.

[0008] One possible implementation involves forwarding the target access request to the target security node based on its attribute information, including: Detect whether the target identity and target policy label are the same as the identity and policy label of the secure network node; In response to the target identity and target policy label being identical to the identity and policy label of the secure network node, corresponding feedback information is generated based on the target access request and returned to the client; In response to the fact that the target identity and policy label are different from those of the secure network node, the target access request is forwarded to the target secure node based on the preset list of peer devices and the attribute information of the target secure node.

[0009] One possible implementation involves forwarding the target access request to the target security node based on a pre-defined list of peer devices and the target security node's attribute information, including: In the list of peer devices, search for whether there is an identity and policy label that are the same as the target identity and target policy label; Among them, the list of peer devices pre-stores multiple sets of peer device identity identifiers and policy tags. A peer device refers to another secure network node that establishes a communication connection with the current secure network node through the interconnection network interface. In response to the fulfillment of the first preset condition, the target access request is sent to the node location indicated by the same identity identifier; The first preset condition is used to indicate that the same identity identifier and the same policy label exist at the same time.

[0010] One possible implementation involves generating a prompt message based on the target identity and target policy tag in response to the fulfillment of a second preset condition, and then returning the prompt message to the client via a switch to remind the user to re-enter the access request. The second preset condition is used to indicate any of the following: only the same identity identifier exists, only the same policy label exists, and neither the same identity identifier nor the same policy label exists.

[0011] One possible implementation involves detecting whether a network link has been established with the client; wherein the network link includes at least one network node in an aggregated link environment. In response to establishing a network link with the client, obtain the target access request sent by the client; In response to the lack of a network link with the client, it waits for the peer device to forward the access request until a network link is established with the client.

[0012] Secondly, this application provides a communication device for an aggregated link environment, comprising: The acquisition module is used to acquire the target access request sent by the client; wherein, the target access request is used to indicate the client's access data to the target security node; The processing module is used to forward the target access request to the target security node based on the target security node's attribute information; wherein, the attribute information is used to indicate the target security node's network attribute information and policy attribute information.

[0013] Thirdly, this application provides an electronic device comprising: a processor and a memory; the memory storing processor-executable instructions; when the processor is configured to execute the instructions, causing the electronic device to implement the method of the first aspect described above.

[0014] Fourthly, this application provides a computer-readable storage medium comprising: computer software instructions; which, when executed in an electronic device, cause the electronic device to implement the method described in the first aspect.

[0015] Fifthly, this application provides a computer program product comprising a computer program that, when run on an electronic device, causes the electronic device to perform the method described in the first aspect.

[0016] The beneficial effects of the second to fifth aspects mentioned above are described in the corresponding description of the first aspect and will not be repeated here. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of an aggregated link network environment; Figure 2 This is a schematic diagram of lead wire communication management; Figure 3 A flowchart illustrating a communication method in an aggregated link environment provided in an embodiment of this application; Figure 4 This is a schematic diagram of a transparent communication scenario provided in an embodiment of this application; Figure 5 A schematic diagram illustrating the composition of a communication device in an aggregated link environment, provided as an embodiment of this application; Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0018] In this article, the term "and / or" is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone.

[0019] To facilitate a clear description of the technical solutions of the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish the same or similar items with essentially the same function and effect. Those skilled in the art can understand that the terms "first" and "second" are not intended to limit the quantity or execution order.

[0020] Furthermore, the terms "comprising" and "having," and any variations thereof, used in the description of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0021] In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0022] Currently, with the continuous expansion of social informatization, network communication methods are also constantly innovating and developing. In order to improve the reliability of network communication, more and more users are choosing network aggregation link communication as their networking method.

[0023] In aggregated link communication scenarios, there are usually multiple network lines connecting the starting and ending devices. The node devices on each network line forward IP packets based on a predetermined communication strategy (such as routing based on the destination MAC address). The communication data stream is transmitted along the same or different communication links according to the communication strategy. When one of the communication lines has a problem, it can quickly switch to other communication lines according to the aggregated link rules to ensure the security and reliability of data transmission.

