A kind of acceleration communicator that quickens gateway based on wide area network VPN
Technical field
The utility model relates to a kind ofly recombinates, replaces, compresses the technology of encapsulation process to the network service message, relates in particular to a kind of acceleration communicator that quickens gateway based on wide area network VPN.
Background technology
Development along with Internet (internet or wide area network); More and more enterprises, colleges and universities and government bodies begin to adopt the internet to communicate application; E-Government, ecommerce have become a kind of live and work mode of people; The mutual dependence that Internet has been produced height of data between the distributed enterprise, large transfer of data such as Web TV, video conference, file transfer have become a kind of trend in addition.But in fact, this environment complicated and changeable of Internet, cause postponing big, packet loss is high, has greatly influenced the transmission of data.
Current, the agreement of developing for Network Transmission is difficult to adapt to the wide area network complex environment.TCP is common transport layer network communication protocol, and UDP (User Datagram Protoco, User Datagram Protocol) difference, and TCP has mechanism such as ACK affirmation, overtime re-transmission, traffic management and congested control.But, because it is mutual to need two of transmitting-receivings to carry out, cause the expense of communication thus, in the bigger wide area network of retardation ratio, will cause the decline of communication performance.The application protocol that part is commonly used such as People Near Me agreement CIFS, microsoft mail interface protocol MAPI etc., also exists a large amount of alternately, causes data transmission rate low.
Secondly, be flooded with the bulk redundancy repeating data in the network, taken massive band width, influenced other business.Notice such as the corporate HQ; Each employee of affiliated institutions is if need read; Usually each computer all reaches corresponding file through transmission line above headquarters server, and identical data has transmitted many times in the line like this, and is lower to the utilance of line bandwidth.And as the Distribution Center of business data storage backup, there is a large amount of repeating data transmission in data center especially.Repeating data takies valuable network bandwidth resources, has caused important business data can't obtain sufficient Internet resources.
In addition; In order to protect fail safe in the wide area network message transmission; VPN technologies are through encrypting and the checking network traffics are protected at wide area network transmission private information and can be stolen and distort, thus and unsafe Internet on opened up the private network of a safety.But the data of encryption using ipsec are because additional overhead further reduces communication performance.
To sum up several kinds of reasons make that wide area network internetwork communication speed of performance is seriously influenced, even are difficult to keep normal use.
In order to address this problem, traditional method is exactly the bandwidth of constantly upgrading, and restriction is used, and (Quality of Service, service quality are a kind of security mechanisms of network, are with a kind of technology that solves problems such as network delay and obstruction to implement Qos.) etc., but this is to cure the symptoms, not the disease, and the upgrading bandwidth incurs great expense, Qos can only be difficult to the wan environment of complicacy is exerted an influence to specific zone and specific service.Therefore traditional method is passive, cures the symptoms, not the disease.
Summary of the invention
The purpose of the utility model is exactly to overcome the shortcoming and deficiency that prior art exists, and a kind of acceleration communicator that quickens gateway based on wide area network VPN is provided.The utility model can improve the transmission speed of network data greatly, reduces redundant repeating data occupied bandwidth, can safe guarantee be provided to the transmission data, and has increased the adaptive capacity of communication to wan networking environment.
One, a kind of wide area network VPN quickens gateway
This acceleration gateway is that a kind of its Hardware configuration is Intel Core 2Duo E6400CPU, 128M FLASH, 1G RAM, 1TB HardDisk, and the main frame of linux operating system is installed.
Its operational module comprises network protocol stack, IPSec and internet key exchange module, ACK proxy module, TCP agency and tunnel module, group bag/data label buffer memory/compression module, uses encapsulation library module and data label buffer memory storehouse;
Network protocol stack, IPSec and internet key exchange module, TCP agency and tunnel module and network protocol stack call successively, go into a closed-loop system power function that the library module of the then unidirectional calling application encapsulation of TCP agency and tunnel module simultaneously provides;
ACK proxy module, group bag/data label buffer memory/compression module, IPSec and internet key exchange module are called successively, organize simultaneously that bag/data label buffer memory/compression module is then unidirectional to call the power function that data label buffer memory storehouse provides.
