Communication connection method and system, and electronic device and computer storage medium

WO2026166377A1PCT designated stage Publication Date: 2026-08-13CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-01-28
Publication Date
2026-08-13

Smart Images

  • Figure CN2026075323_13082026_PF_FP_ABST
    Figure CN2026075323_13082026_PF_FP_ABST
Patent Text Reader

Abstract

The present disclosure relates to a communication connection method and system, and an electronic device and a computer storage medium. The method comprises: sending a domain name resolution request to a domain name resolution server, wherein the domain name resolution request is used for indicating request data, and the request data comprises a user-defined domain name; receiving a domain name resolution response returned by the domain name resolution server, wherein response data carried in the domain name resolution response comprises an access point network address of a first intermediate server, and the access point network address is determined on the basis of the user-defined domain name; and on the basis of the access point network address, establishing a connection between a source server and a destination server. The present disclosure solves the technical problems in the related art of the high operation and maintenance costs and low communication efficiency of a communication connection mode provided in a multi-cloud deployment environment.
Need to check novelty before this filing date? Find Prior Art

Description

Communication connection methods, systems, electronic devices, and computer storage media Technical Field

[0001] This disclosure relates to the field of cloud security technology, and more specifically, to a communication connection method, system, electronic device, and computer storage medium. Background Technology

[0002] With the acceleration of enterprise digital transformation and the popularization of cloud computing technology, multi-cloud strategies have become a common choice for enterprise infrastructure. In multi-cloud deployment scenarios, enterprise users often need to run and manage applications and data in Virtual Private Clouds (VPCs) of different cloud service providers. To ensure the normal operation of network services, each cloud service provider reserves certain specific internal Internet Protocol (IP) network segments, which are not exposed to users, thereby ensuring the isolation and security of cloud services and avoiding network interference between different users or services. However, when enterprise users try to connect their cloud servers from one cloud environment to another, network segment conflicts can occur. To resolve network segment conflicts, proxy servers are commonly used, deploying one or more proxy servers between the enterprise cloud server and the cloud security center to relay communication data. While these technologies can alleviate network segment conflicts to some extent, the additional operational costs they bring limit their widespread application in multi-cloud deployment environments, further leading to low communication efficiency.

[0003] There is currently no effective solution to the above problems. Summary of the Invention

[0004] This disclosure provides a communication connection method, system, electronic device, and computer storage medium to at least solve the technical problems of high operation and maintenance costs and low communication efficiency in the communication connection methods provided by related technologies in multi-cloud deployment environments.

[0005] According to one aspect of the present disclosure, a communication connection method is provided, comprising: sending a domain name resolution request to a domain name resolution server, wherein the domain name resolution request is used to indicate request data, the request data including: a custom domain name; receiving a domain name resolution response returned by the domain name resolution server, wherein the response data carried in the domain name resolution response includes: an access point network address of a first intermediate server, the access point network address being determined based on the custom domain name; and establishing a connection between a source server and a destination server based on the access point network address.

[0006] According to another aspect of the embodiments of this disclosure, a communication connection system is also provided, including: a domain name resolution server, a source server, a first intermediate server, and a destination server; the domain name resolution server is used to receive a domain name resolution request sent by the source server and to return a domain name resolution response, wherein the domain name resolution request is used to indicate request data, the request data includes: a custom domain name, and the response data carried in the domain name resolution response includes: the access point network address of the first intermediate server, the access point network address being determined based on the custom domain name; the source server is used to establish a connection between the source server and the destination server based on the access point network address.

[0007] According to another aspect of the present disclosure, an electronic device is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods in various embodiments of the present disclosure when it runs.

[0008] According to another aspect of the embodiments of the present disclosure, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is executed, it controls the device where the computer-readable storage medium is located to perform the methods of the various embodiments of the present disclosure.

[0009] According to another aspect of the embodiments of this disclosure, a computer program product is also provided, including a computer program that, when executed by a processor, implements the methods of various embodiments of this disclosure.

[0010] According to another aspect of the embodiments of this disclosure, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the methods of various embodiments of this disclosure.

[0011] According to another aspect of the embodiments of this disclosure, a computer program is also provided, which, when executed by a processor, implements the methods of the various embodiments of this disclosure.

[0012] In this embodiment, by sending a domain name resolution request to a domain name resolution server, the request indicates requested data, including a custom domain name. Then, a domain name resolution response is received from the domain name resolution server. This response carries the access point network address of a first intermediate server, determined based on the custom domain name. Finally, a connection is established between the source server and the destination server based on the access point network address. This avoids additional hardware deployment and software maintenance in multi-cloud deployment environments, significantly reducing enterprise operation and maintenance costs. By using a domain name resolution server to resolve the custom domain name, the source server can quickly obtain the access point network address of the first intermediate server and establish a connection between the source server and the destination server using this address. This avoids communication failures or interruptions caused by internal network segment conflicts between the source and destination servers, ensuring the stability and reliability of the communication connection and further improving communication efficiency. Meanwhile, by establishing a connection between the source server and the destination server based on the access point network address, the source servers in different cloud environments can uniformly access the destination server, which can enhance the security monitoring and management capabilities across cloud environments. This solves the technical problems of high operation and maintenance costs and low communication efficiency in the communication connection methods provided by related technologies in multi-cloud deployment environments.

[0013] It is worth noting that the above general description and the following detailed description are merely for illustrative and explanatory purposes and do not constitute a limitation thereof. Attached Figure Description

[0014] The accompanying drawings, which are included to provide a further understanding of this disclosure and form part of this disclosure, illustrate exemplary embodiments of the present disclosure and are used to explain the disclosure, but do not constitute an undue limitation of the disclosure. In the drawings:

[0015] Figure 1 is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a communication connection method according to an embodiment of the present disclosure;

[0016] Figure 2 is a structural block diagram of a computing environment according to an embodiment of the present disclosure;

[0017] Figure 3 is a structural block diagram of a service mesh according to an embodiment of the present disclosure;

[0018] Figure 4 is a flowchart of a communication connection method according to an embodiment of the present disclosure;

[0019] Figure 5 is a schematic diagram of a communication connection system based on related technologies;

[0020] Figure 6 is a schematic diagram of a communication connection system according to an embodiment of the present disclosure;

[0021] Figure 7 is a schematic diagram of a communication connection method according to an embodiment of the present disclosure;

[0022] Figure 8 is a schematic diagram of another communication connection method according to an embodiment of the present disclosure;

[0023] Figure 9 is a structural block diagram of a communication connection device according to an embodiment of the present disclosure;

[0024] Figure 10 is a structural block diagram of an electronic device according to an embodiment of the present disclosure. Detailed Implementation

[0025] To enable those skilled in the art to better understand the present disclosure, the technical solutions of the present disclosure will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present disclosure, and not all embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present disclosure.

[0026] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0027] First, some nouns or terms that appear in the description of the embodiments of this disclosure shall be interpreted as follows:

[0028] Domain Name System (DNS) resolution: DNS is a distributed system that translates domain names into IP addresses. It is an important part of the Internet infrastructure, allowing users to access websites and other network services using easy-to-remember domain names without having to remember complex IP addresses.

