Data transmission methods and apparatus, device, and storage medium
Patent Information
- Application Number
- PCT/CN2026/078551
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-03-17
- Filing Date
- 2026-02-11
- Publication Date
- 2026-09-24
Smart Images

Figure CN2026078551_24092026_PF_FP_ABST
Abstract
Description
Data transmission methods, apparatus, equipment and storage media
[0001] This application claims priority to Chinese Patent Application No. 202510315880X, filed on March 17, 2025, entitled “Data Transmission Method, Apparatus, Device and Storage Medium”, the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of Internet technology, specifically to the field of cloud technology, and in particular to a data transmission method, apparatus, device, and storage medium. Background Technology
[0003] With the development of cloud technology, cloud-local dedicated clusters have been widely used. The so-called cloud-local dedicated cluster is not only a distributed cloud product, but also a fully managed infrastructure cloud product. By deploying public cloud computing, storage, network and other resources in the customer's local data center in a hardware and software integrated manner, it meets the customer's business needs for business data security and low transmission latency.
[0004] As a cloud product in a distributed cloud environment, the cloud-local dedicated cluster needs to be deployed in a customer-designated local data center. The management service of the cloud-local dedicated cluster shares a common set with the central cloud management service (located in the cloud central area) in the public cloud region. When performing management operations (such as producing virtual sub-machines), there will inevitably be communication between the cloud-local dedicated cluster and the cloud central area in the public cloud region. For cloud vendors, allowing the cloud-local dedicated cluster deployed in the customer's data center to directly access the cloud central area (i.e., directly sending data packets to a management service in the cloud central area) poses a certain security risk. This would make it easy for attackers to breach the network defenses between the cloud-local dedicated cluster and the cloud central area. Once this network defense is breached, it could have catastrophic consequences for the entire central cloud environment.
[0005] Therefore, how to realize data transmission between cloud-local dedicated clusters and management services in public cloud regions, and improve the security of the central cloud environment where the management services are located, has become a current research hotspot. Summary of the Invention
[0006] This application provides a data transmission method, apparatus, device, and storage medium that enables data transmission between cloud-local dedicated clusters and management services in public cloud regions, and improves the security of the central cloud environment where the management services reside.
[0007] On one hand, this application provides a data transmission method, which is applied to a first virtual private network gateway on the cloud-local dedicated cluster side, wherein a virtual private network service channel exists between the first virtual private network gateway and a second virtual private network gateway on the public cloud region side, and the method includes:
[0008] Receive the first data packet sent by the cloud local dedicated cluster, wherein the destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service in the public cloud region;
[0009] Obtain the virtual Internet Protocol address of the target management service, which is obtained by mapping the real Internet Protocol address of the target management service;
[0010] The destination Internet Protocol address of the first data packet is modified to the virtual Internet Protocol address to obtain the second data packet;
[0011] The second data packet is sent to the second virtual private network gateway through the virtual private network service channel, so that the second virtual private network gateway modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtains the first data packet, and sends the first data packet to the target management service.
[0012] On the other hand, this application provides a data transmission method applied to a second virtual private network gateway on the public cloud regional side, wherein a virtual private network service channel exists between the second virtual private network gateway and a first virtual private network gateway on the cloud-local dedicated cluster side, and the method includes:
[0013] The second data packet sent by the first virtual private network gateway is received through the virtual private network service channel. The second data packet is obtained by modifying the destination Internet Protocol address of the first data packet to the virtual Internet Protocol address of the target management service in the public cloud region. The virtual Internet Protocol address is obtained by mapping the real Internet Protocol address of the target management service. The destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service.
[0014] The destination Internet Protocol address of the second data packet is modified to the real Internet Protocol address of the target management service to obtain the first data packet, and the first data packet is sent to the target management service.
[0015] In another aspect, embodiments of this application provide a data transmission apparatus, which is applied to a first virtual private network gateway on the cloud-local dedicated cluster side. A virtual private network service channel exists between the first virtual private network gateway and a second virtual private network gateway on the public cloud region side. The apparatus includes:
[0016] The first transmission unit is used to receive the first data packet sent by the cloud local dedicated cluster, wherein the destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service in the public cloud region.
[0017] The first processing unit is used to obtain the virtual Internet Protocol address of the target management service, wherein the virtual Internet Protocol address is obtained by mapping the real Internet Protocol address of the target management service.
[0018] The first processing unit is further configured to modify the destination Internet Protocol address of the first data packet to the virtual Internet Protocol address to obtain the second data packet;
[0019] The first transmission unit is further configured to send the second data packet to the second virtual private network gateway through the virtual private network service channel, so that the second virtual private network gateway modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtains the first data packet, and sends the first data packet to the target management service.
[0020] In another aspect, embodiments of this application provide a data transmission device, characterized in that the device is applied to a second virtual private network gateway on the public cloud regional side, and a virtual private network service channel exists between the second virtual private network gateway and a first virtual private network gateway on the cloud local dedicated cluster side, the device comprising:
[0021] The second transmission unit is used to receive a second data packet sent by the first virtual private network gateway through the virtual private network service channel. The second data packet is obtained by modifying the destination Internet Protocol address of the first data packet to the virtual Internet Protocol address of the target management service in the public cloud region. The virtual Internet Protocol address is obtained by mapping the real Internet Protocol address of the target management service. The destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service.
[0022] The second processing unit is configured to modify the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtain the first data packet, and send the first data packet to the target management service.
[0023] In another aspect, embodiments of this application provide a computer device, the computer device including an input interface and an output interface, the computer device further including:
[0024] Processor and computer storage media;
[0025] The processor is adapted to implement one or more instructions, the computer storage medium stores one or more instructions, and the one or more instructions are adapted to be loaded by the processor and executed by any of the aforementioned data transmission methods.
[0026] In another aspect, embodiments of this application provide a computer storage medium storing one or more instructions, which are adapted to be loaded by a processor and executed by any of the aforementioned data transmission methods.
[0027] In another aspect, embodiments of this application provide a computer program product comprising one or more instructions; when one or more instructions in the computer program product are executed by a processor, they implement any of the data transmission methods mentioned above.
[0028] This application embodiment deploys a first virtual private network (VPN) gateway on the cloud-local dedicated cluster side and a second VPN gateway on the public cloud region side, establishing a VPN service channel between the first and second VPN gateways. This allows the first VPN gateway to receive a first data packet sent by the cloud-local dedicated cluster, modify the destination Internet Protocol (IP) address of the first data packet to a virtual IP address obtained by mapping the real IP address of the target management service, and obtain a second data packet. The second data packet is then sent to the second VPN gateway on the public cloud region side via the VPN service channel. This avoids directly exposing the real IP address of the target management service during data transmission between the cloud-local dedicated cluster and the public cloud region, thus preventing attackers from breaching the network defenses between the cloud-local dedicated cluster and the cloud central area based on the real IP address of the target management service, thereby improving the security of the central cloud environment where the target management service resides. Furthermore, after receiving the second data packet, the second virtual private network gateway can modify the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service to obtain the first data packet, and then send the first data packet to the target management service. This enables the first data packet to be successfully transmitted from the cloud-local dedicated cluster to the target management service in the public cloud region, thereby improving the security of data transmission. Attached Figure Description
[0029] Figure 1a is a schematic diagram of a data transmission system provided in an embodiment of this application;
[0030] Figure 1b is a schematic diagram illustrating the implementation logic of a data transmission method provided in an embodiment of this application;
[0031] Figure 1c is a schematic diagram of another data transmission system provided in an embodiment of this application;
[0032] Figure 1d is a schematic diagram illustrating the implementation logic of another data transmission method provided in an embodiment of this application;
[0033] Figure 2a is a schematic diagram of a data transmission system provided in another embodiment of this application;
[0034] Figure 2b is a schematic diagram illustrating the implementation logic of a data transmission method according to another embodiment of this application;
[0035] Figure 2c is a schematic diagram of another data transmission system provided in another embodiment of this application;
[0036] Figure 2d is a schematic diagram illustrating the implementation logic of another data transmission method provided in another embodiment of this application;
[0037] Figure 3 is a flowchart illustrating a data transmission method provided in an embodiment of this application;
[0038] Figure 4 is a schematic diagram of a first virtual private gateway address mapping generation strategy provided in an embodiment of this application;
[0039] Figure 5a is a schematic diagram of a return packet access link provided in an embodiment of this application;
[0040] Figure 5b is a schematic diagram of another packet return access link provided in an embodiment of this application;
[0041] Figure 6a is a system architecture diagram of a cloud-local dedicated cluster and a public cloud region in a distributed cloud scenario provided by an embodiment of this application;
[0042] Figure 6b is a schematic diagram of uplink access to a service mapping architecture provided in an embodiment of this application;
[0043] Figure 6c is a schematic diagram of a NAT front-end operation interface provided in an embodiment of this application;
[0044] Figure 6d is a schematic diagram of a configuration window provided in an embodiment of this application;
[0045] Figure 6e is a schematic diagram of a terminal interface provided in an embodiment of this application;
[0046] Figure 6f is a schematic diagram of another NAT front-end operation interface provided in an embodiment of this application;
[0047] Figure 7 is a logical schematic diagram of a distributed cloud backend implementation provided in an embodiment of this application;
[0048] Figure 8a is a schematic diagram of a data transmission device provided in an embodiment of this application;
[0049] Figure 8b is a schematic diagram of another data transmission device provided in an embodiment of this application;
[0050] Figure 9 is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0051] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0052] This application proposes a data transmission method. This method involves deploying a first virtual private network gateway on the cloud-local dedicated cluster side and a second virtual private network gateway on the public cloud region side, and establishing a virtual private network service channel between the first and second virtual private network gateways. This allows for the smooth establishment of an access link between the cloud-local dedicated cluster and the cloud central area of the public cloud region. Based on this established access link, data transmission between the management services in the cloud-local dedicated cluster and the cloud central area of the public cloud region can be achieved. During data transmission, the security of the central cloud environment where the management services reside is improved by using NAT (Network Address Translation) service.
[0053] To better understand the data transmission method proposed in the embodiments of this application, the relevant concepts involved in the embodiments of this application will be introduced below:
[0054] (I) Cloud-local dedicated cluster
[0055] A cloud-local dedicated cluster is both a distributed cloud product and a fully managed infrastructure cloud product. It deploys public cloud computing, storage, network and other resources in a hardware and software integrated manner in the customer's local data center, and can interconnect internally with the customer's IDC (Internet Data Center) in the customer's local data center, thereby meeting the customer's business needs for business data security and low latency transmission. For example, this cloud-local dedicated cluster can be a cloud-dedicated cluster (CDC) for an enterprise.
[0056] From a device perspective, a cloud-native dedicated cluster can be understood as a cluster of devices deployed in the customer's local data center. This cluster can include one or more (i.e., at least two) hosts. A host refers to a physical device (such as a server) that contains public cloud computing, storage, network, and other resource facilities. Based on these resource facilities, it can provide customers with various types of cloud services locally, such as cloud virtual machines (CVM), cloud block storage (CBS), cloud object storage (COS), container services (such as TKE), databases, big data (ElasticSearch), and so on.
[0057] Understandably, in addition to deploying local computing power in the customer's local data center through an integrated rack, cloud-local dedicated clusters can also connect resources to public cloud regions for unified management.
[0058] (II) Public Cloud Regions
[0059] A public cloud region refers to the physical area where a public cloud data center is located. It can be divided according to the city where the data center is located. For example, if a public cloud has a data center in city A, then city A can be considered a public cloud region. Public cloud typically refers to a cloud service provided by a third-party provider to users. It is generally accessible via the internet and may be free or low-cost. The core attribute of a public cloud is shared resource service.
