Local area network communication method and device, electronic equipment, storage medium and program product
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-05-09
- Publication Date
- 2026-08-11
AI Technical Summary
[0004]然而,该架构虽能满足基础上网需求,但存在明显技术缺陷:不同家庭用户的下挂终端无法直接进行二层局域网互访,终端间通信必须经由公网转发,不仅占用大量公网带宽资源,还存在时延高、安全性不足等问题;同时,还会存在增加网络负载与设备处理压力,难以适配大规模家庭用户内网互通的业务场景的问题
[0010] According to another aspect of this disclosure, a computer program product is provided, which, when executed by a processor, implements a local area network communication method as described in any of the embodiments of this disclosure.
Smart Images

Figure CN122554263A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of cloud computing technology, and in particular to a local area network communication method, apparatus, electronic device, storage medium, and program product. Background Technology
[0002] With the deepening development of computing networks, cloud computing and edge computing have become the core directions for broadband network architecture upgrades. To meet the needs of large-scale user access, flexible service scheduling, and efficient utilization of network resources, operators are building a new cloud-network converged broadband architecture using cloud-based gateways combined with Virtual Extensible Local Area Network (VXLAN) technology. How to improve the efficiency of user intranet communication and reduce public network bandwidth consumption in a large Layer 2 network has become a key issue for the industry.
[0003] In related technologies, the current mainstream cloud gateway solution uses a single-user dedicated VXLAN tunnel to enable terminal access. The user terminal obtains an Internet IP address through PPPoE dialing and establishes an independent VXLAN tunnel with the cloud gateway. The internal network address is assigned by a unified DHCP server. Service traffic is distinguished by the cloud gateway and then offloaded to the public network or forwarded at an accelerated speed.
[0004] However, while this architecture can meet basic internet access requirements, it has obvious technical defects: different home users' downstream terminals cannot directly access each other on a Layer 2 local area network. Communication between terminals must be forwarded through the public network, which not only consumes a lot of public network bandwidth resources, but also has problems such as high latency and insufficient security. At the same time, it will also increase network load and equipment processing pressure, making it difficult to adapt to business scenarios of large-scale home user intranet interconnection. Summary of the Invention
[0005] This disclosure provides a local area network (LAN) communication method, apparatus, electronic device, storage medium, and program product to achieve low-latency, high-security transmission of LAN cross-gateway communication, as well as accurate management of terminal information and orderly transmission of cross-gateway data, adapting to the needs of large-scale home user intranet interconnection and ensuring the efficiency and security of LAN cross-gateway communication.
[0006] According to one aspect of this disclosure, a local area network (LAN) communication method is provided, the method being applied to a first cloud gateway, comprising: Upon receiving an address resolution request message for a second terminal sent by a first terminal, the Ethernet address of the terminal corresponding to the second terminal is determined based on a pre-created user forwarding table and the address resolution request message. Based on the terminal's Ethernet address, a request-response message is generated and sent to the first terminal, so that the first terminal generates an access request message for the second terminal based on the request-response message; wherein, the user forwarding table is at least used to characterize the mapping relationship between the terminal's Internet Protocol address, the terminal's Ethernet address and the terminal's network identifier. The system receives an access request message sent by the first terminal to the second terminal. If it is determined that the first terminal and the second terminal are communicating across gateways based on the access request message and the user forwarding table, the system determines the second cloud gateway to which the second terminal belongs. The system encapsulates the access request message based on the interconnection network identifier between the first cloud gateway and the second cloud gateway and the terminal network identifier corresponding to the first terminal to obtain an encrypted data packet. The encrypted data packet is sent to the second cloud gateway through the inter-gateway interconnection tunnel between the first cloud gateway and the second cloud gateway, so that the second cloud gateway sends the access request message to the second terminal based on the encrypted data packet.
[0007] According to another aspect of this disclosure, a local area network (LAN) communication device is provided, configured in a first cloud gateway, comprising: The first module is used to determine the Ethernet address of the terminal corresponding to the second terminal based on a pre-created user forwarding table and the address resolution request message when receiving an address resolution request message for the second terminal sent by the first terminal. The second module is used to generate a request-response message based on the terminal's Ethernet address and send it to the first terminal, so that the first terminal generates an access request message for the second terminal based on the request-response message; wherein, the user forwarding table is used to characterize at least the mapping relationship between the terminal's Internet Protocol address, the terminal's Ethernet address and the terminal's network identifier. The third module is used to receive the access request message sent by the first terminal to the second terminal. If it is determined that the first terminal and the second terminal are communicating across gateways based on the access request message and the user forwarding table, the module determines the second cloud gateway to which the second terminal belongs. The module encapsulates the access request message based on the interconnection network identifier between the first cloud gateway and the second cloud gateway and the terminal network identifier corresponding to the first terminal to obtain an encrypted data packet. The fourth module is used to send the encrypted data packet to the second cloud gateway through the inter-gateway interconnection tunnel between the first cloud gateway and the second cloud gateway, so that the second cloud gateway sends the access request message to the second terminal based on the encrypted data packet.
[0008] According to another aspect of this disclosure, an electronic device is provided, the electronic device comprising: One or more processors; Storage device for storing one or more programs. When one or more programs are executed by one or more processors, the one or more processors implement a local area network communication method as described in any of the embodiments of this disclosure.
[0009] According to another aspect of this disclosure, a computer-readable storage medium is provided that stores computer instructions for causing a processor to execute and implement any of the local area network communication methods in the embodiments of this disclosure.
[0010] According to another aspect of this disclosure, a computer program product is provided, which, when executed by a processor, implements a local area network communication method as described in any of the embodiments of this disclosure.
[0011] The technical solution of this disclosure, upon receiving an address resolution request message for a second terminal from a first terminal, determines the Ethernet address corresponding to the second terminal based on a pre-created user forwarding table and the address resolution request message. This achieves accurate location of the second terminal's Ethernet address, providing an addressing basis for subsequent communication between the first and second terminals and ensuring the normal establishment of the communication link. Furthermore, by generating a request-response message based on the terminal's Ethernet address and sending it to the first terminal, the first terminal generates an access request message for the second terminal based on the request-response message, feeding back the second terminal's Ethernet address to the first terminal, triggering the first terminal to generate its own access request message, and promoting the orderly progress of the communication process. Furthermore, by receiving the access request message for the second terminal sent by the first terminal, and determining, based on the access request message and the user forwarding table, that the first and second terminals are communicating across gateways, the second cloud gateway to which the second terminal belongs is identified. The access request message is then encapsulated using the interconnection network identifier between the first and second cloud gateways and the terminal network identifier corresponding to the first terminal, resulting in an encrypted data packet. This achieves secure encapsulation and accurate identification of the cross-gateway access request message. It distinguishes and isolates cross-gateway traffic using the interconnection network identifier and the terminal network identifier, while also ensuring the security and integrity of the access request message. This lays the foundation for subsequent cross-gateway data transmission, ensuring normal cross-gateway communication between the requesting terminal and the target terminal. Furthermore, by sending the encrypted data packet through the inter-gateway interconnection tunnel between the first and second cloud gateways to the second cloud gateway, the second cloud gateway forwards the access request message to the second terminal based on the encrypted data packet. This ensures the secure and accurate delivery of the access request message to the second cloud gateway, which then forwards it to the target terminal, ultimately achieving stable cross-gateway communication while ensuring the security and isolation of data transmission. The technical solution of this disclosure addresses the problems of excessive public network bandwidth consumption, high latency, insufficient security, and difficulty in adapting to business scenarios involving large-scale home user intranet interconnection in related technologies. It achieves low-latency and high-security transmission of inter-gateway communication in local area networks. Through processes such as address resolution, packet encapsulation, and dedicated tunnel transmission, it ensures stable and secure inter-gateway communication between the requesting terminal and the target terminal. Furthermore, it enables precise management of terminal information and orderly transmission of inter-gateway data, adapting to the needs of large-scale home user intranet interconnection and ensuring the efficiency and security of inter-gateway communication in local area networks.