[0029] Network segment conflict: This refers to the existence of the same IP address or subnet in two different network environments, which can cause problems in network communication.

[0030] Cloud Security Center: The Cloud Security Center is a server host security management system that identifies, analyzes, and provides early warnings of security threats in real time, helping users protect the security of cloud hosts, local servers, and containers.

[0031] According to embodiments of this disclosure, a communication connection method is provided. It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowcharts, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0032] The method embodiments provided in this disclosure can be executed in a mobile terminal, computer terminal, or similar computing device. Figure 1 shows a hardware structure block diagram of a computer terminal (or mobile device) for implementing a communication connection method. As shown in Figure 1, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b, ..., 102n in the figure) (processor 102 may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a Universal Serial Bus (USB) port (which may be included as one of the ports of a BUS bus), a network interface, a power supply, and / or a camera. Those skilled in the art will understand that the structure shown in Figure 1 is merely illustrative and does not limit the structure of the above-described electronic device. For example, the computer terminal 10 may also include more or fewer components than shown in Figure 1, or have a different configuration than shown in Figure 1.

[0033] It should be noted that the aforementioned one or more processors 102 and / or other data processing circuitry are generally referred to herein as "data processing circuitry". This data processing circuitry may be embodied, in whole or in part, in software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be integrated, in whole or in part, into any other element within the computer terminal 10 (or mobile device). As involved in embodiments of this disclosure, the data processing circuitry serves as a processor control mechanism (e.g., selection of a variable resistor termination path connected to an interface).

[0034] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the method in the embodiments of this disclosure. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby implementing the method in the above embodiments. The memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0035] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0036] The display can be, for example, a touchscreen liquid crystal display (LCD), which allows the user to interact with the user interface of the computer terminal 10 (or mobile device).

[0037] The hardware structure block diagram shown in Figure 1 can serve as an exemplary block diagram not only for the aforementioned computer terminal 10 (or mobile device) but also for the aforementioned server. In an optional embodiment, Figure 2 illustrates a block diagram of using the computer terminal 10 (or mobile device) shown in Figure 1 as a computing node in the computing environment 201. Figure 2 shows a structural block diagram of a computing environment. As shown in Figure 2, the computing environment 201 includes multiple computing nodes (such as servers) running on a distributed network (shown as 210-1, 210-2, ... in the figure). Each computing node contains local processing and memory resources, and the end user 202 can remotely run applications or store data in the computing environment 201. Applications can be provided as multiple services 220-1, 220-2, 220-3, and 220-4 in the computing environment 201, representing services "A", "D", "E", and "H", respectively.

[0038] End user 202 can provide and access services through a web browser or other software application on a client. In some embodiments, the provisioning and / or requests of end user 202 can be provided to ingress gateway 230. Ingress gateway 230 may include a corresponding agent to handle the provisioning and / or requests for services (one or more services provided in computing environment 201).

[0039] The services are provided or deployed based on various virtualization technologies supported by the computing environment 201. In some embodiments, services may be provided based on virtual machine (VM)-based virtualization, container-based virtualization, and / or similar methods. VM-based virtualization can simulate a real computer by initializing a virtual machine, executing programs and applications without directly accessing any actual hardware resources. While the machine is virtualized by a virtual machine, container-based virtualization can launch containers to virtualize an entire operating system (OS), allowing multiple workloads to run on a single OS instance.

[0040] In one embodiment based on container virtualization, several containers of a service can be assembled into a Pod (e.g., a Kubernetes Pod). For example, as shown in Figure 2, service 220-2 can be equipped with one or more Pods 240-1, 240-2, ..., 240-N (collectively referred to as Pods). A Pod can include a proxy 245 and one or more containers 242-1, 242-2, ..., 242-M (collectively referred to as containers). One or more containers in a Pod handle requests related to one or more corresponding functions of the service. The proxy 245 typically controls service-related network functions such as routing and load balancing. Other services can also be equipped with similar Pods.

[0041] During operation, executing a user request from end user 202 may require calling one or more services in computing environment 201, and executing one or more functions of one service may require calling one or more functions of another service. As shown in Figure 2, service "A" 220-1 receives a user request from end user 202 from ingress gateway 230. Service "A" 220-1 can call service "D" 220-2, and service "D" 220-2 can request service "E" 220-3 to execute one or more functions.

[0042] The aforementioned computing environment can be a cloud computing environment, where resource allocation is managed by cloud services, allowing functionality development without needing to consider implementation, adjustment, or server scaling. This computing environment allows developers to execute event-responsive code without building or maintaining complex infrastructure. Services can be partitioned into a set of functions that can automatically and independently scale, rather than scaling a single hardware device to handle potential loads.

[0043] In another alternative embodiment, FIG3 illustrates a block diagram of an example using the computer terminal 10 (or mobile device) shown in FIG1 above as a service mesh. FIG3 shows a structural block diagram of a service mesh 300, which is mainly used to facilitate secure and reliable communication between multiple microservices. Microservices refer to decomposing an application into multiple smaller services or instances and distributing them across different clusters / machines.

[0044] As shown in Figure 3, a microservice may include application service instance A and application service instance B, which together form the functional application layer of service mesh 300. In one implementation, application service instance A runs as a container / process 308 on machine / workload container group 314 (Pod), and application service instance B runs as a container / process 310 on machine / workload container group 316 (Pod).

[0045] In one implementation, application service instance A can be a product query service, and application service instance B can be a product order placement service.

[0046] As shown in Figure 3, application service instance A and grid proxy (sidecar) 303 coexist in machine / workload container group 314, and application service instance B and grid proxy 305 coexist in machine / workload container group 316. Grid proxy 303 and grid proxy 305 form the data plane layer of service mesh 300. Grid proxy 303 and grid proxy 305 run as containers / processes 304 and 306 respectively, and can receive requests 312 for product query services. Grid proxy 303 and application service instance A can communicate bidirectionally, and grid proxy 305 and application service instance B can also communicate bidirectionally. Furthermore, grid proxy 303 and grid proxy 305 can also communicate bidirectionally with each other.

[0047] In one implementation, traffic from application service instance A is routed to the appropriate destination via mesh proxy 303, and network traffic from application service instance B is routed to the appropriate destination via mesh proxy 305. It should be noted that the network traffic mentioned here includes, but is not limited to, Hypertext Transfer Protocol (HTTP), Representational State Transfer (REST), high-performance, general-purpose open-source frameworks (Google Remote Procedure Call, gRPC), and open-source in-memory data structure storage systems (Redis).

[0048] In one implementation, the functionality of the extended data plane layer can be achieved by writing custom filters for the proxy (Envoy) in service mesh 300. The service mesh proxy configuration can enable the service mesh to correctly proxy service traffic, achieving service interoperability and service governance. Mesh proxies 303 and 305 can be configured to perform at least one of the following functions: service discovery, health checking, routing, load balancing, authentication and authorization, and observability.