Two, a kind of acceleration communicator that quickens gateway based on wide area network VPN
This acceleration communicator is to quicken communicator between a kind of two sub-net of striding wide area network.
This acceleration communicator comprises that first subnet, the VPN that are communicated with successively quicken gateway, wide area network, the 2nd VPN acceleration gateway and second subnet;
In first subnet, be provided with a client computer;
Be provided with a data server at second subnet.
This acceleration communicator operation principle embodies through following steps:
1. at first corresponding acceleration strategy is set, and foundation need be carried out the vpn tunneling that TCP uses encapsulation at VPN acceleration gateway and the 2nd VPN acceleration gateway;
2. a VPN quickens gateway to mail to the TCP message of data server from client computer; The surrogate data method server is forged fast and is replied to client computer on the one hand, and the request msg that causes client computer will send to data server fast sends to a VPN and quickens gateway; On the other hand with the request msg that receives package, the data label buffer memory is quoted, processed compressed;
3. VPN acceleration gateway carries out IPSec encapsulation and TCP application encapsulation process to the TCP message of going out, and mails to the 2nd VPN at last and quickens gateway;
4. the 2nd VPN quickens the TCP encapsulation of data that gateway received and handled entering, carries out the IPSec decapsulation successively, quickens the message decapsulation, is dealt into data server to the message after handling at last;
5. the 2nd VPN acceleration gateway carries out the encapsulation process of similar VPN acceleration gateway and sends to a VPN quickening gateway to the response message of data server;
6. VPN acceleration gateway carries out decapsulation reduction processing to the TCP encapsulation of data that quickens gateway 20 from the 2nd VPN, handles sending to client computer at last, to communication process of this completion.
The utility model is compared with traditional approach and is had the following advantages:
1, adopt innovation based on Transmission Control Protocol ACK agent skill group
Through monitoring the TCP message, the analog end main frame carries out ACK replys, and confirms that on wide area network this has great importance for increasing substantially transmission speed thereby avoided both sides to wait for;
2, based on the group packet technology and the compress technique of data flow
At a data message that quickens to carry in the message a plurality of common messages; Improve the once quantity of the data message of transmission; Simultaneously message is carried out LZO (Lempel-Ziv-Oberhumer; Be a kind of data compression algorithm of being devoted to decompress(ion) speed, this algorithm is a lossless compression, and the reference implementation program is a thread-safe.) the high velocity stream compression, eliminate redundant data, further improve the efficient of transfer of data;
3, adopt data label buffer memory (DLC) technology of innovation
When identical data slice secondary transmitted, server end only need transmit and refer to client gateways accordingly, and client is searched data slice, restore data by reference;
4, technological based on the secure tunnel of IPSec VPN;
This structure is quickened the tunnel transmission data through encrypting on the gateway system at wide area network VPN, has guaranteed the security reliability of data;
5, adopt the disk buffering technology
Accelerate the conventional data access speed on the one hand, have huge memory space on the other hand;
6, can compatible NAT (network address translation) agreement, can pass through any common NAT device, and can not cause data problem;
7, employing is based on the tunnel transmission safeguards technique of http protocol
The IPSec message is encapsulated in passing through NAT in the HTTP message, improves the reliability of tunnel transmission.
In a word; The utility model through Transmission Control Protocol ACK agent skill group and to message package, data label buffer memory replacement, compression encapsulation process; Reduce the transmission of repeating data, and improve the transfer of data of some application, thus elevator chain circuit-switched data transfer rate significantly; The utility model has been saved the cost that the different sub-network connection is disposed between wide area network greatly; Through disposing accelerating system; Solved problems such as wide area network bandwidth, delay with low cost, made communication between the different sub-network, greatly strengthened the high speed property and the reliability of network as same local area network communication.
Description of drawings
Fig. 1 is that this wide area network VPN quickens gateway operational module block diagram;
Fig. 2 is to the TCP message form behind the burst that packages;
Fig. 3 carries out the form after the data label buffer memory is quoted replacement to the TCP message;
Fig. 4 is the form that the TCP message is carried out IPSec and TCP application encapsulation;
Fig. 5 is a kind of structural representation that quickens the acceleration communicator of gateway based on wide area network VPN;
Fig. 6 is that VPN acceleration gateway quickens transmission encapsulation flow chart to the TCP message;
Fig. 7 is that VPN acceleration gateway quickens to transmit the decapsulation flow chart to the TCP message.