[0060] A public cloud region may include at least one management service. These management services may be located in the cloud central area of the public cloud and used to manage the resources of the cloud-local dedicated cluster. The cloud central area of the public cloud mentioned here may also be called the central cloud management area, which can be an area in the public cloud region used to store management services. It may contain one or more physical devices (such as servers). For example, the management services mentioned in the embodiments of this application may include, but are not limited to: CBS management service, TGW (gateway) management service, etc. Each management service may have a real Internet Protocol (IP) address. It can be understood that the management service can essentially be understood as a program running on a physical device (such as a server), and the real Internet Protocol address of the management service refers to the real Internet Protocol address of the physical device running the management service. The so-called real Internet Protocol address refers to an Internet Protocol address that can be successfully accessed (i.e., successfully send and receive data).
[0061] (III) Virtual Private Network Gateway
[0062] A Virtual Private Network (VPN) gateway, also known as a VPN gateway, is a product that enables interconnection between different networks using VPN (Virtual Private Network) technology. It is primarily used to establish secure, encrypted channels to ensure the security of data transmission over public networks. In specific implementations, a VPN gateway can be implemented through servers, hardware, software, and other methods; that is, the VPN gateway mentioned in this application's embodiments can be a server, or a hardware or software module located within a server, without limitation. Furthermore, the server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms, etc.
[0063] (iv) NAT service
[0064] NAT (Network Address Translation) is a service that translates Internet Protocol (IP) addresses. It primarily uses two modes: Source Network Address Translation (SNAT) and Destination Network Address Translation (DNAT). Source NAT replaces the source IP address of a data packet with another IP address, while Destination NAT replaces the destination IP address of a data packet with another IP address. The source IP address refers to the IP address of the device sending the data packet, and the destination IP address refers to the IP address of the device receiving the data packet. For example, if a data packet needs to be transmitted from device A to device B, then device A is the sending device, and device B is the receiving device. Therefore, the source IP address of this data packet is the IP address of device A, and the destination IP address is the IP address of device B.
[0065] Based on the above conceptual introduction, the data transmission method proposed in the embodiments of this application is described below:
[0066] In one embodiment, the data transmission method proposed in this application proposes a data transmission system as shown in Figure 1a. Referring to Figure 1a, the data transmission system may include two parts: a customer site and a public cloud region. The customer site may include a customer data center (IDC), a cloud-local dedicated cluster, and a first virtual private network (VPN) gateway. Each host in the cloud-local dedicated cluster may deploy a NAT (Network Address Translation) service. The public cloud region may include at least a cloud central area (or a central cloud management area) and a second VPN gateway. The cloud central area may include at least one management service.
[0067] In the data transmission system shown in Figure 1a, the specific implementation logic of the data transmission method proposed in this application embodiment can be seen in Figure 1b, which roughly includes the following steps s11-s16:
[0068] s11, The host in the cloud local dedicated cluster can generate the first data packet. The first data packet is the data packet to be sent to the target management service in the public cloud region. The source IP address of the first data packet is the real IP address of the cloud local dedicated cluster, and the destination IP address of the first data packet is the real IP address of the target management service.
[0069] In s12, a host in a cloud-local dedicated cluster can invoke the NAT service to translate the destination IP address of the first data packet, obtaining the second data packet. Specifically, the NAT service can use DNAT mode to determine the virtual IP address obtained by mapping the real IP address of the target management service, and then modify the destination IP address of the first data packet from the real IP address of the target management service to the virtual IP address, thus obtaining the second data packet. The virtual IP address refers to an Internet Protocol address that cannot be successfully accessed (i.e., cannot successfully send or receive data).
[0070] s13, hosts in the cloud-local dedicated cluster can send the second data packet to the first virtual private network gateway (i.e., the first VPN gateway).
[0071] s14, the first virtual private network gateway sends the second data packet to the second virtual private network gateway (i.e., the second VPN gateway) through the virtual private network service channel.
[0072] s15, the second virtual private network gateway directly modifies the destination IP address of the second data packet to the real IP address of the target management service, thus obtaining the first data packet.
[0073] s16, the second virtual private network gateway sends the first data packet to the target management service.
[0074] In another embodiment, the data transmission method proposed in this application presents a data transmission system as shown in Figure 1c. Based on the system architecture shown in Figure 1a, the data transmission system further adds a service mapping module in the public cloud region. The service mapping module is a module used to map the IP address of the management service. It can be a physical device or program code running on the physical device, and there is no limitation on this.
[0075] In the data transmission system shown in Figure 1c, the specific implementation logic of the data transmission method proposed in this application embodiment can be seen in Figure 1d, which roughly includes the following steps s21-s27:
[0076] s21, the host in the cloud-local dedicated cluster can generate the first data packet.
[0077] s22, hosts in a cloud-local dedicated cluster can call the NAT service to translate the destination IP address of the first data packet to obtain the second data packet.
[0078] s23, hosts in the cloud-local dedicated cluster can send the second data packet to the first virtual private network gateway (i.e., the first VPN gateway).
[0079] s24, the first virtual private network gateway sends the second data packet to the second virtual private network gateway (i.e., the second VPN gateway) through the virtual private network service channel.
[0080] S25, the second virtual private network gateway sends the second data packet to the service mapping module.
[0081] s26, the service mapping module modifies the destination IP address of the second data packet to the real IP address of the target management service, and obtains the first data packet.
[0082] s27, the service mapping module sends the first data packet to the target management service.
[0083] As described in Figures 1a-1d above, the data transmission method proposed in this application allows any host in the cloud-local dedicated cluster to access the target management service in the cloud central area of the public cloud region when the host calls its internally deployed NAT service to modify the destination IP address of the first data packet to a virtual IP address obtained by mapping the real IP address of the target management service, thus obtaining the second data packet. The second data packet is then sent to the second VPN gateway on the public cloud region side through the VPN service channel between the first VPN gateway and the second VPN gateway. This avoids directly exposing the real IP address of the target management service during data transmission between the cloud-local dedicated cluster and the public cloud region, thereby preventing attackers from breaking through the network defense between the cloud-local dedicated cluster and the cloud central area based on the real IP address of the target management service, and thus improving the security of the central cloud environment where the target management service is located. Furthermore, after receiving the second data packet, the second VPN gateway can directly or with the help of the service mapping module modify the destination IP address of the second data packet to the real IP address of the target management service to obtain the first data packet, and then send the first data packet to the target management service. This enables the first data packet to be successfully transmitted from the cloud-local dedicated cluster to the target management service in the public cloud region, thereby improving the security of data transmission.
[0084] Understandably, in the specific implementation of the data transmission method shown in Figures 1a-1d above, the address mapping relationship of each management service (i.e., the mapping relationship between the real IP address and virtual IP address of each management service) can be directly configured on each host in the cloud-local dedicated cluster. This allows any host to call the internally deployed NAT service to translate the destination IP address of the first data packet, and then call the internally deployed NAT service to determine the virtual IP address of the target management service based on the address mapping relationship. In this way, the destination IP address of the first data packet can be translated based on the virtual IP address. For example, if a CVM host (i.e., a host in the cloud-local dedicated cluster that can provide CVM services) needs to access the compute service (a management service) on the cloud, then the address mapping relationship needs to be configured on each CVM host. This allows the CVM host to call the NAT service to translate the real IP address of the compute service carried in the first data packet into the service-mapped virtual IP address through DNAT based on the address mapping relationship, thereby obtaining the second data packet. Similarly, the CBS host (i.e., a host in the cloud-local dedicated cluster that can provide CBS services) can also do the same.
[0085] However, considering the potential large number of CVM and CBS hosts (e.g., thousands) in a cloud-native dedicated cluster environment, the implementation method shown in Figures 1a-1d requires configuring address mapping relationships on each host individually. This is extremely time-consuming and labor-intensive. Furthermore, if the virtual IP addresses of the management services change later, it is necessary to log in to each host individually to make modifications, which is detrimental to later operation and maintenance. Moreover, configuring NAT services on each host requires modifying the processing logic code on each host, which may not only increase manpower costs but also affect the normal operation of each host due to unreasonable code modifications.
[0086] Based on this, the embodiments of this application propose another data transmission method to overcome the above problems, as detailed below:
[0087] In one embodiment, another data transmission method proposed in this application presents a data transmission system as shown in Figure 2a. This data transmission system may include two parts: a customer site and a public cloud region. The customer site may include a customer data center (IDC), a cloud-local dedicated cluster, and a first virtual private network (VPN) gateway. The first VPN gateway may deploy NAT services. The public cloud region may include at least a cloud central area and a second VPN gateway. The cloud central area may include at least one management service.
[0088] In the data transmission system shown in Figure 2a, the specific implementation logic of another data transmission method proposed in this application embodiment can be shown in Figure 2b, and can generally include the following steps s31-s36:
[0089] s31, the host in the cloud-local dedicated cluster can generate the first data packet.
[0090] s32, a host in a cloud-local dedicated cluster can send the first data packet to the first virtual private network gateway (i.e., the first VPN gateway).
[0091] s33, the first virtual private network gateway calls the NAT service to translate the destination IP address of the first data packet, and obtains the second data packet.
[0092] s34, the first virtual private network gateway sends the second data packet to the second virtual private network gateway (i.e., the second VPN gateway) through the virtual private network service channel.
[0093] s35, the second virtual private network gateway directly modifies the destination IP address of the second data packet to the real IP address of the target management service, thus obtaining the first data packet.
[0094] s36, the second virtual private network gateway sends the first data packet to the target management service.
[0095] In another embodiment, the data transmission method proposed in this application presents a data transmission system as shown in Figure 2c. Based on the system architecture shown in Figure 2a, this data transmission system further adds a service mapping module in the public cloud region. The service mapping module is a module used to map the IP address of the management service. It can be a physical device or program code running on the physical device, and there is no limitation on the latter.
[0096] In the data transmission system shown in Figure 2c, the specific implementation logic of another data transmission method proposed in this application embodiment can be seen in Figure 2d, which roughly includes the following steps s41-s47:
[0097] s41, the host in the cloud-local dedicated cluster can generate the first data packet.
[0098] s42, a host in a cloud-local dedicated cluster can send the first data packet to the first virtual private network gateway (i.e., the first VPN gateway).
[0099] s43, the first virtual private network gateway calls the NAT service to translate the destination IP address of the first data packet, and obtains the second data packet.
[0100] s44, the first virtual private network gateway sends the second data packet to the second virtual private network gateway (i.e., the second VPN gateway) through the virtual private network service channel.
[0101] S45, the second virtual private network gateway sends the message to the service mapping module.
[0102] s46, the service mapping module modifies the destination IP address of the second data packet to the real IP address of the target management service, and obtains the first data packet.
[0103] s47, the service mapping module sends the first data packet to the target management service.
[0104] As can be seen from the description in Figures 2a-2d above, the other data transmission method proposed in this application embodiment can not only successfully transmit the first data packet from the cloud-local dedicated cluster to the target management service in the public cloud region, improving the security of data transmission, but also avoid directly exposing the real IP address of the target management service during the data transmission process between the cloud-local dedicated cluster and the public cloud region. This prevents attackers from breaking through the network defense line between the cloud-local dedicated cluster and the cloud central area based on the real IP address of the target management service, thereby improving the security of the central cloud environment where the target management service is located. In addition, this data transmission method utilizes aspect-oriented programming to add NAT services to the first VPN gateway, enabling unified NAT configuration (i.e., unified address mapping). This allows for one-time configuration with global effectiveness, facilitating operation and maintenance. In other words, by centralizing NAT configuration at the first VPN, and considering that traffic between the cloud-local dedicated cluster and the public cloud region passes through the VPN, configuring NAT in the first VPN ensures that the NAT configuration takes effect in real-time on all hosts within the cloud-local dedicated cluster. This unified aspect-oriented approach avoids fragmented configuration (i.e., configuring NAT on individual hosts), saving time and manpower costs, and facilitating both current configuration and future maintenance. When the virtual IP addresses of various management services change, only the NAT configuration in the first VPN gateway needs to be modified, avoiding modifications to the processing logic code on individual hosts and ensuring their normal operation.