[0049] As shown in Figure 3, the service mesh 300 also includes a control plane layer. This control plane layer can consist of a set of services running in a dedicated namespace, managed by a managed control plane component 301 within machine / workload container groups (machine / Pods) 302. As shown in Figure 3, the managed control plane component 301 communicates bidirectionally with mesh agents 303 and 305. The managed control plane component 301 is configured to perform control and management functions. For example, it receives telemetry data from mesh agents 303 and 305 and can further aggregate this telemetry data. The managed control plane component 301 can also provide a user-facing Application Programming Interface (API) for these services, facilitating easier manipulation of network behavior and providing configuration data to mesh agents 303 and 305.

[0050] Under the above operating environment, this disclosure provides a communication connection method as shown in Figure 4. Figure 4 is a flowchart of a communication connection method according to an embodiment of this disclosure. As shown in Figure 4, the method includes the following steps:

[0051] Step S41: Send a domain name resolution request to the domain name resolution server, wherein the domain name resolution request is used to indicate the requested data, and the requested data includes: a custom domain name;

[0052] Step S42: Receive the domain name resolution response returned by the domain name resolution server. The response data carried in the domain name resolution response includes: the access point network address of the first intermediate server, which is determined based on the custom domain name.

[0053] Step S43: Establish a connection between the source server and the destination server based on the access point network address.

[0054] The aforementioned domain name resolution request can be sent from the client in the Internet Data Center (IDC) server room to the domain name resolution server, carrying a custom domain name. This custom domain name can be a pre-configured public domain name chosen by the user, or it can be customized by the user. Regardless of whether the user chooses the pre-configured default public domain name or a customized domain name, the core objective is to ensure that the client can correctly find and access the destination server through DNS resolution.

[0055] For example, when users want to deploy quickly or have no special requirements for the domain name, they can choose the default domain name provided by the destination server, thereby simplifying the deployment process. This enables rapid domain name deployment without requiring additional domain name management and maintenance work from the user, and the server can centrally manage domain name resolution and security policies. For instance, the destination server can provide a default, globally available domain name that users can directly use when configuring the client without needing to perform additional DNS configuration.

[0056] For example, users can personalize their domain names when they have brand, service consistency, or specific network policy requirements. For instance, enterprise users may want to use a domain name related to their own brand to access the target server to improve the uniformity and recognizability of their services, further enhance brand recognition, facilitate service integration and management, and better comply with the enterprise user's internal network access control policies.

[0057] For example, when a user personalizes a custom domain name, they typically need to register or select a custom domain name that conforms to DNS naming rules. Then, they configure the DNS resolution server to point the custom domain name to the server address of the destination server. On the destination server's console or other management interface, they configure the relevant access settings to associate the custom domain name with the server's services. When a client accesses the destination server through the custom domain name, the DNS resolution server resolves the custom domain name into an actual IP address or server endpoint, thus establishing a communication connection. For enterprise users with multiple data centers or cloud environments, a unified custom domain name simplifies client configuration and management while ensuring the consistency and security of the enterprise's internal network policies.

[0058] Furthermore, after resolving the custom domain name in the domain name resolution request, the domain name resolution server returns a domain name resolution response to the IDC data center client. This response carries the access point network address of the first intermediate server. This first intermediate server can be a Virtual Private Cloud (VPC) server, acting as a bridge between the client and the server. In a cloud security center scenario, the first intermediate server can be a VPC endpoint node, typically deployed at the edge of the cloud security center, communicating directly with the public network or other cloud environments. This provides protection for the cloud security center, preventing direct external access and helping to isolate traffic from different clients, ensuring secure and private communication. For example, the first intermediate server can also perform preliminary security checks, load balancing, and data preprocessing on incoming traffic, improving the overall performance and security of the cloud security center.

[0059] The aforementioned access point network address is obtained by resolving a custom domain name, and this address points to the first intermediate server. Specifically, the domain name resolution server contains pre-registered Domain Name System (DNS) records for the target server. These records contain the mapping between access point network addresses and custom domain names. When the DNS server receives a domain name resolution request, it can quickly determine the access point network address corresponding to the custom domain name in the request data using these DNS records. After receiving the domain name resolution response, the IDC data center client uses the access point network address carried in the response data to establish communication with the first intermediate server, thereby accessing the cloud security center's services.

[0060] After obtaining the access point network address of the first intermediate server, a connection is established between the source server and the destination server based on the access point network address. The source server can be the server where the client of the cloud security center is located, and the destination server can be the server where the server of the cloud security center is located. The access point network address is used to establish a connection between the client and the server of the cloud security center. During the connection establishment process, the access point network address acts as a crucial bridge, ensuring that the client can access the cloud security center through a stable and secure path. Obtaining the access point network address based on public DNS resolution can effectively avoid network segment conflicts and provide a unified service access method between multi-cloud environments and local networks.

[0061] Based on steps S41 to S43 above, a domain name resolution request is sent to the domain name resolution server. This request indicates the requested data, which includes a custom domain name. The server then receives a domain name resolution response, which includes the access point network address of the first intermediate server, determined based on the custom domain name. Finally, a connection is established between the source server and the destination server based on the access point network address. This avoids additional hardware deployment and software maintenance in multi-cloud deployment environments, significantly reducing enterprise operation and maintenance costs. By using the domain name resolution server to resolve the custom domain name, the source server can quickly obtain the access point network address of the first intermediate server and establish a connection between the source server and the destination server. This avoids communication failures or interruptions caused by internal network segment conflicts between the source and destination servers, ensuring the stability and reliability of the communication connection and further improving communication efficiency. Meanwhile, by establishing a connection between the source server and the destination server based on the access point network address, the source servers in different cloud environments can uniformly access the destination server, which can enhance the security monitoring and management capabilities across cloud environments. This solves the technical problems of high operation and maintenance costs and low communication efficiency in the communication connection methods provided by related technologies in multi-cloud deployment environments.

[0062] The communication connection method in the embodiments of this disclosure will be further described below.

[0063] In one alternative embodiment, the source server is used to deploy the client of the cloud security center, the destination server is used to deploy the server of the cloud security center, and the first intermediate server is equipped with an access point.

[0064] The aforementioned source server can be a server deployed by the user in an IDC data center, other cloud environments, or a local network. The source server must be able to install and run the Cloud Security Center's client software. The Cloud Security Center's client software is responsible for monitoring and collecting security information from the source server, such as system logs, network activity, and security events, and after establishing a connection with the first intermediate server, it uploads the security information to the Cloud Security Center's server.

[0065] The aforementioned destination server can be a core service node of the cloud security center, deployed within the cloud service provider's network. The destination server can receive and process security data uploaded by clients, perform real-time analysis, detect potential risks, and generate security warnings, provide protection recommendations, or implement automated protection measures based on the analysis results.

[0066] The aforementioned first intermediate server is a network node located between the source server and the destination server, enabling clients to establish connections with the cloud security center server. In the cloud security center's architecture, the access point network address of the first intermediate server can be obtained through public DNS resolution of a custom domain name. This access point network address can be used by cloud security center clients to establish communication with the server.

