CN104468315A - Method for accelerating VPN based on intelligent gateway - Google Patents

Method for accelerating VPN based on intelligent gateway Download PDF

Info

Publication number
CN104468315A
CN104468315A CN201410783995.3A CN201410783995A CN104468315A CN 104468315 A CN104468315 A CN 104468315A CN 201410783995 A CN201410783995 A CN 201410783995A CN 104468315 A CN104468315 A CN 104468315A
Authority
CN
China
Prior art keywords
vpn
intelligent gateway
routing rule
passage
acceleration based
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CN201410783995.3A
Other languages
Chinese (zh)
Inventor
陈永超
晏春平
张定理
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Shanghai Gongjin Communication Technology Co Ltd
Original Assignee
Shanghai Gongjin Communication Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Shanghai Gongjin Communication Technology Co Ltd filed Critical Shanghai Gongjin Communication Technology Co Ltd
Priority to CN201410783995.3A priority Critical patent/CN104468315A/en
Publication of CN104468315A publication Critical patent/CN104468315A/en
Pending legal-status Critical Current

Links

Abstract

The invention relates to a method for accelerating a VPN based on an intelligent gateway. The method includes the steps that a VPN channel is established based on an L2TP protocol; VPN acceleration configuration is issued, and a strategy routing rule is added; a user selects the mode for accessing Internet data according to a matching result of the strategy routing rule, in other words, the user judges whether the strategy routing rule can be matched or not, if yes, the user accesses the Internet data from the VPN channel, and otherwise the user accesses the Internet data from common broadband connection. By the adoption of the structure, the method for accelerating the VPN based on the intelligent gateway introduces the realization process of the VPN acceleration technology on the intelligent gateway; a target address needing VPN acceleration is configured on the intelligent gateway, so a terminal device can enter an acceleration channel only when accessing data in VPN configuration while the terminal device still enters a common broadband network when accessing common data; thus, the user can access the network without pressure, and the method is wider in application range.