[0012] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0013] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 A flowchart illustrating a local area network communication method provided in an embodiment of this disclosure; Figure 2 A flowchart illustrating another local area network communication method provided in this embodiment of the present disclosure; Figure 3 This is a schematic diagram of the structure of a local area network communication device provided in an embodiment of the present disclosure; Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. Detailed Implementation
[0015] To enable those skilled in the art to better understand the present disclosure, the technical solutions of the present disclosure will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present disclosure, and not all embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present disclosure.
[0016] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0017] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.
[0018] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this disclosed technical solution, based on the prompt message.
[0019] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0020] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.
[0021] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.
[0022] Before introducing this technical solution, an exemplary application scenario can be provided. The technical solution provided in this disclosure can be applied to any scenario that requires seamless cross-LAN communication between terminals connected to a multi-cloud gateway.
[0023] Currently, in the field of LAN communication and multi-cloud gateway deployment, with the continuous growth in the number of smart home and enterprise intranet terminals, the demand for multi-region, multi-gateway collaborative networking is becoming increasingly prominent. For example, scenarios such as multiple households sharing a LAN, interconnecting multiple branch intranets within an enterprise, and interoperability of distributed office terminals place higher demands on the seamless experience, transmission efficiency, and network security of cross-gateway communication. Cross-gateway LAN communication, as a key technology for achieving multi-terminal collaboration and resource sharing, has been widely applied in network deployments for the aforementioned scenarios. In the actual deployment of multi-cloud gateway cross-LAN communication, manual routing configuration, independent network segment allocation, broadcast address resolution, and single-tunnel transmission are typically employed. However, these methods have the following technical problems: Address allocation for cross-gateway terminals lacks uniformity; terminals under multiple gateways are often located on different network segments, making seamless access as with terminals on the same local area network impossible, and communication configuration is complex; address resolution uses a network-wide broadcast mode, which easily generates broadcast storms, consuming a large amount of network bandwidth, and the address resolution efficiency of remote terminals is low; cross-gateway traffic and user local traffic are not effectively isolated, easily leading to traffic confusion and forwarding errors, affecting communication stability; there is a lack of a systematic terminal information synchronization mechanism, each cloud gateway can only manage local terminals and cannot accurately locate the affiliation of remote terminals, resulting in chaotic cross-gateway forwarding paths; when cross-gateway communication anomalies occur, there is a lack of automated closed-loop adjustment strategies, often relying on manual troubleshooting and configuration adjustments of tunnel parameters, resulting in low operational efficiency and a high risk of communication interruption.
[0024] To address the aforementioned issues, this disclosure provides a cross-LAN communication scheme based on user forwarding table synchronization and dual-layer VXLAN encapsulation. It achieves terminal network segment collaboration through globally unified address allocation, enables precise positioning of remote terminals based on user forwarding table synchronization, avoids broadcast flooding by using ARP proxy, isolates cross-gateway traffic from local traffic through dual-layer VXLAN encapsulation, and establishes an automated tunnel maintenance mechanism, thereby improving the seamless experience, transmission efficiency, and network stability of cross-gateway communication.
[0025] Figure 1 This is a flowchart illustrating a local area network (LAN) communication method provided in an embodiment of this disclosure. This embodiment is applicable to any scenario requiring seamless cross-LAN communication between terminals connected to a multi-cloud gateway. The method is applied to a first cloud gateway and executed by a LAN communication device within the first cloud gateway. This LAN communication device can be implemented in hardware and / or software and can be configured in electronic devices such as computers or servers. Figure 1 As shown, the method in this embodiment includes: S110. Upon receiving an address resolution request message for the second terminal sent by the first terminal, determine the Ethernet address of the terminal corresponding to the second terminal based on the pre-created user forwarding table and the address resolution request message.
[0026] In this context, the first cloud gateway can be understood as a network device with functions such as terminal access, packet forwarding, address resolution, Virtual Extensible Local Area Network (VXLAN) encapsulation and decapsulation, and user forwarding table establishment and maintenance. It can be understood that a cloud gateway is a network device connecting local facilities and cloud services, supporting hardware or software deployment, and achieving seamless integration between local and public clouds through protocol conversion. In this embodiment, the first cloud gateway can be a direct access gateway for the first terminal, used to receive various packets from the first terminal, perform address resolution, cross-gateway determination, packet encapsulation, and establish a communication link with the second cloud gateway to achieve cross-gateway packet transmission. The first terminal can be a terminal device connected to the first cloud gateway, acting as the initiator of the access request. The first terminal can be a device with LAN communication capabilities, such as a computer, smart home device, server, or mobile terminal. As the initiator of the access request, the first terminal needs to connect to the first cloud gateway to achieve LAN communication and cross-gateway access. The first cloud gateway is the direct access gateway for the first terminal. It is responsible for receiving and processing various messages such as address resolution request messages and access request messages sent by the first terminal. It is the main entity upon which the first terminal initiates cross-gateway access, and the two work together to initiate and initially process the access request. The second terminal can be the recipient of the access request. The second terminal can be a device with LAN communication capabilities, such as a computer, smart home device, server, or mobile terminal. It can receive access request messages forwarded by the cloud gateway from the first terminal and perform corresponding response operations (such as returning data or providing services) according to the message content. It is the target terminal accessed by the first terminal. The second terminal can be a terminal device connected to the first cloud gateway or a terminal device connected to a second cloud gateway different from the first cloud gateway. When the second terminal is a terminal device connected to the first cloud gateway, the communication between the first terminal and the second terminal is intra-gateway communication; when the second terminal is a terminal device connected to the second cloud gateway, the communication between the first terminal and the second terminal is cross-gateway communication.
[0027] The Address Resolution Request (ARP) message can be understood as a request message sent by the first terminal to query the Ethernet address (MAC address) of the second terminal. The ARP message is equivalent to the ARP (Address Resolution Protocol) request message in the communications field. The ARP message can carry the first terminal's Internet Protocol address (IP address) and Ethernet address, as well as the target terminal's (second terminal's) IP address. Generally, the first terminal knows the second terminal's IP address but cannot directly obtain its Ethernet address (MAC address). It sends this ARP message to request the MAC address, laying the foundation for subsequent access request messages. The user forwarding table can be understood as a data table pre-created and maintained by the first cloud gateway to store the mapping relationships of key terminal information. The user forwarding table can be used to query and match terminal information. Specifically, it represents the one-to-one correspondence between the terminal's Internet Protocol address (IP address), Ethernet address (MAC address), and VXLAN Network Identifier (VNI). It can also store auxiliary information such as the terminal's home cloud gateway identifier, gateway interconnection address, and interconnection tunnel identifier, providing core basis for address resolution, cross-gateway determination, and encapsulation operations. The terminal network identifier is the core identifier in a VXLAN network, used to identify the virtual LAN to which the terminal belongs, achieving traffic isolation between different users or terminal groups. Compared to the virtual LAN identifier in traditional networks, it supports a larger number of virtual network partitions, adapting to networking scenarios with multiple terminals and multiple gateways. The terminal Ethernet address, also known as the terminal MAC address (Media Access Control address), is the unique identifier of the terminal device's physical network card, preset by the device manufacturer, and used for physical layer communication between devices within the local area network. The terminal Ethernet address can be used to identify the physical identity of the terminal, ensuring that access request packets are accurately delivered to the target terminal.
[0028] In general, data transmission within a local area network relies on Ethernet addresses for physical layer addressing. However, terminals only maintain their own protocol address information and cannot know the Ethernet addresses of other terminals in advance. Therefore, they need to obtain the Ethernet address of the target terminal by sending an address resolution request message in order to establish effective communication.
