A communication method, apparatus, storage medium, and computer program product

CN122534110APending Publication Date: 2026-08-07CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610516619.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-17
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0002]虚拟专用网络(Virtual Private Network,VPN)技术中,通过公网互联网协议(Internet Protocol,IP)或端口映射建立VPN隧道,但该过程依赖中心化VPN服务器,所有流量需经该节点中转,导致对服务器的依赖度较高,成本较高,系统可靠性较低

Benefits of technology

通过第一云桌面向终端发送第一请求,终端基于第一请求确定网卡配置信息并发送至第一云桌面,第一云桌面基于网卡配置信息配置虚拟网卡,并通过反向TCP建立第一云桌面与终端之间的第一隧道,根据虚拟网卡和第一隧道构建第一云桌面与终端之间的虚拟局域网,通过第一云桌面与终端之间构建点对点的第一隧道,消除对外部服务器依赖,降低成本,显著提升可靠性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122534110A_ABST
    Figure CN122534110A_ABST
Patent Text Reader

Abstract

The application provides a communication method, device, storage medium and computer program product. The method comprises the following steps: a first request is sent to a terminal; the first request is used for the terminal to determine network card configuration information; the network card configuration information sent by the terminal is received; a virtual network card is configured based on the network card configuration information, and a first tunnel between the first cloud desktop and the terminal is established through reverse TCP; a virtual local area network between the first cloud desktop and the terminal is constructed according to the virtual network card and the first tunnel; the virtual local area network is used for communication between the first cloud desktop and the terminal. The cost can be reduced, and the reliability can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a communication method, device, storage medium, and computer program product. Background Technology

[0002] Virtual Private Network (VPN) technology establishes VPN tunnels through public Internet Protocol (IP) or port mapping. However, this process relies on a centralized VPN server, and all traffic must be relayed through this node, resulting in high dependence on the server, high cost, and low system reliability. Summary of the Invention

[0003] This application provides a communication method, apparatus, storage medium, and computer program product that can reduce costs and improve reliability.

[0004] The technical solution of this application embodiment is implemented as follows: This application provides a communication method applied to a first cloud desktop; the method includes: A first request is sent to the terminal; the first request is used by the terminal to determine network interface card configuration information. Receive the network card configuration information sent by the terminal; Configure a virtual network card based on the network card configuration information, and establish a first tunnel between the first cloud desktop and the terminal through the Transmission Control Protocol (TCP); A virtual local area network (VLAN) is constructed between the first cloud desktop and the terminal based on the virtual network card and the first tunnel; the VLAN is used for communication between the first cloud desktop and the terminal.

[0005] This application provides a communication method applied to a terminal, the method comprising: Receive the first request sent by the first cloud desktop; Determine the network interface card configuration information based on the first request; The network interface card (NIC) configuration information is sent to the first cloud desktop; the NIC configuration information is used by the first cloud desktop to configure a virtual NIC based on the NIC configuration information, and to establish a first tunnel between the first cloud desktop and the terminal through reverse TCP; a virtual local area network (VLAN) is constructed between the first cloud desktop and the terminal based on the virtual NIC and the first tunnel; the VLAN is used for communication between the first cloud desktop and the terminal.

[0006] This application provides a communication device applied to a first cloud desktop; the device includes: The first sending unit is configured to send a first request to the terminal; the first request is used by the terminal to determine network interface card configuration information. The first receiving unit is used to receive the network card configuration information sent by the terminal; The processing unit is configured to configure a virtual network card based on the network card configuration information, and establish a first tunnel between the first cloud desktop and the terminal through reverse TCP; The construction unit is used to construct a virtual local area network (VLAN) between the first cloud desktop and the terminal based on the virtual network card and the first tunnel; the VLAN is used for communication between the first cloud desktop and the terminal.

[0007] This application provides a communication device for use in a terminal; the device includes: The second receiving unit is used to receive the first request sent by the first cloud desktop; The determining unit is configured to determine network interface card (NIC) configuration information based on the first request. The second sending unit is used to send the network card configuration information to the first cloud desktop; the network card configuration information is used by the first cloud desktop to configure a virtual network card based on the network card configuration information, and to establish a first tunnel between the first cloud desktop and the terminal through reverse TCP; a virtual local area network is constructed between the first cloud desktop and the terminal according to the virtual network card and the first tunnel; the virtual local area network is used for communication between the first cloud desktop and the terminal.

[0008] This application provides a storage medium storing a computer program or computer-executable instructions. The computer program is stored thereon, and when executed by a processor, it implements the above-described communication method.

[0009] Fifthly, this application proposes a computer program product, including a computer program that implements the above-described communication method when executed by a processor.