Description

The method of VPN acceleration is realized based on intelligent gateway
Technical field
The present invention relates to Internet technical field, particularly relate to VPN speed technology field, specifically refer to a kind of method realizing VPN acceleration based on intelligent gateway.
Background technology
Along with the development of computer technology explosion type and universal, more people are more and more higher to computer applications demand, some needs are under the environment of low network speed, want to realize connecting game server at a high speed, the app store needing high-speed downloads mobile device had, also somebody needs to browse external immigrant or other study abroad relevant website, these demands are due to the restriction of certain current conditions, cannot realize on common broadband network, just need to rely on VPN speed technology, and a lot of VPN service is charged according to uninterrupted, if dialled by terminal equipment VPN or other gateway devices VPN dialing, will cause to browse does not need the content accelerated also can walk VPN passage, cause unnecessary waste.
In network practical application, often there will be these problems: for online game player, because of the limitation of network speed, often perplex by the problem of network delay, for the scholar preparing to study abroad, due to the limitation of various condition, each World Jam of wanting to access cannot be accessed abroad, for the white collar of often going on business, the secret of frequent worry company is intercepted on the internet by hacker, if often to the app store downloading software of mobile device, time what but network speed was slow allows people go mad, one is just needed to support the family gateway equipment that VPN accelerates, if dialled by common PC process VPN, just cannot realize sharing of VPN passage, if by the dialing of common VPN acceleration equipment, the VPN passage that just establishment one is common, all data all can be gone out from this passage, if VPN service is by flow charging, the waste that there is no need will be caused.
Summary of the invention
The object of the invention is the shortcoming overcoming above-mentioned prior art, provide a kind of can realize support terminal equipment only just can walk to accelerate when accessing the data in VPN configuration logical, user without pressure accesses network, there is broader applications scope realize based on intelligent gateway the method that VPN accelerates.
To achieve these goals, of the present invention based on intelligent gateway realize VPN accelerate method there is following formation:
Should realize the method for VPN acceleration based on intelligent gateway, its main feature is, described method comprises the following steps:
(1) VPN passage is created;
(2) VPN accelerates configuration distributing and adds policybased routing rule;
(3) user selects the mode of access internet data according to the matching result of policybased routing rule.
Preferably, described establishment VPN passage, comprises the following steps:
(1-1) judge that wide area network connects whether opening, if so, then continue step (1-2), otherwise continue step (1-3);
(1-2) create VPN passage, then continue step (2);
(1-3), when waiting until that wide area network connects unlatching, step (1-2) is continued.
Preferably, described establishment VPN passage, is specially:
VPN passage is created based on L2TP agreement.
Preferably, described VPN accelerates configuration distributing, is specially:
VPN accelerates to be configured to JavaScript object representation and issues.
Preferably, described VPN accelerates configuration distributing and adds policybased routing rule, comprises the following steps:
(2-1) judge that VPN accelerates the linking objective of configuration, if target is domain name, then continue step (2-2), if target is IP address, then continue step (2-3);
(2-2) be IP address by aiming field name analysis, then continue step (2-3);
(2-3) policybased routing rule is added.
More preferably, described is IP address by aiming field name analysis, is specially:
Parsing this aiming field name analysis by DNS proxy process is IP address.
More preferably, described interpolation policybased routing rule, comprises the following steps:
(2-3-1) whether the VPN passage described in judgement is successfully established, and if so, then continues step (2-3-2), otherwise continues step (2-3-3);
(2-3-2) add routing rule, then continue step (3);
(2-3-3), after waiting for the success of VPN Path Setup, step (2-3-2) is continued.
Preferably, described user selects the mode of access internet data according to the matching result of policybased routing rule, comprises the following steps:
(3-1) user judges whether to match policybased routing rule, if so, then continues step (3-2), otherwise continues step (3-3);
(3-2) user is from described VPN channel access internet data;
(3-3) user is from common wide connected reference internet data.
Preferably, described intelligent gateway is home gateway.
Have employed the method realizing VPN acceleration based on intelligent gateway in this invention, describe the implementation procedure of a kind of VPN speed technology on intelligent gateway, by intelligent gateway configuring the destination address needing VPN to accelerate, can support terminal equipment only access VPN configuration in data time, just can walk accelerated passage, and access common data, still walk common broadband network, thus make user's power accesses network with no pressure, there is range of application widely.
Accompanying drawing explanation
Fig. 1 is the flow chart realizing the method that VPN accelerates based on intelligent gateway of the present invention.
Fig. 2 of the present inventionly realizes based on intelligent gateway the method that VPN accelerates and is applied to the flow chart of a specific embodiment.
Embodiment
In order to more clearly describe technology contents of the present invention, conduct further description below in conjunction with specific embodiment.
PPTP (Point to Point Tunneling Protocol, Point to Point Tunnel Protocol) and L2TP (Layer 2TunnelingProtocol, Level 2 Tunnel Protocol) be the conventional agreements of VPN technologies two, L2TP uses Multiple tunnel, Header compression, tunnel authentication are provided, and PPTP does not support tunnel authentication, and use single tunnel, so patent of the present invention uses L2TP agreement to create VPN passage.
