TW512263B - On-demand system and method for access repeater used in Virtual Private Network - Google Patents

On-demand system and method for access repeater used in Virtual Private Network Download PDF

Info

Publication number
TW512263B
TW512263B TW88108149A TW88108149A TW512263B TW 512263 B TW512263 B TW 512263B TW 88108149 A TW88108149 A TW 88108149A TW 88108149 A TW88108149 A TW 88108149A TW 512263 B TW512263 B TW 512263B
Authority
TW
Taiwan
Prior art keywords
user
virtual private
private network
dial
scope
Prior art date
Application number
TW88108149A
Other languages
Chinese (zh)
Inventor
Li-Guo Bau
Wei-Yuan Du
Yi-Yuan Li
Original Assignee
Inst Information Industry
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Inst Information Industry filed Critical Inst Information Industry
Priority to TW88108149A priority Critical patent/TW512263B/en
Application granted granted Critical
Publication of TW512263B publication Critical patent/TW512263B/en

Links

Abstract

The invention processes user's connection request with two-stage PPP link. The first-stage PPP link proceeds communication coordination between user and access repeater and verification of user's identity. If the user is a legal user, the user will be given a new network address. Then user can select a service item from the function menu provided by on-demand repeater, including virtual private network (VPN) services and NON-VPN services. If user selects NON-VPN service, access repeater will transmit packets to its destination address. If user requests a VPN service, access repeater will create a second-stage PPP link with VPN. As such, user can access services in connection with NON-VPN without having to directly connect to VPN server.

Description

1.,¾¾示<^年彳Θ厂ΓΓϊΐί 經濟部智慧財產局員工消費合作社印製 512263 五、發明說明() 5 — 1發明領域及背景 A·發明領域 本發明係為一種應用於虛擬私有網路(Virtual pHvate NetW〇rkS,VPN)的存取中繼器(Access Concentrator),尤 指一種可提供隨選服務(0n_Demand)的存取中繼器,以讓 使用者了在連結至虛擬私有網路伺服器前,可有其它的服 務選擇。 B·發明背景 虛擬私有網路(Virtual Private Netw〇rk,以下簡稱 VpN )為一使用公共電訊傳輸系統(pubHc telecommunication infrastructure )的資料網路(心以 network),如圖}所示。VPN的網路系統通常是以專線方 式來連結,因此較具隱私性。透過一授權的網路服務公司 (ISP) 13,一個公司或企業14可將—網際網路15當作 一大型的區域網路。在經由公共電話網路12及網際網路 1 5從VPN傳送資料至另一端的VPN時,通常要經過加 密及解密的程序,以保障資料的安全。為保障資料的私密 性及安全性,網際網路(Internet)更應用隧道化 (tUnneHng) 16的方式,提供一特別的通道(path)給 一特定之公司透過網際網路15傳遞訊息或檔案。而提供 此溝通的協定便稱為點對點隧道化協定(p〇int_t〇_p〇int Tunneling Protocol,以下簡稱 ρρτρ)。透過 ρρτρ,公司 可在網際網路透過隨道產生一 VPN,而安全地傳送資料。 2 本紙張尺度適用中國國家標準(CNS)A4規格(210 X 297公釐) --—--- -------------------訂 --------- S (請先閱讀背面之注意事項再填寫本頁)1., ¾¾ < ^ year 彳 Θ factory ΓΓϊΐί Printed by the Consumer Cooperatives of the Intellectual Property Bureau of the Ministry of Economic Affairs 512263 5. Description of the invention () 5 — 1 Field of invention and background A · Field of the invention The present invention is an application for virtual private Network (Virtual pHvate NetWorks, VPN) access relay (Access Concentrator), especially an access relay that can provide on-demand services (0n_Demand), so that users can connect to the virtual private In front of the web server, there are other service options available. B. Background of the Invention A virtual private network (Virtual Private Network, hereinafter referred to as VpN) is a data network (heart network) using a public telecommunication transmission system (pubHc telecommunication infrastructure), as shown in Figure}. VPN's network system is usually connected by a dedicated line, so it has more privacy. Through an authorized Internet service company (ISP) 13, a company or enterprise 14 can treat the Internet 15 as a large local area network. When data is transmitted from the VPN to the VPN at the other end via the public telephone network 12 and the Internet 15, encryption and decryption procedures are usually required to ensure data security. In order to protect the privacy and security of data, the Internet (tUnneHng) 16 is used to provide a special path for a specific company to transmit messages or files through the Internet 15. The protocol that provides this communication is called a point-to-point tunneling protocol (hereinafter referred to as ρρτρ). Through ρρτρ, the company can securely transmit data by generating a VPN on the Internet. 2 This paper size is applicable to China National Standard (CNS) A4 specification (210 X 297 mm) ------------------- Order ---- ----- S (Please read the notes on the back before filling this page)