[0105] It is worth emphasizing that, in the embodiments of this application, if user information and other related data are involved, when any method embodiment proposed in this application is applied to a specific product or technology, such related data is collected with the user's permission or consent, and the collection, use and processing of such data comply with the relevant laws, regulations and standards of the relevant regions.
[0106] Based on the above description, this application proposes a data transmission method that can be applied to the data transmission system shown in Figure 2a or Figure 2c. Specifically, it can be jointly executed by a first virtual private network gateway and a second virtual private network gateway in the data transmission system. The first virtual private network gateway refers to a VPN gateway located on the cloud-local dedicated cluster side (i.e., a VPN gateway located in the same customer site as the cloud-local dedicated cluster), and the second virtual private network gateway refers to a VPN gateway on the public cloud region side (i.e., a VPN gateway located in the public cloud region). A virtual private network service channel exists between the first and second virtual private network gateways. This virtual private network service channel is an encrypted channel (encrypted channel) established between the first and second virtual private network gateways, which enables mutual access between the first and second virtual private network gateways.
[0107] Please refer to Figure 3. The data transmission method proposed in this application embodiment can be roughly divided into the following steps S301-S305:
[0108] S301, the first virtual private network gateway receives the first data packet sent by the cloud local private cluster.
[0109] The first data packet refers to the data packet used by the cloud-local dedicated cluster to access the target management service in the public cloud region, i.e., the data packet to be sent to the target management service in the public cloud region. Specifically, the source internet address of the first data packet is the real internet protocol address of the cloud-local dedicated cluster, while the destination internet protocol address of the first data packet is the real internet protocol address of the target management service in the public cloud region; whereby the target management service refers to the management service that the cloud-local dedicated cluster wishes to access.
[0110] In a specific implementation, when a host in a cloud-local dedicated cluster wants to access a management service in a public cloud region, it can take the management service it wants to access as the target management service, and generate a first data packet for accessing the target management service based on the real Internet Protocol address of the target management service and the real Internet Protocol address of the cloud-local dedicated cluster, and send the first data packet to the first virtual private network gateway; accordingly, the first virtual private network gateway can receive the first data packet sent by the cloud-local dedicated cluster through step S301.
[0111] S302, the first virtual private network gateway obtains the virtual Internet Protocol address of the target management service, which is obtained by mapping the real Internet Protocol address of the target management service.
[0112] In one specific implementation, when executing step S302, the first virtual private network gateway can obtain at least one address mapping policy from its device system. Each address mapping policy includes: a real Internet Protocol (IP) address for a management service, and a virtual IP address configured for the corresponding management service. Further, the first virtual private network gateway can search for a first address mapping policy from the at least one address mapping policy based on the real IP address of the target management service. This first address mapping policy is an address mapping policy that includes the real IP address of the target management service, thereby obtaining the virtual IP address of the target management service from the found first address mapping policy.
[0113] For example, suppose the device system of the first virtual private network gateway includes two address mapping policies. The first address mapping policy is "11.132.224.10->100.115.83.221 (CBS IP)", which involves the CBS service as its management service, and the real Internet Protocol address of the CBS service is 100.115.83.221, while the virtual Internet Protocol address of the CBS service is 11.132.224.10. The second address mapping policy is "11.132.224.20->100.121.151.152 (TGW IP)", which involves the TGW service as its management service, and the real Internet Protocol address of the TGW service is 11.132.224.20, while the virtual Internet Protocol address of the TGW service is 100.121.151.152. If the target management service is a CBS service and its real Internet Protocol address is 11.132.224.10, then based on this real Internet Protocol address, the first address mapping policy can be found from the two address mapping policies as the first address mapping policy, and the virtual Internet Protocol address of the target management service, 100.115.83.221, can be obtained from the first address mapping policy.
[0114] Therefore, this application embodiment can pre-configure at least one address mapping policy in the device system of the first virtual private network gateway, so that the first virtual private network gateway can directly obtain the virtual Internet Protocol address of the target management service from the pre-configured address mapping policy in actual application. This can not only effectively improve the efficiency of obtaining the virtual Internet Protocol address of the target management service, thereby improving the efficiency of subsequent data transmission, but also reduce the probability of attackers stealing the virtual Internet Protocol address of the target management service based on the pre-configured address mapping policy in the device system, thereby further improving the security of data transmission.
[0115] At least one of the address mapping policies mentioned above can be pre-configured in the device system of the first virtual private network gateway through code. Alternatively, it can be dynamically configured in real time in the device system of the first virtual private network gateway through a user interface. In this case, the public cloud region may also include a virtual private network controller (VPN controller), which is the VPN's backend control server. Referring to Figure 4: The virtual private network controller can generate address configuration instructions based on the address configuration operation detected in the terminal interface and send the address configuration instructions to the second virtual private network gateway. The address configuration instructions include a real Internet Protocol address for a management service and a virtual Internet Protocol address configured for the corresponding management service. Correspondingly, the second virtual private network gateway can receive the address configuration instructions issued by the virtual private network controller, store the address configuration instructions, and issue the stored address configuration instructions to the first virtual private network gateway through the virtual private network service channel. This allows the first virtual private network gateway to receive the address configuration instructions issued by the second virtual private network gateway through the virtual private network service channel and generate an address mapping policy in its device system based on the received address configuration instructions. As can be seen, by setting up a virtual private network controller in a public cloud region, this application embodiment not only enables dynamic configuration of address mapping policies based on actual needs, improving the flexibility of address mapping policy configuration, but also allows the virtual private network controller and the second virtual private network gateway to transmit address configuration instructions in the same public cloud region during the dynamic configuration of address mapping policies. This improves instruction transmission efficiency and security. Furthermore, the second virtual private network gateway sends the address configuration instructions to the first virtual private network gateway through the virtual private network service channel. The privacy of the virtual private network service channel also helps to avoid directly exposing the real IP address of the management service in the address configuration instructions. This prevents attackers from using the real IP address of the management service to break through the network defense between the cloud-local dedicated cluster and the cloud central area, thereby improving the security of the central cloud environment where the management service is located.
[0116] In this system, after receiving address configuration instructions from the VPN controller, the second VPN gateway can store the instructions either directly or by converting them to a format supported by the second VPN gateway. Similarly, the first VPN gateway can generate an address mapping policy based on the received instructions in either any storage space within its system, or by searching for a firewall within the first VPN gateway's system and generating an address mapping policy within that firewall. A firewall is a network security system used to allow or restrict data transmission according to specific rules; generating address mapping policies within the firewall enhances the security of those policies.
[0117] In another specific implementation, when the first virtual private network gateway executes step S302, it can obtain the source Internet Protocol address and destination Internet Protocol address of the first data packet, and perform a reversible operation on the source and destination Internet Protocol addresses of the first data packet to obtain a new Internet Protocol address. This new Internet Protocol address is used to map the real Internet Protocol address of the target management service, and thus the new Internet Protocol address can be used as the virtual Internet Protocol address of the target management service. Here, a reversible operation refers to an operation with an inverse operation, meaning that the result of the operation can be recovered to the original data. For example, after performing a certain operation on original data a and original data b, if original data a can be recovered from the result of the operation and original data b, or vice versa, then the operation can be considered to have an inverse operation, and thus the operation can be determined to be reversible. For example, a reversible operation could be, for instance, addition, whose inverse operation is subtraction, or a reversible operation could be, for instance, multiplication, whose inverse operation is subtraction, and so on.
[0118] Therefore, this application embodiment can pre-configure reversible operations in the first virtual private network gateway, enabling the first virtual private network gateway to dynamically calculate a new Internet Protocol address based on the source Internet Protocol address and destination Internet Protocol address of the first data packet in practical applications. This new Internet Protocol address is then used to map the real Internet Protocol address of the target management service. This not only strengthens the role of address mapping and improves its reliability, thereby enhancing the security of data transmission, but also avoids storing a large number of address mapping policies in the device system. This effectively saves storage space in the device system and prevents the first virtual private network gateway from experiencing operational lag due to excessive memory usage.
[0119] S303, the first virtual private network gateway modifies the destination Internet Protocol address of the first data packet to the virtual Internet Protocol address, and obtains the second data packet.
[0120] In a specific implementation, the first virtual private network gateway can modify the destination Internet Protocol address of the first data packet from the real Internet Protocol address of the target management service to the virtual Internet Protocol address of the target management service to obtain the second data packet; wherein, the destination Internet Protocol address of the second data packet is the virtual Internet Protocol address of the target management service, while the source Internet Protocol address of the second data packet is still the real Internet Protocol address of the cloud local private cluster.
[0121] Understandably, the second data packet and the first data packet are identical in all aspects except for the destination Internet Protocol address; that is, the data portion of the second data packet is the same as the data portion of the first data packet, and the source Internet Protocol address of the second data packet is also the same as the source Internet Protocol address of the first data packet.
[0122] S304, the first virtual private network gateway sends the second data packet to the second virtual private network gateway through the virtual private network service channel, so that the second virtual private network gateway modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtains the first data packet, and sends the first data packet to the target management service.
[0123] In a practical implementation, the first virtual private network (VPN) gateway can directly send the second data packet to the second VPN gateway through the VPN service channel. Alternatively, to further improve the reliability and security of data transmission, the first VPN gateway can encrypt the second data packet using a preset encryption algorithm to obtain an encrypted data packet. The source Internet Protocol (IP) address of this encrypted data packet is the real IP address of the first VPN gateway, and the destination IP address is the real IP address of the second VPN gateway. Furthermore, the first VPN gateway can send the encrypted data packet to the second VPN gateway through the VPN service channel. Upon receiving the encrypted data packet, the second VPN gateway can decrypt it using a decryption algorithm corresponding to the preset encryption algorithm to obtain the second data packet. This enables the second data packet to be transmitted from the first VPN gateway to the second VPN gateway through the VPN service channel.
[0124] Correspondingly, the second virtual private network gateway can receive the second data packet sent by the first virtual private network gateway through the virtual private network service channel and execute the subsequent step S305.
[0125] S305, the second virtual private network gateway modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtains the first data packet, and sends the first data packet to the target management service.
[0126] In one specific implementation, the second virtual private network gateway can directly perform operations such as address translation. In this case, when the second virtual private network gateway executes step S305, it can obtain the real Internet Protocol address of the target management service and modify the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service to obtain the first data packet.
[0127] In another specific implementation, the public cloud region also includes a service mapping module. In this case, when the second virtual private network gateway executes step S305, it can obtain the Internet Protocol address of the service mapping module and route the second data packet to the service mapping module based on the obtained Internet Protocol address (i.e., send the second data packet to the service mapping module based on the obtained Internet Protocol address). This allows the service mapping module to obtain the real Internet Protocol address of the target management service, modify the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtain the first data packet, and send the first data packet to the target management service. It is evident that by introducing a service mapping module, some operations of the second virtual private network gateway (such as address acquisition and address modification operations) can be performed by the service mapping module, thus reducing the operational burden on the second virtual private network gateway.
[0128] If the virtual Internet Protocol (IP) address of the target management service is pre-configured for the target management service, meaning the IP address is obtained by the first virtual private network gateway from the address mapping policy, then the second virtual private network gateway or service mapping module can obtain service mapping information when obtaining the real IP address of the target management service. This service mapping information includes: the real IP address of at least one management service that is allowed to be accessed by the cloud-local dedicated cluster, and the virtual IP address configured for the corresponding management service. Furthermore, the real IP address of the target management service can be obtained from the service mapping information. Therefore, this implementation method simplifies the process of obtaining the real IP address of the target management service and improves its efficiency.