[0067] In a multi-cloud environment, the network segments reserved for internal communication by different cloud service providers may overlap, leading to the inability to achieve direct network communication or conflicts. By obtaining the access point network address of the first intermediate server through public DNS resolution, clients can bypass internal network segments and successfully establish a connection with the cloud security center even if there are conflicts between internal network segments. Regardless of whether the client is located in an IDC data center, other cloud environments, or a local network, it can access the cloud security center server through the same access point network address. This unified access method facilitates the deployment and management of cloud security centers across different environments.

[0068] Based on the above optional embodiments, the architecture design of source server, destination server and first intermediate server, combined with the access method of public network DNS resolution, can significantly improve the security of cloud security center and reduce deployment difficulty, thereby providing users with an efficient and reliable security management service.

[0069] In an optional embodiment, step S43, establishing a connection between the source server and the destination server based on the access point network address, includes:

[0070] Step S431: Based on the access point network address, send a connection request from the source server to the first intermediate server, and transmit the connection request to the destination server via the second intermediate server;

[0071] Step S432: Receive the connection response corresponding to the connection request returned by the destination server;

[0072] Step S433: Determine whether a connection is established between the source server and the destination server based on the connection response.

[0073] The aforementioned second intermediate server is located between the first intermediate server and the destination server. It can be the VPC server of the service provider. Based on the access point network address, it sends a connection request from the source server to the first intermediate server and transmits the connection request to the destination server via the second intermediate server.

[0074] Furthermore, upon receiving the connection request, the destination server will process it accordingly. If the connection request is verified and authorized, the destination server can send a connection response to the second intermediate server, indicating that the connection request has been accepted. After receiving the connection response from the destination server, the second intermediate server will send the response information back to the first intermediate server, which will then forward it to the source server. Upon receiving the connection response, the source server can confirm that the connection with the destination server has been established by parsing the connection response. For example, the security and validity of the connection can be ensured by confirming the status code of the connection response, verifying the encryption key, or other authentication information.

[0075] For example, once a connection is successfully established between the source server and the destination server, the source server can transmit data with the destination server, including but not limited to sending security events, receiving security updates, and executing security policies.

[0076] The aforementioned second intermediate server, as a resource within the cloud environment, can overcome network segment conflicts in multi-cloud environments, establishing a reliable communication bridge between the source server and the destination server. The second intermediate server can act as a unified access point in the second cloud network, handling connection requests from source servers in different cloud environments and then transmitting these requests to the destination server according to preset rules or policies. Through the forwarding by the second intermediate server, the connection establishment process between the source and destination servers can be more secure, stable, and efficient.

[0077] Based on the above optional embodiments, a connection request is sent from the source server to the first intermediate server based on the access point network address, and then transmitted to the destination server via the second intermediate server. Subsequently, the connection response corresponding to the connection request is received from the destination server. Finally, the connection between the source server and the destination server is established based on the connection response. In this way, the connection with the destination server is quickly established through the first and second intermediate servers, without the need to manually set complex network rules or maintain additional proxy servers. This greatly simplifies the client deployment and management process and further improves communication efficiency.

[0078] In one optional embodiment, the source server and the first intermediate server are located in a first cloud network, and the destination server and the second intermediate server are located in a second cloud network, wherein the first cloud network and the second cloud network are different cloud environments.

[0079] The first cloud network can be a user network, and the second cloud network can be a cloud service provider network. The source server can find the access point network address of the first intermediate server through public DNS resolution, and then send a connection request from the source server in the first cloud network to the first intermediate server based on the access point network address. Subsequently, the connection request is transmitted to the destination server through the second intermediate server in the second cloud network. By setting up an intermediate server between the two cloud networks, the obstacle to direct communication between the source server and the destination server can be solved. Even if there is network isolation or network segment conflict between the first cloud network and the second cloud network, the source server can still indirectly access the destination server through the first intermediate server and public DNS resolution, realizing secure data transmission across cloud environments.

[0080] The aforementioned first cloud network and second cloud network are different cloud environments. Different cloud environments can adopt different network architectures and protocols. The deployment of the source server and the first intermediate server in the first cloud network, and the deployment of the destination server and the second intermediate server in the second cloud network, ensures communication compatibility and efficiency within each cloud environment. At the same time, seamless connection between heterogeneous cloud environments is achieved through public DNS resolution and the forwarding mechanism of the first and second intermediate servers.

[0081] For example, in cross-cloud communication, the first and second intermediate servers can also serve as isolation and protection mechanisms. Connection requests from the source server are first received and inspected by the first intermediate server; only legitimate requests are forwarded to the destination server through the second intermediate server. This multi-layered protection mechanism effectively defends against network attacks and malicious traffic, further protecting the core services of the cloud security center.

[0082] In one alternative embodiment, the source server is a physical server or a cloud server, and the first intermediate server, the second intermediate server, and the destination server are all virtual private cloud servers.

[0083] The aforementioned source server can be a physical server, such as a server in an IDC data center, or a cloud server deployed in another cloud service provider's environment. The source server can connect to the first intermediate server of the cloud security center through public DNS resolution. This ensures that regardless of the physical location or cloud environment of the source server, it can access the cloud security center through a standardized process, thereby achieving unified security management across environments.

[0084] The aforementioned first intermediate server, second intermediate server, and destination server are all Virtual Private Cloud (VPNs). VPNs possess network isolation capabilities, providing multi-layered security protection for communication between the source and destination servers. For example, by setting up first and second intermediate servers, security checks, encryption, and access control can be performed during data transmission, further ensuring communication security. Furthermore, using VPNs as an intermediate layer allows bypassing conflicting internal network segments between different cloud environments through public DNS resolution mechanisms, ensuring smooth data flow between the source and destination servers and avoiding communication obstacles caused by network segment conflicts.

[0085] In one alternative embodiment, a connection request is transmitted between the source server and the first intermediate server via a dedicated line route.

[0086] Dedicated lines provide high-speed, stable, and secure data transmission channels, especially in multi-cloud environments, avoiding the latency and security risks of public network transmission. Dedicated lines typically require users to apply for and configure them through the cloud service provider's console. For example, establishing a physical line connection forms the basis of a dedicated line, providing physical isolation and high bandwidth for data transmission. After the physical line is established, virtual interfaces are configured on the network boundaries of the source server and the first intermediate server to achieve connectivity between the two networks. The virtual interfaces can be configured with routing tables, dynamically exchanging routing information through specific communication protocols to ensure that connection information is correctly forwarded to the first intermediate server. Users need to configure routing policies in the network environment where the source server resides, pointing to the virtual interface of the dedicated line. When the source server needs to communicate with the first intermediate server, data packets will be preferentially transmitted through the dedicated line, rather than using the public network or other network paths.

[0087] Using dedicated lines to transmit connection requests between the source server and the first intermediate server provides a higher level of performance and security for cloud security center access in multi-cloud environments. Dedicated lines establish a secure network connection channel between the source server and the first intermediate server, significantly reducing data transmission latency and improving the speed of connection requests and responses. Dedicated lines are also unaffected by network congestion, providing a more stable and reliable network connection, thus ensuring the communication quality between the source server and the first intermediate server.