[0010] The embodiments of this application have the following beneficial effects: The first cloud desktop sends a first request to the terminal. The terminal determines the network card configuration information based on the first request and sends it to the first cloud desktop. The first cloud desktop configures a virtual network card based on the network card configuration information and establishes a first tunnel between the first cloud desktop and the terminal through reverse TCP. A virtual local area network is built between the first cloud desktop and the terminal based on the virtual network card and the first tunnel. By building a point-to-point first tunnel between the first cloud desktop and the terminal, the dependence on external servers is eliminated, costs are reduced, and reliability is significantly improved. Attached Figure Description

[0011] Figure 1 A flowchart illustrating a communication method provided in an embodiment of this application; Figure 2 A flowchart illustrating another communication method provided in an embodiment of this application; Figure 3 A schematic diagram illustrating an exemplary structure for building a virtual local area network between a cloud desktop and a local terminal, provided for embodiments of this application; Figure 4 This is an exemplary diagram illustrating the connection between a local terminal and the cloud, provided as an embodiment of this application. Figure 5 A timing diagram illustrating an exemplary cloud desktop joining a virtual local area network (VLAN) connection, provided for an embodiment of this application; Figure 6 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application; Figure 7 This is a schematic diagram of another communication device provided in an embodiment of this application; Figure 8 This application provides a schematic diagram of the structure of a first cloud desktop according to an embodiment of the present application. Figure 9 This is a schematic diagram of the structure of a terminal provided in an embodiment of this application. Detailed Implementation

[0012] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0013] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0014] In the following description, references to "some embodiments" refer to a subset of all possible embodiments. It is understood that "some embodiments" may be the same or different subsets of all possible embodiments and may be combined with each other without conflict. It should also be noted that the terms "first, second, third" used in the embodiments of this application are merely for distinguishing similar objects and do not represent a specific ordering of objects. It is understood that "first, second, third" may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0015] In relevant VPN solutions, VPN tunnels are established through public IP addresses or port mapping (such as Internet Protocol Security (IPSec) and Open Virtual Private Network (OpenVPN)). These rely on a centralized VPN server, requiring all traffic to pass through this node. Software-Defined Wide Area Network (SD-WAN) technology uses dedicated equipment or SD-WAN technology to achieve multi-point interconnection. This requires pre-configured network equipment and typically requires nodes to have public network reachability. Reverse proxy solutions forward traffic through intermediate servers (such as Engine X (Nginx) and Fast Reverse Proxy (frp)). This introduces a single point of failure risk and has high latency. Cloud vendor-native solutions, such as AWS Direct Connect and Azure ExpressRoute, require dedicated lines and are costly. They are not supported on other cloud providers.

[0016] The above scheme has the following certainties: Public IP dependency: Traditional VPNs and SD-WAN require at least one end to have a public IP address or port forwarding capability.

[0017] Intrusive network architecture: Requires modification of cloud desktop network configuration (such as security groups and routing tables).

[0018] Cloud isolation limitations: It cannot directly solve the network isolation problem between cloud desktops from multiple vendors.

[0019] Performance bottleneck: Reverse proxy solutions have a single point of failure in throughput.

[0020] Based on this, embodiments of this application provide a communication method. Figure 1 A flowchart illustrating a communication method provided in an embodiment of this application; as shown Figure 1 As shown, this method is applied to the first cloud desktop; the method includes: S101. Send a first request to the terminal; the first request is used by the terminal to determine the network card configuration information.

[0021] It should be noted that the first request can be understood as a request to establish a virtual local area network (VLAN) or a request to join a VLAN. Sending the first request to the terminal can be understood as sending the first request to the terminal after the first cloud desktop instance starts. Network interface card (NIC) configuration information can be understood as IP address information; the first request is used by the terminal to determine the NIC configuration information. This can be understood as the terminal's network controller reviewing the first request after receiving it, and allocating IP address information after approval.

[0022] S102, Receive network card configuration information sent by the terminal.

[0023] It should be noted that the network card configuration information sent by the receiving terminal can be understood as the IP address information sent by the receiving terminal of the First Cloud Desktop. The terminal can send the network card configuration information through a private protocol. This private protocol can be any transmission protocol, and the specific transmission protocol can be determined based on the actual situation; no restrictions are imposed here.

[0024] S103. Configure a virtual network card based on the network card configuration information, and establish the first tunnel between the first cloud desktop and the terminal through reverse TCP.

[0025] It should be noted that configuring a virtual network interface card (NIC) based on NIC configuration information can be understood as the First Cloud Desktop creating and configuring a virtual NIC based on IP address information. The First Tunnel can be understood as the tunnel between the First Cloud Desktop and the terminal. Establishing the First Tunnel between the First Cloud Desktop and the terminal via reverse TCP can be understood as the First Cloud Desktop establishing a first tunnel with the terminal through a reverse TCP connection.

[0026] S104. Construct a virtual local area network (VLAN) between the first cloud desktop and the terminal based on the virtual network card and the first tunnel; the VLAN is used for communication between the first cloud desktop and the terminal.