II

II

^2263 中年^月i 广、 A7 - yij —B7 五、發明說明() 如此,公司或企業14便不需要使用自己租用的廣域網路 線,而能安全地利用一般的網路系統。 網路服務公司1 3使用存取中繼器1 7及一資料庫i 8 以處理VPN的通訊。存取中繼器17具有兩個介面:VpN 介面171以提供使用公用電話交換網路(psTNs)或整體 服務數位網路(ISDN )的點對點存取,以及一般的網路 通訊介面172,可提供TCP/IP通訊協定,以將封包傳送 至網際網路1 5或非虛擬私有網路。 PPTP 使用增強型的 GRE (Generic R〇uting Encapsulation)機制以提供流量及阻塞控制的包裹 (encapsulated)資料框(datagram)服務,以傳送 ppp 封包。當一企業的使用者11使用PPTP通訊協定,並撥 接至一網路服務公司 13時,封包將被包裹起來 (encapsulated),然後傳送到存取中繼器17。包裹的ppp 封包將用IP的方式來傳送。因此,包裹的PPP封包的資 料袼式將如圖2所示。包含一媒介標頭2 1,一 I p標頭2 2, 一 GRE標頭23,以及ΡΡΡ的封包24。 習知之存取中繼器17將只從ΡΡΡ封包中的eaU m 攔位來確認撥號使用者身份的真確性,然後賦于—合法的 網路位址給該撥號使用者,以取代其來源位址。如此便可 在不必將該封包解密的情況下,使該撥號使用者可存取虛 3 本紙張尺度適用中國國家標準(CNS)A4規格(210 X 297公釐) 閱 背 之 注 意 事 項 再 填 寫 本 頁^ 2263 Middle-aged ^ month i Guang, A7-yij — B7 V. Description of the invention () In this way, the company or enterprise 14 does not need to use the leased wide area network cable, and can safely use the general network system. The network service company 1 3 uses the access repeater 17 and a database i 8 to handle the VPN communication. The access repeater 17 has two interfaces: a VpN interface 171 to provide point-to-point access using public switched telephone networks (psTNs) or Integrated Services Digital Network (ISDN), and a general network communication interface 172, which can provide TCP / IP protocol to send packets to the Internet 15 or non-virtual private networks. PPTP uses an enhanced GRE (Generic Routing Encapsulation) mechanism to provide traffic and congestion-encapsulated datagram services to transmit ppp packets. When the user 11 of an enterprise uses the PPTP protocol and dials to an Internet service company 13, the packet is encapsulated and then transmitted to the access repeater 17. The wrapped ppp packets will be transmitted using IP. Therefore, the data format of the wrapped PPP packet will be shown in Figure 2. It includes a media header 21, an IP header 22, a GRE header 23, and a packet 24 of PP. The conventional access repeater 17 will only confirm the authenticity of the dial-up user's identity from the eaUm block in the PP packet, and then assign a legitimate network address to the dial-up user to replace its source bit. site. In this way, without having to decrypt the packet, the dial-up user can access the virtual 3 paper size applicable to the Chinese National Standard (CNS) A4 specification (210 X 297 mm). page

訂 酵Order leaven

經 濟 部 智 慧 財 產 局 員 工 消 費 合 社 印 製 512263 經濟部智慧財產局員工消費合作社印製 A7 B7 五、發明說明() 擬私有網路。換而言之,網路服務公司1 3可使撥號使用 者U直接執行與伺服器14的ppp通訊協定。結果,如 果該撥號使用者只想瀏覽網際網路或使用遠程登錄 (TELNET ),檔案傳輸(FTP ),電子佈告攔(BBS ),及 網際網路(WWW )等功能,他仍必需連結至位於VPN 1 9 的伺服器1 4 。這樣的結果並不但耗費連結的時間,而且 也產生不必要的通訊流量。 另外’就目刖存取中繼器的架構而言,如果要增加隨 選服務的功能,便須配合「遠端身份確認撥號使用者服務」 (Remote Authentication Dial-In User Service, RADI〇U )認證的架構來達成。如此不但必須修正既有的 PPP通訊協定,以支援ΕΑΡ ( PPP的可擴充式認證, RFC2284 )標準,更要增加RADms認證架構的成本。如 此’在實務架設及程式設計上皆較為困難且複雜。另外, 在單一 PPP鏈結的設計下,存取中繼器對遠端使用者所 傳运的PPP資料(payl〇ad )封包,僅能作包裹vpN標頭 及轉送的動作’無法隨時分析封包内的資料,例如Ιρ,Ιρχ 等位址,以作為鏈結服務品質選擇的依據,所以在實用上 較缺乏彈性。 5 — 2發明目的及概述 依據上述之問題,本發明的目的之一在提出一種應用 於VPN之存取中繼器的隨選服務系統與方法,係可讓使 4 本紙張尺度翻中國國家標準(cjNsA規格(210 X 297公餐) -----------— ----- — 訂------- ——蠢| (請先閱讀背面之注意事項再填寫本頁) 512263Printed by the Intellectual Property Bureau of the Ministry of Economic Affairs and Consumer Affairs Co., Ltd. 512263 Printed by the Consumer Cooperatives of the Intellectual Property Bureau of the Ministry of Economic Affairs A7 B7 5. Description of the invention () It is intended to be a private network. In other words, the network service company 13 can enable the dial-up user U to directly execute the ppp communication protocol with the server 14. As a result, if the dial-up user only wants to browse the Internet or use remote login (TELNET), file transfer (FTP), electronic bulletin board (BBS), and Internet (WWW) functions, he still has to link to VPN 1 9 server 1 4. This result not only consumes connection time, but also generates unnecessary communication traffic. In addition, as far as the architecture of the eye access repeater is concerned, if you want to add on-demand services, you must cooperate with the "Remote Authentication Dial-In User Service (RADI〇U)" Certified architecture to achieve. In this way, not only must the existing PPP communication protocol be modified to support EAP (PPP Extensible Authentication, RFC2284) standard, but also the cost of the RADms authentication architecture must be increased. In this way, it is difficult and complicated to set up and program. In addition, under the design of a single PPP link, the access repeater can send packets of PPP data (payload) transmitted by the remote user, which can only be used to wrap the vpN header and forward the action. 'The packet cannot be analyzed at any time. The internal data, such as Ιρ, Ιρχ, etc., are used as the basis for the selection of link service quality, so it is less flexible in practice. 5 — 2 Objects and Summary of the Invention According to the above-mentioned problems, one of the objects of the present invention is to propose an on-demand service system and method for an access repeater for VPN, which can make 4 paper sizes turn over Chinese national standards (CjNsA specifications (210 X 297 meals) ------------- ----- — Order ------- ---- stupid | (Please read the precautions on the back before filling (This page) 512263