[0024] Figure 1 This is a schematic diagram of an aggregated link network environment, such as... Figure 1As shown, in most aggregated link network environments, in addition to network node devices, there are also a considerable number of security node devices, i.e., security devices A / B, such as VPNs and security gateways. These security devices not only process IP, TCP / UDP protocol messages sent to them for the secure transmission of business data (such as confidentiality protection and integrity protection), but also conduct application layer management data communication based on TCP, UDP, and other protocols for their own interconnection management needs. Because this type of communication data, which includes business and management data, occurs between the client (i.e., the application terminal) and the security devices, it may be subject to network rule restrictions due to the randomness of network communication routing in the aggregated link business network environment, resulting in communication failures.

[0025] Figure 2 This is a schematic diagram of lead wire communication management, such as Figure 2 As shown, to avoid the aforementioned communication failures, the relevant solution involves extending a network cable from a separate communication port to the outside of the aggregated link network, enabling access communication between the client (application terminal) and the security node (security device). In other words, by extending a network cable from a separate communication port to the outside of the aggregated link network, business data traversing itself is transmitted via the aggregated link network; communication data sent to itself is transmitted via a non-aggregated link communication port, simultaneously meeting the needs for interconnection and management of services.

[0026] However, while related solutions can enable network communication in aggregated link network environments, they require additional network cables, consuming limited communication lines. When there are many similar security devices in an aggregated link environment, this increases network deployment difficulty and cost. Furthermore, this approach cannot achieve network transparency, failing to meet the needs of scenarios where business and management use the same network.

[0027] To address the aforementioned technical issues, this application provides a communication method, apparatus, device, medium, and product for an aggregated link environment. Based on a secure network node capable of forwarding data, it acquires a target access request sent by a client, instructing the client to communicate with a target secure node. Based on the target secure node's attribute information, it forwards the target access request to the target secure node. Thus, by leveraging a secure network node capable of forwarding data, combined with the target security node's target identity and target policy tag, the target access request is automatically forwarded to the target secure node. This adapts to the same business and management scenarios without requiring a large number of new hardware devices, thereby reducing deployment difficulty and costs.

[0028] The following is a detailed description of a communication method for an aggregated link environment provided by an embodiment of this application, with reference to the accompanying drawings.

[0029] Figure 3This is a flowchart illustrating a communication method in an aggregated link environment provided in an embodiment of this application. Figure 4 This is a schematic diagram of a transparent communication scenario provided in an embodiment of this application.

[0030] It should be noted that, Figure 4 This is merely an illustrative scenario diagram. Figure 4 The number of devices included, and the names of each device, are not limited.

[0031] The application environment of the embodiments in this application is not limited. The scenarios described in the embodiments of this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the emergence of new business scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0032] Combination Figure 3 and Figure 4 The following describes the communication method for the aggregated link environment provided in the embodiments of this application: S101. Obtain the target access request sent by the client.

[0033] In one possible implementation, before a secure network node obtains a target access request through a switch, the kernel of the communication system to which the secure network node belongs needs to be configured so that the secure network node can perform the data forwarding function.

[0034] For example, when configuring the kernel of a communication system to which a secure network node belongs, for LACP (Link Aggregation Control Protocol) used in aggregated link environments, according to IEEE 802.1D, Linux-based communication system kernels by default prohibit forwarding of LACP protocols with a destination MAC address of 01-80-C2-00-00-02. In system kernels starting with Linux 2.6, the forwarding configuration can be viewed and modified through the ` / sys / class / net / br / bridge / group_fwd_mask` file (this file path is for reference only; it may differ across systems). However, in default Linux distributions, the forwarding configuration for LACP protocols with a destination MAC address of 01-80-C2-00-00-02 is prohibited from being modified at the kernel code level through the `group_fwd_mask` file; only the configuration can be viewed. The same situation exists for STP protocols with a destination MAC address of 01-80-C2-00-00-00 and Ethernet flow control forwarding configurations with a destination MAC address of 01-80-C2-00-00-01.