[0088] In one alternative embodiment, connection requests are transmitted between the first intermediate server and the second intermediate server via a private link.

[0089] Specifically, connection requests are transmitted between the first intermediate server and the second intermediate server via a private link. The private link allows data to be transmitted directly between the two virtual private cloud servers, thereby avoiding the risk of data leakage and providing a more stable and reliable network connection.

[0090] In an optional embodiment, the communication connection method in this disclosure further includes: detecting whether there is a network segment conflict between the first cloud network and the second cloud network; and in response to the existence of a network segment conflict between the first cloud network and the second cloud network, determining to establish a connection between the source server and the destination server based on the access point network address.

[0091] Specifically, network scanning tools can be used to detect whether there are identical or overlapping IP address ranges between the first cloud network and the second cloud network, thereby determining whether there are network segment conflicts between the first cloud network and the second cloud network.

[0092] Whether there is a network segment conflict between the first cloud network and the second cloud network, or no conflict exists between them, a connection can be established between the source server and the destination server based on the access point network address. Even if the first cloud network and the second cloud network share the same internal network segment, the source server can bypass the internal network segment and directly connect to the first intermediate server, and then establish a connection with the destination server via the second intermediate server. This avoids communication restrictions caused by network segment conflicts.

[0093] Based on the above optional embodiments, by detecting whether there is a network segment conflict between the first cloud network and the second cloud network, and then responding to the existence of a network segment conflict between the first cloud network and the second cloud network, a connection is established between the source server and the destination server based on the access point network address. Thus, regardless of whether there is a network conflict between the first cloud network and the second cloud network, a stable, secure, and efficient connection between the source server and the destination server can be ensured based on the access point network address, further improving the communication efficiency in a multi-cloud deployment environment.

[0094] In one optional embodiment, the access point network address and the custom domain name are configured through the front-end control page provided by the destination server. The correspondence between the access point network address and the custom domain name is recorded in the domain name system record, and the domain name system record is filed by the destination server with the domain name resolution server.

[0095] The front-end control page provided by the aforementioned target server can be the management console of the cloud security center. On the front-end control page, users can configure the access point network address and custom domain name. After the user submits the configuration information, the target server can be triggered to register the correspondence between the access point network address and the custom domain name on the domain name resolution server.

[0096] By pre-registering the domain name system records the correspondence between the access point network address and the custom domain name, the source server only needs to resolve the custom domain name through the domain name resolution server to quickly obtain the corresponding access point network address, and then it can quickly connect to the destination server without being limited by the internal network configuration of different cloud environments.

[0097] For example, when registering a domain name in the filing system, the destination server can employ a secure communication protocol to ensure the security of the filing request during transmission. Furthermore, the selection of a custom domain name can also follow certain security strategies, such as using a random string that is difficult to guess, further enhancing the security of the communication process.

[0098] Based on the above optional embodiments, the access point network address and custom domain name can be configured through the front-end control page provided by the destination server, triggering the destination server to file a domain name system record with the domain name resolution server. This can overcome network challenges in a multi-cloud deployment environment and further improve communication efficiency.

[0099] In one optional embodiment, the access point network address is configured through a front-end control page provided by the destination server, the custom domain name corresponding to the access point network address is generated by the destination server, the correspondence between the access point network address and the custom domain name is recorded in the domain name system record, and the domain name system record is filed by the destination server with the domain name resolution server.

[0100] On the front-end control page, users can configure the access point network address and trigger the target server to quickly generate a custom domain name corresponding to the access point network address. The generation process of the custom domain name can be based on preset rules or algorithms of the target server and requires the global uniqueness of the custom domain name to avoid conflicts with domain names of other users or applications. Furthermore, after obtaining the access point network address and the custom domain name, the target server is triggered to register the mapping between the access point network address and the custom domain name with the domain name resolution server.

[0101] Based on the above optional embodiments, the access point network address can be configured through the front-end control page provided by the destination server, triggering the destination server to generate a custom domain name corresponding to the access point network address, and triggering the destination server to file a domain name system record with the domain name resolution server. This can overcome the network challenges in a multi-cloud deployment environment and further improve communication efficiency.

[0102] In an optional embodiment, step S41, sending a domain name resolution request to the domain name resolution server includes:

[0103] The client startup script sends a domain name resolution request to the domain name resolution server. The client startup script is configured with a custom domain name and is used to obtain the client installation package of the cloud security center.

[0104] The aforementioned client startup script is an automated deployment tool, typically used for software installation, configuration, and initialization processes on remote servers or in cloud environments. As a key tool enabling efficient and secure access to cloud security centers, the client startup script sends domain name resolution requests to the domain name resolution server, effectively simplifying the client installation and configuration process.

[0105] For example, the client startup script can include security verification logic, such as using certificates, keys, or API tokens, to ensure that only authorized source servers can access and download the Cloud Security Center client installation package. This can protect Cloud Security Center resources from unauthorized access while ensuring the security of the installation process.

[0106] After a user configures a custom domain name in the Cloud Security Center console, the Cloud Security Center can add this configuration to its client startup script. This allows the user to execute the script on a server within the IDC (Internet Data Center) to install the Cloud Security Center client. Upon successful installation, the client, upon startup, sends a domain name resolution request to the DNS server to obtain the access point network address, thereby connecting to the Cloud Security Center.

[0107] Based on the above optional embodiments, by sending a domain name resolution request to the domain name resolution server based on the client startup script, the automation and security of the cloud security center client deployment can be improved, while further optimizing network connectivity in a multi-cloud deployment environment, further reducing operation and maintenance costs, and improving communication efficiency.

[0108] The communication connection method in the embodiments of this disclosure will be further described below with reference to the accompanying drawings.

[0109] Figure 5 is a schematic diagram of a communication connection system based on related technologies. As shown in Figure 5, the first cloud network contains user assets, and the second cloud network deploys open-source proxies and a management and control center. To resolve network segment conflicts, related technologies typically employ a proxy server approach, deploying one or more open-source proxies between the enterprise management and control center and user assets to relay communication data. The data channel used in this approach is a non-internal IP data segment. While these technologies can alleviate network segment conflicts to some extent, the additional operational costs and limitations of non-standard access methods restrict their widespread application in multi-cloud deployment environments, further leading to low communication efficiency.

[0110] Figure 6 is a schematic diagram of a communication connection system according to an embodiment of the present disclosure. As shown in Figure 6, the source server and the first intermediate server are located in a first cloud network, and the destination server and the second intermediate server are located in a second cloud network. The first cloud network and the second cloud network are different cloud environments. The source server is a physical server or a cloud server. Connection requests are transmitted between the source server and the first intermediate server via a dedicated line route, and connection requests are transmitted between the first intermediate server and the second intermediate server via a private link. A domain name resolution request is sent to a domain name resolution server. The domain name resolution request is used to indicate request data, which includes a custom domain name. A domain name resolution response is received from the domain name resolution server, wherein the response data carried in the domain name resolution response includes the access point network address of the first intermediate server. Based on the access point network address, a connection request is sent from the source server to the first intermediate server, and the connection request is transmitted to the destination server via the second intermediate server. A connection response corresponding to the connection request is received from the destination server, and a connection is established between the source server and the destination server based on the connection response.