經濟部智慧財產局員工消費合作社印製 五、發明說明() 用者在連結至VPN伺服器之前,可對存取中繼器要求非 虛擬私有網路的服務。 本發明之另一目的在提出一種可提供隨選服務的存取 中繼器系統與方法,係可延續既有之ppp通訊協定機制, 而能提供中繼器隨選服務的功能,以減少程式安裝及修正 的成本。 本發明之又一目的在提出一種應用於虛擬私有網路之 PPTP鏈結分段的方法,係可僅針對虛擬私有網路部份程 式碼作少許的修改,便可提供中繼器進行功能的新增或程 式碼升級,減少設備裝置及維持的複雜度。 本發明之又一目的在提出一種不須額外支援radius 機制的PPTP鏈結分段的方法,係可節省建置radius代 理伺服器與伺服器設備的費用,進而節省成本。 依據上述之目的’本發明主要以兩階段式的ppp鏈 結來處理使用者的連線須求。第一階段的ppp鏈結是為 了進行使用者與存取中繼器之間的協調。在第一階段的 PPP鏈結時,使用者的身份將被確認。如果該使用者為合 法的使用者,則該使用者便會被賦于一個新的網路位址。 然後’使用者便可自隨選中繼器所提供的功能選單中選取 一個服務項目,包含虛擬私有網路及非虛擬私有網路,如 5 本紙張尺度適用中國ΐ家標準(CNS)A4規格(210 X 29「公f ) 一 嶋 --- -______III — — ill — — — — ^«1—--I--- (請先閱讀背面之注意事項再填寫本頁) A7 512263 Ψ Ί Γ ......................- .......Β7__ 五、發明說明() 遠程登錄(TELNET ),檔案傳輸(FTP ),電子佈告欄 (BBS )’及網際網路(WWW )。如果使用者選擇非虛擬 私有網路,存取中繼器便會將封包傳送到其目的位址。如 果使用者要求一虛擬網路服務,則存取中繼器便會建立一 與虛擬私有網路連結的 PPP通訊協定。如此,使用者便 可存取非虛擬私有網路連結的服務,而不必直接連接到虛 擬私有網路的伺服器。 5 — 3圖式之簡單說明 圖1顯示習知之虛擬私有網路的系統示意圖。 圖2顯示一包裹之PPP封包的格式。 圖3顯示一本發明之具有隨選功能的中繼器系統運作 不意圖。 圖4顯示本發明之方法的流程圖。 圖號說明: 11 :使用者 1 3 :網路服務公司 1 5 :網際網路 1 7 :存取中繼器 1 72 :網路通訊介面 21 :媒介標頭 23 : GRE標頭 3 0 :網路服務公司 本紙張尺度適用中國國家標準(CNS)A4規格(210 X 297公釐) ---------------------訂·-----— (請先閱讀背面之注意事項再填寫本頁) 1 2 :公共電話網路 14 :企業 16 :隧道 171 : VPN 介面 1 8 :資料庫 22 : IP標頭 24 : PPP的封包 3 1 :存取中繼器 6 經濟部智慧財產局員工消費合作社印製 512263Printed by the Consumer Cooperative of the Intellectual Property Bureau of the Ministry of Economic Affairs 5. Description of the Invention () Before connecting to the VPN server, the user can request the service of the non-virtual private network for the access repeater. Another object of the present invention is to provide an access repeater system and method that can provide on-demand services, which can continue the existing ppp communication protocol mechanism and can provide the function of repeater on-demand services to reduce programs. Installation and correction costs. Another object of the present invention is to propose a method for segmenting a PPTP link applied to a virtual private network, which can only provide a function of a repeater for only a small modification of some codes of the virtual private network. Add or upgrade code to reduce the complexity of equipment installation and maintenance. Another object of the present invention is to propose a method for segmenting a PPTP link without additional support for a radius mechanism, which can save the cost of setting up a radius proxy server and server equipment, thereby saving costs. According to the above-mentioned object ', the present invention mainly uses two-stage ppp links to handle user connection requirements. The first stage of the ppp link is for coordination between the user and the access repeater. During the first PPP link, the identity of the user will be confirmed. If the user is a legitimate user, the user is assigned a new network address. Then the user can select a service item from the function menu provided by the on-demand repeater, including virtual private network and non-virtual private network. (210 X 29 「公 f) 嶋---- -______ III — — ill — — — — ^« 1 —-- I --- (Please read the notes on the back before filling this page) A7 512263 Ψ Ί Γ ......................-....... Β7__ 5. Description of the invention () Remote login (TELNET), file transfer (FTP), electronic Bulletin Board (BBS) 'and Internet (WWW). If the user chooses a non-virtual private network, the access repeater will send the packet to its destination address. If the user requests a virtual network service, The access repeater will establish a PPP communication protocol that is connected to the virtual private network. In this way, users can access services that are not connected to the virtual private network without having to connect directly to the server of the virtual private network 5 — 3 Brief description of the diagrams Figure 1 shows a schematic diagram of a conventional virtual private network system. Figure 2 shows a parcel of PPP The format of the packet. Figure 3 shows the operation of the repeater system with on-demand function of the present invention. Figure 4 shows the flowchart of the method of the present invention. Figure number description: 11: user 1 3: network service company 1 5: Internet 1 7: Access repeater 1 72: Network communication interface 21: Media header 23: GRE header 3 0: Network service company This paper standard applies to China National Standard (CNS) A4 specifications (210 X 297 mm) --------------------- Order · -----— (Please read the notes on the back before filling this page) 1 2: Public telephone network 14: Enterprise 16: Tunnel 171: VPN interface 1 8: Database 22: IP header 24: PPP packet 3 1: Access repeater 6 Printed by the Consumer Cooperative of Intellectual Property Bureau of the Ministry of Economic Affairs 512263