[0129] Alternatively, if the virtual Internet Protocol address (IPA) of the target management service is obtained by reversibly operating on the source and destination IPA addresses of the first data packet, and the source IPA address of the first data packet is the real IPA address of the cloud-local dedicated cluster, then the aforementioned second virtual private network gateway or service mapping module can perform the inverse operation of the reversible operation on the virtual IPA address and the source IPA address of the first data packet when obtaining the real IPA address of the target management service. Therefore, this implementation method can obtain the real IPA address of the target management service without storing storage mapping information, thus effectively saving storage space in the device system and avoiding operational lag caused by excessive memory usage in the second virtual private network gateway or service mapping module.
[0130] This application embodiment deploys a first virtual private network (VPN) gateway on the cloud-local dedicated cluster side and a second VPN gateway on the public cloud region side, establishing a VPN service channel between the first and second VPN gateways. This allows the first VPN gateway to receive a first data packet sent by the cloud-local dedicated cluster, modify the destination Internet Protocol (IP) address of the first data packet to a virtual IP address obtained by mapping the real IP address of the target management service, and obtain a second data packet. The second data packet is then sent to the second VPN gateway on the public cloud region side via the VPN service channel. This avoids directly exposing the real IP address of the target management service during data transmission between the cloud-local dedicated cluster and the public cloud region, thus preventing attackers from breaching the network defenses between the cloud-local dedicated cluster and the cloud central area based on the real IP address of the target management service, thereby improving the security of the central cloud environment where the target management service resides. Furthermore, after receiving the second data packet, the second virtual private network gateway can modify the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service to obtain the first data packet, and then send the first data packet to the target management service. This enables the first data packet to be successfully transmitted from the cloud-local dedicated cluster to the target management service in the public cloud region, thereby improving the security of data transmission.
[0131] It should be noted that steps S301-S305 in Figure 3 above describe the packet sending and accessing link from the cloud-local dedicated cluster to the target management service in the public cloud region; optionally, the return packet accessing link from the target management service to the cloud-local dedicated cluster can also be realized through communication between the second virtual private network gateway and the first virtual private network gateway. The specific implementation of the return packet accessing link is similar to the specific implementation of the aforementioned packet sending and accessing link. The difference is that the packet sending and accessing link modifies the destination Internet Protocol address of the data packet, while the return packet accessing link modifies the source Internet Protocol address of the data packet.
[0132] For example, in the specific implementation of the return packet access link, the second virtual private network gateway and the first virtual private network gateway can roughly perform the following steps S501-S505:
[0133] S501, after the target management service generates the third data packet, the second virtual private network gateway can obtain the fourth data packet generated based on the third data packet.
[0134] The third data packet is the data packet to be sent to the cloud-local dedicated cluster. The source Internet Protocol address of the third data packet is the real Internet Protocol address of the target management service, and the destination Internet Protocol address of the third data packet is the real Internet Protocol address of the cloud-local dedicated cluster. Specifically, it can be the real Internet Protocol address of the target host in the cloud-local dedicated cluster. The target host refers to the host to receive the third data packet.
[0135] The fourth data packet is obtained by modifying the source Internet Protocol address of the third data packet to the virtual Internet Protocol address of the target management service. It is understandable that the third and fourth data packets are identical except for their source Internet Protocol addresses; that is, the data portions of the third and fourth data packets are the same, and the destination Internet Protocol addresses of the third and fourth data packets are also the same.
[0136] In one specific implementation, the fourth data packet can be generated by the second virtual private network gateway. That is, the second virtual private network gateway can receive the third data packet sent by the target management service, obtain the virtual Internet Protocol address (VLAN address) of the target management service, and then modify the source VLAN address of the third data packet to the VLAN address of the target management service to obtain the fourth data packet. The return packet access link in this case can be shown in Figure 5a. In another specific implementation, the fourth data packet can also be generated by the service mapping module in the public cloud region and sent to the second virtual private network gateway. That is, the service mapping module can receive the third data packet sent by the target management service, obtain the VLAN address of the target management service, and then modify the source VLAN address of the third data packet to the VLAN address of the target management service to obtain the fourth data packet, which is then sent to the second virtual private network gateway. The return packet access link in this case can be shown in Figure 5b.
[0137] It is understood that the specific implementation method for the second virtual private network gateway or service mapping module to obtain the virtual Internet Protocol address of the target management service is the same as the specific implementation method in step S302 above, and will not be repeated here. That is to say, the embodiments of this application can pre-configure at least one address mapping policy in the device system of the second virtual private network gateway or service mapping module, so that the second virtual private network gateway or service mapping module can directly obtain the virtual Internet Protocol address of the target management service from the pre-configured address mapping policy in actual application. This can not only effectively improve the efficiency of obtaining the virtual Internet Protocol address of the target management service, thereby improving the efficiency of subsequent data transmission, but also reduce the probability of attackers stealing the virtual Internet Protocol address of the target management service based on the pre-configured address mapping policy in the device system, thereby further improving the security of data transmission. Alternatively, reversible operations can be pre-configured in the second virtual private network gateway or service mapping module. This allows the second virtual private network gateway or service mapping module to dynamically calculate a new Internet Protocol address (IPA) based on the source and destination IPA addresses of the third data packet during practical applications. This new IPA address can then be used to map the target management service's real IPA address. This not only strengthens the address mapping function and improves its reliability, thereby enhancing data transmission security, but also avoids storing a large number of address mapping policies in the device system. This effectively saves storage space in the device system and prevents the second virtual private network gateway or service mapping module from experiencing operational lag due to excessive memory usage.
[0138] S502, the second virtual private network gateway sends the fourth data packet to the first virtual private network gateway through the virtual private network service channel, so that the first virtual private network gateway modifies the source Internet Protocol address of the fourth data packet to the real Internet Protocol address of the target management service, obtains the third data packet, and forwards the third data packet to the cloud local dedicated cluster.
[0139] In a practical implementation, the second VPN gateway can directly send the fourth data packet to the first VPN gateway through the VPN service channel. Alternatively, to further improve the reliability and security of data transmission, the second VPN gateway can encrypt the fourth data packet using a preset encryption algorithm to obtain the target data packet. The source Internet Protocol address of the target data packet is the real Internet Protocol address of the second VPN gateway, while the destination Internet Protocol address of the target data packet is the real Internet Protocol address of the first VPN gateway. Furthermore, the second VPN gateway can send the target data packet to the first VPN gateway through the VPN service channel. Upon receiving the target data packet, the first VPN gateway can decrypt it using a decryption algorithm corresponding to the preset encryption algorithm to obtain the fourth data packet. This enables the fourth data packet to be transmitted from the second VPN gateway to the first VPN gateway through the VPN service channel.
[0140] Correspondingly, after the target management service generates the third data packet, the first virtual private network gateway can receive the fourth data packet sent by the second virtual private network gateway through the virtual private network service channel, and execute subsequent steps S503-S505.
[0141] S503, the first virtual private network gateway obtains the real Internet Protocol address of the target management service.
[0142] In one specific implementation, when executing step S503, the first virtual private network gateway can obtain at least one address mapping policy from its device system. Each address mapping policy includes: a real Internet Protocol (IP) address for a management service, and a virtual IP address configured for the corresponding management service. Further, the first virtual private network gateway can search for a second address mapping policy from the at least one address mapping policy based on the virtual IP address of the target management service. This second address mapping policy is an address mapping policy that includes the real IP address of the target management service, thereby obtaining the real IP address of the target management service from the found second address mapping policy.
[0143] Therefore, this application embodiment can pre-configure at least one address mapping policy in the device system of the first virtual private network gateway, so that the first virtual private network gateway can directly obtain the real Internet Protocol address of the target management service from the pre-configured address mapping policy in actual application. This can not only effectively improve the efficiency of obtaining the real Internet Protocol address of the target management service, thereby improving the efficiency of address modification of subsequent data packets and the transmission efficiency of data packets, but also reduce the probability of attackers stealing the real Internet Protocol address of the target management service based on the pre-configured address mapping policy in the device system, thereby further improving the security of data transmission.
[0144] In another specific implementation, when the first virtual private network gateway executes step S503, it can obtain the source Internet Protocol address and destination Internet Protocol address of the fourth data packet. The destination Internet Protocol address of the fourth data packet is the real Internet Protocol address of the cloud local private cluster, while the source Internet Protocol address of the fourth data packet is obtained by performing a reversible operation on the source Internet Protocol address of the third data packet and the destination Internet Protocol address of the fourth data packet. Furthermore, the inverse operation of the reversible operation can be performed on the source Internet Protocol address and destination Internet Protocol address of the fourth data packet to obtain the source Internet Protocol address of the third data packet. Thus, the source Internet Protocol address of the third data packet can be used as the real Internet Protocol address of the target management service.
[0145] Therefore, this embodiment of the application can pre-configure the inverse operation of the reversible operation in the first virtual private network gateway, so that the first virtual private network gateway can dynamically calculate the real Internet Protocol address of the target management service based on the source Internet Protocol address and destination Internet Protocol address of the fourth data packet in actual application. This not only enables the acquisition of the real Internet Protocol address of the target management service, but also avoids storing a large number of address mapping policies in the device system, thereby effectively saving the storage space of the device system and avoiding the phenomenon of the first virtual private network gateway running slowly due to excessive memory usage.
[0146] S504, the first virtual private network gateway modifies the source Internet Protocol address of the fourth data packet to the real Internet Protocol address of the target management service, thus obtaining the third data packet.
[0147] S505, the first virtual private network gateway forwards the third data packet to the cloud-local dedicated cluster.
[0148] Based on the description of steps S501-S505 above, it can be seen that the embodiments of this application can avoid directly exposing the real Internet Protocol address of the target management service during the data transmission process between the cloud local dedicated cluster and the public cloud region in the entire return packet access link. This prevents attackers from breaking through the network defense line between the cloud local dedicated cluster and the cloud central area based on the real Internet Protocol address of the target management service, thereby improving the security of the central cloud environment where the target management service is located.
[0149] Based on the above description, this application proposes a service mapping-based data transmission scheme in a distributed cloud environment. This scheme can be applied to cloud products in distributed cloud scenarios, where the deployment data center (i.e., customer site) is independent of the public cloud and connected to the customer's data center. Referring to Figure 6a: In a distributed cloud scenario, the cloud-local dedicated cluster deployed at the customer site and the public cloud region share a single cloud central area management service, and traffic (i.e., data packets) is transmitted via VPN (Virtual Private Network). That is, traffic (i.e., data packets) between hosts in the cloud-local dedicated cluster and the cloud management service will all be transmitted through the VPN. Therefore, DNAT can be configured on the VPN side to avoid configuration dispersion. Since the destination of the VPN connection can pass through the service mapping module, after DNAT configuration, the real IP address of the management service can be converted to a service-mapped virtual IP address and enter the service mapping module. After processing by the service mapping module, the virtual IP address of the management service will be converted back to the real IP address and accessed through the cloud central area.
[0150] The data transmission scheme proposed in this application will be described below from two aspects: service mapping architecture and distributed cloud backend implementation.
[0151] (I) Service Mapping Architecture:
[0152] When a cloud-native dedicated cluster deployed in the customer's local data center and a management service in the cloud central area communicate with each other, the data packets used for access are no longer simply allowed directly. Instead, these data packets need to be processed through service mapping. Service mapping prevents the cloud-native dedicated cluster in the customer's local data center from directly accessing the real IP address of the management service in the cloud central area. Instead, it indirectly accesses the management service in the cloud central area through a virtual IP address generated by service mapping, thereby achieving security hardening and network link control.
