Summary of the invention
For solving the problem, the embodiment of the present invention proposes a kind of method and multiple operating system terminal of multiple operating system accessing terminal to network.
First aspect, embodiments provide a kind of method of multiple operating system accessing terminal to network, described method comprises:
Operating system sends network insertion request by corresponding virtual network access module to VN agents module;
After described VN agents module obtains described network insertion request, for described operating system distributes the first internet protocol address, and by described virtual network access module, a described IP address being sent to described operating system, described VN agents module is that the IP address that different operating system is distributed is different;
Described operating system is according to a described IP address access network.
Alternatively, describedly distribute the first internet protocol address for described operating system, comprising:
Determine the 2nd IP address of described multiple operating system accessing terminal to network;
According to the network security policy preset and described 2nd IP address, for described operating system distributes an IP address.
Alternatively, described the 2nd IP address determining described multiple operating system accessing terminal to network, comprising:
The public network IP address of described multiple operating system accessing terminal to network is determined, using described public network IP address as the 2nd IP address according to the network-driven of described multiple operating system terminal.
Alternatively, the network security policy that described basis is preset and described 2nd IP address, for described operating system distributes an IP address, comprising:
Determine the network type that described operating system accesses;
If described network type is dedicated network, then according to the network security policy preset and default proprietary network protocol stack, be the 3rd IP address by described 2nd IP address transition, using described 3rd IP address as an IP address;
Described 3rd IP address is the virtual ip address relevant to described 2nd IP address.
Alternatively, described using described 3rd IP address as an IP address, comprising:
Sub-network division is carried out to described 3rd IP address;
From the subnet divided, select an IP address as an IP address.
Alternatively, described dedicated network is VPN (virtual private network) VPN.
Alternatively, described determine the network type that described operating system accesses after, also comprise:
If described network type is common network, then according to the network security policy preset, sub-network division is carried out to described 2nd IP address, from the subnet divided, select an IP address as an IP address.
Second aspect, embodiments provides a kind of multiple operating system terminal, and described multiple operating system terminal comprises: multiple operating system, virtual network access module, VN agents module;
The corresponding virtual network access module of each operating system;
Described operating system, for sending network insertion request by corresponding described virtual network access module to described VN agents module; The first internet protocol address of described VN agents module assignment is obtained, according to a described IP address access network by described virtual network access module;
Described virtual network access module, for sending the network insertion request of described operating system to described VN agents module; A described IP address of described VN agents module assignment is sent to described operating system;
Described VN agents module, after obtaining described network insertion request, for described operating system distributes an IP address, and by described virtual network access module, a described IP address being sent to described operating system, described VN agents module is that the IP address that different operating system is distributed is different.
Alternatively, described VN agents module, for determining the 2nd IP address of described multiple operating system accessing terminal to network; According to the network security policy preset and described 2nd IP address, for described operating system distributes an IP address.
Alternatively, described VN agents module, for determining the public network IP address of described multiple operating system accessing terminal to network according to the network-driven of described multiple operating system terminal, using described public network IP address as the 2nd IP address.
Alternatively, described VN agents module, for determining the network type that described operating system accesses; When described network type is dedicated network, according to the network security policy preset and default proprietary network protocol stack, be the 3rd IP address by described 2nd IP address transition, using described 3rd IP address as an IP address; Described 3rd IP address is the virtual ip address relevant to described 2nd IP address.
Alternatively, described VN agents module, for carrying out sub-network division to described 3rd IP address; From the subnet divided, select an IP address as an IP address.
Alternatively, described dedicated network is VPN (virtual private network) VPN.
Alternatively, described VN agents module, also for when described network type is common network, the network security policy according to presetting carries out sub-network division to described 2nd IP address, selects an IP address as an IP address from the subnet divided.
Beneficial effect is as follows:
Operating system sends network insertion request by corresponding virtual network access module to VN agents module; After VN agents module obtains network insertion request, for operating system distributing IP address, and by virtual network access module, IP address is sent to operating system, wherein, VN agents module is that the IP address that different operating system is distributed is different; Operating system according to IP address access network, thus makes each operating system can access network simultaneously according to different IP addresses.