五、發明說明( 32 :公共交換電話線路 34 :使用者 3 6 1 :連結層控制裝置 33:實體層介面裝置 35 : VPN伺服器 3 62 :身份確認裝置 經濟部智慧財產局員工消費合作社印製 ’罔路層的通吼控制裝置3 7 :服務提供裝置 3 8 1 ·連結層控制裝置 3 82 :網路層連結控制裝置 5 — 4本發明之詳細說明 假5又網路撥接服務性質為網際網路漫遊,且虛擬私有 ,、罔路祠服端所聯結之區域網路使用TCP/IP通訊協定,本 發明之方法在PPP鏈結中區分為兩階段,如圖3所示。 圖3顯不本發明之具有隨選服務功能的存取中繼器。存取 中繼器31在一可接受撥接存取的平台上執行,並可控制 來自a共父換電話線路(卩心以Switched Telephone NetW〇rks) 32’或整體服務數位網路(ISDN)的撥接 電話存取控制,或者發出一向外的電路交換連結。 存取中繼器31也提供實體層介面裝置33(physical native interfacing device),以連結公共交電話線路32。 在遠端使用者撥號成功,並要求一與網路服務公司3 〇的 連結層(data link layer )通訊協調時,連結層控制裝置361 便為該撥號使用者執行一 PPP的連結層通訊協調,以與 該撥號使用者的主機3 4連結。連結時,身份確認裝置3 62 查詢一 V P N使用者資料庫,以執行身份的確認,例如查 詢使用者封包中的來源位址,使用權限,使用者身份識別 本紙張尺度適用中國國家標準(CNS)A4規格(210 X 297公釐) --------itii! — 訂------- ——S (請先閱讀背面之注意事項再填寫本頁) A7V. Description of the invention (32: Public switched telephone line 34: User 3 6 1: Link layer control device 33: Physical layer interface device 35: VPN server 3 62: Identity confirmation device Printed by the Consumer Cooperative of the Intellectual Property Bureau of the Ministry of Economic Affairs The communication control device 3 of the Kushiro layer: the service providing device 3 8 1 · the connection layer control device 3 82: the network layer connection control device 5-4 The detailed description of the present invention is 5 and the nature of the network dial-up service is The Internet is roaming and virtual private. The local network connected to the Kushiro Temple server uses the TCP / IP communication protocol. The method of the present invention is divided into two stages in the PPP link, as shown in Figure 3. Figure 3 Shows the access repeater with the on-demand service function of the present invention. The access repeater 31 is executed on a platform that can accept dial-up access, and can control the exchange of telephone lines from a parent Switched Telephone NetWrks) 32 'or dial-up telephone access control for the Integrated Services Digital Network (ISDN), or issue an outward circuit-switched connection. The access repeater 31 also provides a physical layer interface device 33 (physical native interfacing device ) To connect to the public telephone line 32. When the remote user dials up successfully and requests a communication coordination with the data link layer of the network service company 30, the link layer control device 361 is used for the dialing The user performs a PPP link-layer communication coordination to connect with the dial-up user's host 34. When connecting, the identity confirmation device 3 62 queries a VPN user database to perform identity verification, such as querying the user packet Source address, usage rights, and user identification This paper size is applicable to China National Standard (CNS) A4 (210 X 297 mm) -------- itii! — Order ------- ——S (Please read the notes on the back before filling this page) A7