[0111] Figure 7 is a schematic diagram of a communication connection method according to an embodiment of the present disclosure. As shown in Figure 7, the method includes the following steps:

[0112] Step S701: Send a domain name resolution request to the domain name resolution server, wherein the domain name resolution request is used to indicate the requested data, and the requested data includes: a custom domain name;

[0113] Step S702: Receive the domain name resolution response returned by the domain name resolution server, wherein the response data carried in the domain name resolution response includes: the access point network address of the first intermediate server;

[0114] Step S703: Send a connection request to the first intermediate server based on the access point network address;

[0115] Step S704: Use the private link to send the connection request from the first intermediate server to the second intermediate server;

[0116] Step S705: The connection request is transmitted to the destination server via the second intermediate server;

[0117] Step S706: Receive the connection response corresponding to the connection request returned by the destination server;

[0118] Step S707: Determine whether a connection is established between the source server and the destination server based on the connection response.

[0119] Based on the above steps, by using a domain name resolution server to resolve the custom domain name, the source server can quickly obtain the access point network address of the first intermediate server. Using this access point network address, a connection is established between the source server and the destination server. This avoids communication failures or interruptions caused by internal network segment conflicts between the source and destination servers, thus ensuring the stability and reliability of the communication connection and further improving communication efficiency. Simultaneously, establishing a connection between the source and destination servers based on the access point network address allows source servers in different cloud environments to uniformly access the destination server, strengthening cross-cloud environment security monitoring and management capabilities.

[0120] Figure 8 is a schematic diagram of another communication connection method according to an embodiment of the present disclosure. As shown in Figure 8, the method includes the following steps:

[0121] Step S801: Configure the access point network address through the front-end control page provided by the destination server;

[0122] Step S802: Obtain the network address of the access point configured by the user;

[0123] Step S803: Generate a custom domain name corresponding to the access point network address;

[0124] Step S804: File the Domain Name System Record with the Domain Name Resolution Server. The Domain Name System Record is used to record the correspondence between the access point network address and the custom domain name.

[0125] Step S805: Return a successful filing message;

[0126] Step S806: Return configuration success message;

[0127] Step S807: Configure the client startup script;

[0128] Step S808: Generate the client startup script based on the custom domain name.

[0129] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation portals are provided for users to choose to authorize or refuse.

[0130] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this disclosure is not limited to the described order of actions, because according to this disclosure, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions and modules involved are not necessarily essential to this disclosure.

[0131] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods according to the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, they can also be implemented by hardware. Based on this understanding, the technical solutions of this disclosure, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this disclosure.

[0132] According to embodiments of this disclosure, a communication connection device for implementing the above-described communication connection method is also provided. FIG9 is a structural block diagram of a communication connection device according to an embodiment of this disclosure. As shown in FIG9, the device includes:

[0133] Sending module 901 is configured to send a domain name resolution request to a domain name resolution server, wherein the domain name resolution request is used to indicate the requested data, and the requested data includes: a custom domain name;

[0134] The receiving module 902 is configured to receive the domain name resolution response returned by the domain name resolution server. The response data carried in the domain name resolution response includes: the access point network address of the first intermediate server, which is determined based on the custom domain name.

[0135] Connection module 903 is configured to establish a connection between the source server and the destination server based on the access point network address.

[0136] Optionally, the source server is used to deploy the client of the cloud security center, the destination server is used to deploy the server of the cloud security center, and the first intermediate server is equipped with an access point.

[0137] Optionally, the connection module 903 is further configured to: send a connection request from the source server to the first intermediate server based on the access point network address, and transmit the connection request to the destination server via the second intermediate server; receive the connection response corresponding to the connection request returned by the destination server; and determine the establishment of a connection between the source server and the destination server based on the connection response.

[0138] Optionally, the source server and the first intermediate server are located in the first cloud network, and the destination server and the second intermediate server are located in the second cloud network, wherein the first cloud network and the second cloud network are different cloud environments.

[0139] Optionally, the source server can be a physical server or a cloud server, and the first intermediate server, the second intermediate server, and the destination server can all be virtual private cloud servers.

[0140] Optionally, a connection request can be transmitted between the source server and the first intermediate server via a dedicated line.

[0141] Optionally, connection requests can be transmitted between the first intermediate server and the second intermediate server via a private link.

[0142] Optionally, the communication connection device further includes: a detection module 904, configured to detect whether there is a network segment conflict between the first cloud network and the second cloud network; and a determination module 905, configured to determine, in response to the existence of a network segment conflict between the first cloud network and the second cloud network, to establish a connection between the source server and the destination server based on the access point network address.

[0143] Optionally, the access point network address and the custom domain name are configured through the front-end control page provided by the destination server. The correspondence between the access point network address and the custom domain name is recorded in the domain name system record, and the domain name system record is filed by the destination server with the domain name resolution server.

[0144] Optionally, the access point network address is configured through the front-end control page provided by the destination server, the custom domain name corresponding to the access point network address is generated by the destination server, the correspondence between the access point network address and the custom domain name is recorded in the domain name system record, and the domain name system record is filed by the destination server with the domain name resolution server.

[0145] Optionally, the sending module 901 is also used to: send a domain name resolution request to the domain name resolution server based on the client startup script, wherein the client startup script is configured with a custom domain name and is used to obtain the client installation package of the cloud security center.

[0146] It should be noted that the sending module 901, receiving module 902, and connection module 903 correspond to steps S41 to S43 in the above embodiments. The three modules and their corresponding steps implement the same instances and application scenarios, but are not limited to the content disclosed in the above embodiments. It should be noted that the above modules or units can be hardware or software components stored in memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b, ..., 102n). The above modules can also be part of a device and run in the computer terminal 10 provided in the above embodiments.

[0147] It should be noted that the preferred embodiments involved in the above embodiments of this disclosure are the same as the solutions, application scenarios and implementation processes provided in the above embodiments, but are not limited to the solutions provided in the above embodiments.

[0148] Embodiments of this disclosure can provide a communication connection system, including: a domain name resolution server, a source server, a first intermediate server, and a destination server; the domain name resolution server is used to receive a domain name resolution request sent by the source server and return a domain name resolution response, wherein the domain name resolution request is used to indicate request data, the request data includes: a custom domain name, and the response data carried in the domain name resolution response includes: the access point network address of the first intermediate server, the access point network address being determined based on the custom domain name; the source server is used to establish a connection between the source server and the destination server based on the access point network address.

[0149] Embodiments of this disclosure can provide an electronic device, which can be any one of a group of electronic devices. Optionally, in this embodiment, the aforementioned electronic device can also be replaced with a terminal device such as a mobile terminal.

[0150] Optionally, in this embodiment, the aforementioned electronic device may be located in at least one of a plurality of network devices in a computer network.