Patent of the present invention employs and includes but not limited to: cross compile openl2tp source code, DNS (Domain Name System, domain name system) agency, regular expression is resolved, policybased routing, JSON (JavaScript Object Notation, JavaScript object representation) resolve, the technology such as PPP (Point to Point Protocol, point-to-point protocol) process PID (Packet Identifier, bag indications) identification.
As shown in Figure 1, to achieve these goals, the method realizing VPN acceleration based on family's webmaster of the present invention, comprises the following steps:
(1) VPN passage is created;
(2) VPN accelerates configuration distributing and adds policybased routing rule;
(3) user selects the mode of access internet data according to the matching result of policybased routing rule.
In one preferably execution mode, described establishment VPN passage, comprises the following steps:
(1-1) judge that wide area network connects whether opening, if so, then continue step (1-2), otherwise continue step (1-3);
(1-2) create VPN passage, then continue step (2);
(1-3), when waiting until that wide area network connects unlatching, step (1-2) is continued.
In one preferably execution mode, described establishment VPN passage, is specially:
VPN passage is created based on L2TP agreement.In actual applications, when not needing tunnel authentication, the agreement of other modes can also be adopted to carry out the foundation of VPN passage.
In one preferably execution mode, described VPN accelerates configuration distributing, is specially:
VPN accelerates to be configured to JavaScript object representation and issues.
In one preferably execution mode, described VPN accelerates configuration distributing and adds policybased routing rule, comprises the following steps:
(2-1) judge that VPN accelerates the linking objective of configuration, if target is domain name, then continue step (2-2), if target is IP address, then continue step (2-3);
(2-2) be IP address by aiming field name analysis, then continue step (2-3);
(2-3) policybased routing rule is added.
In a kind of better execution mode, described is IP address by aiming field name analysis, is specially:
Parsing this aiming field name analysis by DNS proxy process is IP address.
In a kind of better execution mode, described interpolation policybased routing rule, comprises the following steps:
(2-3-1) whether the VPN passage described in judgement is successfully established, and if so, then continues step (2-3-2), otherwise continues step (2-3-3);
(2-3-2) add routing rule, then continue step (3);
(2-3-3), after waiting for the success of VPN Path Setup, step (2-3-2) is continued.
In one preferably execution mode, described user selects the mode of access internet data according to the matching result of policybased routing rule, comprises the following steps:
(3-1) user judges whether to match policybased routing rule, if so, then continues step (3-2), otherwise continues step (3-3);
(3-2) user is from described VPN channel access internet data;
(3-3) user is from common wide connected reference internet data.
In one preferably execution mode, described intelligent gateway is home gateway.In actual applications, can also be that other can configure the intelligent gateway that VPN accelerates destination address.
The present invention is introduced further below with a specific embodiment:
As shown in Figure 2, the method concrete steps in this specific embodiment are as follows:
Patent of the present invention needs to use embedded cross Compile toolchain cross compile openl2tp source code, obtains L2TP binary file and carries out VPN dialing.Owing to needing the pid of the ppp process recording openl2tp pull-up, L2TP configuration information is removed to facilitate when pull-up L2TP process record L2TP Tunnel IP address or WAN connect fault when WAN connects UP, so need amendment ppp_unix.c file, after l2tp pull-up ppp process, the PID of this PPP process is needed to send out message to state processing process, preserve this PID, after tunnel dial-up success, preserve tunnel address and tunnel state.
(1) VPN passage is created.Maximum support 8 VPN passages, passage is called in ppp0 ~ 7 minimum untapped as tunnel name.When VPN creates, whether be UP state, as then created VPN passage for UP state, creating successfully, returning successfully, and recording success status, VPN passage creates unsuccessfully, returns and creates unsuccessfully if judging that WAN connects.As WAN connects for DOWN state, when waiting for that WAN connects UP, then create VPN passage.
(2) be configured to JSON form issue, IP address is supported in this configuration, IP address range, IP/ mask, domain name, the forms such as the regular expression of domain name.If the target issuing configuration is IP address, then judge whether VPN passage creates successfully, if passage is normal, then directly add policybased routing rule, if channel abnormal, then wait for that passage adds policybased routing rule time normal again.If the target issued is domain name, then this configuration is sent to DNS proxy process, when user accesses this domain name, DNS proxy process is had to parse the IP address of this domain name, be saved in database, if passage is normal, add policybased routing rule, if channel abnormal, wait for that passage adds policybased routing rule after normal again.
(3), when user surfs the Net, meeting first matching strategy routing rule, if match policybased routing rule, from VPN channel access internet data, otherwise can walk default route from common wide connected reference internet data.
Have employed the method realizing VPN acceleration based on intelligent gateway in this invention, describe the implementation procedure of a kind of VPN speed technology on intelligent gateway, by intelligent gateway configuring the destination address needing VPN to accelerate, can support terminal equipment only access VPN configuration in data time, just can walk accelerated passage, and access common data, still walk common broadband network, thus make user's power accesses network with no pressure, there is range of application widely.
In this description, the present invention is described with reference to its specific embodiment.But, still can make various amendment and conversion obviously and not deviate from the spirit and scope of the present invention.Therefore, specification and accompanying drawing are regarded in an illustrative, rather than a restrictive.