512263 五、發明說明( 碼’及密碼等窨斗 寸貝枓疋否真確。如果判定使用者34為一合 法的V P N使用| 寻’ P P P協定將繼續執行網路層(N e t w 〇 r k layer )的通訊 協5周。與習知技術不同的是,網路層的通 訊控制裝置:U q _ 將封包解碼並取得其網路號碼及服務需求512263 V. Description of the invention (codes and passwords are not correct. If it is determined that the user 34 is a legitimate VPN use | find 'PPP protocol will continue to implement the network layer (N etw rk layer) Communication Association 5 weeks. Unlike the conventional technology, the communication control device at the network layer: U q _ decodes the packet and obtains its network number and service requirements

等資料。在PPP 通訊協調完成後,遠端的使用者34將被 賦于一個糸祕& μ /、、、、斤、心的新網路位址,如ip位址。由於此網 路位址與;^太# ' &使用者所屬的VPN網路位址不同,因此 該使用者所蘇+ AA4·, kAnd other information. After the PPP communication is coordinated, the remote user 34 will be assigned a secret new network address, such as an IP address. Because the address of this network is different from ^ 太 # '& the VPN network address to which the user belongs, so the user has + AA4, k

X出的封包將不會被傳送到其所屬的VPN 中。而該使用去^ 考也不必先連結到其所屬的VPN伺服器35, 再u VpN伺服器3 5連結至其它的網路服務或使用其資 源。網路連結控制裝i 363 ,亦可決定封包的路由方式。 然後,在第一次的ppp通訊協調完成後,具有新網 路位址的封包便會被傳送到服務提供裝置37。服務提供 裝置37提供了隨選的服務給撥號使用者選擇。由於撥 號使用者已有了新^ Ip位址,於是便可自由選取各種不 同的非虛擬私有網路服務,如遠程登錄(丁elne丁),檔 案傳輸(FTP ) ’電子佈告攔(BBS ),及網際網路()。 士果使用者34選擇N〇n_VPN的服務時,服務提供裝置η 便會直接傳送這些封包至其目的位址,而不必再連結至該 使用者公司的VPN伺服器35。另一方面,如果使用者34 選擇VPN服務,存取中繼器31便會對vpN伺服器h建 立第二次的PPP連結。在ppp的通訊協定中,連結層控 制裝置381可以從笛—^ PPP ^ yj- « 攸弟_人連結的連結層通訊協定中 ---------!丨-------訂--------- (請先閱讀背面之注意事項再填寫本頁) 經濟部智慧財產局員工消費合作社印製 經濟部智慧財產局員工消費合作社印製 A? B7 五'發明說明() 所獲得使用者資料,不必再執行使用者的身份確認,所 以可加快連結的速度。然後,封包便會轉送到網路層連結 控制裝置3 82,以對虛擬私有網路伺服器3 5建立網路層 的通汛。此時,使用者丨i可自vpN伺服器3 5獲取一合 法的VPN位址,如1P位址或IPX位址,因此使用者可 存取VPN伺服器35的資源。 圖4顯不本發明之應用vpn之存取中繼器的隨選方 法,包含下列步驟: 40 1 :在接收到一連結的需求時,對一撥接使用者執 行一連結層的通訊協調。 402 ·查詢一虛擬私有網路使用者資料庫以判定該撥 接使用者的身份。如果該撥接使用者的身份無誤,執行步 驟4 04 ;否則執行步驟403。 403 ·•拒絕撥接使用者的連結需求。 4 04 :對該撥接使用者執行一網路層的通訊協調,包 括對PPP封包解密,以取得網路位址,及服務需求資料。 405 :賦于一新的網路位址給該撥接使用者。 406 :提供一隨選服務的選單給該撥接使用者選擇。 如果該使用者要求一個非虛擬私有網路的服務時,執行牛 驟407。否則,執行步驟408。 407 ·如果撥接使用者選擇一個非虛擬私有網路的服 務時,如TELNET,FTP,BBS及WWW,轉送封包至其 9 本紙張尺度適用中國國家標準(CNS)A4規格(210 X 297公釐) •— !ί!丨丨.丨丨丨丨丨..丨訂丨——丨i- ί請先閱讀背面之注意事項再填寫本頁} 1The packets from X will not be transmitted to the VPN to which they belong. And for this use, you do not need to connect to the VPN server 35 to which it belongs first, and then connect the VpN server 35 to other network services or use its resources. The network link control device i 363 can also determine the routing mode of the packet. Then, after the first ppp communication coordination is completed, the packet with the new network address is transmitted to the service providing device 37. The service providing means 37 provides on-demand services for the dialing user to select. Since the dial-up user already has a new IP address, he can freely choose various non-virtual private network services, such as remote login (Delne Ding), file transfer (FTP), and electronic bulletin board (BBS). And the internet (). When the Shiguo user 34 selects the service of Non_VPN, the service providing device η will directly send these packets to its destination address, without having to connect to the VPN server 35 of the user company. On the other hand, if the user 34 chooses a VPN service, the access repeater 31 establishes a second PPP connection to the vpN server h. In the ppp communication protocol, the link layer control device 381 can select the link layer communication protocol from 笛 — ^ PPP ^ yj- «Youdi_ren linking link layer protocol ---------! 丨 ------ -Order --------- (Please read the notes on the back before filling out this page) Printed by the Consumer Cooperatives of the Intellectual Property Bureau of the Ministry of Economic Affairs Printed by the Consumer Cooperatives of the Intellectual Property Bureau of the Ministry of Economic Affairs Printed A? B7 Five 'Invention Explanation () The obtained user data does not need to perform the identity verification of the user, so the connection speed can be accelerated. The packet is then forwarded to the network layer link control device 3 82 to establish a network layer flood to the virtual private network server 3 5. At this time, the user can obtain a valid VPN address, such as a 1P address or an IPX address, from the vpN server 35, so the user can access the resources of the VPN server 35. Fig. 4 shows the on-demand method of the VPN access repeater according to the present invention, which includes the following steps: 40 1: When a connection request is received, a link layer communication coordination is performed for a dial-up user. 402. Query a virtual private network user database to determine the identity of the dial-up user. If the identity of the dial-up user is correct, perform step 4 04; otherwise, perform step 403. 403 · • Deny connection request from dial-up user. 4 04: Perform a network layer communication coordination for the dial-up user, including decrypting the PPP packet to obtain the network address and service demand data. 405: Assign a new network address to the dial-up user. 406: Provide a menu of on-demand services for the dialing user to choose. If the user requests a service from a non-virtual private network, perform step 407. Otherwise, step 408 is performed. 407 · If the dial-up user selects a service other than a virtual private network, such as TELNET, FTP, BBS, and WWW, the packet is forwarded to 9 of this paper. The paper size applies the Chinese National Standard (CNS) A4 specification (210 X 297 mm) ) • —! Ί! 丨 丨. 丨 丨 丨 丨 丨 .. 丨 Order 丨 —— 丨 i- ί Please read the notes on the back before filling in this page} 1