Embodiment
Clearly understand to make technical scheme of the present invention and advantage, below in conjunction with accompanying drawing, exemplary embodiment of the present invention is described in more detail, obviously, described embodiment is only a part of embodiment of the present invention, instead of all embodiments is exhaustive.And when not conflicting, the embodiment in this explanation and the feature in embodiment can be combined with each other.
When multiple operating systems in current same equipment carry out network insertion, need a public IP address, make multiple operating system can not carry out network insertion simultaneously.In addition, when the network type that multiple operating system accesses is different, there is the demand that different operating system connects each automatic network, and under this scene, the method for current access network can not meet this demand.Therefore, present applicant proposes a kind of method of multiple operating system accessing terminal to network, the method is applied to a kind of multiple operating system terminal, the multiple operating system terminal of this multiple operating system terminal as described in Fig. 4 to shown embodiment.This multiple operating system terminal comprises multiple operating system, virtual network access module, VN agents module.Wherein, operating system sends network insertion request by corresponding virtual network access module to VN agents module; After VN agents module obtains network insertion request, for operating system distributes an IP (InternetProtocol, Internet protocol) address, and by virtual network access module, the one IP address being sent to operating system, VN agents module is that the IP address that different operating system is distributed is different; Operating system according to an IP address access network, thus makes each operating system can access network simultaneously according to different IP addresses.
In conjunction with above-mentioned implementation environment, embodiment shown in Figure 1, present embodiments provide a kind of method of multiple operating system accessing terminal to network, the method flow that the present embodiment provides is specific as follows:
101: operating system sends network insertion request by corresponding virtual network access module to VN agents module;
102: after VN agents module obtains network insertion request, for operating system distributes the first internet protocol address, and by virtual network access module, the one IP address being sent to operating system, VN agents module is that the IP address that different operating system is distributed is different;
Alternatively, for operating system distributes the first internet protocol address, comprising:
Determine the 2nd IP address of multiple operating system accessing terminal to network;
According to the network security policy preset and the 2nd IP address, for operating system distributes an IP address.
Alternatively, determine the 2nd IP address of multiple operating system accessing terminal to network, comprising:
According to the public network IP address of the network-driven determination multiple operating system accessing terminal to network of multiple operating system terminal, using public network IP address as the 2nd IP address.
Alternatively, according to the network security policy preset and the 2nd IP address, for operating system distributes an IP address, comprising:
The network type of determination operation system access;
If network type is dedicated network, then according to the network security policy preset and default proprietary network protocol stack, be the 3rd IP address by the 2nd IP address transition, using the 3rd IP address as an IP address;
3rd IP address is the virtual ip address relevant to the 2nd IP address.
Alternatively, using the 3rd IP address as an IP address, comprising:
Sub-network division is carried out to the 3rd IP address;
From the subnet divided, select an IP address as an IP address.
Alternatively, dedicated network is VPN (virtual private network) VPN.
Alternatively, after the network type of determination operation system access, also comprise:
If network type is common network, then according to the network security policy preset, sub-network division is carried out to the 2nd IP address, from the subnet divided, select an IP address as an IP address.
103: operating system is according to an IP address access network.
Beneficial effect:
Operating system sends network insertion request by corresponding virtual network access module to VN agents module; After VN agents module obtains network insertion request, for operating system distributing IP address, and by virtual network access module, IP address is sent to operating system, wherein, VN agents module is that the IP address that different operating system is distributed is different; Operating system according to IP address access network, thus makes each operating system can access network simultaneously according to different IP addresses.
In conjunction with above-mentioned implementation environment, present embodiments provide a kind of method of multiple operating system accessing terminal to network, for convenience of explanation, the present embodiment is with the multiple operating system terminal shown in Fig. 2, this multiple operating system terminal comprises 2 operating systems, virtual network access module (vWIFI-P module 201 and vWIFI-E module 202), VN agents module (vWIFI-BE module 204), and this multiple operating system terminal to carry out network insertion by WIFI mode be that example is described.