[0029] In practical applications, ARP tables are typically used to determine the Ethernet address of a target terminal. Traditional ARP tables only maintain a binary mapping between IP addresses and MAC addresses, enabling only basic Layer 2 address resolution. Furthermore, the generation and updating of these entries depend on ARP broadcast messages sent by the terminal, which has several limitations: Firstly, ARP broadcast messages flood the local area network, consuming significant network bandwidth and potentially triggering broadcast storms, thus affecting network transmission efficiency and stability. Secondly, traditional ARP tables lack network isolation-related identification fields, making them unsuitable for large Layer 2 networking scenarios involving cloud gateways and VXLAN tunnels. They also fail to provide effective basis for packet tunnel encapsulation. Additionally, the entries lack standardized lifecycle management rules, leading to the accumulation of invalid entries. Moreover, they can only maintain local terminal address mapping information and do not support address information synchronization across gateways, failing to meet the interoperability requirements of cross-terminal local area networks under multi-cloud gateway networking. It is understandable that Layer 2 networking is a network virtualization technology concept relative to traditional Layer 2 LANs. It refers to breaking through the physical geographical and device boundary limitations of traditional Layer 2 networks and using tunneling technologies such as VXLAN to virtually integrate terminals / devices scattered in different physical locations and different Layer 3 networks into a single logical Layer 2 LAN. This allows devices across regions and gateways to communicate directly at Layer 2 (e.g., via MAC addresses and ARP protocols) as if they were in the same physical Layer 2 network, without the need for complex Layer 3 routing and forwarding. Essentially, it is a wide-area and virtualized extension of Layer 2 networks.
[0030] To address the above issues, this embodiment employs a triplet user forwarding table to determine the Ethernet address of the target terminal. Compared to traditional ARP tables, this approach offers multiple core advantages. Specifically adapted for large Layer 2 cross-VXLAN tunnel scenarios, this user forwarding table not only overcomes the limitations of traditional ARP tables that only maintain binary mappings of IP and MAC addresses, offering limited functionality and lacking lifecycle management, but also adds a core VNI field and associates it with metadata such as Dynamic Host Configuration Protocol (DHCP) lease duration and receiving port. It combines global ARP proxying with VXLAN tunnel encapsulation and location functions, locating the VXLAN tunnel to which the terminal belongs via VNI. It also includes a complete triplet for bidirectional index queries, focusing on Layer 2 LAN connectivity without requiring Layer 3 routing support. VNI enables precise tunnel encapsulation and efficient Layer 2 forwarding, and also facilitates traffic isolation. Furthermore, this user forwarding table overcomes the limitations of traditional entries that only maintain local information. This technology supports table entry synchronization between multi-cloud gateways based on the EVPN Type 2 protocol, marking remote terminal entries with their respective gateways and interconnection tunnel identifiers. This enables global management of local and remote terminal information. Combined with dedicated VXLAN10000 interconnection tunnels between gateways, it can also distinguish between terminal-side user VNIs and gateway interconnection VNIs through VNIs, achieving complete isolation of the two types of traffic and avoiding traffic mixing. At the same time, the table entry lifecycle is strongly bound to the DHCP lease period, and it will also verify validity through targeted ARP probes and automatically clean up invalid entries, making table entry management more intelligent. Overall, through triplet mapping, multi-data association, and cross-gateway synchronization, it integrates and supports core requirements such as ARP proxy, tunnel encapsulation, table entry management, and traffic isolation. It perfectly solves the industry pain points of traditional table entries, such as single functionality, poor scenario adaptability, and inability to support cross-tunnel or cross-gateway Layer 2 interconnection. It is the core technology carrier for cloud gateways to achieve intranet interconnection between different user terminals.
[0031] In this embodiment, when the first terminal wants to communicate with the second terminal, it only knows the second terminal's Internet Protocol (IP) address and not its Ethernet address used for local area network (LAN) data transmission. Therefore, in this case, the first terminal can send an address resolution request (IPR) message to the first cloud gateway to obtain the second terminal's Ethernet address. Upon receiving the IPR message, the first cloud gateway can parse it to obtain the IPR address of the second terminal. Furthermore, based on the user forwarding table and the obtained IPR address, the corresponding Ethernet address of the second terminal can be determined.
[0032] Optionally, based on a pre-established user forwarding table and address resolution request messages, the terminal Ethernet address corresponding to the second terminal is determined, including: parsing the address resolution request messages to obtain the target Internet Protocol address, and determining the target Internet Protocol address as the terminal Internet Protocol address corresponding to the second terminal; querying the pre-established user forwarding table based on the terminal Internet Protocol address to obtain the terminal Ethernet address corresponding to the second terminal.
[0033] The target Internet Protocol address (IP address) can be the IP address of the target terminal that the first terminal wants to access, carried in the address resolution request message. It can also be the internal network logical address assigned to the target terminal by a globally unified DHCP server, used for logical addressing of the target terminal within the network, and is the core index for querying the Ethernet address of the second terminal. The terminal IIP address corresponding to the second terminal can be the same as the target IIP address, used to clearly identify it as the second terminal being accessed in cross-gateway communication, and is the unique logical identifier for the cloud gateway to query the Ethernet address of the second terminal.
[0034] In one implementation, after receiving an address resolution request message from a first terminal, the first cloud gateway first performs protocol parsing on the message to extract the target Internet Protocol address (IPA) carried within it. Since this target IPA is the logical addressing identifier of the second terminal the first terminal intends to access, it is directly identified as the IPA corresponding to the second terminal. Further, using the second terminal's IPA as a unique query index, the first cloud gateway performs a precise search in a pre-created and maintained user forwarding table to determine the corresponding Ethernet address and assigns it as the Ethernet address corresponding to the second terminal.
[0035] S120. Based on the terminal's Ethernet address, generate a request-response message and send it to the first terminal, so that the first terminal can generate an access request message for the second terminal based on the request-response message.
[0036] The request-response message can be understood as a response message generated by the first cloud gateway in response to the address resolution request message sent by the first terminal. It carries the mapping relationship between the second terminal's Internet Protocol address (IP address) and its corresponding Ethernet address. The request-response message is essentially an ARP response message. This message can be generated by the first cloud gateway simulating the target terminal and is the core message for implementing ARP proxy responses. The access request message can be understood as the actual business communication message sent by the first terminal to the second terminal after obtaining the second terminal's Ethernet address. It carries the first terminal's IIP address (source IP) and Ethernet address (source MAC address), the second terminal's IIP address (target IP) and Ethernet address (target MAC address), and specific business data (such as file access, data transfer requests, etc.). The access request message can be the core business carrier for actual local area network communication between the first and second terminals.
[0037] It should be noted that in traditional LANs, terminal address resolution requests are sent in broadcast form. However, in the cloud gateway networking architecture with large Layer 2 cross-VXLAN tunnels provided in this technical solution, to avoid bandwidth consumption and broadcast storms caused by broadcast messages flooding in each VXLAN tunnel, and to achieve seamless Layer 2 communication between cross-gateway terminals, the first cloud gateway, as the core node for global ARP proxy, needs to replace the second terminal in completing the address resolution response operation. Moreover, the first terminal only knows the IP address of the second terminal and has no direct way to obtain its Ethernet address. The first cloud gateway can query the corresponding Ethernet address through the user forwarding table and generate a request-response message containing the mapping relationship between the IP address and the Ethernet address. Only then can the first terminal obtain the physical address identifier of the second terminal required for communication, thus having the basis to generate access request messages for the second terminal and carry out subsequent actual Layer 2 communication. At the same time, this proxy method can also ensure the efficiency of address resolution and the communication stability in cross-gateway networking scenarios.
[0038] It should also be noted that the first cloud gateway can independently complete ARP proxying through the pre-created user forwarding table without needing to request feedback from other devices via broadcast. Therefore, after receiving the address resolution request packet, the first cloud gateway needs to actively suppress its broadcast forwarding to prevent broadcast flooding from the source. This reduces invalid packet interactions, saves bandwidth resources, and ensures network smoothness and stability in cross-gateway Layer 2 networking scenarios. At the same time, in conjunction with the first cloud gateway's ARP proxying function, it does not affect the first terminal's normal acquisition of the second terminal's Ethernet address.
[0039] Optionally, after receiving the address resolution request message for the second terminal sent by the first terminal, the method further includes: suppressing the broadcast forwarding of the address resolution request message and not forwarding it to other devices in the local area network or other cloud gateways.