私 調 ^2263 ^ . - r "— 丨丨丨__圓丨"丨 __, 五、發明說明() 目的位址。 408:依據第一次連結層#通訊所得的資料,對虛擬 有網路伺服器執行一連結層的通訊協調。 4〇9 ·對虛擬私有網路伺服器執行一網路層的通訊協 〇 4 0提供β法的虛擬私有網路位址給該撥接使用 者,如IP位址或IPX位址。 4 1 0 ·連結該虛擬私有網路伺服器。 本發明之最佳實施例已詳述如上,但在上述之實施例 所作的若干變更,仍在本發明之專利範圍内,例如:本發 明可適用於任何可應用於未來的虛擬私有網路連結的類似 通訊協定。而且,隨選服務的項目也可依實際的狀況而設 定,並不限於以上所述之FTP,FTp,Bbs,及www等服務。 以上所述僅為本發明之較佳實施例而已,且已達廣 泛之實用功效,凡依本發明申請專利範圍所作之均等變 化與修飾,皆仍屬本發明專利涵蓋之範圍内。 -----------------丨訂---------^9— (請先閱讀背面之注意事項再填寫本頁) 經濟部智慧財產局員工消費合作社印製 10 本紙張尺度適用中國國家標準(CNS)A4規格(210 X 297公釐)Private adjustment ^ 2263 ^.-R " — 丨 丨 丨 __ 圆 丨 " 丨 __, V. Description of the invention () Destination address. 408: Based on the data obtained from the first link layer # communication, perform a link layer communication coordination on the virtual network server. 409 • Implement a network layer communication protocol to the virtual private network server. 040 provide the virtual private network address of the beta method to the dial-up user, such as an IP address or IPX address. 4 1 0 · Connect to the virtual private network server. The preferred embodiment of the present invention has been described in detail above, but several changes made in the above embodiments are still within the scope of the patent of the present invention. For example, the present invention can be applied to any future virtual private network connection. Similar protocol. Moreover, the on-demand service items can also be set according to the actual situation, and are not limited to the FTP, FTp, Bbs, and www services mentioned above. The above description is only the preferred embodiment of the present invention, and has achieved a wide range of practical effects. Any equivalent changes and modifications made in accordance with the scope of the patent application of the present invention are still covered by the patent of the present invention. ----------------- 丨 Order --------- ^ 9— (Please read the notes on the back before filling this page) Employees of the Intellectual Property Bureau of the Ministry of Economic Affairs Printed by Consumer Cooperatives 10 This paper is sized for China National Standard (CNS) A4 (210 X 297 mm)

Claims (1)