[0153] The uplink access diagram of the service mapping architecture can be seen in Figure 6b, and its specific implementation may include the following operations:
[0154] ①Preparation:
[0155] Before a cloud-local dedicated cluster can officially access management services in the cloud central area, service mapping data needs to be pre-configured through the terminal interface of the product example. This involves configuring the real IP address (rsIp) of the management service to be accessed into the service mapping list, thereby registering it with the service mapping module (or service mapping configuration center). Taking CBS management service and TGW management service as examples, the pre-configured service mapping data can be as shown in Figure 6b: "a) 11.132.224.10->100.115.83.221 (CBS IP)" and "b) 11.132.224.20->100.121.151.152 (TGW IP)". It is understood that at least one address mapping policy can also be configured in the first VPN gateway through the address configuration operation detected by the terminal interface of the product example.
[0156] For example, the aforementioned terminal interface may include the NAT front-end operation interface shown in Figure 6c. This interface may include a "Add Configuration" button, such as the "Add DNAT Configuration" button. When a new NAT configuration needs to be added, the user can click this button to trigger the display of the new configuration window. In this window, DNAT configuration can be performed on different VPN PNGW sub-machines (the physical devices that actually carry the VPN gateway service). The configuration mainly includes the rsIp (real IP address) and vip (virtual IP address), as well as the corresponding port (generally consistent). For example, the new configuration window is shown in Figure 6d. The user can enter the following parameters in this window to perform DNAT configuration:
[0157] 1) VPN ID is the name of the vpngw sub-machine. You need to configure one or more vpngw sub-machine names. For example, you can configure two vpngw names to form a primary and backup architecture, which improves the availability of the system.
[0158] 2) DNATName is the name of the DNAT, which can be named according to the configuration data.
[0159] 3) Proto is the name of the data transmission protocol, which can generally be TCP (Transmission Control Protocol) or UDP (Open Systems Interconnection). It can be filled in according to the specific data transmission protocol used.
[0160] 4) RealIp is the real IP address of the cloud management service (i.e., the management service in the public cloud region), such as 37.64.220.11. This real IP address is seen as rsIp by the service mapping module.
[0161] 5) VIP is the virtual IP address mapped to the cloud management service (i.e., the management service in the public cloud region), for example, 11.164.224.44.
[0162] 6) RealPort and VipVport are the port of the real IP address and the port of the virtual IP address after service mapping, respectively. They are generally kept the same, for example, both are 14070.
[0163] Optionally, if a user needs to check whether a specific vpngw sub-machine has DNAT configuration for related management services, they can search for it by entering the vpngw sub-machine's VPN ID in the search box of the NAT front-end operation interface. For example, as shown in Figure 6e, when a user enters the VPN ID "vpngw-2" in the search box, the terminal interface can display all DNAT data configured on the vpngw2 gateway, including information such as the real IP address and virtual IP address. It is evident that by setting up a search box in the NAT front-end operation interface, it is convenient to uniformly view which DNAT configurations have been performed, thereby enabling rapid operation and maintenance and statistics.
[0164] Optionally, after logging into the NAT front-end operation interface, users can view all NAT information configured under the cloud-local dedicated cluster, as shown in Figure 6f; furthermore, they can export the information into reports for data review and maintenance. Additionally, when a DNAT configuration needs to be taken offline, users can use the "Offline" operation in the NAT front-end operation interface to take the corresponding DNAT configuration offline (i.e., delete the corresponding configuration data in the VPN gateway).
[0165] ② Formal visit action:
[0166] The cloud-native dedicated cluster at the customer site can initiate access to the target management service in the cloud central area through the first VPN gateway, thereby generating the first data packet. For example, if the target management service accessed by the first data packet is the CBS management service, then the destination IP address of the first data packet is the real IP address of the CBS management service, 100.115.83.221; if the target management service accessed by the first data packet is the TGW management service, then the destination IP address of the second data packet is the real IP address of the TGW management service, 100.121.151.152.
[0167] The cloud-native dedicated cluster at the customer site sends the first data packet to the first VPN gateway. The first VPN gateway then obtains the virtual IP address of the target management service and modifies the destination IP address of the first data packet to the virtual IP address, thus obtaining the second data packet. For example, if the target management service accessed by the first data packet is the CBS management service, the first VPN gateway can obtain the virtual IP address of the CBS management service (11.132.224.10) from at least one built-in address mapping policy, thereby modifying the destination IP address of the first data packet from 100.115.83.221 to 11.132.224.10, and obtaining the second data packet. If the target management service accessed by the first data packet is the TGW management service, the first VPN gateway can obtain the virtual IP address of the TGW management service (11.132.224.20) from at least one built-in address mapping policy, thereby modifying the destination IP address of the first data packet from 100.121.151.152 to 11.132.224.10, and obtaining the second data packet.
[0168] The second data packet can be used as uplink access traffic, routed through the VPN to the service mapping module. This service mapping module can look up pre-configured service mapping data based on the destination IP address of the second data packet to obtain the real IP address of the target management service. For example, if the destination IP address of the second data packet is 11.132.224.10, the corresponding rsIp (i.e., the real IP address of the target management service) can be found in the service mapping data as 100.115.83.221; if the destination IP address of the second data packet is 11.132.224.20, the corresponding rsIp can be found in the service mapping data as 100.121.151.152.
[0169] The service mapping module can modify the destination IP address of the second data packet to the real IP address of the target management service, obtain the first data packet, and use the found real IP address as the destination IP address for addressing. This routes the first data packet to the CBS management service or TGW management service under the management service, enabling successful access to the corresponding management service. Understandably, if the service mapping module cannot find the real IP address of the target management service, it can directly indicate that the target management service is inaccessible.
[0170] (II) Distributed Cloud Backend Implementation:
[0171] As shown in Figure 7, in the distributed cloud backend implementation, the entire VPN-side DNAT configuration can be divided into a data plane and a control plane. The control plane is responsible for distributing and maintaining the DNAT configuration, while the data plane is responsible for forwarding data packet traffic according to the DNAT configuration after it takes effect, thereby ensuring the smooth flow of data. Specifically:
[0172] (1) Control plane flow:
[0173] 1. When a new DNAT configuration is required, the DNAT configuration data (data generated based on address configuration operations) can be sent to the VPN controller through the operator's terminal. At this time, you can log in to the operator's system, select the corresponding cloud-local dedicated cluster, and configure the corresponding vpngw data (vpngw1 and vpngw2 can be used to form a primary / backup architecture) in the corresponding terminal interface. For example, if the management service to be accessed is the CVM management service, its real IP address is 37.64.220.11, its service port is 14070, and its virtual IP address after service mapping is 11.164.224.44, then the actual DNAT configuration data sent is:
[0174] {
[0175] "Action":"AddVpnDnatView",
[0176] "ApiModule":"api",
[0177] "Region":"gz"
[0178] "RequestSource":"CVM_VS",
[0179] "CdcId":"cluster-262n63e8",
[0180] "GroupId":"vpngw-2",
[0181] "DnatName":"DNAT Test"
[0182] "Proto":"TCP"
[0183] "RealIp":"37.64.220.11",
[0184] "RealPort":"14070",
[0185] "VIP":"11.164.224.44",
[0186] "VipVport":"14070"
[0187] }
[0188] 2. The VPN controller is the background control service for VPNs, specifically used to manage and configure VPN services. When the DNAT configuration data AddVpnDnatView from the operator arrives at the cloud VPN controller, the VPN controller can regenerate an address configuration command based on this DNAT configuration data and forward this address configuration command to the cloud-side VPN gateway (i.e., the second VPN gateway). This address configuration command can be as follows:
[0189] {
[0190] "uniqCdcId":"cluster-262n63e8",
[0191] "name":"DNAT test"
[0192] "protocol":"TCP"
[0193] "localIP":"37.64.220.11",
[0194] "localPort":14070,
[0195] "externalIp":"11.164.224.44",
[0196] "externalPort":14070
[0197] }
[0198] 3. After receiving the address configuration command, the cloud-side VPN gateway can internally generate a storageable address configuration command (such as an iptables (firewall) configuration command). Its data format can be as follows: iptables -t nat -IOUTPUT -d 37.64.220.11 -p tcp --dport 14070 -jDNAT --to-destination 11.164.224.44:14070; and the cloud-side VPN gateway can store the relevant metadata information of the generated address configuration command in its database and send the address configuration command to the cloud-local dedicated cluster-side VPN gateway (i.e., the first VPN gateway) through the VPN service channel.
[0199] 4. After receiving the address configuration command, the cloud-local dedicated cluster VPN can officially implement the address configuration command within the corresponding vpngw sub-machine. For example, the vpngw1 sub-machine can generate an address mapping policy in the iptables firewall. The relevant information of this address mapping policy can be as follows:
[0200] Chain OUTPUT (policy ACCEPT)
[0201] num target prot opt source destination
[0202] 1DNAT tcp--0.0.0.0 / 0 37.64.220.11 tcp dpt:14070to:11.165.224.44:14070
[0203] Based on the above, all subsequent data packets originating from the cloud-local dedicated cluster with a destination IP address of 37.64.220.11 and a port of 14070 will have their destination IP address converted to 11.164.224.44, thus achieving the goal of a single modification taking effect globally.
[0204] (2) Data plane process:
[0205] 1. A host with a real IP address of 11.164.49.56 within a cloud-local dedicated cluster wants to access the CVM management service in the cloud central area. The real IP address of the CVM management service is 37.64.220.11, and its service port is 14070. At this time, the source IP address (srcIp) of the first data packet (also known as a traffic packet) sent by the cloud-local dedicated cluster is 11.164.49.56, and the port is 10456 (which can be randomly generated), while the destination IP address (desIp) of the first data packet is 37.64.220.11, and the port is 14070.
[0206] 2. After being routed and forwarded, the first data packet arrives at the unified traffic exit of the cloud-local dedicated cluster (i.e., the VPN on the cloud-local dedicated cluster side). At this point, it hits the address mapping policy of the vpngw submachine and matches the address mapping policy with the real IP address 37.64.220.11 and port 14070. Therefore, the destination IP address of the first data packet can be converted to the virtual IP address 11.165.224.44 in the matched address mapping policy, while the port remains unchanged, thus obtaining the second data packet. This makes the traffic packet sent by the VPN on the cloud-local dedicated cluster side the second data packet. The srcIp of the second data packet is 11.164.49.56, port 10456 (randomly generated), and the desIp of the second data packet is 11.165.224.44, port 14070.
[0207] 3. The traffic packet (i.e. the second data packet) is sent up from the local dedicated cluster VPN to the cloud VPN. At this time, the traffic packet is still the same as in the previous step, that is, the traffic packet is still the second data packet, with srcIp 11.164.49.56, port 10456, desIp 11.165.224.44, and port 14070.
[0208] 4. After the traffic packet at the cloud-side VPN (i.e., the second data packet) is routed and forwarded, it will reach the service mapping module. The service mapping module can look up the pre-configured data. Based on the desIp (i.e., the virtual IP address of the CVM management service) of the second data packet (11.165.224.44), it finds the corresponding rsIp (i.e., the real IP address of the CVM management service) as 37.64.220.11. The service mapping module can use the found rsIp as the destination IP address to access. At this time, the destination IP address of the second data packet can be modified to the found rsIp to obtain the first data packet. The srcIp of the first data packet is 11.164.49.56, the port is 10456, and the desIp of the first data packet is 37.64.220.11, the port is 14070.
[0209] 5. After the service mapping module forwards the first data packet via routing, the first data packet can reach the CVM management service in the cloud center area according to the destination IP address 37.64.220.11. At this point, the entire packet sending and accessing link is completed. Similarly, the return packet accessing link can also be completed hop by hop.
[0210] Based on the above description, the data transmission scheme proposed in this application embodiment can have at least the following beneficial effects:
[0211] (1) Add service mapping on the cloud-local dedicated cluster side. By registering the cloud management service that the cloud-local dedicated cluster needs to access to the "Service Mapping Management Center" and generating a new virtual IP address dedicated to the management service accessed by the cloud-local dedicated cluster, the real service IP address of the cloud central area can be avoided, thus playing a role in security hardening. At this time, if the original business in the cloud-local dedicated cluster needs to access the cloud management service, the destination IP address of the data packet originally used to access the management service needs to be converted into the virtual IP address after service mapping through DNAT, so that the access link can be successfully established without modifying the code.