[0027] It should be noted that constructing a virtual local area network (VLAN) between the first cloud desktop and the terminal based on the virtual network card and the first tunnel can be understood as the data packets of the virtual network card being encapsulated and transmitted to the terminal through the first tunnel, thus constructing a VLAN between the first cloud desktop and the terminal.

[0028] The solution in this application embodiment sends a first request to the terminal through a first cloud desktop. The terminal determines network card configuration information based on the first request and sends it to the first cloud desktop. The first cloud desktop configures a virtual network card based on the network card configuration information and establishes a first tunnel between the first cloud desktop and the terminal through reverse TCP. A virtual local area network is constructed between the first cloud desktop and the terminal based on the virtual network card and the first tunnel. By constructing a point-to-point first tunnel between the first cloud desktop and the terminal, the dependence on external servers is eliminated, costs are reduced, and reliability is significantly improved.

[0029] In this embodiment of the application, the method further includes: receiving first routing information sent by a management platform; determining first pointing information corresponding to the first traffic data sent or received based on the first routing information; the first pointing information represents information about the gateway to which the first traffic data points to the virtual network card.

[0030] It should be noted that the management platform can be understood as the management platform of the cloud computer, or the system of the cloud computer. The first routing information can be understood as the allocated routing table. The first pointing information can be understood as the gateway information that correctly points to the virtual network interface card. The first traffic data can be understood as the traffic data generated by the application or system of the first cloud desktop. Receiving the first routing information sent by the management platform; determining the first pointing information corresponding to the first traffic data sent or received based on the first routing information can be understood as the first cloud desktop receiving the routing table allocated by the management platform and determining, according to the routing table, the information that the first traffic data sent or received (incoming and outgoing traffic data) correctly points to the gateway of the virtual network interface card.

[0031] In this embodiment of the application, the process of sending a first request to the terminal specifically includes: sending a first request to the terminal when the terminal is connected to the first cloud desktop through a transmission protocol.

[0032] It should be noted that the transmission protocol can be understood as a proprietary protocol, and the specific transmission protocol can be determined according to the actual situation, without being limited here. When the terminal connects to the first cloud desktop through the transmission protocol, sending the first request to the terminal can be understood as the terminal connecting to the first cloud desktop through the transmission protocol (proprietary protocol), and the first cloud desktop sending the first request to the terminal.

[0033] In this embodiment of the application, after constructing a virtual local area network between the first cloud desktop and the terminal based on the virtual network card and the first tunnel, the method further includes: encapsulating the first data packet corresponding to the virtual network card through the first tunnel to obtain a second data packet; sending the second data packet to the terminal so that the terminal can unpack the second data packet to obtain the first data packet, and sending the first data packet to the second cloud desktop.

[0034] It should be noted that both the first and second cloud desktops establish a virtual local area network (VLAN) with the terminal. The first data packet can be understood as the raw IP packet obtained from the virtual network interface card (NIC); the second data packet can be understood as the data packet obtained after encrypting the first data packet. The second cloud desktop can be understood as the cloud desktop to which the first data packet needs to be transmitted. The process involves encapsulating the first data packet corresponding to the virtual NIC through the first tunnel to obtain the second data packet; sending the second data packet to the terminal, allowing the terminal to decapsulate it to obtain the first data packet, and then sending the first data packet to the second cloud desktop. This can be understood as the first cloud desktop encapsulating the raw IP packet to obtain the second data packet, transmitting the second data packet to the terminal, and the terminal decapsulating the second data packet to obtain the first data packet, which is then transmitted to the second cloud desktop. The second data packet can be sent to the terminal through the first tunnel.

[0035] It should be noted that when the First Cloud Desktop communicates with the terminal, the terminal can send the public key of the traffic data to the First Cloud Desktop and keep the private key. The terminal can receive the traffic data encrypted by the First Cloud Desktop using the public key and decrypt it using the private key to ensure the security of the communication.

[0036] The solution in this application embodiment uses a terminal as a central hub to achieve cross-cloud virtual local area networks without requiring a public IP address or modification of cloud network configuration.

[0037] This application also provides a communication method. Figure 2 A flowchart illustrating another communication method provided in an embodiment of this application; as shown Figure 2 As shown, applied to a terminal, the method includes: S201, Receive the first request sent by the first cloud desktop.

[0038] It should be noted that the first request can be understood as a request to establish a virtual local area network (VLAN) or a request to join a VLAN. Receiving the first request sent by the first cloud desktop can be understood as the first cloud desktop instance sending a first request to the terminal after starting up, and the terminal receiving the first request sent by the first cloud desktop.

[0039] S202. Determine the network card configuration information based on the first request.

[0040] It should be noted that network interface card (NIC) configuration information can be understood as IP address information. Determining NIC configuration information based on the first request can be understood as follows: after receiving the first request, the terminal's network controller reviews the request, and upon successful review, assigns IP address information. The terminal can send NIC configuration information via a private protocol. This private protocol can be any transmission protocol, and the specific protocol can be determined based on actual circumstances; no restrictions are imposed here.