Wherein:
00-VPN quickens gateway,
The 1-network protocol stack,
2-IPSec and internet key exchange module,
3-ACK proxy module module,
4-TCP agency and tunnel module,
5-organizes bag/compression/data label cache module,
6-uses the encapsulation library module,
7-data label buffer memory storehouse;
10-the one VPN quickens gateway;
20-the 2nd VPN quickens gateway;
100-first subnet;
200-client computer (client);
300-Internet (wide area network or internet);
400-second subnet;
500-server (server).
Main abbreviation:
VPN (Virtual Private Network)-Virtual Private Network;
IPSec (IP Security)-IP layer security protocol;
The Internet-internet;
The TCP-transmission control protocol;
The HTTP-HTTP;
The TCP/IP-network protocol stack;
IPSec/IKE-IPSec and internet key exchange module;
TCPPT-TCP agency and tunnel module;
The ACKP-ACK proxy module;
RNSPEED-group bag/data label buffer memory/compression module;
Intel Core 2Duo E6400CPU-model is the central processing unit of Core 2Duo E6400;
128M FLASH-capacity is the flash memory of 128M;
1G RAM-capacity is the random access memory of 1G;
1TB HardDisk-capacity is the disk of 1TB.
Embodiment
Further specify below in conjunction with accompanying drawing and embodiment:
One, a kind of wide area network VPN quickens gateway
1, overall
Like Fig. 1, this acceleration gateway is that a kind of its Hardware configuration is Intel Core 2Duo E6400CPU, 128M FLASH, 1G RAM, 1TB HardDisk, and the main frame of linux operating system is installed.
Described Intel Core 2Duo E6400CPU is the central processing unit that is fit to quicken gateway 00 normal operation;
Described 128M FLASH is used for storing the memory device that quickens gateway 00 each operational module, and the FLASH flash memory is a nonvolatile storage;
Described 1G RAM is meant the needed internal memory of whole acceleration gateway 00 normal operation;
Described 1TB HardDisk quickens gateway 00 to be used for storing the external memory storage of data in the data label buffer memory storehouse 7.
Described linux quickens the operating system that gateway 00 each operational module operate as normal is relied on, and this linux operating system is to quicken gateway 00 each operational module and the mutual bridge of hardware.
Its operational module comprises network protocol stack 1, IPSec and internet key exchange module 2, ACK proxy module 3, TCP agency and tunnel module 4, group bag/data label buffer memory/compression module 5, uses encapsulation library module 6 and data label buffer memory storehouse 7;
Network protocol stack 1, IPSec and internet key exchange module 2, TCP agency and tunnel module 4 and network protocol stack 1 call successively; Go into a closed-loop system, 4 unidirectional calling application of TCP agency and tunnel module encapsulate the power function that library modules 6 provide simultaneously;
ACK proxy module 3, group bag/data label buffer memory/compression module 5, IPSec and internet key exchange module 2 are called successively, organize simultaneously that 5 of bag/data label buffer memory/compression modules are unidirectional to call the power function that data label buffer memory storehouse 7 provides.
2, functional block
1. network protocol stack (TCP/IP) 1
Network protocol stack (TCP/IP) the 1st, the Internet network communication protocol stack;
Its typical case's representative is network operating systems such as Windows, UNIX, Linux.
2. IPSec and internet key exchange module (IPSec/IKE) 2
IPSec and internet key exchange module (IPSec/IKE) the 2nd a kind ofly are used for carrying out internet key and consult and carry out the module that the encryption and decryption of IPSec message are handled;
Its typical case realizes it being Internet open source software FreeSWAN; FreeSWAN is the software of a kind of IPSec that on (SuSE) Linux OS, realizes and internet key exchange.
3. the ACK proxy module 3
ACK proxy module 3 is that a kind of being used for carried out the module of proxy response with quick transmission to message.