[0035] To enable secure network nodes to forward data, the LACP protocol forwarding is manually configured to be allowed or disabled via the `group_fwd_mask` file. The main code file to modify is `net / bridge / br_private.h` (this file path is for reference only; it may differ on different systems), adjusting the macro definition of `BR_GROUPFWD_RESTRICTED` (this macro name is for reference only; it may differ on different systems).

[0036] The macro name BR_GROUPFWD_RESTRICTED is defined as follows (disabling manual configuration of STP, Ethernet flow control, and LACP forwarding enable / disable via the group_fwd_mask file): #define BR_GROUPFWD_RESTRICTED (BR_GROUPFWD_STP | BR_GROUPFWD_MACPAUSE | BR_GROUPFWD_LACP).

[0037] Furthermore, if it is only necessary to manually configure LACP protocol forwarding permission or disallowing via the group_fwd_mask file, then remove BR_GROUPFWD_LACP from the macro definition, and adjust as follows: #define BR_GROUPFWD_RESTRICTED (BR_GROUPFWD_STP | BR_GROUPFWD_MACPAUSE).

[0038] Furthermore, to facilitate flexible configuration and management, it is advisable to allow or disable STP protocol with a destination MAC address of 01-80-C2-00-00-00 and Ethernet flow control forwarding with a destination MAC address of 01-80-C2-00-00-01 via the group_fwd_mask file. The corresponding adjusted code would be as follows: #define BR_GROUPFWD_RESTRICTED 0.

[0039] After modifying, compiling, and replacing the kernel code as required, the LACP protocol forwarding configuration can now be enabled via the ` / sys / class / net / br / bridge / group_fwd_mask` file. From this point on, secure network nodes in an aggregated link environment can forward data.

[0040] In one possible implementation, after the secure network node is able to perform the data forwarding function, it is detected whether a network link has been established with the client, wherein the network link includes at least one network node in the aggregated link environment.

[0041] For example, in response to establishing a network link with the client, the system obtains the target access request sent by the client; in response to not establishing a network link with the client, the system waits for the access request forwarded by the peer device until a network link is established with the client.

[0042] The target access request includes at least the attribute information and management data of the target security node. The attribute information is used to indicate the target identity and target policy label of the target security node, and the communication data is used to indicate the business and management information for interconnection between the security nodes.

[0043] The target identity identifier is used to describe the location of the target security node in the aggregated link environment, i.e., its IP address, while the target policy tag is used to describe the communication behavior of the target security node, i.e., its network rules.

[0044] S102. Based on the attribute information of the target security node, forward the target access request to the target security node.

[0045] In a network aggregation environment, when a client outside the network tries to access a secure node inside, the randomness of network communication routing can prevent the successful establishment of a network socket. For example, in... Figure 1 In the network environment shown, the client and the application layer communication between the secure network node, i.e., the security device A / B, may actually choose a different communication line, resulting in the inability to establish a network socket connection.

[0046] Therefore, as Figure 4 As shown, in one possible implementation, network connections are established between corresponding secure network nodes, i.e., secure devices, within the aggregated link network to create direct communication links, allowing network access requests destined for the other device to be forwarded through themselves.

[0047] For example, when a client, i.e., an application terminal, accesses security device A, its network link may follow the path of "application terminal ---> switch A ---> security device A" or it may follow the path of "application terminal ---> switch A ---> security device B ---> security device A". Similarly, when an application terminal accesses security device B, its network link is similar.

[0048] In one possible implementation, after connecting secure network nodes, security devices A and B, along with the adjacent switch, may form a loop, affecting network communication. Therefore, a Layer 2 firewall configuration is needed to ensure that only communication data destined for the peer device is forwarded through the interconnecting network interface, while other data is prohibited from passing through this path, thus preventing the loop from occurring.