[0041] S203. Send network card configuration information to the first cloud desktop; the network card configuration information is used by the first cloud desktop to configure a virtual network card based on the network card configuration information, and to establish a first tunnel between the first cloud desktop and the terminal through reverse TCP; construct a virtual local area network between the first cloud desktop and the terminal based on the virtual network card and the first tunnel; the virtual local area network is used for communication between the first cloud desktop and the terminal.

[0042] It should be noted that sending network interface card (NIC) configuration information to the first cloud desktop can be understood as the terminal sending NIC configuration information to the first cloud desktop. This NIC configuration information is used by the first cloud desktop to configure the virtual NIC; in other words, the first cloud desktop creates and configures the virtual NIC based on the IP address information. The first tunnel can be understood as the tunnel between the first cloud desktop and the terminal. Establishing the first tunnel between the first cloud desktop and the terminal via reverse TCP can be understood as the first cloud desktop establishing a first tunnel with the terminal through a reverse TCP connection. Building a virtual local area network (VLAN) between the first cloud desktop and the terminal based on the virtual NIC and the first tunnel can be understood as the data packets of the virtual NIC being encapsulated through the first tunnel and transmitted to the terminal, thus constructing a VLAN between the first cloud desktop and the terminal.

[0043] The solution in this application embodiment sends a first request to the terminal through a first cloud desktop. The terminal determines network card configuration information based on the first request and sends it to the first cloud desktop. The first cloud desktop configures a virtual network card based on the network card configuration information and establishes a first tunnel between the first cloud desktop and the terminal through reverse TCP. A virtual local area network is constructed between the first cloud desktop and the terminal based on the virtual network card and the first tunnel. By constructing a point-to-point first tunnel between the first cloud desktop and the terminal, the dependence on external servers is eliminated, costs are reduced, and reliability is significantly improved.

[0044] In this embodiment of the application, the process of receiving the first request sent by the first cloud desktop specifically includes: when the terminal is connected to the first cloud desktop through a transmission protocol, receiving the first request sent by the first cloud desktop.

[0045] It should be noted that the transmission protocol can be understood as a proprietary protocol, and the specific transmission protocol can be determined according to the actual situation, without being limited here. When the terminal connects to the first cloud desktop through the transmission protocol, receiving the first request sent by the first cloud desktop can be understood as the terminal connecting to the first cloud desktop through the transmission protocol (proprietary protocol) and receiving the first request sent by the first cloud desktop.

[0046] In this embodiment of the application, after sending the network card configuration information to the first cloud desktop, the method further includes: receiving a second data packet sent by the first cloud desktop; the second data packet is obtained by the first cloud desktop encapsulating the first data packet corresponding to the virtual network card through the first tunnel; unpacking the second data packet to obtain the first data packet; and sending the first data packet to the second cloud desktop.

[0047] It should be noted that both the first and second cloud desktops establish a virtual local area network (VLAN) with the terminal. The first data packet can be understood as the raw IP packet obtained from the virtual network interface card (NIC); the second data packet can be understood as the data packet obtained after encrypting the first data packet. The second cloud desktop can be understood as the cloud desktop to which the first data packet needs to be transmitted. The process involves receiving the second data packet sent by the first cloud desktop; the second data packet is obtained by the first cloud desktop encapsulating the first data packet corresponding to the virtual NIC through the first tunnel; decapsulating the second data packet to obtain the first data packet; and sending the first data packet to the second cloud desktop. This can be understood as the first cloud desktop encapsulating the raw IP packet to obtain the second data packet, transmitting the second data packet to the terminal, and the terminal decapsulating the second data packet to obtain the first data packet, which is then transmitted to the second cloud desktop. The second data packet can be sent to the terminal through the first tunnel.

[0048] It should be noted that when the First Cloud Desktop communicates with the terminal, the terminal can send the public key of the traffic data to the First Cloud Desktop and keep the private key. The terminal can receive the traffic data encrypted by the First Cloud Desktop using the public key and decrypt it using the private key to ensure the security of the communication.

[0049] The solution in this application embodiment uses a terminal as a central hub to achieve cross-cloud virtual local area networks without requiring a public IP address or modification of cloud network configuration.

[0050] For ease of understanding, the above solutions are illustrated here. The solutions in this application can form a network without a public IP address, that is, allow local terminals to establish a virtual local area network with only outbound TCP connections; non-intrusive deployment, that is, without modifying the existing network policies of the cloud desktop, and reuse existing TCP connections; cross-cloud interoperability, that is, penetrate the network isolation between cloud vendors to realize a virtual Layer 2 network; and low-latency communication, that is, reduce the number of hops through intelligent routing and avoid bottlenecks at the central node.