4. TCP acts on behalf of and tunnel module 4
TCP agency and tunnel module 4 are that a kind of being used for carried out format analysis and message is carried out the encapsulation of TCP application protocol and the module of decapsulation and transmission and received communication message IPSec and internet key exchange message.
5. organize bag/data label buffer memory/compression module 5
Group bag/data label buffer memory/compression module 5 be a kind of be used for to the TCP application data package mergings, data label quote replace and processed compressed with the module of reduction network redundancy re-transmitted flow.
6. use encapsulation library module 6
Using encapsulation library module 6 is function libraries that a kind of encapsulation function that is used to provide various application communications calls to TCPP, for example HTTP (HTTP) application and FTP (FTP) application etc.
7. data label buffer memory library module 7
Data label buffer memory library module 7 is that a kind of being used to provide quoted the function library that the replacement function is called to group bag/data label buffer memory/compression module to message.
Two, a kind of acceleration communicator that quickens gateway based on wide area network VPN
This acceleration communicator is to quicken communicator between a kind of two sub-net of striding wide area network.
1, overall
Like Fig. 5, this acceleration communicator comprises that successively first subnet 100, the VPN that are communicated with quicken gateway 10, wide area network 300, the 2nd VPN and quicken the gateway and second subnet 400;
In first subnet 100, be provided with a client computer 200;
In second subnet 400, be provided with a data server 500.
2, functional block
1. first subnet 100 and second subnet 400
Described first subnet 100 is to quicken the subnet that gateway 10 is the outlet gateway with a VPN;
Described second subnet 400 is to quicken the subnet that gateway 20 is the outlet gateway with the 2nd VPN;
2. a VPN quickens gateway 10 and the 2nd VPN acceleration gateway 20
A described VPN quickens gateway 10 and the 2nd VPN acceleration gateway 20 is VPN acceleration gateway 00.
3. client computer 200
Described client computer 200 is any common PC that are arranged in first subnet 100, and it wants the accesses network data must quicken gateway 10 through a VPN.
4. data server 500
Described data server 500 is one and is arranged in the server that second subnet 400 externally provides data, services that extraneous visit will be quickened gateway 20 through the 2nd VPN.
Three, a kind of acceleration communication means that quickens the acceleration communicator of gateway based on wide area network VPN
This acceleration communication means comprises the following steps:
1. be provided with and carry out the vpn tunneling that TCP uses encapsulation;
2. a VPN quickens 10 pairs of TCP messages that mail to data server 500 from client computer 200 of gateway; Surrogate data method server 500 is forged fast and is replied to client computer 200 on the one hand, and the request msg that causes client computer 200 will send to data server 500 fast sends to a VPN and quickens gateway 10; On the other hand with the request msg that receives package, the data label buffer memory is quoted, processed compressed;
3. a VPN quickens that TCP message that 10 pairs of gateways go out carries out the IPSec encapsulation and TCP uses encapsulation process;
4. the 2nd VPN quickens gateway 20 and receives and handle the TCP encapsulation of data that gets into, and is dealt into data server 500 to the message after handling;
5. the response message of 20 pairs of data servers 500 of the 2nd VPN acceleration gateway carries out encapsulation process and the transmission that a similar VPN quickens gateway 10;
6. 10 pairs of TCP encapsulation of data from the 2nd VPN acceleration gateway 20 of VPN acceleration gateway carry out decapsulation reduction processing.
After the group packet fragmentation, the message load data after the combination are divided into a plurality of data fragmentations, and are as shown in Figure 2; Buffer memory burst in each burst and the data label buffer memory storehouse 7 is mated, if coupling just with the identification data burst quote the surrogate data method burst, encapsulate as shown in Figure 3 again.Again message load is carried out processed compressed, at last message is carried out IPSec encapsulation and use to encapsulate with TCP and obtain message as shown in Figure 4.
Therefore can find out from the message encapsulation,, reduce the upward number of message transmissions of Internet, also just reduce the chance that packet loss retransmits through behind the message group package; After quoting replacement through the data label buffer memory, be a string sign message data burst character string, be much smaller, therefore also just reduced redundant repeating data than the data slice length of reality because quote; Message further is optimized after overcompression, has removed redundant data; Encapsulation has guaranteed the fail safe of message through IPSec; Use encapsulation through TCP, guaranteed that message breaks through the restriction of fire compartment wall on wide area network.Therefore message just can reach the reliable Network Transmission of high-speed secure through above-mentioned encapsulation.