[0049] For example, the Layer 2 firewall rules configured on a secure network node, i.e., a secure device, are as follows: (1) Allow LACP data with a destination MAC (Media Access Control Address) of 01-80-C2-00-00-02 to be forwarded out via the service interface; (2) Allow LACP data with destination MAC address 01-80-C2-00-00-02 to be forwarded out via the internal service port; (3) Allow data with source MAC addresses of the peer device to be forwarded through the established interconnection network interface; (4) Allow data whose destination MAC address is the peer device to be forwarded through the established interconnection network interface; (5) Allow ARP request packets with destination IP address to be forwarded through the established interconnection network interface.

[0050] In the above Layer 2 firewall rules, rules (1) and (2) enable the security device to forward LACP data normally and ensure that the associated switch in the aggregated link working state can work normally; rules (3) and (4) enable the data accessing the peer device to be forwarded normally through the interconnection network port; and rule (5) ensures that the peer device's ARP can be learned normally through the interconnection network port.

[0051] The specific instructions for configuring Layer 2 firewall rules based on ebtables commands are as follows: ebtables -A FORWARD -d 01:80:c2:00:00:02 -o business external interface name (e.g., eth0) -jACCEPT; ebtables -A FORWARD -d 01:80:c2:00:00:02 -o Service port name (e.g., eth1) -jACCEPT; ebtables -A FORWARD -s peer device MAC (e.g., 11:22:33:44:55:66) -i interconnecting network interface name (e.g., eth2) -j ACCEPT; ebtables -A FORWARD -d peer device MAC address (e.g., 11:22:33:44:55:66) -o interconnecting network interface name (e.g., eth2) -j ACCEPT; ebtables -A FORWARD -p ARP --arp-op Request --arp-ip-dst peer device IP (e.g., 192.168.1.100) -o interconnecting network interface name (e.g., eth2) -j ACCEPT.

[0052] Therefore, rules configured based on a Layer 2 firewall can be used to detect whether the target identity and policy label are the same as those of the secure network node.

[0053] In one possible implementation, in response to the target identity and target policy label being identical to the identity and policy label of the secure network node, corresponding feedback information is generated based on the target access request, and the feedback information is returned to the client.

[0054] Furthermore, in response to the fact that the target identity and target policy label are different from the identity and policy label of the secure network node, the target access request is forwarded to the target secure node based on the preset list of peer devices and the attribute information of the target secure node.

[0055] In one possible implementation, when forwarding a target access request to a target security node based on a preset list of peer devices and the attribute information of the target security node, the peer device list is searched to see if there is an identity identifier and policy label that are the same as the target identity identifier and the target policy label.

[0056] The list of peer devices contains multiple sets of peer device identifiers and policy tags stored in advance. A peer device refers to another secure network node that establishes a communication connection with the current secure network node through the interconnection network port.

[0057] Furthermore, in response to the fulfillment of the first preset condition, the target access request is sent to the node location indicated by the same identity identifier.

[0058] The first preset condition is used to indicate that the same identity identifier and the same policy label exist at the same time.

[0059] Furthermore, in response to the fulfillment of the second preset condition, a prompt message is generated based on the target identity identifier and the target policy label, and the prompt message is returned to the client through the switch to remind the user to re-enter the access request.

[0060] The second preset condition is used to indicate any of the following: only the same identity identifier exists, only the same policy label exists, and neither the same identity identifier nor the same policy label exists.

[0061] In this embodiment, based on a secure network node capable of forwarding data, a target access request sent by a client, instructing the client to communicate with a target secure node, is obtained. Based on the attribute information of the target secure node, the target access request is forwarded to the target secure node. Thus, by using a secure network node capable of forwarding data, combined with the target identity and target policy tag of the target secure node, the target access request is automatically forwarded to the target secure node. This adapts to the same business and management scenarios without requiring a large number of new hardware devices, thereby reducing deployment difficulty and cost.

[0062] In some embodiments, this application also provides a communication device for an aggregated link environment. This communication device for an aggregated link environment may include one or more functional modules for implementing a communication method for an aggregated link environment as described in the above method embodiments.

[0063] For example, Figure 5 This is a schematic diagram illustrating the composition of a communication device in an aggregated link environment, as provided in an embodiment of this application. Figure 5 As shown, the communication device for this aggregated link environment includes: an acquisition module 501 and a processing module 502.