[0051] This application embodiment implements user authentication and authorization functions through an authentication module, and constructs and manages a virtual local area network (VLAN) through a network module. The core idea is to achieve cloud desktop networking without a public IP address by carrying virtual network interface card (NIC) traffic through a TCP tunnel. The local terminal acts as the central hub, creating virtual NICs and dynamically assigning virtual IP addresses; each cloud desktop registers as a peer through a reverse TCP connection. Data flows through the local terminal for routing and relay, with the protocol conversion process as follows: original IP packet from the cloud desktop → virtual interface encryption → TCP encapsulation → transmission to the local terminal → depacketization and forwarding to the target cloud desktop. The entire process reuses the cloud desktop service's TCP connection, eliminating the need for a public IP address or modification of cloud network configurations, thus achieving cross-cloud VLANs.

[0052] Figure 3 This application provides an exemplary schematic diagram of a virtual local area network (VLAN) constructed between a cloud desktop and a local terminal, as illustrated in the embodiments of this application. Figure 3 As shown, the system includes cloud desktop service provider A, a local terminal, and cloud desktop service provider B. Cloud desktop service provider A includes an authentication server, resource pool A, and resource pool B. The authentication server includes Access Key ID / Secret Access Key (AK / SK), JSON Web Token (JWT), and HTTP Basic Authentication (Basic). Both resource pool A and resource pool B contain cloud desktops. The local terminal includes an authentication module and a network module. The authentication module includes user authentication, terminal device authorization, cloud desktop credentials, and key management. The network module includes tunnels, network interfaces, network controllers, routing engines, and virtual routing tables. Cloud desktop service provider B includes an authentication server, resource pool A, resource pool B, and resource pool C. The authentication server includes AK / SK, JWT, and Basic. Resource pool C contains cloud desktops. The authentication module of the local terminal can authenticate its identity on the authentication servers of cloud desktop service provider A and cloud desktop service provider B. The cloud desktops of cloud desktop service providers A and B are connected to the network interface.

[0053] The above modules are described in detail here.

[0054] The authentication module includes the following three functions: User authentication: This is achieved by using methods such as AK / SK, JWT, or Basic to authenticate the user's identity on the authentication server of the cloud desktop service provider, thereby enabling access to the user's resources.

[0055] Terminal device authorization: A short-term certificate is issued when the device is registered, and the signature is verified when connecting; ensure that only legitimate devices can connect (such as Media Access Control (MAC) / IP whitelist).

[0056] Cloud desktop credentials and key management: issued via TLS encrypted channel, with keys stored in memory or a hardware security module (HSM); secure distribution / rotation of connection credentials for cloud desktops and keys for virtual network card connections.

[0057] The network module includes the following five functions: Tunnel: When creating a virtual LAN, a channel for establishing a virtual LAN connection is established through multiplexing or similar technologies.

[0058] Network Controller: Assigns virtual network addresses, listens for connection requests, maintains the tunnel state machine and virtual network interfaces, and manages the lifecycle of tunnel and virtual network connections.

[0059] Network interface: The virtual network interface of the local terminal, which assigns a network address to the virtual network card of the cloud desktop and provides IP layer communication capabilities for the virtual network card.

[0060] Routing engine: Based on the target network address matching rules, it decides the direction of traffic (local processing or forwarding to the tunnel).

[0061] Virtual routing table: A hash table that stores key-value pairs of <network address, transmission tunnel> for the routing engine to query; it maintains the mapping relationship between cloud desktop network addresses and tunnels.

[0062] Figure 4 This application provides an exemplary diagram illustrating the connection between a local terminal and the cloud; as shown in the embodiments. Figure 4 As shown, the local terminal includes a virtual routing table, a network controller, a routing engine, a tunnel (transmission protocol), and a virtual network interface card (NIC). The cloud includes cloud desktop 1, cloud desktop 2, and cloud desktop 3. Each of cloud desktop 1, cloud desktop 2, and cloud desktop 3 includes a tunnel (transmission protocol) and a virtual NIC. The tunnel of the local terminal is connected to the tunnel of each cloud desktop to send the routing table and key. The virtual network interface of the local terminal is connected to the virtual NIC of each cloud desktop.

[0063] The following section provides a detailed explanation of how to build a virtual LAN for a cloud desktop.

[0064] 1. User login and identity authentication: The user enters their account and password or logs in using other methods. After the system verifies the user's identity, it generates a short-term valid identity token for subsequent operation authorization.

[0065] 2. Terminal device registration and authorization: When the device is connected for the first time, it submits a hardware fingerprint. After successful authentication, it obtains a certificate that is valid for a certain period of time. Subsequent communication requires authentication based on the bidirectional secure transport layer protocol.

[0066] 3. Start the cloud desktop and request access credentials: After the cloud desktop instance starts, it requests access permissions from the key management service and submits login credentials and device certificates for dual verification.