[0151] In this embodiment, the computer terminal described above can execute the program code in the method.

[0152] Optionally, FIG10 is a structural block diagram of an electronic device according to an embodiment of the present disclosure. As shown in FIG10, the electronic device may include: one or more (only one is shown in the figure) processors 102, memory 104, memory controller, and peripheral interfaces, wherein the peripheral interfaces are connected to a radio frequency module, an audio module, and a display.

[0153] The memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the methods and apparatus in the embodiments of this disclosure. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, thereby implementing the methods in the above embodiments. The memory may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0154] The processor can invoke information and applications stored in memory via a transmission device to perform the following steps: sending a domain name resolution request to a domain name resolution server, wherein the domain name resolution request is used to indicate requested data, and the requested data includes: a custom domain name; receiving a domain name resolution response returned by the domain name resolution server, wherein the response data carried in the domain name resolution response includes: the access point network address of a first intermediate server, the access point network address being determined based on the custom domain name; and establishing a connection between the source server and the destination server based on the access point network address.

[0155] Optionally, the source server is used to deploy the client of the cloud security center, the destination server is used to deploy the server of the cloud security center, and the first intermediate server is equipped with an access point.

[0156] Optionally, the processor may also execute program code that performs the following steps: sending a connection request from the source server to the first intermediate server based on the access point network address, and transmitting the connection request to the destination server via the second intermediate server; receiving the connection response corresponding to the connection request returned by the destination server; and determining the establishment of a connection between the source server and the destination server based on the connection response.

[0157] Optionally, the source server and the first intermediate server are located in the first cloud network, and the destination server and the second intermediate server are located in the second cloud network, wherein the first cloud network and the second cloud network are different cloud environments.

[0158] Optionally, the source server can be a physical server or a cloud server, and the first intermediate server, the second intermediate server, and the destination server can all be virtual private cloud servers.

[0159] Optionally, a connection request can be transmitted between the source server and the first intermediate server via a dedicated line.

[0160] Optionally, connection requests can be transmitted between the first intermediate server and the second intermediate server via a private link.

[0161] Optionally, the processor may also execute program code that performs the following steps: detects whether there is a network segment conflict between the first cloud network and the second cloud network; and in response to the existence of a network segment conflict between the first cloud network and the second cloud network, determines to establish a connection between the source server and the destination server based on the access point network address.

[0162] Optionally, the processor may also execute program code that performs the following steps: the access point network address and the custom domain name are configured through the front-end control page provided by the destination server, the correspondence between the access point network address and the custom domain name is recorded in the domain name system record, and the domain name system record is filed by the destination server with the domain name resolution server.

[0163] Optionally, the processor may also execute program code that performs the following steps: the access point network address is configured through the front-end control page provided by the destination server, the custom domain name corresponding to the access point network address is generated by the destination server, the correspondence between the access point network address and the custom domain name is recorded in the domain name system record, and the domain name system record is filed by the destination server with the domain name resolution server.

[0164] Optionally, the processor may also execute program code that performs the following steps: sending a domain name resolution request to a domain name resolution server based on a client startup script, wherein the client startup script is configured with a custom domain name and is used to obtain the client installation package of the cloud security center.

[0165] By employing the embodiments of this disclosure, a domain name resolution request is sent to a domain name resolution server. This request indicates requested data, including a custom domain name. The server then receives a domain name resolution response, which includes the access point network address of a first intermediate server, determined based on the custom domain name. Finally, a connection is established between the source server and the destination server based on the access point network address. This avoids additional hardware deployment and software maintenance in multi-cloud deployment environments, significantly reducing enterprise operational costs. By using a domain name resolution server to resolve the custom domain name, the source server can quickly obtain the access point network address of the first intermediate server and establish a connection between the source server and the destination server. This avoids communication failures or interruptions caused by internal network segment conflicts between the source and destination servers, ensuring the stability and reliability of the communication connection and further improving communication efficiency. Meanwhile, by establishing a connection between the source server and the destination server based on the access point network address, the source servers in different cloud environments can uniformly access the destination server, which can enhance the security monitoring and management capabilities across cloud environments. This solves the technical problems of high operation and maintenance costs and low communication efficiency in the communication connection methods provided by related technologies in multi-cloud deployment environments.

[0166] It will be understood by those skilled in the art that the structure shown in the figure is merely illustrative, and the electronic device may also be a smartphone, tablet computer, PDA, mobile internet device (MID), PAD, or other terminal device. This figure does not limit the structure of the aforementioned electronic device. For example, the electronic device may include more or fewer components (such as network interfaces, display devices, etc.) than shown in the figure, or may have a different configuration than that shown in the figure.

[0167] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, which may include: flash drive, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc.

[0168] Embodiments of this disclosure also provide a computer-readable storage medium. Optionally, in this embodiment, the computer-readable storage medium can be used to store program code executed by the method provided in the above embodiments.

[0169] Optionally, in this embodiment, the storage medium may be located in any one of the electronic devices in the group of electronic devices in the computer network, or in any one of the mobile terminals in the group of mobile terminals.

[0170] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: sending a domain name resolution request to a domain name resolution server, wherein the domain name resolution request is used to indicate request data, the request data including: a custom domain name; receiving a domain name resolution response returned by the domain name resolution server, wherein the response data carried in the domain name resolution response includes: the access point network address of a first intermediate server, the access point network address being determined based on the custom domain name; and establishing a connection between the source server and the destination server based on the access point network address.

[0171] Optionally, the source server is used to deploy the client of the cloud security center, the destination server is used to deploy the server of the cloud security center, and the first intermediate server is equipped with an access point.

[0172] Optionally, the computer-readable storage medium is further configured to store program code for performing the following steps: sending a connection request from the source server to a first intermediate server based on the access point network address, and transmitting the connection request to the destination server via a second intermediate server; receiving a connection response corresponding to the connection request returned by the destination server; and determining, based on the connection response, that a connection is established between the source server and the destination server.

[0173] Optionally, the source server and the first intermediate server are located in the first cloud network, and the destination server and the second intermediate server are located in the second cloud network, wherein the first cloud network and the second cloud network are different cloud environments.

[0174] Optionally, the source server can be a physical server or a cloud server, and the first intermediate server, the second intermediate server, and the destination server can all be virtual private cloud servers.

[0175] Optionally, a connection request can be transmitted between the source server and the first intermediate server via a dedicated line.

[0176] Optionally, connection requests can be transmitted between the first intermediate server and the second intermediate server via a private link.

[0177] Optionally, the computer-readable storage medium is also configured to store program code for performing the following steps: detecting whether there is a network segment conflict between the first cloud network and the second cloud network; and in response to the existence of a network segment conflict between the first cloud network and the second cloud network, determining to establish a connection between the source server and the destination server based on the access point network address.

[0178] Optionally, the computer-readable storage medium is also configured to store program code for performing the following steps: the access point network address and the custom domain name are configured through a front-end control page provided by the destination server, the correspondence between the access point network address and the custom domain name is recorded in the domain name system record, and the domain name system record is filed by the destination server with the domain name resolution server.