Claims (9)

1. realize a method for VPN acceleration based on intelligent gateway, it is characterized in that, described method comprises the following steps:
(1) VPN passage is created;
(2) VPN accelerates configuration distributing and adds policybased routing rule;
(3) user selects the mode of access internet data according to the matching result of policybased routing rule.
2. the method realizing VPN acceleration based on intelligent gateway according to claim 1, it is characterized in that, described establishment VPN passage, comprises the following steps:
(1-1) judge that wide area network connects whether opening, if so, then continue step (1-2), otherwise continue step (1-3);
(1-2) create VPN passage, then continue step (2);
(1-3), when waiting until that wide area network connects unlatching, step (1-2) is continued.
3. the method realizing VPN acceleration based on intelligent gateway according to claim 1, it is characterized in that, described establishment VPN passage, is specially:
VPN passage is created based on L2TP agreement.
4. the method realizing VPN acceleration based on intelligent gateway according to claim 1, is characterized in that, described VPN accelerates configuration distributing, is specially:
VPN accelerates to be configured to JavaScript object representation and issues.
5. the method realizing VPN acceleration based on intelligent gateway according to claim 1, is characterized in that, described VPN accelerates configuration distributing and also adds policybased routing rule, comprises the following steps:
(2-1) judge that VPN accelerates the linking objective of configuration, if target is domain name, then continue step (2-2), if target is IP address, then continue step (2-3);
(2-2) be IP address by aiming field name analysis, then continue step (2-3);
(2-3) policybased routing rule is added.
6. the method realizing VPN acceleration based on intelligent gateway according to claim 5, it is characterized in that, described is IP address by aiming field name analysis, is specially:
Parsing this aiming field name analysis by DNS proxy process is IP address.
7. the method realizing VPN acceleration based on intelligent gateway according to claim 5, is characterized in that, described interpolation policybased routing rule, comprises the following steps:
(2-3-1) whether the VPN passage described in judgement is successfully established, and if so, then continues step (2-3-2), otherwise continues step (2-3-3);
(2-3-2) add routing rule, then continue step (3);
(2-3-3), after waiting for the success of VPN Path Setup, step (2-3-2) is continued.
8. the method realizing VPN acceleration based on intelligent gateway according to claim 1, is characterized in that, described user selects the mode of access internet data according to the matching result of policybased routing rule, comprises the following steps:
(3-1) user judges whether to match policybased routing rule, if so, then continues step (3-2), otherwise continues step (3-3);
(3-2) user is from described VPN channel access internet data;
(3-3) user is from common wide connected reference internet data.
9. the method realizing VPN acceleration based on intelligent gateway according to claim 1, it is characterized in that, described intelligent gateway is home gateway.
CN201410783995.3A 2014-12-16 2014-12-16 Method for accelerating VPN based on intelligent gateway Pending CN104468315A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201410783995.3A CN104468315A (en) 2014-12-16 2014-12-16 Method for accelerating VPN based on intelligent gateway

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201410783995.3A CN104468315A (en) 2014-12-16 2014-12-16 Method for accelerating VPN based on intelligent gateway

Publications (1)

Publication Number Publication Date
CN104468315A true CN104468315A (en) 2015-03-25

Family

ID=52913720

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201410783995.3A Pending CN104468315A (en) 2014-12-16 2014-12-16 Method for accelerating VPN based on intelligent gateway

Country Status (1)

Country Link
CN (1) CN104468315A (en)