[0067] 4. Dynamically generate and distribute encryption keys: After the key management service verifies the key, it generates a temporary network interface key pair for the cloud desktop and distributes it through a secure channel.

[0068] 5. Network controller coordinates connection establishment: The network controller reviews the cloud desktop request, confirms permissions, assigns an IP address, and notifies both ends to prepare for connection.

[0069] 6. Configure virtual network interface: The cloud desktop creates and configures a virtual network card based on the issued IP address, loads the key and sets the encryption parameters to establish an encrypted tunnel.

[0070] 7. Update the virtual routing table: The system allocates a dedicated routing table for the cloud desktop to ensure that incoming and outgoing traffic correctly points to the gateway of the virtual network card, while isolating the routing rules of different tenants.

[0071] 8. Establish an encrypted tunnel and begin communication: The cloud desktop establishes a tunnel with the terminal through a reverse TCP connection. After the traffic is converted, it is transmitted encrypted through a virtual network interface to achieve secure communication.

[0072] Figure 5 This application provides an exemplary timing diagram for adding a virtual local area network (VLAN) connection to a cloud desktop; as shown in the embodiments of this application. Figure 5 As shown, this includes users / terminals, systems / platforms, and cloud desktops. The specific steps are as follows: 1. Login + Device Authentication.

[0073] It should be noted that users / terminals log in to the system / platform and authenticate their devices.

[0074] 2. Issuance of certificates and tokens.

[0075] It should be noted that the system / platform issues certificates and tokens to users / terminals.

[0076] 3. Connect to the desktop via a private protocol.

[0077] It should be noted that users / terminals connect to the cloud desktop via a proprietary protocol.

[0078] 4. Request to join the virtual LAN.

[0079] It should be noted that the cloud desktop requests the user / terminal to join the virtual LAN.

[0080] 5. Establish a tunnel through a private protocol.

[0081] It should be noted that the user / terminal establishes the tunnel through a proprietary protocol.

[0082] 6. Send network card configuration and key information via a private protocol.

[0083] It should be noted that users / terminals send network card configuration and key information to the cloud desktop via a private protocol.

[0084] 7. Configure the virtual network adapter.

[0085] It should be noted that the cloud desktop is configured with a virtual network adapter.

[0086] 8. Join the virtual local area network through the tunnel terminal network interface.

[0087] 9. Transmit virtual network data traffic via key.

[0088] It should be noted that users / terminals transmit virtual network data traffic to the cloud desktop via a key.

[0089] By following the steps above, users can build a small local area network using the existing channels of the cloud desktop without the need for a proxy server or other additional network resources (such as a public IP address) on their local terminal.

[0090] Compared to traditional reverse proxies that rely on a central server for relaying, the solution in this application employs point-to-point dynamic tunneling technology, eliminating dependence on external servers, reducing costs, and significantly improving system reliability. It integrates User Datagram Protocol (UDP) hole punching, TCP relay, and protocol masquerading technologies to achieve higher connection success rates in various Network Address Translation (NAT) environments. With low resource consumption, the solution in this application achieves direct connection after establishment, reducing resource usage by more than 80%. Point-to-point communication in this application reduces latency by 40%-60%, approaching the limits of the physical network. This application natively supports transport layer protocols such as TCP / UDP / Internet Control Message Protocol (ICMP), perfectly adapting to real-time services such as video streaming and voice.

[0091] This application also provides a communication device. Figure 6 This is a schematic diagram of the structure of a communication device provided in an embodiment of this application; as shown below. Figure 6As shown, the communication device 600, applied to the first cloud desktop, includes: The first sending unit 601 is used to send a first request to the terminal; the first request is used by the terminal to determine network card configuration information. The first receiving unit 602 is used to receive the network card configuration information sent by the terminal; Processing unit 603 is used to configure a virtual network card based on the network card configuration information, and to establish a first tunnel between the first cloud desktop and the terminal through reverse TCP; The construction unit 604 is used to construct a virtual local area network between the first cloud desktop and the terminal based on the virtual network card and the first tunnel; the virtual local area network is used for communication between the first cloud desktop and the terminal.

[0092] In some embodiments, the first receiving unit 602 is further configured to receive first routing information sent by the management platform; The processing unit 603 is further configured to determine, based on the first routing information, the first pointing information corresponding to the first traffic data being sent or received; the first pointing information represents the gateway information of the first traffic data pointing to the virtual network card.

[0093] In some embodiments, the first sending unit 601 is further configured to send the first request to the terminal when the terminal is connected to the first cloud desktop via a transmission protocol.

[0094] In some embodiments, after constructing a virtual local area network between the first cloud desktop and the terminal based on the virtual network card and the first tunnel, the communication device 600 further includes an encapsulation unit for encapsulating the first data packet corresponding to the virtual network card through the first tunnel to obtain a second data packet; The first sending unit 601 is further configured to send the second data packet to the terminal, so that the terminal can unpack the second data packet to obtain the first data packet, and send the first data packet to the second cloud desktop.