[0212] (2) Avoiding a large amount of repetitive manual work, the automated configuration interface greatly improves efficiency. This data transmission solution can be added by performing DNAT configuration on the operation interface. At this time, the configuration has already taken effect under the VPN, thus avoiding a large amount of repetitive configuration on multiple servers and greatly improving efficiency.
[0213] (3) Utilizing aspect-oriented programming (AOP) technology, DNAT configuration is unified and applied globally with a single configuration, facilitating operation and maintenance. This data transmission scheme unifies DNAT configuration at the VPN, ensuring real-time application of the configuration since all traffic passes through the VPN. This unified aspect-oriented approach avoids fragmented configurations, benefiting both current configuration and future maintenance. In other words, by adding DNAT configuration and other data to the VPN, services can be interconnected, avoiding the problems of scattered DNAT configurations hindering setup and maintenance, and significantly improving operational efficiency.
[0214] Based on the description of the above method embodiments, this application also discloses a data transmission device.
[0215] In one embodiment, the data transmission device can be applied to a first virtual private network gateway on the cloud-local dedicated cluster side. Specifically, it can be a computer program (including one or more instructions) running on the first virtual private network gateway, and the data transmission device can execute each step in the above method flow. Referring to Figure 8a, the data transmission device can operate the following units:
[0216] The first transmission unit 801 is used to receive the first data packet sent by the cloud local dedicated cluster, wherein the destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service in the public cloud region.
[0217] The first processing unit 802 is used to obtain the virtual Internet Protocol address of the target management service, wherein the virtual Internet Protocol address is obtained by mapping the real Internet Protocol address of the target management service.
[0218] The first processing unit 802 is further configured to modify the destination Internet Protocol address of the first data packet to the virtual Internet Protocol address to obtain the second data packet;
[0219] The first transmission unit 801 is further configured to send the second data packet to the second virtual private network gateway through the virtual private network service channel, so that the second virtual private network gateway modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtains the first data packet, and sends the first data packet to the target management service.
[0220] In one specific implementation, when the first processing unit 802 is used to obtain the virtual Internet Protocol address of the target management service, it may specifically be used to:
[0221] At least one address mapping policy is obtained from the device system of the first virtual private network gateway; wherein, an address mapping policy includes: a real Internet Protocol address of a management service, and a virtual Internet Protocol address configured for the corresponding management service;
[0222] Based on the real Internet Protocol address of the target management service, a first address mapping policy is searched from the at least one address mapping policy, wherein the first address mapping policy is an address mapping policy that includes the real Internet Protocol address of the target management service;
[0223] Obtain the virtual Internet Protocol address of the target management service from the first address mapping policy found.
[0224] In another specific implementation, the public cloud region further includes a virtual private network controller. The virtual private network controller is used to generate an address configuration instruction based on the address configuration operation detected in the terminal interface, and send the address configuration instruction to the second virtual private network gateway. The address configuration instruction includes a real Internet Protocol address for a management service and a virtual Internet Protocol address configured for the corresponding management service.
[0225] The second virtual private network gateway is used to store the address configuration instructions and send the stored address configuration instructions to the first virtual private network gateway through the virtual private network service channel;
[0226] The first transmission unit 801 can also be used to: receive address configuration instructions sent by the second virtual private network gateway through the virtual private network service channel;
[0227] The first processing unit 802 can also be used to generate an address mapping strategy in the device system of the first virtual private network gateway according to the received address configuration instruction.
[0228] In another specific embodiment, when the first processing unit 802 generates an address mapping policy in the device system of the first virtual private network gateway according to the received address configuration instruction, it may specifically be used for:
[0229] Locate the firewall in the device system of the first virtual private network gateway;
[0230] The firewall generates an address mapping policy based on the received address configuration instructions.
[0231] In another specific embodiment, when the first processing unit 802 is used to obtain the virtual Internet Protocol address of the target management service, it may specifically be used to:
[0232] Obtain the source Internet Protocol address and destination Internet Protocol address of the first data packet, wherein the source Internet Protocol address of the first data packet is the real Internet Protocol address of the cloud local dedicated cluster;
[0233] A reversible operation is performed on the source Internet Protocol address and the destination Internet Protocol address of the first data packet to obtain a new Internet Protocol address, which is used to map the real Internet Protocol address of the target management service.
[0234] The new Internet Protocol address will be used as the virtual Internet Protocol address for the target management service.
[0235] In another specific embodiment, the first transmission unit 801 can also be used to: after the target management service generates the third data packet, receive the fourth data packet sent by the second virtual private network gateway through the virtual private network service channel; wherein, the third data packet is a data packet to be sent to the cloud local dedicated cluster, the source Internet Protocol address of the third data packet is the real Internet Protocol address of the target management service, and the fourth data packet is obtained by modifying the source Internet Protocol address of the third data packet to the virtual Internet Protocol address of the target management service;
[0236] The first processing unit 802 can also be used to: obtain the real Internet Protocol address of the target management service, and modify the source Internet Protocol address of the fourth data packet to the real Internet Protocol address of the target management service to obtain the third data packet;
[0237] The first transmission unit 801 can also be used to forward the third data packet to the cloud-local dedicated cluster.
[0238] In another specific embodiment, when the first processing unit 802 is used to obtain the real Internet Protocol address of the target management service, it may specifically be used to:
[0239] At least one address mapping policy is obtained from the device system of the first virtual private network gateway; wherein, an address mapping policy includes: a real Internet Protocol address of a management service, and a virtual Internet Protocol address configured for the corresponding management service;
[0240] Based on the virtual Internet Protocol address of the target management service, a second address mapping strategy is searched from the at least one address mapping strategy, wherein the second address mapping strategy is an address mapping strategy that includes the real Internet Protocol address of the target management service;
[0241] Obtain the real Internet Protocol address of the target management service from the found second address mapping strategy.
[0242] In another specific embodiment, when the first processing unit 802 is used to obtain the real Internet Protocol address of the target management service, it may specifically be used to:
[0243] Obtain the source Internet Protocol address and destination Internet Protocol address of the fourth data packet. The destination Internet Protocol address of the fourth data packet is the real Internet Protocol address of the cloud local dedicated cluster. The source Internet Protocol address of the fourth data packet is obtained by performing a reversible operation on the source Internet Protocol address of the third data packet and the destination Internet Protocol address of the fourth data packet.
[0244] Perform the inverse operation of the reversible operation on the source Internet Protocol address and destination Internet Protocol address of the fourth data packet to obtain the source Internet Protocol address of the third data packet;
[0245] The source Internet Protocol address of the third data packet is used as the real Internet Protocol address of the target management service.
[0246] In another embodiment, the data transmission device can be applied to a second virtual private network gateway on the public cloud regional side. Specifically, it can be a computer program (including one or more instructions) running on the second virtual private network gateway, and the data transmission device can execute each step in the above method flow. Referring to Figure 8b, the data transmission device can operate the following units:
[0247] The second transmission unit 803 is used to receive a second data packet sent by the first virtual private network gateway through the virtual private network service channel. The second data packet is obtained by modifying the destination Internet Protocol address of the first data packet to the virtual Internet Protocol address of the target management service in the public cloud region. The virtual Internet Protocol address is obtained by mapping the real Internet Protocol address of the target management service. The destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service.
[0248] The second processing unit 804 is configured to modify the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtain the first data packet, and send the first data packet to the target management service.
[0249] In one specific implementation, the public cloud region further includes a service mapping module;
[0250] Accordingly, when the second processing unit 804 modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service to obtain the first data packet, and sends the first data packet to the target management service, it can be specifically used for:
[0251] Obtain the Internet Protocol address of the service mapping module;
[0252] Based on the obtained Internet Protocol address, the second data packet is routed to the service mapping module, which then obtains the real Internet Protocol address of the target management service, modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtains the first data packet, and sends the first data packet to the target management service.
[0253] In another specific embodiment, when the second processing unit 804 modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service to obtain the first data packet, it may specifically be used to:
[0254] Obtain the real Internet Protocol address of the target management service;
[0255] The destination Internet Protocol address of the second data packet is modified to the real Internet Protocol address of the target management service to obtain the first data packet.
[0256] In another specific embodiment, the virtual Internet Protocol address of the target management service is pre-configured for the target management service; correspondingly, when the second processing unit 804 obtains the real Internet Protocol address of the target management service, it may specifically be used to:
[0257] Obtain service mapping information, which includes: the real Internet Protocol address of at least one management service that the cloud-local dedicated cluster is allowed to access, and the virtual Internet Protocol address configured for the corresponding management service;
[0258] Obtain the real Internet Protocol address of the target management service from the service mapping information.
[0259] In another specific implementation, the virtual Internet Protocol address of the target management service is obtained by performing a reversible operation on the source Internet Protocol address and the destination Internet Protocol address of the first data packet, where the source Internet Protocol address of the first data packet is the real Internet Protocol address of the cloud local dedicated cluster.
[0260] Accordingly, when the second processing unit 804 is used to obtain the real Internet Protocol address of the target management service, it can specifically be used for:
[0261] Perform the inverse operation of the reversible operation on the virtual Internet Protocol address and the source Internet Protocol address of the first data packet to obtain the real Internet Protocol address of the target management service.
[0262] In another specific embodiment, the second processing unit 804 can also be used for:
[0263] After the target management service generates the third data packet, a fourth data packet generated based on the third data packet is obtained; wherein, the third data packet is a data packet to be sent to the cloud local dedicated cluster, the source Internet Protocol address of the third data packet is the real Internet Protocol address of the target management service, and the fourth data packet is obtained by modifying the source Internet Protocol address of the third data packet to the virtual Internet Protocol address of the target management service;
[0264] Correspondingly, the second transmission unit 803 can also be used to: send the fourth data packet to the first virtual private network gateway through the virtual private network service channel, so that the first virtual private network gateway modifies the source Internet Protocol address of the fourth data packet to the real Internet Protocol address of the target management service, obtains the third data packet, and forwards the third data packet to the cloud local dedicated cluster.
[0265] According to another embodiment of this application, the various units in the data transmission device shown in FIG8a or FIG8b can be individually or entirely merged into one or more other units, or some of the units can be further divided into multiple functionally smaller units. This can achieve the same operation without affecting the technical effect of the embodiments of this application. The above-mentioned units are based on logical function division. In practical applications, the function of one unit can also be implemented by multiple units, or the function of multiple units can be implemented by one unit. In other embodiments of this application, the data transmission device may also include other units. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented by multiple units working together.
[0266] According to another embodiment of this application, the data transmission apparatus shown in FIG8a or FIG8b, and the data transmission method of the embodiments of this application, can be constructed and implemented by running a computer program (including one or more instructions) capable of performing the steps involved in the various methods described above on a general-purpose computing device, such as a computer, which includes processing elements and storage elements such as a central processing unit (CPU), random access memory (RAM), and read-only memory (ROM). The computer program can be recorded on, for example, a computer-readable storage medium, loaded into the aforementioned computing device via the computer-readable storage medium, and run therein.
[0267] It is worth noting that, in the embodiments of this application, the terms "module" or "unit" refer to a computer program or part of a computer program with a predetermined function, which works together with other related parts to achieve a predetermined goal, and can be implemented wholly or partially using software, hardware (such as processing circuitry or memory), or a combination thereof. Similarly, a processor (or multiple processors or memory) can be used to implement one or more modules or units. Furthermore, each module or unit can contain a portion of the overall module or unit's functionality.