The one VPN quickens first subnet 100 of gateway 10 protections, and a client computer client200 is wherein arranged; The 2nd VPN quickens second subnet 400 of gateway 20 protections, and a data server server500 is wherein arranged; In this case, though implemented Qos under the conventional method, each communication message all will pass through complicated wide area network and arrive the other side, and the centre relates to a series of unsafe factors such as packet loss delay, greatly reduces communication speed and efficient.For can high-speed secure communicate; First and second VPN quickens gateway 10,20 needs to start ACK agent functionality and group bag/data label buffer memory/compression function; Reduce redundant repeating data to greatest extent, and by IPSec and the safe and reliable transmission data of application encapsulation function.
(1) VPN quickens 00 pair of TCP message of gateway and quickens transmission encapsulation flow process
Like Fig. 6,00 pair of TCP message of VPN acceleration gateway quickens transmission encapsulation flow process and is:
1. replace far-end server that local Intranet client is carried out ACK and reply a;
2. open Group Package Policy? 3. b does not get into step when opening, and then gets into step more 3. behind the many messages combined treatment c to same connection during unlatching;
3. turn-on data label cache policy? 4. d gets into step when opening, during unlatching then matched data label buffer memory storehouse message is carried out getting into step more 4. after data label is quoted replacement e;
4. open Compression Strategies? 5. f does not get into step when opening, and then message is carried out getting into step more 5. behind the processed compressed g during unlatching;
5. message is carried out ipsec security encapsulation h;
6. message is used and sealed processing and transmitting i.
At first quicken to dispose on the gateway 10 to launch and organize bag/data label buffer memory/Compression Strategies at a VPN; The ACK agency is launched in configuration and TCP uses encapsulation; VPN consults and when communicate by letter, will carry out speeding scheme to the message in the connection of foundation when first vpn gateway 10 carries out to second vpn gateway 20 so.
The one VPN quickens 10 pairs of TCP messages that mail to server500 from client200 of gateway; Replace server500 to forge fast on the one hand and reply to client200, the request msg that causes client200 will send to server500 fast sends to a VPN and quickens gateway 10; On the other hand the request msg of receiving is judged successively whether system has disposed group bag, the data label buffer memory is quoted replacement, processed compressed strategy, just organize accordingly that bag, data label buffer memory are quoted, processed compressed if disposed; And then message is carried out IPSec encapsulation process and TCP use encapsulation process, send to the 2nd VPN and quicken gateway 20.
(2) 00 pair of IPSec message of VPN acceleration gateway carries out HTTP application decapsulation flow process
Like Fig. 7,00 pair of IPSec message of VPN acceleration gateway carries out HTTP application decapsulation flow process and is:
1. monitor j at tcp port (for example 80);
2. receive the TCP message k that gets into;
3. message is carried out application layer protocol reduction l,
4. reduce and give RNSPEED module m behind the IPSec message;
5. open Compression Strategies? 6. n does not get into step when opening, and then message is carried out getting into step more 6. behind the decompression o during unlatching;
6. turn-on data label cache policy? 7. p gets into step when opening, during unlatching then matched data label buffer memory storehouse message is carried out getting into step more 7. after data label is quoted reduction q;
7. open Group Package Policy? 8. r does not get into step when opening, and then message is carried out getting into step more 8. after system of solutions bag is handled s during unlatching;
8. message reduces to finish and mails to interior network server t.
Second vpn gateway 20 is monitored and on tcp port, is monitored, and receives the encapsulated message that gets into, and at first message is carried out TCP and uses decapsulation, and the message after the reduction will be given operating system again has the IPSec module to carry out decapsulation.Next judge successively whether system has disposed compression, the bag processing policy is quoted, organized to the data label buffer memory, if just disposed decompress accordingly, the data label buffer memory is quoted reduction, system of solutions bag is handled; Finally obtain raw data packets and send to server500 in second subnet 400.