[0095] This application also provides a communication device. Figure 7 This is a schematic diagram of another communication device provided in an embodiment of this application; as shown below. Figure 7 As shown, the communication device 700, applied to a terminal, includes: The second receiving unit 701 is used to receive the first request sent by the first cloud desktop; Determining unit 702 is used to determine network interface card configuration information based on the first request; The second sending unit 703 is used to send the network card configuration information to the first cloud desktop; the network card configuration information is used by the first cloud desktop to configure a virtual network card based on the network card configuration information, and to establish a first tunnel between the first cloud desktop and the terminal through reverse TCP; a virtual local area network is constructed between the first cloud desktop and the terminal according to the virtual network card and the first tunnel; the virtual local area network is used for communication between the first cloud desktop and the terminal.

[0096] In some embodiments, the second receiving unit 701 is further configured to receive the first request sent by the first cloud desktop when the terminal is connected to the first cloud desktop via a transmission protocol.

[0097] In some embodiments, after sending the network card configuration information to the first cloud desktop, the second receiving unit 701 is further configured to receive a second data packet sent by the first cloud desktop; the second data packet is obtained by the first cloud desktop encapsulating the first data packet corresponding to the virtual network card through the first tunnel; The communication device 700 further includes an unpacking unit for unpacking the second data packet to obtain the first data packet; The second sending unit 703 is also used to send the first data packet to the second cloud desktop.

[0098] This application provides a first cloud desktop. Figure 8 This is a schematic diagram of the structure of a first cloud desktop provided in an embodiment of this application; as shown below. Figure 8 As shown, the first cloud desktop 800 includes a first processor 801 and a first memory 802. Optionally, the first cloud desktop 800 may also include a first communication bus 803.

[0099] In specific embodiments, the first processor 801 can be at least one of the following: Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), CPU, controller, microcontroller, and microprocessor. It is understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other types, and this embodiment does not specifically limit it.

[0100] In this embodiment, the first communication bus 803 is used to establish communication between the first processor 801 and the first memory 802; when the first processor 801 executes the running program stored in the first memory 802, it implements the following communication method: A first request is sent to the terminal; the first request is used by the terminal to determine network interface card (NIC) configuration information; the NIC configuration information sent by the terminal is received; a virtual NIC is configured based on the NIC configuration information, and a first tunnel is established between the first cloud desktop and the terminal through reverse TCP; a virtual local area network (VLAN) is constructed between the first cloud desktop and the terminal based on the virtual NIC and the first tunnel; the VLAN is used for communication between the first cloud desktop and the terminal.

[0101] Furthermore, the aforementioned first processor 801 is also used to receive first routing information sent by the management platform; determine first pointing information corresponding to the first traffic data sent or received based on the first routing information; the first pointing information represents the information of the gateway to which the first traffic data points to the virtual network card.

[0102] Furthermore, the aforementioned first processor 801 is also configured to send the first request to the terminal when the terminal is connected to the first cloud desktop via a transmission protocol.

[0103] Furthermore, the aforementioned first processor 801 is also configured to encapsulate the first data packet corresponding to the virtual network card through the first tunnel to obtain a second data packet; send the second data packet to the terminal so that the terminal can unpack the second data packet to obtain the first data packet, and send the first data packet to the second cloud desktop.

[0104] This application provides a terminal. Figure 9 This is a schematic diagram of the structure of a terminal provided in an embodiment of this application; as shown below. Figure 9 As shown, the terminal 900 includes a second processor 901 and a second memory 902. Optionally, the terminal 900 may also include a second communication bus 903.

[0105] In specific embodiments, the second processor 901 can be at least one of the following: Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), CPU, controller, microcontroller, and microprocessor. It is understood that for different devices, the electronic device used to implement the above-mentioned processor function can also be other types, and this embodiment does not specifically limit it.

[0106] In this embodiment, the second communication bus 903 is used to realize the connection and communication between the second processor 901 and the second memory 902; when the second processor 901 executes the running program stored in the second memory 902, it implements the following communication method: The system receives a first request from a first cloud desktop; determines network interface card (NIC) configuration information based on the first request; sends the NIC configuration information to the first cloud desktop; the NIC configuration information is used by the first cloud desktop to configure a virtual NIC based on the NIC configuration information, and establish a first tunnel between the first cloud desktop and the terminal through reverse TCP; a virtual local area network (VLAN) is constructed between the first cloud desktop and the terminal based on the virtual NIC and the first tunnel; the VLAN is used for communication between the first cloud desktop and the terminal.

[0107] Furthermore, the second processor 901 is also configured to receive the first request sent by the first cloud desktop when the terminal is connected to the first cloud desktop via a transmission protocol.