[0064] The acquisition module 501 is used to acquire the target access request sent by the client; wherein the target access request is used to indicate the client's access data to the target security node.

[0065] The processing module 502 is used to forward the target access request to the target security node based on the attribute information of the target security node; wherein the attribute information is used to indicate the network attribute information and policy attribute information of the target security node.

[0066] In some embodiments, the acquisition module 501 is specifically used to acquire a target access request through a switch in a combined link environment; wherein the target access request includes at least the attribute information and communication data of the target security node, and the communication data is used to indicate the service and management information for interconnection and interoperability of the security node; The target identity identifier is used to describe the location of the target security node in the aggregated link environment, and the target policy label is used to describe the communication behavior of the target security node.

[0067] In some embodiments, the processing module 502 is specifically used to detect whether the target identity and target policy label are the same as the identity and policy label of the secure network node; In response to the target identity and target policy label being identical to the identity and policy label of the secure network node, corresponding feedback information is generated based on the target access request and returned to the client; In response to the fact that the target identity and policy label are different from those of the secure network node, the target access request is forwarded to the target secure node based on the preset list of peer devices and the attribute information of the target secure node.

[0068] In some embodiments, the processing module 502 is specifically used to search in the list of peer devices for whether there is an identity and policy label that are the same as the target identity and target policy label. Among them, the list of peer devices pre-stores multiple sets of peer device identity identifiers and policy tags. A peer device refers to another secure network node that establishes a communication connection with the current secure network node through the interconnection network interface. In response to the fulfillment of the first preset condition, the target access request is sent to the node location indicated by the same identity identifier; The first preset condition is used to indicate that the same identity identifier and the same policy label exist at the same time.

[0069] In some embodiments, the processing module 502 is further configured to, in response to the fulfillment of a second preset condition, generate a prompt message based on the target identity and target policy label, and return the prompt message to the client via a switch to remind the user to re-enter the access request; The second preset condition is used to indicate any of the following: only the same identity identifier exists, only the same policy label exists, and neither the same identity identifier nor the same policy label exists.

[0070] In some embodiments, the processing module 502 is further configured to detect whether a network link has been established with the client; wherein the network link includes at least one network node in an aggregated link environment; In response to establishing a network link with the client, obtain the target access request sent by the client; In response to the lack of a network link with the client, it waits for the peer device to forward the access request until a network link is established with the client.

[0071] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. The electronic device includes: a processor 602, a communication interface 603, and a bus 604. Optionally, the electronic device may also include a memory 601.

[0072] Processor 602 may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 602 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 602 may also be a combination of functions implementing computing capabilities, such as a combination of CPU0 and CPU1, a DSP, and a microprocessor.

[0073] The communication interface 603 includes a receiving unit and a transmitting unit, and is used to connect with other devices via a communication network. This communication network can be Ethernet, a wireless access network, a wireless local area network (WLAN), etc.

[0074] The memory 601 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.

[0075] In one possible implementation, the memory 601 can exist independently of the processor 602. The memory 601 can be connected to the processor 602 via a bus 604 and is used to store instructions or program code. When the processor 602 calls the instructions or program code stored in the memory 601, it can implement the communication method of the aggregated link environment provided in this embodiment of the invention.

[0076] In another possible implementation, the memory 601 can also be integrated with the processor 602.

[0077] Bus 604 can be an extended industry standard architecture (EISA) bus, etc. Bus 604 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 6 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0078] Through the above description of the implementation methods, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the service calling device can be divided into different functional modules to complete all or part of the functions described above.

[0079] This application also provides a computer-readable storage medium. All or part of the processes in the above method embodiments can be executed by computer instructions instructing related hardware. The program can be stored in the aforementioned computer-readable storage medium, and when executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be any of the foregoing embodiments or memory. The aforementioned computer-readable storage medium can also be an external storage device of the aforementioned service invocation device, such as a plug-in hard drive, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the aforementioned service invocation device. Further, the aforementioned computer-readable storage medium can include both internal storage units of the aforementioned service invocation device and external storage devices. The aforementioned computer-readable storage medium is used to store the aforementioned computer program and other programs and data required by the aforementioned service invocation device. The aforementioned computer-readable storage medium can also be used to temporarily store data that has been output or will be output.