[0040] In one implementation, after the first cloud gateway retrieves the Ethernet address of the second terminal from the user forwarding table, it immediately constructs a corresponding request-response message based on that Ethernet address according to the ARP protocol specification. This request-response message accurately encapsulates the mapping relationship between the second terminal's Internet Protocol address (IPA) and its Ethernet address. Simultaneously, the source MAC address of the request-response message is configured as the dedicated MAC address of the cloud gateway's virtual Layer 2 interface, and the destination MAC address is configured as the Ethernet address of the first terminal. Further, after constructing the request-response message, the first cloud gateway encapsulates it within the VXLAN tunnel belonging to the first terminal and sends it down the reverse uplink to the requesting first terminal. Further, upon receiving the request-response message, the first terminal parses the obtained Ethernet address of the second terminal and caches the mapping relationship between the second terminal's IPA and its Ethernet address in its local ARP table. Furthermore, once the Ethernet address of the second terminal is obtained, an access request message for the second terminal can be generated according to the local area network communication rules. This message includes the source IP address, destination IP address, source MAC address, destination MAC address, and specific business data. The generated access request message is then sent to the first cloud gateway.
[0041] S130. Receive an access request message for the second terminal sent by the first terminal. If it is determined that the first terminal and the second terminal are communicating across gateways based on the access request message and the user forwarding table, determine the second cloud gateway to which the second terminal belongs. Encapsulate the access request message according to the interconnection network identifier between the first cloud gateway and the second cloud gateway and the terminal network identifier corresponding to the first terminal to obtain an encrypted data packet.
[0042] Cross-gateway communication can be understood as the first terminal and the second terminal not being connected to the same cloud gateway, but belonging to the first cloud gateway and the second cloud gateway respectively. Their communication requires forwarding through a dedicated tunnel between the two cloud gateways, unlike local area network communication between terminals under the same cloud gateway. The second cloud gateway can be the direct access gateway for the second terminal, possessing the same core functions as the first cloud gateway (packet forwarding, encapsulation and decapsulation, user forwarding table management, etc.). In cross-gateway communication, it receives encrypted data packets forwarded by the first cloud gateway and sends the decapsulated access request packets to the remote gateway device of the second terminal. The Internet Network Identifier (IVI) can be understood as a dedicated Internet VNI for cloud gateway devices, a unique number identifying the dedicated communication tunnel between the first and second cloud gateways. It is used only to carry cross-gateway LAN traffic between cloud gateways and is completely isolated from the user VNI on the terminal side, ensuring dedicated link transmission for cross-gateway traffic. The terminal network identifier (VNI) can be understood as the user's VNI to which the first terminal belongs. It is a unique number that identifies the VXLAN tunnel corresponding to the first terminal when it accesses the cloud gateway. It is used to mark the internal network traffic on the terminal side, realizing traffic isolation between different users and different terminals. It is also the core identifier for the cloud gateway to perform VXLAN encapsulation on the terminal side packets. Encapsulation can be understood as a two-layer VXLAN encapsulation operation performed by the first cloud gateway on cross-gateway access request packets. That is, the terminal network identifier and the interconnection network identifier are encapsulated into the tunnel header of the access request packet in sequence, forming a nested tunnel encapsulation structure to achieve traffic identification and isolation. The encrypted data packet can be understood as the cross-gateway transmission data packet obtained after the first cloud gateway performs two-layer encapsulation on the access request packet. Through two-layer encapsulation, traffic isolation and precise addressing are achieved, ensuring that the packet can only be transmitted in the dedicated tunnels of the first cloud gateway and the second cloud gateway, avoiding data leakage or tampering, while ensuring the accuracy of cross-gateway forwarding.
[0043] In this embodiment, the first cloud gateway receives an access request message for the second terminal, generated and sent by the first terminal based on the obtained Ethernet address of the second terminal. The gateway then performs protocol parsing on the access request message, extracting core addressing information such as the Internet Protocol address (IPA) of the first terminal and the IPA of the second terminal. Next, using the IPA addresses of the first and second terminals as dual indexes, the gateway performs a precise query in a user forwarding table pre-created and maintained within the first cloud gateway. This table contains local and remote terminal information and is marked with the terminal's home gateway identifier. The gateway matches the entries corresponding to the first and second terminals. The home gateway identifier in the entry determines whether the two terminals are connected to the same cloud gateway. If the query results show that their home gateway identifiers are different, it is determined that the first and second terminals are communicating across gateways. Furthermore, the pre-marked home gateway information is extracted from the entry corresponding to the second terminal, thereby accurately determining the second cloud gateway to which the second terminal belongs. Furthermore, the interconnection network identifier between the first cloud gateway and the second cloud gateway and the terminal network identifier corresponding to the first terminal can be obtained, and the access request message can be encapsulated based on the interconnection network identifier and the terminal network identifier to obtain an encrypted data packet.
[0044] It should be noted that in the cloud gateway networking architecture with large Layer 2 cross-VXLAN tunnels provided in this technical solution, network identifiers are required to achieve accurate traffic addressing, isolation, and tunneled transmission. Specifically, the terminal network identifier is a unique identifier for the VXLAN tunnel to which the first terminal belongs. Encapsulating this terminal network identifier marks the source terminal affiliation of the access request packet, enabling exclusive differentiation of intranet traffic on the terminal side and preventing mixing with traffic from other user terminals. The interconnect network identifier is a unique identifier for the dedicated tunnel between cloud gateways. Encapsulating this interconnect network identifier allows access request packets to be accurately located to the dedicated interconnect link of the second cloud gateway, ensuring that cross-gateway packets are transmitted only in the dedicated tunnel between cloud gateways and do not propagate to the public network or other unrelated links. Simultaneously, the encrypted data packets, encapsulated in a dual-layer VXLAN format, achieve precise end-to-end forwarding of cross-gateway messages from the source terminal to the remote cloud gateway through the collaboration of two layers of identifiers. Furthermore, tunneling encapsulation provides transmission isolation and security protection for access request messages, preventing data leakage and tampering during cross-gateway transmission. It can also adapt to the networking rules of large Layer 2 cross-VXLAN tunnels, ensuring that cross-gateway access request messages are correctly identified and forwarded to the second cloud gateway according to the cloud gateway's forwarding logic, ultimately guaranteeing the accuracy, security, and stability of cross-gateway communication.
[0045] Optionally, the access request message is encapsulated based on the interconnection network identifier between the first cloud gateway and the second cloud gateway and the terminal network identifier corresponding to the first terminal to obtain an encrypted data packet. This includes: querying the user forwarding table based on the source Internet Protocol address in the access request message to obtain the terminal network identifier corresponding to the first terminal; determining the preset interconnection network identifier corresponding to cross-gateway communication as the interconnection network identifier between the first cloud gateway and the second cloud gateway; performing inner encapsulation on the access request message based on the terminal network identifier to obtain an inner encapsulated data packet; and performing outer encapsulation on the inner encapsulated data packet based on the interconnection network identifier to obtain an encrypted data packet.
[0046] The source Internet Protocol address (IP address) can be the IP address of the first terminal carried in the access request message. It is the logical network identifier of the first terminal and serves as the core index for querying the corresponding terminal network identifier, used to accurately match the first terminal's dedicated entry in the user forwarding table. The terminal network identifier can be the user VNI (VXLAN Network Identifier) to which the first terminal belongs. It is a unique number identifying the VXLAN tunnel corresponding to the first terminal when it accesses the first cloud gateway. It is obtained by the cloud gateway by querying the user forwarding table using the source IP address and is used as the inner tunnel identifier during cross-gateway encapsulation, marking the origin of the message. The preset Internet identifier can be understood as a pre-planned interconnection VNI between cloud gateways, dedicated to cross-gateway LAN communication. It is the unique identifier of the dedicated communication tunnel between the first and second cloud gateways, isolated from the terminal-side user VNI, and used for cross-gateway traffic transmission. Optionally, the preset Internet identifier can be VXLAN10000. The inner encapsulation can be the operation by which the cloud gateway, using the terminal network identifier as the core, encapsulates the access request message with the first-layer VXLAN tunnel header according to the VXLAN protocol specification, only marking the tunnel information of the source terminal. After completion, the inner encapsulated data packet is obtained. The inner encapsulated data packet can be a data packet formed by encapsulating an access request message with the terminal network identifier's inner VXLAN layer. It already carries the unique VNI information of the first terminal, achieving identification and isolation of terminal-side traffic, and serves as the base data packet for the outer encapsulation layer. The outer encapsulation layer can be an operation where the cloud gateway, using the Internet network identifier as its core, further encapsulates the inner encapsulated data packet according to the VXLAN protocol specification, marking the dedicated tunnel information between cloud gateways and preparing for cross-gateway transmission. The encrypted data packet can be a double-layer VXLAN encapsulated data packet formed by encapsulating an access request message with both the terminal network identifier's inner encapsulation layer and the Internet network identifier's outer encapsulation layer. This is not encryption in the narrow sense, but rather achieves precise traffic addressing, transmission isolation, and security protection through double-layer tunnel encapsulation, ensuring that messages can only be transmitted within the dedicated tunnels of the first and second cloud gateways.