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104993994A (en) * 2015-05-25 2015-10-21 小米科技有限责任公司 Connection method and device of virtual private network
CN106533887A (en) * 2016-12-13 2017-03-22 安徽声讯信息技术有限公司 Method for accelerating data transmission at voice terminal of intelligent network based on cloud computing
CN106656648A (en) * 2015-11-04 2017-05-10 中国电信股份有限公司 Application flow dynamic protection method and system based on household gateway, and household gateway
CN107666444A (en) * 2017-10-10 2018-02-06 网宿科技股份有限公司 A kind of method and system of data traffic route
CN108600010A (en) * 2018-04-26 2018-09-28 昆明俊云科技有限公司 Data transmission method and device
CN109274704A (en) * 2017-07-17 2019-01-25 中国电信股份有限公司 TCP acceleration method and device, acceleration effect judge controller and gateway
CN109547270A (en) * 2019-01-04 2019-03-29 烽火通信科技股份有限公司 A kind of method for network access control and system based on vCPE
CN110557320A (en) * 2019-09-11 2019-12-10 上海市共进通信技术有限公司 System and method for realizing VPN plug-in sea panning acceleration function based on home intelligent gateway
CN112565048A (en) * 2020-11-20 2021-03-26 华云数据控股集团有限公司 Three-layer VPN (virtual private network) network creation method, three-layer VPN network data transmission method, three-layer VPN network creation device, three-layer VPN network data transmission device and electronic equipment
CN114050948A (en) * 2021-11-09 2022-02-15 中国电信股份有限公司 VPN acceleration method, device, system and storage medium thereof
CN114765580A (en) * 2020-12-30 2022-07-19 腾讯科技(深圳)有限公司 Network acceleration method, device, equipment and storage medium for out-of-domain network resources
CN114978806A (en) * 2022-05-05 2022-08-30 上海联虹技术有限公司 Data transmission method based on hardware acceleration, device and processor thereof

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN201467150U (en) * 2009-05-25 2010-05-12 上海恩际恩网络科技有限公司 Network game accelerating system based on overlay network
CN102263687A (en) * 2011-08-11 2011-11-30 武汉思为同飞网络技术有限公司 VPN (virtual private network) speed-up gateway in WAN (wide area network) as well as speed-up communication and method thereof
EP2403206A1 (en) * 2010-06-30 2012-01-04 Juniper Networks, Inc. Multi-service vpn network client for mobile device having integrated acceleration
CN202160197U (en) * 2011-08-11 2012-03-07 武汉思为同飞网络技术有限公司 Accelerating communication device based on virtual private network (VPN) accelerating gateway of wide area network
CN103532867A (en) * 2013-10-30 2014-01-22 四川迅游网络科技股份有限公司 Acceleration transmission method and system for network data

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN201467150U (en) * 2009-05-25 2010-05-12 上海恩际恩网络科技有限公司 Network game accelerating system based on overlay network
EP2403206A1 (en) * 2010-06-30 2012-01-04 Juniper Networks, Inc. Multi-service vpn network client for mobile device having integrated acceleration
CN102263687A (en) * 2011-08-11 2011-11-30 武汉思为同飞网络技术有限公司 VPN (virtual private network) speed-up gateway in WAN (wide area network) as well as speed-up communication and method thereof
CN202160197U (en) * 2011-08-11 2012-03-07 武汉思为同飞网络技术有限公司 Accelerating communication device based on virtual private network (VPN) accelerating gateway of wide area network
CN103532867A (en) * 2013-10-30 2014-01-22 四川迅游网络科技股份有限公司 Acceleration transmission method and system for network data