Wherein, multiple operating system terminal shown in Fig. 2, this multiple operating system terminal passes through Intel Virtualization Technology, virtual Kernerl (kernel) 203 fictionalizes 2 operating systems, one of them operating system is individual operating system, for running individual application program, another operating system is Enterprise Operation System, for running enterprise application.By individual application program and enterprise application are run in different operating system respectively, application data in two operating systems can be made to be transmitted by different data channel, in individual operating system while individual application normal program operation, enterprise application in Enterprise Operation System can be isolated, by the data channel transmission enterprise application data of isolation, reduce the risk of enterprise application leaking data.
While fictionalized 2 operating systems by Intel Virtualization Technology, 2 virtual network access module can be fictionalized, vWIFI-P module 201 and vWIFI-E module 202.
Wherein, the specific implementation fictionalizing 2 network access modules includes but not limited to: realized under the assistance of WIFIDriver (WIFI network driving) and VPNStack (VPN (virtual private network) protocol stack) by Intel Virtualization Technology.Individual's operating system carries out network insertion by vWIFI-P module 201, according to VPNStack and SecurePolicy (network security policy) for individual operating system distributes independently network channel.Enterprise Operation System carries out network insertion by vWIFI-E module 202, and under the assistance of VPNStack, realize the complete encrypted transmission that system data is worried about by enterprise, strengthens the fail safe of business data.
VWIFI-P module 201, realize the network agent interface of vWIFI-P module 201 as true WIFI equipment by the device virtualization framework API calling virtual support, its function is the agency of live network equipment.Possess independently IP address, carrying out communicating with vWIFI-BE module 204 realizes the transmission of network data.
VWIFI-E module 202, realize the network agent interface of vWIFI-P module 201 as true WIFI equipment by the device virtualization framework API calling virtual support, its function is the agency of live network equipment.Possess independently IP address, carrying out communicating with vWIFI-BE module 204 realizes the transmission of network data.
VWIFI-BE module 204, vWIFI-BE module 204 is realized as vWIFI-P module 201 by the device virtualization framework API calling virtual support, the external network proxy services end of vWIFI-E module 202, its function is connected with virtual network device by live network equipment.VWIFI-BE module 204 communicates with real WIFIDriver and realizes the transmission of data.VWIFI-BE module 204 communicates with VPNStack, sets up dissimilar network connect, for different vWIFI-P module 201, vWIFI-E modules 202 provides special, independent, safe passage according to SecurePolicy.
SecurePolicy, can according to the security level required of user, Dynamic Establishing network security policy, forms networking dynamic security mechanism.For upper system provides dynamic safeguard protection.And SecurePolicy can be arranged by special purpose interface in advance, also can be arranged by the webserver in advance, the concrete mode that the present embodiment is completely not tactful to default network, and concrete setup times limits.
See Fig. 3, the method flow that the present embodiment provides is specific as follows:
301: operating system sends network insertion request by corresponding virtual network access module to VN agents module;
Wherein, the corresponding virtual network access module of each operating system.
Such as: during APP1 (Application, application program) interconnection network in individual operating system, individual operating system initiates network insertion request 1 by vWIFI-P module 201 to vWIFI-BE module 204, asks to access public network by WIFI.
Can also when individual os starting, individual's operating system initiates network insertion request 1 by vWIFI-P module 201 to vWIFI-BE module 204, and the concrete trigger condition that the present embodiment individual operating system initiates network insertion request 1 by vWIFI-P module 201 to vWIFI-BE module 204 limits.
302: after VN agents module obtains network insertion request, for operating system distributes the first internet protocol address;
Wherein, VN agents module is that the IP address that different operating system is distributed is different;
This step in the specific implementation, includes but not limited to be realized by following 2 sub-steps:
Sub-step 1: VN agents module determines the 2nd IP address of multiple operating system accessing terminal to network after obtaining network insertion request;
Concrete, according to the public network IP address of the network-driven determination multiple operating system accessing terminal to network of multiple operating system terminal, using public network IP address as the 2nd IP address.