[0047] In one implementation, the first cloud gateway first performs protocol parsing on the received access request message, extracting the source Internet Protocol address (IPA) corresponding to the first terminal in the message. Then, using this source IPA as a unique query index, it performs a precise search in the locally maintained user forwarding table, extracting the unique terminal network identifier (User VNI) from the matched entry corresponding to the first terminal. Simultaneously, since this communication is determined to be inter-gateway communication, a pre-determined pre-defined interconnection network identifier (Interconnection VNI), specifically used for inter-gateway LAN communication between cloud gateways, can be used as the interconnection network identifier for messages transmitted between the first and second cloud gateways. Further, according to the VXLAN protocol specification, the extracted terminal network identifier is encapsulated into the VXLAN tunnel header of the access request message, completing the inner encapsulation of the original access request message and generating an inner encapsulated data packet that only marks the tunnel information to which the source terminal belongs. Furthermore, based on the inner encapsulated data packet, the VXLAN protocol is followed again to encapsulate the determined cloud gateway interconnection network identifier into a new VXLAN tunnel header, completing the outer encapsulation of the data packet. Finally, an encrypted data packet with a two-layer VXLAN encapsulation structure containing the terminal-side VNI and the gateway interconnection VNI is formed, preparing for accurate cross-gateway transmission.
[0048] S140. The encrypted data packet is sent to the second cloud gateway through the inter-gateway interconnection tunnel between the first cloud gateway and the second cloud gateway, so that the second cloud gateway sends the access request message to the second terminal based on the encrypted data packet.
[0049] The inter-gateway interconnection tunnel can be a dedicated communication tunnel dynamically established between the first cloud gateway and the second cloud gateway based on VXLAN technology. It is uniquely identified by a preset interconnection network identifier and carries only LAN communication traffic between gateways, completely isolated from public network traffic and terminal-side access traffic. It is a dedicated link for cross-gateway data packet transmission. Each inter-gateway interconnection tunnel corresponds one-to-one with an interconnection network identifier. For example, if the internet identifier is VXLAN10000, the corresponding inter-gateway interconnection tunnel is the VXLAN10000 tunnel.
[0050] In one implementation, after the first cloud gateway completes the double-layer VXLAN encapsulation of the access request message to obtain an encrypted data packet, it sends the encrypted data packet through a pre-established inter-gateway interconnection tunnel between the first and second cloud gateways based on the interconnection network identifier between the first and second cloud gateways. This dedicated tunnel is a dedicated link for cross-LAN communication between cloud gateways and only carries intranet traffic across gateways. Further, after receiving the encrypted data packet through the inter-gateway interconnection tunnel, the second cloud gateway first performs an outer decapsulation operation according to the VXLAN protocol, stripping the outer tunnel header corresponding to the cloud gateway interconnection network identifier to obtain the inner encapsulated data packet. Then, it performs an inner decapsulation operation on the inner encapsulated data packet, stripping the inner tunnel header corresponding to the terminal network identifier of the first terminal to restore the original access request message sent by the first terminal. Furthermore, the second cloud gateway parses and restores the access request message, extracts the terminal Internet Protocol address and terminal Ethernet address of the second terminal, queries the user forwarding table maintained within the second cloud gateway using the terminal Internet Protocol address as an index, obtains the VXLAN tunnel information to which the second terminal belongs, encapsulates the original access request message into the tunnel, and forwards it downlink along the tunnel to the access device of the second terminal. Finally, the access device accurately sends the access request message to the second terminal, completing the cross-gateway message transmission and delivery.
[0051] In this embodiment, for the case where the first terminal and the second terminal communicate within the same gateway, communication can be completed through single-layer encapsulation forwarding. Optionally, the local area network communication method further includes: if it is determined from the access request message and the user forwarding table that the first terminal and the second terminal communicate within the same gateway, performing single-layer encapsulation on the access request message based on the terminal network identifier corresponding to the first terminal and forwarding it to the second terminal.
[0052] In this context, communication within the same gateway refers to situations where both the first and second terminals are connected to and belong to the same cloud gateway, eliminating the need for inter-gateway tunnel forwarding and enabling direct Layer 2 communication within the same gateway. Single-layer encapsulation can be understood as, compared to the double-layer VXLAN encapsulation used across gateways, communication within the same gateway only requires a single VXLAN header, carrying only the terminal network identifier and eliminating the need for additional outer identifiers for the inter-gateway interconnection tunnel.
[0053] In one implementation, when the access request message is compared with the user forwarding table and it is determined that the first terminal and the second terminal belong to the same cloud gateway and do not need to be transmitted across gateway tunnels, a lightweight forwarding strategy can be directly adopted. The access request message is encapsulated with a single-layer VXLAN using only the terminal network identifier corresponding to the first terminal, which can meet the requirements of traffic isolation and local addressing. Then, the encapsulated access request message is directly forwarded to the second terminal, thereby simplifying the message encapsulation process, reducing gateway processing overhead, improving the efficiency of communication between terminals within the same gateway, and ensuring compatibility with cross-gateway forwarding logic.
[0054] The technical solution of this disclosure, upon receiving an address resolution request message for a second terminal from a first terminal, determines the Ethernet address corresponding to the second terminal based on a pre-created user forwarding table and the address resolution request message. This achieves accurate location of the second terminal's Ethernet address, providing an addressing basis for subsequent communication between the first and second terminals and ensuring the normal establishment of the communication link. Furthermore, by generating a request-response message based on the terminal's Ethernet address and sending it to the first terminal, the first terminal generates an access request message for the second terminal based on the request-response message, feeding back the second terminal's Ethernet address to the first terminal, triggering the first terminal to generate its own access request message, and promoting the orderly progress of the communication process. Furthermore, by receiving the access request message for the second terminal sent by the first terminal, and determining, based on the access request message and the user forwarding table, that the first and second terminals are communicating across gateways, the second cloud gateway to which the second terminal belongs is identified. The access request message is then encapsulated using the interconnection network identifier between the first and second cloud gateways and the terminal network identifier corresponding to the first terminal, resulting in an encrypted data packet. This achieves secure encapsulation and accurate identification of the cross-gateway access request message. It distinguishes and isolates cross-gateway traffic using the interconnection network identifier and the terminal network identifier, while also ensuring the security and integrity of the access request message. This lays the foundation for subsequent cross-gateway data transmission, ensuring normal cross-gateway communication between the requesting terminal and the target terminal. Furthermore, by sending the encrypted data packet through the inter-gateway interconnection tunnel between the first and second cloud gateways to the second cloud gateway, the second cloud gateway forwards the access request message to the second terminal based on the encrypted data packet. This ensures the secure and accurate delivery of the access request message to the second cloud gateway, which then forwards it to the target terminal, ultimately achieving stable cross-gateway communication while ensuring the security and isolation of data transmission. The technical solution of this disclosure addresses the problems of excessive public network bandwidth consumption, high latency, insufficient security, and difficulty in adapting to business scenarios involving large-scale home user intranet interconnection in related technologies. It achieves low-latency and high-security transmission of inter-gateway communication in local area networks. Through processes such as address resolution, packet encapsulation, and dedicated tunnel transmission, it ensures stable and secure inter-gateway communication between the requesting terminal and the target terminal. Furthermore, it enables precise management of terminal information and orderly transmission of inter-gateway data, adapting to the needs of large-scale home user intranet interconnection and ensuring the efficiency and security of inter-gateway communication in local area networks.