[0179] Optionally, the computer-readable storage medium is also configured to store program code for performing the following steps: the access point network address is configured through a front-end control page provided by the destination server, the custom domain name corresponding to the access point network address is generated by the destination server, the correspondence between the access point network address and the custom domain name is recorded in the domain name system record, and the domain name system record is filed by the destination server with the domain name resolution server.

[0180] Optionally, the computer-readable storage medium is also configured to store program code for performing the following steps: sending a domain name resolution request to a domain name resolution server based on a client startup script, wherein the client startup script is configured with a custom domain name and is used to obtain the client installation package of the cloud security center.

[0181] By employing the embodiments of this disclosure, a domain name resolution request is sent to a domain name resolution server. This request indicates requested data, including a custom domain name. The server then receives a domain name resolution response, which includes the access point network address of a first intermediate server, determined based on the custom domain name. Finally, a connection is established between the source server and the destination server based on the access point network address. This avoids additional hardware deployment and software maintenance in multi-cloud deployment environments, significantly reducing enterprise operational costs. By using a domain name resolution server to resolve the custom domain name, the source server can quickly obtain the access point network address of the first intermediate server and establish a connection between the source server and the destination server. This avoids communication failures or interruptions caused by internal network segment conflicts between the source and destination servers, ensuring the stability and reliability of the communication connection and further improving communication efficiency. Meanwhile, by establishing a connection between the source server and the destination server based on the access point network address, the source servers in different cloud environments can uniformly access the destination server, which can enhance the security monitoring and management capabilities across cloud environments. This solves the technical problems of high operation and maintenance costs and low communication efficiency in the communication connection methods provided by related technologies in multi-cloud deployment environments.

[0182] Embodiments of this disclosure also provide a computer program product. Optionally, in this embodiment, the computer program product may include a computer program that, when executed by a processor, implements the methods provided in the embodiments described above.

[0183] Embodiments of this disclosure also provide a computer program product. Optionally, the computer program product may include a non-volatile computer-readable storage medium, which can be used to store a computer program that, when executed by a processor, implements the methods provided in the embodiments described above.

[0184] Embodiments of this disclosure also provide a computer program. Optionally, in this embodiment, when the computer program is executed by a processor, it implements the method provided in the above embodiments.

[0185] In the above embodiments of this disclosure, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0186] In the several embodiments provided in this disclosure, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.

[0187] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0188] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0189] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0190] The above description is only a preferred embodiment of this disclosure. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principles of this disclosure, and these improvements and modifications should also be considered within the scope of protection of this disclosure.

Claims

1. A communication connection method, comprising: Send a domain name resolution request to a domain name resolution server, wherein the domain name resolution request is used to indicate request data, and the request data includes: a custom domain name; Receive the domain name resolution response returned by the domain name resolution server, wherein the response data carried in the domain name resolution response includes: the access point network address of the first intermediate server, the access point network address being determined based on the custom domain name; A connection is established between the source server and the destination server based on the access point network address.

2. The communication connection method according to claim 1, wherein, The source server is used to deploy the client of the cloud security center, the destination server is used to deploy the server of the cloud security center, and the first intermediate server is equipped with an access point.

3. The communication connection method according to claim 1, wherein, Establishing a connection between the source server and the destination server based on the access point network address includes: Based on the access point network address, a connection request is sent from the source server to the first intermediate server, and then transmitted to the destination server via the second intermediate server. Receive the connection response corresponding to the connection request returned by the destination server; Based on the connection response, a connection is established between the source server and the destination server.

4. The communication connection method according to claim 3, wherein, The source server and the first intermediate server are located in a first cloud network, and the destination server and the second intermediate server are located in a second cloud network, wherein the first cloud network and the second cloud network are different cloud environments.

5. The communication connection method according to claim 4, wherein, The source server is a physical server or a cloud server, and the first intermediate server, the second intermediate server, and the destination server are all virtual private cloud servers.

6. The communication connection method according to claim 3, wherein, The connection request is transmitted between the source server and the first intermediate server via a dedicated line route.

7. The communication connection method according to claim 5, wherein, The connection request is transmitted between the first intermediate server and the second intermediate server via a private link.

8. The communication connection method according to claim 4, wherein, The communication connection method further includes: Detect whether there is a network segment conflict between the first cloud network and the second cloud network; In response to a network segment conflict between the first cloud network and the second cloud network, a connection is established between the source server and the destination server based on the access point network address.

9. The communication connection method according to claim 4, wherein, The access point network address and the custom domain name are configured through the front-end control page provided by the destination server. The correspondence between the access point network address and the custom domain name is recorded in the domain name system record. The domain name system record is filed by the destination server with the domain name resolution server.

10. The communication connection method according to claim 4, wherein, The access point network address is configured through the front-end control page provided by the destination server. The custom domain name corresponding to the access point network address is generated by the destination server. The correspondence between the access point network address and the custom domain name is recorded in the domain name system record. The domain name system record is filed by the destination server with the domain name resolution server.

11. The communication connection method according to claim 2, wherein, Sending the domain name resolution request to the domain name resolution server includes: The client startup script sends the domain name resolution request to the domain name resolution server. The client startup script is configured with the custom domain name and is used to obtain the client installation package of the cloud security center.

12. The communication connection method according to claim 2, wherein, The client software of the cloud security center is used to monitor and collect security information of the source server, and to upload the security information to the server of the cloud security center. The security information includes one of the following: system logs, network activities, and security events.

13. The communication connection method according to claim 3, wherein, The communication connection method further includes: In response to a successful connection being established between the source server and the destination server, at least one of the following data is transmitted between the source server and the destination server: security event data, security update data, and security policy data.

14. The communication connection method according to claim 4, wherein, The first cloud network and the second cloud network are different cloud environments, and different cloud environments use different network architectures and protocols.

15. The communication connection method according to claim 14, wherein, The first cloud network is the user network, and the second cloud network is the cloud service provider network.

16. The communication connection method according to claim 5, wherein, The first intermediate server and the second intermediate server are used to perform security checks, encryption processing and access control during data transmission.

17. The communication connection method according to claim 8, wherein, Detecting whether there is a network segment conflict between the first cloud network and the second cloud network includes: By using network scanning tools to detect whether there are identical or overlapping Internet Protocol address ranges between the first cloud network and the second cloud network, it can be determined whether there is a network segment conflict between the first cloud network and the second cloud network.

18. A communication connection system, comprising: Domain name resolution server, source server, first intermediate server, and destination server; The domain name resolution server is used to receive the domain name resolution request sent by the source server and return the domain name resolution response. The domain name resolution request is used to indicate request data, and the request data includes a custom domain name. The response data carried in the domain name resolution response includes the access point network address of the first intermediate server, and the access point network address is determined based on the custom domain name. The source server is used to establish a connection between the source server and the destination server based on the access point network address.

19. An electronic device comprising: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the communication connection method according to any one of claims 1 to 17.

20. A computer-readable storage medium comprising a stored executable program, wherein, When the executable program is executed, it controls the device containing the storage medium to perform the communication connection method according to any one of claims 1 to 17.