Such as, vWIFI-BE module 204 is according to WIFIdriver real physics WIFI equipment, and the IP address of equipment access network, using this IP address as public network IP address.
The public network IP address of multiple operating system accessing terminal to network due to what obtain in sub-step 1, therefore, which operating system no matter in multiple operating system terminal, the IP site homogeneous that it gets in sub-step 1 with.
Such as, if after the vWIFI-BE module 204 in the terminal of multiple operating system shown in Fig. 2 gets the network insertion request 1 of individual operating system, determine that the public network IP address of this multiple operating system accessing terminal to network is 192.168.1.0, after then vWIFI-BE module 204 gets the network insertion request 2 of Enterprise Operation System in the terminal of multiple operating system shown in Fig. 2, determine that the public network IP address of multiple operating system accessing terminal to network is also 192.168.1.0.
Certainly, public network IP address 192.168.1.0 is herein only and schematically illustrates, and in practical application, public network IP address can be other addresses, and the present embodiment does not limit concrete public network IP address.
Sub-step 2: according to the network security policy preset and the 2nd IP address, for operating system distributes an IP address.
Because the dedicated networks such as VPN need to be encrypted mutual data, and different dedicated network processing modes is different, and therefore, this step includes but not limited to when specific implementation realize as follows:
Step 2.1: the network type of determination operation system access, if network type is dedicated network, then performs step 2.2, if network type is common network, then performs step 2.3;
Such as, if operating system is individual operating system, then determine that its network type accessed is community network, perform step 2.3.If operating system is Enterprise Operation System, then determine that its network type accessed is dedicated network, perform step 2.2.
Step 2.2: according to the network security policy preset and default proprietary network protocol stack, be the 3rd IP address by the 2nd IP address transition is that operating system distributes an IP address according to the 3rd IP address;
Wherein, the 3rd IP address is the virtual ip address relevant to the 2nd IP address.
By the specific implementation that the 2nd IP address transition is the 3rd IP address, include but not limited to: the dedicated network accessed according to network security policy and operating system, corresponding procotol is selected from the proprietary network protocol stack preset, 2nd IP address is changed by the procotol according to selecting, form virtual IP address, this virtual IP address is as the 3rd IP address.
Such as, changed the 2nd IP address if the 2nd IP address is 192.168.1.10, form virtual IP address 192.169.1.2, this virtual IP address is as the 3rd IP address.
For being the specific implementation that operating system distributes an IP address according to the 3rd IP address, include but not limited to the following two kinds mode:
Mode one: using the 3rd IP address as an IP address.
Mode two: sub-network division is carried out to the 3rd IP address; From the subnet divided, select an IP address as an IP address.
Wherein, the concrete grammar of sub-network division can use the mode such as existing NET agreement, bridge, IP translation, and the present embodiment does not specifically limit.
Above-mentioned two kinds of way choice foundations, include but not limited to: if run the operating system having a unique access dedicated network in multiple operating system terminal, then can selection mode one, also can selection mode two.The operating system of multiple access dedicated network is had if run in multiple operating system terminal, in order to ensure that the operating system of each access dedicated network distributes different IP addresses, then can not selection mode one, need selection mode two.
Network security policy, for the VPNPolicy in Fig. 2, mainly according to user to the configuration of upper strata operating system to network access mode, for VPN (virtual private network) is distributed in the front end such as vWIFI-P module 201, vWIFI-E module 202 of different upper strata operating system.Can adopt different communication protocol, different cipher modes, different certificates of certification, the information such as time place carry out strategy configuration.Realize the network access security of each operating system in dynamic conditioning front end, and each operating system in front end is for the observability of external network.
SecurePolicy is mainly according to the configuration of user with require, for upper layer policy, to include but not limited to:
1. whether allow vWIFI-P module 201, vWIFI-E module 202 distributing IP address;
2. distribute the IP address of which kind of type network, can be internal subnet IP address or distribute the IP address of same network with WIFIDriver;
3. whether be that the virtual network address is distributed in the front ends such as vWIFI-P module 201, vWIFI-E module 202;
4. whether be that vWIFI-P module 201, vWIFI-E module 202 configures independently MAC Address.