[0055] Figure 2 This is a flowchart illustrating another local area network communication method provided by an embodiment of this disclosure. The technical solution of this embodiment can be combined with other embodiments; for the same or related parts, they can be described in conjunction with the descriptions of other embodiments, and will not be repeated here. Figure 2 As shown, the method in this embodiment may specifically include: S210. Upon receiving a network protocol routing message sent by the second cloud gateway, determine the gateway configuration information corresponding to the second cloud gateway based on the network protocol routing message, and update the gateway configuration information to the local user table corresponding to the first cloud gateway to obtain the updated local user table.
[0056] The network protocol routing message can be understood as a control message actively sent by the second cloud gateway to the first cloud gateway to synchronize routing and terminal information. It is typically an EVPN routing message, carrying information such as the terminal's Internet Protocol address, Ethernet address, network identifier, and gateway address of the terminal belonging to the second cloud gateway, used to achieve cross-gateway information synchronization. Gateway configuration information can be understood as the forwarding configuration and terminal affiliation information related to the second cloud gateway. This mainly includes: the tunnel address of the second cloud gateway, the Internet Protocol address, the mapping relationship between the terminal's Internet Protocol address, Ethernet address, and network identifier, and the gateway identifier, etc., which are key data for cross-gateway addressing. The local user table can be understood as the basic entries initially maintained locally by the first cloud gateway to record the terminals and related information under this gateway. It does not contain configuration information from other cloud gateways and is the basis for subsequently generating the user forwarding table.
[0057] In one implementation, when the first cloud gateway receives a network protocol routing message sent by the second cloud gateway, it first parses the message and extracts the configuration information related to the second cloud gateway contained therein, that is, the gateway configuration information corresponding to the second cloud gateway. Then, it accurately matches this gateway configuration information to the local user table corresponding to the first cloud gateway, completes the update of the local user table, and obtains the updated local user table. This ensures that the table contains the complete configuration information of the second cloud gateway, providing accurate parameter support for subsequent cross-gateway communication and message forwarding, and realizing the synchronization and unified management of configuration information between gateways.
[0058] In this embodiment, to ensure that the terminal can access the network normally and obtain legitimate network configuration, and to improve the full-process adaptation of local area network communication, after the terminal completes address resolution and access request preparation, it is necessary to first complete the initial allocation of terminal network configuration and the creation of local user table. The specific steps are as follows: Upon receiving the configuration protocol request message sent by the first terminal, the configuration protocol request message is forwarded to the central configuration server so that the central configuration server allocates a terminal Internet Protocol address to the first terminal according to the configuration protocol request message; the terminal Internet Protocol address corresponding to the first terminal is received from the central configuration server, and the terminal Ethernet address and terminal network identifier corresponding to the first terminal are obtained. Based on the terminal Internet Protocol address, terminal Ethernet address, and terminal network identifier, a local user table corresponding to the first cloud gateway is created.
[0059] The configuration protocol request message can be understood as a message sent by the first terminal after powering on (or booting up) to request network configuration (the core of which is the terminal's Internet Protocol address). It is a prerequisite for the terminal to obtain a legitimate network address. The configuration protocol request message is equivalent to the DHCP (Dynamic Host Configuration Protocol) request message in the communications field. The configuration protocol request message allows the terminal to obtain a legitimate network configuration, thus providing the basic conditions for accessing the local area network and realizing data communication, ensuring that the terminal can normally access the network and conduct subsequent business interactions. The central configuration server can be understood as a server shared by all cloud gateways across the network, uniformly allocating network configurations to terminals. It is used to receive configuration protocol requests from terminals and allocate Internet Protocol addresses to terminals. The central configuration server is equivalent to the central DHCP server in the communications field.
[0060] In one implementation, when the first cloud gateway receives a configuration protocol request message from the first terminal, it forwards the message to a preset central configuration server. The central configuration server then assigns a dedicated Internet Protocol (IP) address to the first terminal based on the terminal identification information carried in the message. Further, the first cloud gateway receives the IP address from the central configuration server and obtains the corresponding Ethernet address and network identifier of the first terminal through the terminal access interface. Further, it associates and binds the obtained IP address, Ethernet address, and network identifier, creating a local user table for the first cloud gateway according to a preset format. This initial creation of the local user table provides basic data support for subsequent terminal communication, message forwarding, and other operations.
[0061] It should be noted that during the terminal access process, regardless of whether there is one or more connected terminals, all relevant information of all terminals (including terminal IP, corresponding VNI, MAC address, etc.) can be synchronously stored in the local user table. Even if only a single terminal is connected, its IP, MAC, VNI, and other information can be entered into the local user table. If multiple terminals are connected, the relevant information (IP, MAC, VNI, etc.) of each terminal can be entered into the local user table one by one to complete the synchronous storage of multi-terminal information. Regardless of the number of terminals, the complete recording of all connected terminal information in the local user table can be achieved. This ensures that subsequent communication needs for single or multiple terminals can be met by obtaining the corresponding configuration information from the local user table, guaranteeing the accuracy of communication for various terminals. At the same time, it also takes into account traffic isolation requirements, adapts to the overall process of cross-gateway / local communication, and improves the full-scenario storage function of the local user table.
[0062] S220. In the absence of an inter-gateway interconnection tunnel with the second cloud gateway, establish an inter-gateway interconnection tunnel and update the preset interconnection network identifier corresponding to the inter-gateway interconnection tunnel to the updated local user table to obtain the user forwarding table corresponding to the first cloud gateway.
[0063] The inter-gateway interconnection tunnel can be understood as a dedicated communication link established between the first cloud gateway and the second cloud gateway to enable cross-gateway communication. It carries encrypted data packets, isolates public network traffic from internal network traffic, and ensures the security and stability of cross-gateway data transmission. The preset interconnection network identifier (such as a VXLAN identifier) can be understood as a pre-planned and uniquely bound identifier (such as a VXLAN identifier) to the newly established inter-gateway interconnection tunnel. It is used to distinguish the cross-gateway traffic corresponding to this interconnection tunnel and is the core basis for subsequent packet encapsulation and tunnel identification.
[0064] In one implementation, when the first cloud gateway detects that no inter-gateway interconnection tunnel has been established with the second cloud gateway, it can first verify the identity information and communication requirements of the second cloud gateway. After confirming that no additional cross-gateway adaptation conditions are needed, it immediately initiates the process of establishing the inter-gateway interconnection tunnel, building a dedicated cross-gateway communication link. Furthermore, it extracts the preset interconnection network identifier corresponding to the inter-gateway interconnection tunnel and synchronously updates it to the local user table, which has already undergone a preliminary update, thus supplementing and improving the local user table. Further, the updated local user table can be designated as the user forwarding table corresponding to the first cloud gateway. Based on this user forwarding table, it provides complete table entry support and link guarantees for subsequent cross-gateway message transmission and terminal communication, ensuring that cross-gateway communication can be successfully completed.
[0065] S230. Upon receiving an address resolution request message for the second terminal sent by the first terminal, determine the Ethernet address of the terminal corresponding to the second terminal based on the pre-created user forwarding table and the address resolution request message.
[0066] S240. Based on the terminal's Ethernet address, generate a request-response message and send it to the first terminal, so that the first terminal can generate an access request message for the second terminal based on the request-response message.
[0067] S250: Receive an access request message for the second terminal sent by the first terminal. If the first terminal and the second terminal are determined to be communicating across gateways based on the access request message and the user forwarding table, determine the second cloud gateway to which the second terminal belongs. Encapsulate the access request message based on the interconnection network identifier between the first cloud gateway and the second cloud gateway and the terminal network identifier corresponding to the first terminal to obtain an encrypted data packet.
[0068] S260. The encrypted data packet is sent to the second cloud gateway through the inter-gateway interconnection tunnel between the first cloud gateway and the second cloud gateway, so that the second cloud gateway sends the access request message to the second terminal based on the encrypted data packet.