Cited By (17)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104993994A (en) * 2015-05-25 2015-10-21 小米科技有限责任公司 Connection method and device of virtual private network
CN106656648A (en) * 2015-11-04 2017-05-10 中国电信股份有限公司 Application flow dynamic protection method and system based on household gateway, and household gateway
CN106656648B (en) * 2015-11-04 2020-06-05 中国电信股份有限公司 Application flow dynamic protection method and system based on home gateway and home gateway
CN106533887A (en) * 2016-12-13 2017-03-22 安徽声讯信息技术有限公司 Method for accelerating data transmission at voice terminal of intelligent network based on cloud computing
CN109274704A (en) * 2017-07-17 2019-01-25 中国电信股份有限公司 TCP acceleration method and device, acceleration effect judge controller and gateway
CN107666444B (en) * 2017-10-10 2020-05-26 网宿科技股份有限公司 Method and system for routing data flow
CN107666444A (en) * 2017-10-10 2018-02-06 网宿科技股份有限公司 A kind of method and system of data traffic route
CN108600010A (en) * 2018-04-26 2018-09-28 昆明俊云科技有限公司 Data transmission method and device
CN109547270A (en) * 2019-01-04 2019-03-29 烽火通信科技股份有限公司 A kind of method for network access control and system based on vCPE
CN110557320A (en) * 2019-09-11 2019-12-10 上海市共进通信技术有限公司 System and method for realizing VPN plug-in sea panning acceleration function based on home intelligent gateway
CN110557320B (en) * 2019-09-11 2022-01-28 太仓市同维电子有限公司 System and method for realizing VPN plug-in sea panning acceleration function based on home intelligent gateway
CN112565048A (en) * 2020-11-20 2021-03-26 华云数据控股集团有限公司 Three-layer VPN (virtual private network) network creation method, three-layer VPN network data transmission method, three-layer VPN network creation device, three-layer VPN network data transmission device and electronic equipment
CN114765580A (en) * 2020-12-30 2022-07-19 腾讯科技(深圳)有限公司 Network acceleration method, device, equipment and storage medium for out-of-domain network resources
CN114765580B (en) * 2020-12-30 2023-11-03 腾讯科技(深圳)有限公司 Network acceleration method, device, equipment and storage medium for off-domain network resources
CN114050948A (en) * 2021-11-09 2022-02-15 中国电信股份有限公司 VPN acceleration method, device, system and storage medium thereof
CN114050948B (en) * 2021-11-09 2023-01-06 中国电信股份有限公司 VPN acceleration method, device, system and storage medium thereof
CN114978806A (en) * 2022-05-05 2022-08-30 上海联虹技术有限公司 Data transmission method based on hardware acceleration, device and processor thereof

Similar Documents

Publication Publication Date Title
CN104468315A (en) Method for accelerating VPN based on intelligent gateway
EP3300319B1 (en) Distributing service function chain data and service function instance data in a network
US10313858B2 (en) Service layer interworking using MQTT protocol
US20180287937A1 (en) Processing data packets using a policy based network path
CN103339901B (en) Terminal in content guiding network environment and the communication means of intermediate node and terminal and intermediate node
US7849495B1 (en) Method and apparatus for passing security configuration information between a client and a security policy server
KR102388195B1 (en) BRAS system-based message packaging method and device
US8171541B2 (en) Enabling provider network inter-working with mobile access
CN101902482B (en) Method and system for realizing terminal security admission control based on IPv6 (Internet Protocol Version 6) automatic configuration
WO2012100531A1 (en) Method, apparatus and system for forwarding packet
JP5679343B2 (en) Cloud system, gateway device, communication control method, and communication control program
CN110089078A (en) The method and apparatus of business transponder via dynamic coverage network is provided
JP4598308B2 (en) Data communication system and data communication method
CN104168302B (en) Equipment manipulation implementation method, system and proxy gateway
CN107666426A (en) A kind of IPv6 access systems of Android platform
CN115589383A (en) eBPF-based virtual machine data transmission method, device, equipment and storage medium
JP7339429B2 (en) Message transmission/reception method and device, and communication system
CN103051626A (en) Authentication method and network device
JP2013126219A (en) Transfer server and transfer program
US11836382B2 (en) Data read method, data storage method, electronic device, and computer program product
CN108270869A (en) A kind of method for realizing a variety of portal certifications and suspension advertisement in router gateway
CN102917071B (en) A kind of tunnel connection request distribution method and device
JP2018061244A (en) Device and method for data packet processing
Hata A bridging VPN for connecting wireless sensor networks to data centers
CN101854363B (en) Information resource access method based on inter-network segment based on instant communication protocol

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
RJ01 Rejection of invention patent application after publication

Application publication date: 20150325

RJ01 Rejection of invention patent application after publication