Such as, vWIFI-BE module 204 is according to the strategy of SecurePolicy, the cryptographic protocol that Enterprise Operation System is corresponding is selected from VPNStack, public network IP address 192.168.1.0 is encrypted, obtain the public network IP address 192.169.1.0 after encrypting, using 192.169.1.0 as the IP address of internal network distributing to Enterprise Operation System.
Or, sub-network division is carried out to 192.169.1.0; From the subnet divided, select an IP address 192.169.1.1 as the IP address of internal network distributing to operating system.
By step 2, vWIFI-BE module 204 is according to the strategy of vWIFIPolicy, utilize software inhouse Sharing Technology in Network to set up internal network to share, for vWIFI-E module 202 distributes independently IP address, can be independently IP address of internal network (mode two) or the IP address identical with external equipment access network (mode one).
Step 2.3, the network security policy according to presetting carries out sub-network division to the 2nd IP address, selects an IP address as an IP address from the subnet divided.
By step 2.3, vWIFI-BE module 204, according to the strategy of vWIFIPolicy, utilizes software inhouse Sharing Technology in Network to set up internal network and shares, for vWIFI-P module 201 distributes independently IP address of internal network.
303: an IP address is sent to operating system by virtual network access module by VN agents module;
304: operating system is according to an IP address access network.
The method that the present embodiment provides, by the mode such as sub-network division, VPN, can ensure as each operating system distributes a unique IP address, the network control that not only operating system can be accessed is in the limited scope of application, and due to different operating system use different IP addresses carry out network insertion, therefore each operating system can simultaneously access network, carries out transfer of data.By network security policy, can according to the network insertion of the external information dynamic conditioning Optimum Operation system such as time, place and safety.
It should be noted that, the present embodiment is only described to run 2 operating systems in multiple operating system terminal, in actual application, a multiple operating system terminal can be run more than 2 operating systems, and the present embodiment does not limit the concrete quantity of operating system of multiple operating system terminal actual motion.
In addition, the present embodiment only carries out network insertion with multiple operating system terminal by WIFI mode, in actual application, can also pass through private-line mode access network, or other mode access networks, the present embodiment does not limit the practical ways of multiple operating system accessing terminal to network.
In addition, the present embodiment is only described using VPN as dedicated network, and in actual application, can also be other forms of dedicated network, the present embodiment limit concrete dedicated network.
Beneficial effect:
Operating system sends network insertion request by corresponding virtual network access module to VN agents module; After VN agents module obtains network insertion request, for operating system distributing IP address, and by virtual network access module, IP address is sent to operating system, wherein, VN agents module is that the IP address that different operating system is distributed is different; Operating system according to IP address access network, thus makes each operating system can access network simultaneously according to different IP addresses.
Based on same inventive concept, embodiment shown in Figure 4, present embodiments provide a kind of multiple operating system terminal, the principle of dealing with problems due to multiple operating system terminal is similar to a kind of method of multiple operating system accessing terminal to network, therefore the enforcement of multiple operating system terminal see the enforcement of method, can repeat part and repeats no more.
See Fig. 4, this multiple operating system terminal, comprising: multiple operating system 401, virtual network access module 402, VN agents module 403;
The corresponding virtual network access module 402 of each operating system 401;
Operating system 401, for sending network insertion request by corresponding virtual network access module 402 to VN agents module 403; The first internet protocol address of VN agents module 403 distribution is obtained, according to an IP address access network by virtual network access module 402;
Virtual network access module 402, for the network insertion request to VN agents module 403 transmit operation system 401; IP address VN agents module 403 distributed is sent to operating system 401;
VN agents module 403, after obtaining network insertion request, for operating system 401 distributes an IP address, and by virtual network access module 402, an IP address being sent to operating system 401, VN agents module 403 is that the IP address that different operating system 401 is distributed is different.