[0069] The technical solution of this disclosure, upon receiving a network protocol routing message sent by a second cloud gateway, determines the gateway configuration information corresponding to the second cloud gateway based on the network protocol routing message, and updates the gateway configuration information to the local user table corresponding to the first cloud gateway, thus obtaining an updated local user table. Furthermore, in the absence of an inter-gateway interconnection tunnel with the second cloud gateway, an inter-gateway interconnection tunnel is established, and the interconnection network identifier corresponding to the inter-gateway interconnection tunnel is updated to the updated local user table to obtain a user forwarding table corresponding to the first cloud gateway. This achieves dynamic synchronization of gateway configuration information and automatic on-demand establishment of interconnection tunnels, ensuring that the user forwarding table can cover the status of all network gateways in real time. This provides accurate and complete data support for cross-gateway communication, effectively improving the automation level of gateway interconnection and the robustness of the communication link.
[0070] Figure 3 This is a schematic diagram of a local area network communication device provided in an embodiment of this disclosure. Figure 3 As shown, the local area network communication device is configured on the first cloud gateway and includes: a first module 310, a second module 320, a third module 330 and a fourth module 340. The first module 310 is used to determine the Ethernet address of the terminal corresponding to the second terminal based on a pre-created user forwarding table and the address resolution request message when receiving an address resolution request message for the second terminal sent by the first terminal; the second module 320 is used to generate a request response message based on the terminal Ethernet address and send it to the first terminal so that the first terminal can generate an access request message for the second terminal based on the request response message; wherein the user forwarding table is used to characterize at least the mapping relationship between the terminal Internet Protocol address, the terminal Ethernet address and the terminal network identifier; the third module 330 is used to receive the access request message for the second terminal sent by the first terminal, and if it is determined that the first terminal and the second terminal are communicating across gateways based on the access request message and the user forwarding table, determine the second cloud gateway to which the second terminal belongs, and encapsulate the access request message based on the interconnection network identifier between the first cloud gateway and the second cloud gateway and the terminal network identifier corresponding to the first terminal to obtain an encrypted data packet; the fourth module 340 is used to send the encrypted data packet to the second cloud gateway through the inter-gateway interconnection tunnel between the first cloud gateway and the second cloud gateway so that the second cloud gateway can send the access request message to the second terminal based on the encrypted data packet.
[0071] The technical solution of this disclosure, upon receiving an address resolution request message for a second terminal from a first terminal, determines the Ethernet address corresponding to the second terminal based on a pre-created user forwarding table and the address resolution request message. This achieves accurate location of the second terminal's Ethernet address, providing an addressing basis for subsequent communication between the first and second terminals and ensuring the normal establishment of the communication link. Furthermore, by generating a request-response message based on the terminal's Ethernet address and sending it to the first terminal, the first terminal generates an access request message for the second terminal based on the request-response message, feeding back the second terminal's Ethernet address to the first terminal, triggering the first terminal to generate its own access request message, and promoting the orderly progress of the communication process. Furthermore, by receiving the access request message for the second terminal sent by the first terminal, and determining, based on the access request message and the user forwarding table, that the first and second terminals are communicating across gateways, the second cloud gateway to which the second terminal belongs is identified. The access request message is then encapsulated using the interconnection network identifier between the first and second cloud gateways and the terminal network identifier corresponding to the first terminal, resulting in an encrypted data packet. This achieves secure encapsulation and accurate identification of the cross-gateway access request message. It distinguishes and isolates cross-gateway traffic using the interconnection network identifier and the terminal network identifier, while also ensuring the security and integrity of the access request message. This lays the foundation for subsequent cross-gateway data transmission, ensuring normal cross-gateway communication between the requesting terminal and the target terminal. Furthermore, by sending the encrypted data packet through the inter-gateway interconnection tunnel between the first and second cloud gateways to the second cloud gateway, the second cloud gateway forwards the access request message to the second terminal based on the encrypted data packet. This ensures the secure and accurate delivery of the access request message to the second cloud gateway, which then forwards it to the target terminal, ultimately achieving stable cross-gateway communication while ensuring the security and isolation of data transmission. The technical solution of this disclosure addresses the problems of excessive public network bandwidth consumption, high latency, insufficient security, and difficulty in adapting to business scenarios involving large-scale home user intranet interconnection in related technologies. It achieves low-latency and high-security transmission of inter-gateway communication in local area networks. Through processes such as address resolution, packet encapsulation, and dedicated tunnel transmission, it ensures stable and secure inter-gateway communication between the requesting terminal and the target terminal. Furthermore, it enables precise management of terminal information and orderly transmission of inter-gateway data, adapting to the needs of large-scale home user intranet interconnection and ensuring the efficiency and security of inter-gateway communication in local area networks.
[0072] In some embodiments of this disclosure, optionally, the first module 310 is specifically used to parse the address resolution request message to obtain the target Internet Protocol address, and determine the target Internet Protocol address as the terminal Internet Protocol address corresponding to the second terminal; and to query the pre-established user forwarding table based on the terminal Internet Protocol address to obtain the terminal Ethernet address corresponding to the second terminal.
[0073] In some embodiments of this disclosure, optionally, the third module 330 includes: a network identifier acquisition unit, an inner encapsulation unit, and an outer encapsulation unit. The network identifier acquisition unit is used to query the user forwarding table based on the source Internet Protocol address in the access request message to obtain the terminal network identifier corresponding to the first terminal and the interconnection network identifier between the first cloud gateway and the second cloud gateway. The inner encapsulation unit is used to perform inner encapsulation on the access request message based on the terminal network identifier to obtain an inner encapsulated data packet. The outer encapsulation unit is used to perform outer encapsulation on the inner encapsulated data packet based on the interconnection network identifier to obtain an encrypted data packet.
[0074] Optionally, in some embodiments of this disclosure, the apparatus further includes: a single-layer encapsulation module, used to encapsulate the access request message in a single layer according to the terminal network identifier corresponding to the first terminal and forward it to the second terminal when it is determined from the access request message and the user forwarding table that the first terminal and the second terminal are communicating within the same gateway.
[0075] In some embodiments of this disclosure, the apparatus optionally further includes: a gateway configuration information determination module and a user forwarding table creation module. The gateway configuration information determination module is used to, upon receiving a network protocol routing message sent by a second cloud gateway, determine the gateway configuration information corresponding to the second cloud gateway based on the network protocol routing message, and update the gateway configuration information in the local user table corresponding to the first cloud gateway to obtain an updated local user table. The user forwarding table creation module is used to, in the absence of an inter-gateway interconnection tunnel with the second cloud gateway, establish an inter-gateway interconnection tunnel, and update the interconnection network identifier corresponding to the inter-gateway interconnection tunnel in the updated local user table to obtain a user forwarding table corresponding to the first cloud gateway.
[0076] In some embodiments of this disclosure, the apparatus may optionally further include: a request message forwarding module and a local user table creation module. The request message forwarding module is configured to, upon receiving a configuration protocol request message from the first terminal, forward the configuration protocol request message to the central configuration server, so that the central configuration server allocates a terminal Internet Protocol address to the first terminal based on the configuration protocol request message. The local user table creation module is configured to receive the terminal Internet Protocol address corresponding to the first terminal from the central configuration server, obtain the terminal Ethernet address and terminal network identifier corresponding to the first terminal, and create a local user table corresponding to the first cloud gateway based on the terminal Internet Protocol address, terminal Ethernet address, and terminal network identifier.
[0077] In some embodiments of this disclosure, the apparatus may optionally further include: a decapsulation module, configured to receive a response data packet returned by the second cloud gateway, sequentially perform outer decapsulation and inner decapsulation on the response data packet, and send the decapsulated response message to the first terminal.
[0078] In some embodiments of this disclosure, optionally, the fourth module 340 is specifically used to determine the inter-gateway interconnection tunnel between the first cloud gateway and the second cloud gateway based on the Internet identifier, and to send the encrypted data packet to the second cloud gateway through the inter-gateway interconnection tunnel.
[0079] The local area network communication device provided in this disclosure can execute the local area network communication method provided in any embodiment of this disclosure, and has the corresponding functional modules and beneficial effects of executing the method.
[0080] It is worth noting that the various units and modules included in the above-mentioned local area network communication device are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the protection scope of the embodiments of this disclosure.