經濟部智慧財產局員工消費合作社印製 512263 A8 B8 C8 D8 六、申請專利範圍 1. 一種應用於虛擬私有網路之存取中繼器的隨選服務方 法,包含步驟: 當收到一撥號使用者之連結需求時,建立該撥號使 用者之第一階段的點對點通訊協定; 查詢一虛擬私有網路使用者資料庫以判定該撥號使 用者的身份真確性; 當該撥號使用者之身份判定為真時,賦于該撥號使 用者一網路位址; 提供一隨選服務選單給該撥號使用者選取,及該隨 選服務包含虛擬私有網路的連線服務及非虛擬私有網路的 服務; 當該撥號使用者選取一虛擬私有網路的連線服務 時,與該虛擬私有網路之伺服器建立一第二階段的點對點 通訊連結;及 賦于該撥號使用者一合法的虛擬私有網路位址以存 取該虛擬私有網路。 2. 如申請專利範圍第1項所述之方法,更包含步驟: 建立一虛擬私有網路使用者資料庫,以儲存虛擬私 有網路之使用者資料。 3. 如申請專利範圍第1項所述之方法,更包含步驟: 11 本紙張尺度適用书國國家標準( CNS ) A4規格(210X297公釐) (請先聞讀背面之注意事項再填寫本頁)Printed by the Consumer Cooperative of the Intellectual Property Bureau of the Ministry of Economic Affairs 512263 A8 B8 C8 D8 VI. Application for Patent Scope 1. An on-demand service method for access repeaters applied to virtual private networks, including steps: When a dial-up is used When the connection needs of the dial-up user, establish the first-stage point-to-point communication protocol of the dial-up user; query a virtual private network user database to determine the authenticity of the dial-up user's identity; when the dial-up user's identity is determined as When true, the dial-up user is given a network address; an on-demand service menu is provided for the dial-up user to select, and the on-demand service includes a virtual private network connection service and a non-virtual private network service ; When the dial-up user selects a virtual private network connection service, establishing a second-stage point-to-point communication link with the server of the virtual private network; and assigning the dial-up user a legal virtual private network Address to access the virtual private network. 2. The method described in item 1 of the scope of patent application, further comprising the steps of: establishing a virtual private network user database to store user data of the virtual private network. 3. The method described in item 1 of the scope of patent application, further including the steps: 11 This paper size applies the national standard (CNS) A4 specification (210X297 mm) of the paper (please read the precautions on the back before filling out this page) ) 經濟部智慧財產局員工消费合作社印製 512263 A8 B8 C8 D8 六、申請專利範圍 當上述之撥號使用者的身份判定為不真確時’拒絕 上述之第一階段的點對點通訊連結要求。 4. 如申請專利範圍第1項所述之方法,其中上述之網路位 址為IP位址。 5. 如申請專利範圍第1項所述之方法,其中上述之非虛擬 私有網路服務包含: 遠程登錄,檔案傳輸,網際網路,及電子佈告攔。 6. 如申請專利範圍第1項所述之方法,其中上述之合法的 虛擬私有網路位址為一 IP位址。 7. 如申請專利範圍第1項所述之方法,其中上述之合法的 虛擬私有網路位址為一 IPX位址。 8. 如申請專利範圍第1項所述之方法,更包含步驟: 當上述之撥號使用者選取一非虛擬私有網路的服務 時;轉送上述之撥號使用者的封包至其目的位址。 9. 如申請專利範圍第1項所述之方法,其中上述之第二階 段的PPP通訊連結,係依據上述之第一階段的PPP通訊連 結中所取得的使用者資料來執行。 12 本紙張尺度逋用中國國家標準(CNS ) A4規格(210 X 297公釐) I---------1#_------^------ (請先閱讀背面之注意事項再填寫本頁) 512263 A8 B8 C8Printed by the Consumer Cooperatives of the Intellectual Property Bureau of the Ministry of Economic Affairs 512263 A8 B8 C8 D8 VI. Scope of Patent Application When the identity of the above dial-up user is determined to be inaccurate 'rejection of the above-mentioned first-phase peer-to-peer communication connection request. 4. The method described in item 1 of the scope of patent application, wherein the above-mentioned network address is an IP address. 5. The method described in item 1 of the scope of patent application, wherein the aforementioned non-virtual private network services include: remote login, file transfer, Internet, and electronic bulletin board. 6. The method described in item 1 of the scope of patent application, wherein the legal virtual private network address is an IP address. 7. The method described in item 1 of the scope of patent application, wherein the legal virtual private network address is an IPX address. 8. The method described in item 1 of the scope of patent application, further comprising the steps of: when the dial-up user selects a service of a non-virtual private network; and forwarding the packet of the dial-up user to its destination address. 9. The method described in item 1 of the scope of patent application, wherein the second-stage PPP communication link is performed based on the user data obtained in the first-stage PPP communication link. 12 This paper uses China National Standard (CNS) A4 size (210 X 297 mm) I --------- 1 # _------ ^ ------ (please first (Read the notes on the back and fill out this page) 512263 A8 B8 C8 六、申請專利範圍 1 〇. 一種可提供隨選服務功能的虛擬私有網路存取中繼器 系統’包含: (請先聞讀背面之注意事項再填寫本頁) 一介面裝置,用以接收來自公用電話網路的連結需 求; 一第一連結層控制裝置,用以執行與一撥號使用者 之主機的連結層之通訊協調; 一身份確認裝置,係耦合至一虛擬私有網路使用者 資料庫’用以判定該撥號使用者的身份真確性; 一第一網路層控制裝置,用以執行與該撥號使用者 之主機的網路層之通訊協調,並取得一網路位址; 一服務提供裝置,用以提供一隨選服務選單給該撥 號使用者選擇; 一第二連結層控制裝置,用以對一虛擬私有網路伺 服器建立一第二連結層之通訊協調;及 一第二網路層控制裝置,用以賦于該撥號使用者一 合法的虛擬私有網路位址,以存取該虛擬私有網路伺服 器。、 經濟部智慧財產局員工消費合作社印製 11. 如申請專利範圍第10項所述之系統,其中上述之網路 位址係為IP位址。 12. 如申請專利範圍第1〇項所述之系統,其中上述之隨選 服務包含··虛擬私有網路服務及非虛擬私有網路服務。 13 本紙張尺度適用肀國國家揉準(CNS ) A4規格(210X297公釐) 512263 A8 B8 C8 D8 六、申請專利範圍 1 3 .如申請專利範圍第1 2項所述之系統,其中上述之非虛 擬私有網路服務包含: 遠程登錄,檔案傳輸,網際網路,及電子佈告攔。 1 4.如申請專利範圍第1 〇項所述之系統,其中上述之合法 的虛擬私有網路位址為一 IP位址。 15/如申請專利範圍第10項所述之系統,其中上述之合法 的虛擬私有網路位址為一 IPX位址。 1 6.如申請專利範圍第1 0項所述之系統,其中上述之服務 提供裝置係在上述之撥號使用者要求一非虛擬私有網路服 務時,將上述之撥號使用者的封包轉送至其目的位址。 (請先閱讀背面之注意事項再填寫本頁) 經濟部智慧財產局員工消費合作社印製 14 本紙張尺度適用肀國國家標準(CNS ) A4規格(210X297公釐)6. Scope of Patent Application 1 〇 A virtual private network access repeater system capable of providing on-demand service functions' includes: (Please read the precautions on the back before filling this page) An interface device for receiving A connection request from a public telephone network; a first link layer control device to perform communication coordination with the link layer of a host of a dial-up user; an identity confirmation device coupled to a virtual private network user data The library is used to determine the authenticity of the dial-up user. A first network layer control device is used to perform communication coordination with the network layer of the host of the dial-up user and obtain a network address. A service providing device for providing an on-demand service menu for the dialing user to choose; a second link layer control device for establishing a second link layer communication coordination with a virtual private network server; and a first The second network layer control device is used to give the dial-up user a legal virtual private network address to access the virtual private network server. Printed by the Consumer Cooperatives of the Intellectual Property Bureau of the Ministry of Economic Affairs 11. The system described in item 10 of the scope of patent application, wherein the above-mentioned network address is an IP address. 12. The system described in item 10 of the scope of patent application, wherein the on-demand services mentioned above include a virtual private network service and a non-virtual private network service. 13 This paper size is applicable to Laos National Standard (CNS) A4 (210X297 mm) 512263 A8 B8 C8 D8 VI. Application scope of patents 1 3. The system described in item 12 of the scope of patent applications, where the above non- Virtual private network services include: remote login, file transfer, Internet, and electronic bulletin boards. 14. The system as described in item 10 of the scope of patent application, wherein the legal virtual private network address is an IP address. 15 / The system according to item 10 of the scope of patent application, wherein the legal virtual private network address is an IPX address. 16. The system as described in item 10 of the scope of patent application, wherein the above-mentioned service providing device transfers the above-mentioned dial-up user's packet to the dial-up user when the dial-up user requests a non-virtual private network service. Destination address. (Please read the notes on the back before filling out this page) Printed by the Consumer Cooperatives of the Intellectual Property Bureau of the Ministry of Economic Affairs 14 This paper size applies the national standard (CNS) A4 (210X297 mm)
TW88108149A 1999-05-19 1999-05-19 On-demand system and method for access repeater used in Virtual Private Network TW512263B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW88108149A TW512263B (en) 1999-05-19 1999-05-19 On-demand system and method for access repeater used in Virtual Private Network