[0108] Furthermore, the second processor 901 is also used to receive a second data packet sent by the first cloud desktop; the second data packet is obtained by the first cloud desktop encapsulating the first data packet corresponding to the virtual network card through the first tunnel; the second data packet is unpacked to obtain the first data packet; and the first data packet is sent to the second cloud desktop.

[0109] This application provides a storage medium storing a computer program thereon. The computer-readable storage medium stores one or more programs, which can be executed by one or more processors. The computer program implements the communication method described above for the first cloud desktop side, or implements the communication method described above for the terminal side.

[0110] Based on the above embodiments, this application provides a computer program product, including a computer program that can be executed by one or more processors. The computer program implements the communication method as described above on the first cloud desktop side, or implements the communication method as described above on the terminal side.

[0111] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0112] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the related technology, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to cause an image display device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this disclosure.

[0113] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, and improvements made within the spirit and scope of this application are included within the scope of protection of this application.

Claims

1. A communication method, characterized in that, Applied to the first cloud desktop; the method includes: A first request is sent to the terminal; the first request is used by the terminal to determine network interface card configuration information. Receive the network card configuration information sent by the terminal; Configure a virtual network card based on the network card configuration information, and establish a first tunnel between the first cloud desktop and the terminal through the reverse transmission control protocol TCP. A virtual local area network (VLAN) is constructed between the first cloud desktop and the terminal based on the virtual network card and the first tunnel; the VLAN is used for communication between the first cloud desktop and the terminal.

2. The method according to claim 1, characterized in that, The method further includes: Receive the first routing information sent by the management platform; Based on the first routing information, the first pointing information corresponding to the first traffic data sent or received is determined; the first pointing information represents the gateway information of the first traffic data pointing to the virtual network card.

3. The method according to claim 1, characterized in that, Sending the first request to the terminal includes: When the terminal is connected to the first cloud desktop via a transmission protocol, the first request is sent to the terminal.

4. The method according to claim 1, characterized in that, After constructing the virtual local area network between the first cloud desktop and the terminal based on the virtual network card and the first tunnel, the method further includes: The first data packet corresponding to the virtual network card is encapsulated through the first tunnel to obtain the second data packet; The second data packet is sent to the terminal so that the terminal can unpack the second data packet to obtain the first data packet, and then send the first data packet to the second cloud desktop.

5. A communication method, characterized in that, Applied to a terminal, the method includes: Receive the first request sent by the first cloud desktop; Determine the network interface card configuration information based on the first request; The network interface card (NIC) configuration information is sent to the first cloud desktop; the NIC configuration information is used by the first cloud desktop to configure a virtual NIC based on the NIC configuration information, and to establish a first tunnel between the first cloud desktop and the terminal through the reverse transmission control protocol TCP; a virtual local area network (VLAN) is constructed between the first cloud desktop and the terminal based on the virtual NIC and the first tunnel; the VLAN is used for communication between the first cloud desktop and the terminal.

6. The method according to claim 5, characterized in that, The receiving of the first request sent by the first cloud desktop includes: When the terminal is connected to the first cloud desktop via a transmission protocol, it receives the first request sent by the first cloud desktop.

7. The method according to claim 5, characterized in that, After sending the network card configuration information to the first cloud desktop, the method further includes: Receive the second data packet sent by the first cloud desktop; the second data packet is obtained by the first cloud desktop encapsulating the first data packet corresponding to the virtual network card through the first tunnel; The second data packet is unpacked to obtain the first data packet; Send the first data packet to the second cloud desktop.

8. A communication device, characterized in that, The device, applied to a first cloud desktop, includes: The first sending unit is configured to send a first request to the terminal; the first request is used by the terminal to determine network interface card configuration information. The first receiving unit is used to receive the network card configuration information sent by the terminal; The processing unit is configured to configure a virtual network card based on the network card configuration information, and establish a first tunnel between the first cloud desktop and the terminal through the reverse transmission control protocol TCP. The construction unit is used to construct a virtual local area network (VLAN) between the first cloud desktop and the terminal based on the virtual network card and the first tunnel; the VLAN is used for communication between the first cloud desktop and the terminal.

9. A communication device, characterized in that, Applied to a terminal, the device includes: The second receiving unit is used to receive the first request sent by the first cloud desktop; The determining unit is configured to determine network interface card (NIC) configuration information based on the first request. The second sending unit is used to send the network card configuration information to the first cloud desktop; the network card configuration information is used by the first cloud desktop to configure a virtual network card based on the network card configuration information, and to establish a first tunnel between the first cloud desktop and the terminal through the reverse transmission control protocol TCP; a virtual local area network is constructed between the first cloud desktop and the terminal according to the virtual network card and the first tunnel; the virtual local area network is used for communication between the first cloud desktop and the terminal.

10. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-4; or, it implements the method as described in any one of claims 5-7.

11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-4; or, it performs the method as described in any one of claims 5-7.