[0081] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. The electronic device 10 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0082] like Figure 4As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 may also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0083] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0084] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as local area network communication methods.
[0085] In some embodiments, the local area network (LAN) communication method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via read-only memory (ROM) 12 and / or communication unit 19. When the computer program is loaded into random access memory (RAM) 13 and executed by processor 11, one or more steps of the LAN communication method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the LAN communication method by any other suitable means (e.g., by means of firmware).
[0086] Various implementations of the systems and techniques described above herein can be implemented in digital circuit systems, integrated circuits, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chips (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0087] Computer programs used to implement the local area network communication methods of this disclosure can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The computer programs can be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0088] This disclosure provides a computer-readable storage medium storing computer instructions for causing a processor to execute a local area network (LAN) communication method, comprising: upon receiving an address resolution request message for a second terminal sent by a first terminal, determining a terminal Ethernet address corresponding to the second terminal based on a pre-created user forwarding table and the address resolution request message; generating a request response message based on the terminal Ethernet address and sending it to the first terminal, so that the first terminal generates an access request message for the second terminal based on the request response message; wherein the user forwarding table is at least used to characterize the terminal Internet Protocol (IP) address, the terminal Ethernet address, and the terminal network. The mapping relationship between identifiers; receiving an access request message for the second terminal sent by the first terminal; if it is determined that the first terminal and the second terminal are communicating across gateways based on the access request message and the user forwarding table, determining the second cloud gateway to which the second terminal belongs; encapsulating the access request message according to the interconnection network identifier between the first cloud gateway and the second cloud gateway and the terminal network identifier corresponding to the first terminal to obtain an encrypted data packet; sending the encrypted data packet to the second cloud gateway through the inter-gateway interconnection tunnel between the first cloud gateway and the second cloud gateway, so that the second cloud gateway sends the access request message to the second terminal based on the encrypted data packet.
[0089] In the context of this disclosure, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM, also known as flash memory), optical fiber, compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0090] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a cathode-ray tube (CRT) or liquid crystal display (LCD) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0091] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0092] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0093] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication unit 19, or installed from storage unit 18, or installed from ROM 12. When the computer program is executed by processor 11, it performs the functions defined in the methods of embodiments of this disclosure.
[0094] This disclosure also provides a computer program product, including a computer program that, when executed by a processor, implements a local area network communication method according to any embodiment of this disclosure.
[0095] In implementing a computer program product, computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof. Programming languages include object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0096] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this disclosure can be achieved, and this is not limited herein.
[0097] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A local area network (LAN) communication method, characterized in that, Applied to the first cloud gateway, including: Upon receiving an address resolution request message for a second terminal sent by a first terminal, the Ethernet address of the terminal corresponding to the second terminal is determined based on a pre-created user forwarding table and the address resolution request message. Based on the terminal's Ethernet address, a request-response message is generated and sent to the first terminal, so that the first terminal generates an access request message for the second terminal based on the request-response message; wherein, the user forwarding table is at least used to characterize the mapping relationship between the terminal's Internet Protocol address, the terminal's Ethernet address and the terminal's network identifier. The system receives an access request message sent by the first terminal to the second terminal. If it is determined that the first terminal and the second terminal are communicating across gateways based on the access request message and the user forwarding table, the system determines the second cloud gateway to which the second terminal belongs. The system encapsulates the access request message based on the interconnection network identifier between the first cloud gateway and the second cloud gateway and the terminal network identifier corresponding to the first terminal to obtain an encrypted data packet. The encrypted data packet is sent to the second cloud gateway through the inter-gateway interconnection tunnel between the first cloud gateway and the second cloud gateway, so that the second cloud gateway sends the access request message to the second terminal based on the encrypted data packet.
2. The local area network communication method according to claim 1, characterized in that, The step of determining the terminal Ethernet address corresponding to the second terminal based on the pre-established user forwarding table and the address resolution request message includes: The address resolution request message is parsed to obtain the target Internet Protocol address, and the target Internet Protocol address is determined as the terminal Internet Protocol address corresponding to the second terminal. The terminal Ethernet address corresponding to the second terminal is obtained by querying a pre-established user forwarding table based on the terminal's Internet Protocol address.
3. The local area network communication method according to claim 1, characterized in that, The process of encapsulating the access request message based on the interconnection network identifier between the first cloud gateway and the second cloud gateway and the terminal network identifier corresponding to the first terminal to obtain an encrypted data packet includes: The user forwarding table is queried based on the source Internet Protocol address in the access request message to obtain the terminal network identifier corresponding to the first terminal and the interconnection network identifier between the first cloud gateway and the second cloud gateway. The access request message is encapsulated using the terminal network identifier to obtain an inner encapsulated data packet; The inner encapsulated data packet is encapsulated with an outer layer based on the Internet identifier to obtain an encrypted data packet.
4. The local area network communication method according to claim 1, characterized in that, Also includes: If it is determined from the access request message and the user forwarding table that the first terminal and the second terminal are communicating within the same gateway, the access request message is encapsulated in a single layer according to the terminal network identifier corresponding to the first terminal and forwarded to the second terminal.
5. The local area network communication method according to claim 1, characterized in that, Also includes: Upon receiving a network protocol routing message sent by the second cloud gateway, the gateway configuration information corresponding to the second cloud gateway is determined according to the network protocol routing message, and the gateway configuration information is updated in the local user table corresponding to the first cloud gateway to obtain the updated local user table. In the absence of an inter-gateway interconnection tunnel with the second cloud gateway, an inter-gateway interconnection tunnel is established, and the interconnection network identifier corresponding to the inter-gateway interconnection tunnel is updated to the updated local user table to obtain the user forwarding table corresponding to the first cloud gateway.
6. The local area network communication method according to claim 5, characterized in that, Also includes: Upon receiving a configuration protocol request message from the first terminal, the configuration protocol request message is forwarded to the central configuration server, so that the central configuration server allocates a terminal Internet Protocol address to the first terminal based on the configuration protocol request message. The system receives the terminal Internet Protocol address corresponding to the first terminal from the central configuration server, obtains the terminal Ethernet address and terminal network identifier corresponding to the first terminal, and creates a local user table corresponding to the first cloud gateway based on the terminal Internet Protocol address, the terminal Ethernet address and the terminal network identifier.
7. The local area network communication method according to claim 1, characterized in that, Also includes: The system receives the response data packet returned by the second cloud gateway, performs outer layer decapsulation and inner layer decapsulation on the response data packet in sequence, and sends the decapsulated response message to the first terminal.
8. The local area network communication method according to claim 1, characterized in that, Sending the encrypted data packet to the second cloud gateway through the inter-gateway interconnection tunnel between the first cloud gateway and the second cloud gateway includes: The inter-gateway interconnection tunnel between the first cloud gateway and the second cloud gateway is determined based on the interconnection network identifier, and the encrypted data packet is sent to the second cloud gateway through the inter-gateway interconnection tunnel.
9. A local area network communication device, characterized in that, Configured on the first cloud gateway, including: The first module is used to determine the Ethernet address of the terminal corresponding to the second terminal based on a pre-created user forwarding table and the address resolution request message when receiving an address resolution request message for the second terminal sent by the first terminal. The second module is used to generate a request-response message based on the terminal's Ethernet address and send it to the first terminal, so that the first terminal generates an access request message for the second terminal based on the request-response message; wherein, the user forwarding table is used to characterize at least the mapping relationship between the terminal's Internet Protocol address, the terminal's Ethernet address and the terminal's network identifier. The third module is used to receive the access request message sent by the first terminal to the second terminal. If it is determined that the first terminal and the second terminal are communicating across gateways based on the access request message and the user forwarding table, the module determines the second cloud gateway to which the second terminal belongs. The module encapsulates the access request message based on the interconnection network identifier between the first cloud gateway and the second cloud gateway and the terminal network identifier corresponding to the first terminal to obtain an encrypted data packet. The fourth module is used to send the encrypted data packet to the second cloud gateway through the inter-gateway interconnection tunnel between the first cloud gateway and the second cloud gateway, so that the second cloud gateway sends the access request message to the second terminal based on the encrypted data packet.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the local area network communication method according to any one of claims 1-8.