[0080] This application also provides a computer program product, which includes a computer program that, when run on a computer, causes the computer to execute the communication method of the aggregated link environment provided in the above embodiments.

[0081] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A communication method in an aggregated link environment, characterized in that, The method, applied to a secure network node in the aggregated link environment, wherein the secure network node is capable of forwarding data, includes: Obtain the target access request sent by the client; wherein the target access request is used to instruct the client to communicate with the target security node; Based on the attribute information of the target security node, the target access request is forwarded to the target security node; wherein, the attribute information is used to indicate the target identity identifier and target policy label of the target security node.

2. The communication method for an aggregated link environment according to claim 1, characterized in that, The step of obtaining the target access request sent by the client includes: The target access request is obtained through the switch in the aggregated link environment; The target access request includes at least the attribute information of the target security node and the communication data, wherein the communication data is used to indicate the business and management information for interconnection of the security nodes; The target identity identifier is used to describe the location of the target security node in the aggregated link environment, and the target policy tag is used to describe the communication behavior of the target security node.

3. The communication method for an aggregated link environment according to claim 2, characterized in that, Based on the attribute information of the target security node, forwarding the target access request to the target security node includes: Detect whether the target identity and target policy label are the same as the identity and policy label of the secure network node; In response to the fact that the target identity and target policy label are the same as the identity and policy label of the secure network node, corresponding feedback information is generated according to the target access request, and the feedback information is returned to the client; In response to the fact that the target identity and target policy label are different from the identity and policy label of the security network node, the target access request is forwarded to the target security node based on the preset list of peer devices and the attribute information of the target security node.

4. The communication method in an aggregated link environment according to claim 3, characterized in that, The step of forwarding the target access request to the target security node based on a preset list of peer devices and the attribute information of the target security node includes: Search the list of peer devices for an identity identifier and policy tag that are identical to the target identity identifier and the target policy tag. The list of peer devices pre-stores multiple sets of peer device identity identifiers and policy tags. The peer device refers to another secure network node that establishes a communication connection with the current secure network node through an interconnected network port. In response to the fulfillment of the first preset condition, the target access request is sent to the node location indicated by the same identity identifier; The first preset condition is used to indicate the simultaneous existence of the same identity identifier and the same policy label.

5. The communication method for an aggregated link environment according to claim 4, characterized in that, The method further includes: In response to the fulfillment of the second preset condition, a prompt message is generated based on the target identity identifier and the target policy tag, and the prompt message is returned to the client through the switch to remind the user to re-enter the access request; The second preset condition is used to indicate any of the following: only the same identity exists, only the same policy label exists, and neither the same identity nor the same policy label exists.

6. The communication method in an aggregated link environment according to claim 1, characterized in that, Before obtaining the target access request sent by the client, the method further includes: Detect whether a network link has been established with the client; wherein the network link includes at least one network node in the aggregated link environment; In response to establishing a network link with the client, the target access request sent by the client is obtained; In response to the failure to establish a network link with the client, the system waits for the peer device to forward the access request until a network link is established with the client.

7. A communication device for an aggregated link environment, characterized in that, include: The acquisition module is used to acquire the target access request sent by the client; wherein the target access request is used to indicate the client's access data to the target security node; The processing module is used to forward the target access request to the target security node based on the attribute information of the target security node; wherein the attribute information is used to indicate the network attribute information and policy attribute information of the target security node.

8. An electronic device, characterized in that, It includes a processor and a memory, the processor being coupled to the memory; the memory is used to store computer instructions, which are loaded and executed by the processor to enable the computer device to perform the method as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer-executable instructions that, when executed on a computer, cause the computer to perform the method according to any one of claims 1 to 6.

10. A computer program product, characterized in that, The computer program product includes a computer program that, when run on an electronic device, causes the electronic device to perform the method as described in any one of claims 1 to 6.