Alternatively, VN agents module 403, for determining the 2nd IP address of multiple operating system accessing terminal to network; According to the network security policy preset and the 2nd IP address, for operating system distributes an IP address.
Alternatively, VN agents module 403, for the public network IP address of the network-driven determination multiple operating system accessing terminal to network according to multiple operating system terminal, using public network IP address as the 2nd IP address.
Alternatively, VN agents module 403, for the network type of determination operation system access; When network type is dedicated network, according to the network security policy preset and default proprietary network protocol stack, be the 3rd IP address by the 2nd IP address transition, using the 3rd IP address as an IP address; 3rd IP address is the virtual ip address relevant to the 2nd IP address.
Alternatively, VN agents module 403, for carrying out sub-network division to the 3rd IP address; From the subnet divided, select an IP address as an IP address.
Alternatively, dedicated network is VPN (virtual private network) VPN.
Alternatively, VN agents module 403, also for when network type is common network, the network security policy according to presetting carries out sub-network division to the 2nd IP address, selects an IP address as an IP address from the subnet divided.
Beneficial effect is as follows:
Operating system sends network insertion request by corresponding virtual network access module to VN agents module; After VN agents module obtains network insertion request, for operating system distributing IP address, and by virtual network access module, IP address is sent to operating system, wherein, VN agents module is that the IP address that different operating system is distributed is different; Operating system according to IP address access network, thus makes each operating system can access network simultaneously according to different IP addresses.
In above-described embodiment, existing Functional Unit device blocks all can be adopted to implement.Such as, processing module can adopt existing data processing components and parts, at least, the location-server adopted just possesses realize this Functional Unit device in existing location technology; As for receiver module, be then the components and parts that equipment that any one possesses signal transfer functions all possesses; Meanwhile, what A, n calculation of parameter, intensity adjustment etc. that processing module is carried out adopted is all existing technological means, and those skilled in the art design and develop can realize through accordingly.
For convenience of description, each several part of the above device is divided into various module or unit to describe respectively with function.Certainly, the function of each module or unit can be realized in same or multiple software or hardware when implementing of the present invention.
Those skilled in the art should understand, embodiments of the invention can be provided as method, system or computer program.Therefore, the present invention can adopt the form of complete hardware embodiment, completely software implementation or the embodiment in conjunction with software and hardware aspect.And the present invention can adopt in one or more form wherein including the upper computer program implemented of computer-usable storage medium (including but not limited to magnetic disc store, CD-ROM, optical memory etc.) of computer usable program code.
The present invention describes with reference to according to the flow chart of the method for the embodiment of the present invention, equipment (system) and computer program and/or block diagram.Should understand can by the combination of the flow process in each flow process in computer program instructions realization flow figure and/or block diagram and/or square frame and flow chart and/or block diagram and/or square frame.These computer program instructions can being provided to the processor of all-purpose computer, special-purpose computer, Embedded Processor or other programmable data processing device to produce a machine, making the instruction performed by the processor of computer or other programmable data processing device produce device for realizing the function of specifying in flow chart flow process or multiple flow process and/or block diagram square frame or multiple square frame.
These computer program instructions also can be stored in can in the computer-readable memory that works in a specific way of vectoring computer or other programmable data processing device, the instruction making to be stored in this computer-readable memory produces the manufacture comprising command device, and this command device realizes the function of specifying in flow chart flow process or multiple flow process and/or block diagram square frame or multiple square frame.
These computer program instructions also can be loaded in computer or other programmable data processing device, make on computer or other programmable devices, to perform sequence of operations step to produce computer implemented process, thus the instruction performed on computer or other programmable devices is provided for the step realizing the function of specifying in flow chart flow process or multiple flow process and/or block diagram square frame or multiple square frame.
Although describe the preferred embodiments of the present invention, those skilled in the art once obtain the basic creative concept of cicada, then can make other change and amendment to these embodiments.So claims are intended to be interpreted as comprising preferred embodiment and falling into all changes and the amendment of the scope of the invention.