[0268] This application embodiment not only enables the successful transmission of the first data packet from the cloud-local dedicated cluster to the target management service in the public cloud region, improving the security of data transmission, but also avoids directly exposing the real Internet Protocol address of the target management service during data transmission between the cloud-local dedicated cluster and the public cloud region. This prevents attackers from breaching the network defense between the cloud-local dedicated cluster and the cloud central area based on the real Internet Protocol address of the target management service, thereby improving the security of the central cloud environment where the target management service is located.
[0269] Based on the description of the above method and device embodiments, this application also provides a computer device, which may be the first virtual private network gateway or the second virtual private network gateway mentioned above. Referring to Figure 9, the computer device includes at least a processor 901, an input interface 902, an output interface 903, and a computer storage medium 904. The processor 901, input interface 902, output interface 903, and computer storage medium 904 within the computer device can be connected via a bus or other means. The computer storage medium 904 can be stored in the memory of the computer device. The computer storage medium 904 is used to store a computer program, which includes one or more instructions. The processor 901 is used to execute one or more instructions from the computer program stored in the computer storage medium 904. The processor 901 (or CPU (Central Processing Unit)) is the computing and control core of the computer device, adapted to implement one or more instructions, specifically adapted to load and execute one or more instructions to achieve a corresponding method flow or corresponding function.
[0270] In one embodiment, when the computer device is the aforementioned first virtual private network gateway, the processor 901 described in this application embodiment can be used to perform a series of data transmission processes, specifically including: receiving a first data packet sent by the cloud-local dedicated cluster, wherein the destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service in the public cloud region; obtaining the virtual Internet Protocol address of the target management service, wherein the virtual Internet Protocol address is obtained by mapping the real Internet Protocol address of the target management service; modifying the destination Internet Protocol address of the first data packet to the virtual Internet Protocol address to obtain a second data packet; sending the second data packet to the second virtual private network gateway through the virtual private network service channel, so that the second virtual private network gateway modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service to obtain the first data packet, and sending the first data packet to the target management service, etc.
[0271] In another embodiment, when the computer device is the aforementioned second virtual private network gateway, the processor 901 described in this application embodiment can be used to perform a series of data transmission processes, specifically including: receiving a second data packet sent by the first virtual private network gateway through the virtual private network service channel, wherein the second data packet is obtained by modifying the destination Internet Protocol address of the first data packet to the virtual Internet Protocol address of the target management service in the public cloud region, wherein the virtual Internet Protocol address is obtained by mapping the real Internet Protocol address of the target management service, and the destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service; modifying the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service to obtain the first data packet, and sending the first data packet to the target management service, etc.
[0272] This application embodiment also provides a computer storage medium (memory), which is a memory device in a computer device used to store computer programs and data. It is understood that the computer storage medium here can include both the built-in storage medium in the computer device and extended storage media supported by the computer device. The computer storage medium provides storage space that stores the operating system of the computer device. Furthermore, the storage space also stores a computer program, which includes one or more instructions suitable for loading and execution by the processor 901. These instructions can be one or more program codes. It should be noted that the computer storage medium here can be high-speed RAM or non-volatile memory, such as at least one disk storage device; optionally, it can also be at least one computer storage medium located remotely from the aforementioned processor.
[0273] In one embodiment, a processor may load and execute one or more instructions stored in a computer storage medium to implement the corresponding steps in the various method embodiments described above; specifically, one or more instructions in the computer storage medium may be loaded and executed by the processor in the following steps:
[0274] Receive the first data packet sent by the cloud local dedicated cluster, wherein the destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service in the public cloud region;
[0275] Obtain the virtual Internet Protocol address of the target management service, which is obtained by mapping the real Internet Protocol address of the target management service;
[0276] The destination Internet Protocol address of the first data packet is modified to the virtual Internet Protocol address to obtain the second data packet;
[0277] The second data packet is sent to the second virtual private network gateway through the virtual private network service channel, so that the second virtual private network gateway modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtains the first data packet, and sends the first data packet to the target management service.
[0278] In one specific implementation, when obtaining the virtual Internet Protocol address of the target management service, the one or more instructions can be loaded and executed by the processor:
[0279] At least one address mapping policy is obtained from the device system of the first virtual private network gateway; wherein, an address mapping policy includes: a real Internet Protocol address of a management service, and a virtual Internet Protocol address configured for the corresponding management service;
[0280] Based on the real Internet Protocol address of the target management service, a first address mapping policy is searched from the at least one address mapping policy, wherein the first address mapping policy is an address mapping policy that includes the real Internet Protocol address of the target management service;
[0281] Obtain the virtual Internet Protocol address of the target management service from the first address mapping policy found.
[0282] In another specific implementation, the public cloud region further includes a virtual private network controller. The virtual private network controller is used to generate an address configuration instruction based on the address configuration operation detected in the terminal interface, and send the address configuration instruction to the second virtual private network gateway. The address configuration instruction includes a real Internet Protocol address for a management service and a virtual Internet Protocol address configured for the corresponding management service.
[0283] The second virtual private network gateway is used to store the address configuration instructions and send the stored address configuration instructions to the first virtual private network gateway through the virtual private network service channel;
[0284] Accordingly, the one or more instructions can be loaded and executed by the processor:
[0285] Receive the address configuration instruction sent by the second virtual private network gateway through the virtual private network service channel;
[0286] In the device system of the first virtual private network gateway, an address mapping policy is generated based on the received address configuration instruction.
[0287] In another specific implementation, in the device system of the first virtual private network gateway, when generating an address mapping policy based on the received address configuration instruction, the one or more instructions can be loaded and executed by the processor:
[0288] Locate the firewall in the device system of the first virtual private network gateway;
[0289] The firewall generates an address mapping policy based on the received address configuration instructions.
[0290] In another specific implementation, when obtaining the virtual Internet Protocol address of the target management service, the one or more instructions can be loaded and executed by the processor:
[0291] Obtain the source Internet Protocol address and destination Internet Protocol address of the first data packet, wherein the source Internet Protocol address of the first data packet is the real Internet Protocol address of the cloud local dedicated cluster;
[0292] A reversible operation is performed on the source Internet Protocol address and the destination Internet Protocol address of the first data packet to obtain a new Internet Protocol address, which is used to map the real Internet Protocol address of the target management service.
[0293] The new Internet Protocol address will be used as the virtual Internet Protocol address for the target management service.
[0294] In another specific implementation, the one or more instructions may be loaded and executed by the processor:
[0295] After the target management service generates the third data packet, it receives the fourth data packet sent by the second virtual private network gateway through the virtual private network service channel; wherein, the third data packet is a data packet to be sent to the cloud local dedicated cluster, the source Internet Protocol address of the third data packet is the real Internet Protocol address of the target management service, and the fourth data packet is obtained by modifying the source Internet Protocol address of the third data packet to the virtual Internet Protocol address of the target management service;
[0296] Obtain the real Internet Protocol address of the target management service, and modify the source Internet Protocol address of the fourth data packet to the real Internet Protocol address of the target management service to obtain the third data packet;
[0297] The third data packet is forwarded to the cloud-local dedicated cluster.
[0298] In another specific implementation, when obtaining the real Internet Protocol address of the target management service, the one or more instructions can be loaded and executed by the processor:
[0299] At least one address mapping policy is obtained from the device system of the first virtual private network gateway; wherein, an address mapping policy includes: a real Internet Protocol address of a management service, and a virtual Internet Protocol address configured for the corresponding management service;
[0300] Based on the virtual Internet Protocol address of the target management service, a second address mapping strategy is searched from the at least one address mapping strategy, wherein the second address mapping strategy is an address mapping strategy that includes the real Internet Protocol address of the target management service;
[0301] Obtain the real Internet Protocol address of the target management service from the found second address mapping strategy.
[0302] In another specific implementation, when obtaining the real Internet Protocol address of the target management service, the one or more instructions can be loaded and executed by the processor:
[0303] Obtain the source Internet Protocol address and destination Internet Protocol address of the fourth data packet. The destination Internet Protocol address of the fourth data packet is the real Internet Protocol address of the cloud local dedicated cluster. The source Internet Protocol address of the fourth data packet is obtained by performing a reversible operation on the source Internet Protocol address of the third data packet and the destination Internet Protocol address of the fourth data packet.
[0304] Perform the inverse operation of the reversible operation on the source Internet Protocol address and destination Internet Protocol address of the fourth data packet to obtain the source Internet Protocol address of the third data packet;
[0305] The source Internet Protocol address of the third data packet is used as the real Internet Protocol address of the target management service.
[0306] In another embodiment, the one or more instructions may be loaded and executed by a processor:
[0307] The second data packet sent by the first virtual private network gateway is received through the virtual private network service channel. The second data packet is obtained by modifying the destination Internet Protocol address of the first data packet to the virtual Internet Protocol address of the target management service in the public cloud region. The virtual Internet Protocol address is obtained by mapping the real Internet Protocol address of the target management service. The destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service.
[0308] The destination Internet Protocol address of the second data packet is modified to the real Internet Protocol address of the target management service to obtain the first data packet, and the first data packet is sent to the target management service.
[0309] In one specific implementation, the public cloud region further includes a service mapping module;
[0310] Correspondingly, when the destination Internet Protocol address of the second data packet is modified to the real Internet Protocol address of the target management service to obtain the first data packet, and the first data packet is sent to the target management service, the one or more instructions can be loaded and executed by the processor:
[0311] Obtain the Internet Protocol address of the service mapping module;
[0312] Based on the obtained Internet Protocol address, the second data packet is routed to the service mapping module, which then obtains the real Internet Protocol address of the target management service, modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtains the first data packet, and sends the first data packet to the target management service.
[0313] In another specific implementation, when the destination Internet Protocol address of the second data packet is modified to the real Internet Protocol address of the target management service to obtain the first data packet, the one or more instructions can be loaded and executed by the processor:
[0314] Obtain the real Internet Protocol address of the target management service;
[0315] The destination Internet Protocol address of the second data packet is modified to the real Internet Protocol address of the target management service to obtain the first data packet.
[0316] In another specific implementation, the virtual Internet Protocol address of the target management service is pre-configured for the target management service; correspondingly, when obtaining the real Internet Protocol address of the target management service, the one or more instructions can be loaded and executed by the processor:
[0317] Obtain service mapping information, which includes: the real Internet Protocol address of at least one management service that the cloud-local dedicated cluster is allowed to access, and the virtual Internet Protocol address configured for the corresponding management service;
[0318] Obtain the real Internet Protocol address of the target management service from the service mapping information.
[0319] In another specific implementation, the virtual Internet Protocol address of the target management service is obtained by performing a reversible operation on the source Internet Protocol address and the destination Internet Protocol address of the first data packet, where the source Internet Protocol address of the first data packet is the real Internet Protocol address of the cloud local dedicated cluster.
[0320] Accordingly, when obtaining the real Internet Protocol address of the target management service, the one or more instructions can be loaded and executed by the processor:
[0321] Perform the inverse operation of the reversible operation on the virtual Internet Protocol address and the source Internet Protocol address of the first data packet to obtain the real Internet Protocol address of the target management service.
[0322] In another specific implementation, the one or more instructions may be loaded and executed by the processor:
[0323] After the target management service generates the third data packet, a fourth data packet generated based on the third data packet is obtained; wherein, the third data packet is a data packet to be sent to the cloud local dedicated cluster, the source Internet Protocol address of the third data packet is the real Internet Protocol address of the target management service, and the fourth data packet is obtained by modifying the source Internet Protocol address of the third data packet to the virtual Internet Protocol address of the target management service;
[0324] The fourth data packet is sent to the first virtual private network gateway through the virtual private network service channel, so that the first virtual private network gateway modifies the source Internet Protocol address of the fourth data packet to the real Internet Protocol address of the target management service, obtains the third data packet, and forwards the third data packet to the cloud local dedicated cluster.
[0325] This application embodiment not only enables the successful transmission of the first data packet from the cloud-local dedicated cluster to the target management service in the public cloud region, improving the security of data transmission, but also avoids directly exposing the real Internet Protocol address of the target management service during data transmission between the cloud-local dedicated cluster and the public cloud region. This prevents attackers from breaching the network defense between the cloud-local dedicated cluster and the cloud central area based on the real Internet Protocol address of the target management service, thereby improving the security of the central cloud environment where the target management service is located.
[0326] It should be noted that, according to one aspect of this application, a computer program product or computer program is also provided, comprising one or more instructions stored in a computer storage medium. A processor of a computer device reads one or more instructions from the computer storage medium and executes the one or more instructions, causing the computer device to perform the methods provided in the various optional embodiments of the above-described methods. It should be understood that the above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, equivalent variations made according to the claims of this application are still within the scope of this application.
Claims
1. A data transmission method, characterized by, The method is applied to a first virtual private network gateway on a cloud local private cluster side, a virtual private network service channel exists between the first virtual private network gateway and a second virtual private network gateway on a public cloud region side, and the method comprises the following steps: receiving a first data packet sent by the cloud local private cluster, the destination Internet protocol address of the first data packet being a real Internet protocol address of a target management service in the public cloud region; obtaining a virtual Internet protocol address of the target management service, the virtual Internet protocol address being obtained by performing mapping processing on the real Internet protocol address of the target management service; modifying the destination Internet protocol address of the first data packet to the virtual Internet protocol address to obtain a second data packet; sending the second data packet to the second virtual private network gateway through the virtual private network service channel, so that the second virtual private network gateway modifies the destination Internet protocol address of the second data packet to the real Internet protocol address of the target management service to obtain the first data packet, and sends the first data packet to the target management service.
2. The method of claim 1, wherein, The step of obtaining the virtual Internet protocol address of the target management service comprises the following steps: obtaining at least one address mapping strategy from a device system of the first virtual private network gateway, wherein each address mapping strategy comprises a real Internet protocol address of a management service and a virtual Internet protocol address configured for the corresponding management service; finding a first address mapping strategy from the at least one address mapping strategy based on the real Internet protocol address of the target management service, the first address mapping strategy being the address mapping strategy containing the real Internet protocol address of the target management service; obtaining the virtual Internet protocol address of the target management service from the found first address mapping strategy.
3. The method of claim 1 or 2, wherein, The public cloud region further comprises a virtual private network controller, the virtual private network controller is configured to generate an address configuration instruction according to an address configuration operation detected in a terminal interface, and send the address configuration instruction to the second virtual private network gateway, the address configuration instruction comprising a real Internet protocol address of a management service and a virtual Internet protocol address configured for the corresponding service; the second virtual private network gateway is configured to store the address configuration instruction, and send the stored address configuration instruction to the first virtual private network gateway through the virtual private network service channel; The method further comprises the following steps: receiving the address configuration instruction sent by the second virtual private network gateway through the virtual private network service channel; generating an address mapping strategy in the device system of the first virtual private network gateway according to the received address configuration instruction.
4. The method according to any one of claims 1 to 3, characterized in that, The step of generating an address mapping strategy in the device system of the first virtual private network gateway according to the received configuration instruction comprises the following steps: finding a firewall in the device system of the first virtual private network gateway; generating an address mapping strategy in the firewall according to the received address configuration instruction.
5. The method according to any one of claims 1 to 4, characterized in that, The step of obtaining the virtual Internet protocol address of the target management service comprises the following steps: obtaining a source Internet protocol address and a destination Internet protocol address of the first data packet, the source Internet protocol address of the first data packet being a real Internet protocol address of the cloud local private cluster; performing reversible operation on the source Internet protocol address and the destination Internet protocol address of the first data packet to obtain a new Internet protocol address, the new Internet protocol address being used for mapping a real Internet protocol address of the target management service; taking the new Internet protocol address as a virtual Internet protocol address of the target management service.
6. The method according to any one of claims 1 to 5, wherein, The method further comprises: after the target management service generates a third data packet, receiving a fourth data packet sent by the second virtual private network gateway through the virtual private network service channel, wherein the third data packet is a data packet to be sent to the cloud local private cluster, the source Internet protocol address of the third data packet is a real Internet protocol address of the target management service, and the fourth data packet is obtained by modifying the source Internet protocol address of the third data packet to the virtual Internet protocol address of the target management service; obtaining the real Internet protocol address of the target management service, and modifying the source Internet protocol address of the fourth data packet to the real Internet protocol address of the target management service to obtain the third data packet; forwarding the third data packet to the cloud local private cluster.
7. The method according to any one of claims 1 to 6, wherein The obtaining of the real Internet protocol address of the target management service comprises: obtaining at least one address mapping strategy from a device system of the first virtual private network gateway, wherein each address mapping strategy comprises a real Internet protocol address of a management service and a virtual Internet protocol address configured for the corresponding management service; based on the virtual Internet protocol address of the target management service, searching for a second address mapping strategy from the at least one address mapping strategy, the second address mapping strategy being an address mapping strategy containing the real Internet protocol address of the target management service; obtaining the real Internet protocol address of the management service from the searched second address mapping strategy.
8. The method according to any one of claims 1 to 7, wherein, The obtaining of the real Internet protocol address of the target management service comprises: obtaining a source Internet protocol address and a destination Internet protocol address of the fourth data packet, the destination Internet protocol address of the fourth data packet being a real Internet protocol address of the cloud local private cluster, and the source Internet protocol address of the fourth data packet being obtained by performing reversible operation on the source Internet protocol address of the third data packet and the destination Internet protocol address of the fourth data packet; performing inverse operation on the source Internet protocol address and the destination Internet protocol address of the fourth data packet to obtain the source Internet protocol address of the third data packet; taking the source Internet protocol address of the third data packet as the real Internet protocol address of the target management service.
9. A data transmission method, characterized by, The method is applied to a second virtual private network (VPN) gateway on the public cloud regional side, where a VPN service channel exists between the second VPN gateway and the first VPN gateway on the cloud-local dedicated cluster side. The method includes: The second data packet sent by the first virtual private network gateway is received through the virtual private network service channel. The second data packet is obtained by modifying the destination Internet Protocol address of the first data packet to the virtual Internet Protocol address of the target management service in the public cloud region. The virtual Internet Protocol address is obtained by mapping the real Internet Protocol address of the target management service. The destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service. The destination Internet Protocol address of the second data packet is modified to the real Internet Protocol address of the target management service to obtain the first data packet, and the first data packet is sent to the target management service.
10. The method of claim 9, wherein, The public cloud region also includes a service mapping module; The step of modifying the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service to obtain the first data packet, and sending the first data packet to the target management service, includes: Obtain the Internet Protocol address of the service mapping module; Based on the obtained Internet Protocol address, the second data packet is routed to the service mapping module, which then obtains the real Internet Protocol address of the target management service, modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtains the first data packet, and sends the first data packet to the target management service.
11. The method of claim 9 or 10, wherein, The step of modifying the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service to obtain the first data packet includes: Obtain the real Internet Protocol address of the target management service; The destination Internet Protocol address of the second data packet is modified to the real Internet Protocol address of the target management service to obtain the first data packet.
12. The method according to any one of claims 9 to 11, wherein, The virtual Internet Protocol address of the target management service is pre-configured for the target management service, and obtaining the real Internet Protocol address of the target management service includes: Obtain service mapping information, which includes: the real Internet Protocol address of at least one management service that the cloud-local dedicated cluster is allowed to access, and the virtual Internet Protocol address configured for the corresponding management service; Obtain the real Internet Protocol address of the target management service from the service mapping information.
13. The method according to any one of claims 9 to 12, wherein, The virtual Internet Protocol address of the target management service is obtained by performing a reversible operation on the source Internet Protocol address and the destination Internet Protocol address of the first data packet, where the source Internet Protocol address of the first data packet is the real Internet Protocol address of the cloud local dedicated cluster. The process of obtaining the real Internet Protocol address of the target management service includes: Perform the inverse operation of the reversible operation on the virtual Internet Protocol address and the source Internet Protocol address of the first data packet to obtain the real Internet Protocol address of the target management service.
14. The method according to any one of claims 9 to 13, characterized in that, The method further includes: After the target management service generates the third data packet, a fourth data packet generated based on the third data packet is obtained; wherein, the third data packet is a data packet to be sent to the cloud local dedicated cluster, the source Internet Protocol address of the third data packet is the real Internet Protocol address of the target management service, and the fourth data packet is obtained by modifying the source Internet Protocol address of the third data packet to the virtual Internet Protocol address of the target management service; The fourth data packet is sent to the first virtual private network gateway through the virtual private network service channel, so that the first virtual private network gateway modifies the source Internet Protocol address of the fourth data packet to the real Internet Protocol address of the target management service, obtains the third data packet, and forwards the third data packet to the cloud local dedicated cluster.
15. The method according to any one of claims 9 to 14, wherein, The fourth data packet was generated by the second virtual private network gateway; Alternatively, the fourth data packet may be generated by the service mapping module in the public cloud region and sent to the second virtual private network gateway.
16. A data transmission apparatus, characterized by comprising: The device is applied to a first virtual private network gateway on the cloud-local dedicated cluster side, and a virtual private network service channel exists between the first virtual private network gateway and a second virtual private network gateway on the public cloud region side. The device includes: The first transmission unit is used to receive the first data packet sent by the cloud local dedicated cluster, wherein the destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service in the public cloud region. The first processing unit is used to obtain the virtual Internet Protocol address of the target management service, wherein the virtual Internet Protocol address is obtained by mapping the real Internet Protocol address of the target management service; The first processing unit is further configured to modify the destination Internet Protocol address of the first data packet to the virtual Internet Protocol address to obtain the second data packet; The first transmission unit is further configured to send the second data packet to the second virtual private network gateway through the virtual private network service channel, so that the second virtual private network gateway modifies the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtains the first data packet, and sends the first data packet to the target management service.
17. A data transmission apparatus, characterized by comprising: The device is applied to a second virtual private network gateway on the public cloud regional side, and a virtual private network service channel exists between the second virtual private network gateway and the first virtual private network gateway on the cloud local dedicated cluster side. The device includes: The second transmission unit is configured to receive a second data packet sent by the first virtual private network gateway through the virtual private network service channel, the second data packet is obtained by modifying a destination Internet Protocol address of the first data packet to a virtual Internet Protocol address of a target management service in the public cloud region, the virtual Internet Protocol address is obtained by performing mapping processing on a real Internet Protocol address of the target management service, and the destination Internet Protocol address of the first data packet is the real Internet Protocol address of the target management service. The second processing unit is configured to modify the destination Internet Protocol address of the second data packet to the real Internet Protocol address of the target management service, obtain the first data packet, and send the first data packet to the target management service.
18. A computer device comprising an input interface and an output interface, characterized in that, Further comprising: a processor and a computer storage medium; The processor is adapted to implement one or more instructions, the computer storage medium stores one or more instructions, the one or more instructions are adapted to be loaded and executed by the processor to implement the data transmission method in any one of claims 1-8; or the one or more instructions are adapted to be loaded and executed by the processor to implement the data transmission method in any one of claims 9-15.
19. A computer storage medium, comprising, The computer storage medium stores one or more instructions, the one or more instructions are adapted to be loaded and executed by the processor to implement the data transmission method in any one of claims 1-8; or the one or more instructions are adapted to be loaded and executed by the processor to implement the data transmission method in any one of claims 9-15.
20. A computer program product, characterised in that, The computer program product comprises one or more instructions; when the one or more instructions in the computer program are executed by the processor, the data transmission method in any one of claims 1-8 is implemented; or when the one or more instructions in the computer program are executed by the processor, the data transmission method in any one of claims 9-15 is implemented.