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW88108149A TW512263B (en) 1999-05-19 1999-05-19 On-demand system and method for access repeater used in Virtual Private Network

Publications (1)

Publication Number Publication Date
TW512263B true TW512263B (en) 2002-12-01

Family

ID=27731163

Family Applications (1)

Application Number Title Priority Date Filing Date
TW88108149A TW512263B (en) 1999-05-19 1999-05-19 On-demand system and method for access repeater used in Virtual Private Network

Country Status (1)

Country Link
TW (1) TW512263B (en)

Similar Documents

Publication Publication Date Title
US6694437B1 (en) System and method for on-demand access concentrator for virtual private networks
US7768941B1 (en) Method and system for initiating a virtual private network over a shared network on behalf of a wireless terminal
US7586939B2 (en) Mobile IP communication scheme for supporting mobile computer move over different address spaces
Mamakos et al. A method for transmitting PPP over Ethernet (PPPoE)
JP5161262B2 (en) Method and system for resolving addressing conflicts based on tunnel information
US20180270660A1 (en) Method and system for peer-to-peer enforcement
US5918019A (en) Virtual dial-up protocol for network communication
JP3343064B2 (en) Pseudo network adapter for capturing, encapsulating and encrypting frames
EP1500223B1 (en) Transitive authentication authorization accounting in interworking between access networks
US9088547B2 (en) Connection method, communication system, device, and program
US20010034831A1 (en) Method and apparatus for providing internet access to client computers over a lan
WO1999038081A1 (en) Virtual private network system and method
JP2001160828A (en) Vpn communication method in security gateway device
US20040168049A1 (en) Method for encrypting data of an access virtual private network (VPN)
US20040243837A1 (en) Process and communication equipment for encrypting e-mail traffic between mail domains of the internet
CN112437355B (en) Method and system for realizing three-layer multicast
TW512263B (en) On-demand system and method for access repeater used in Virtual Private Network
JP3344421B2 (en) Virtual private network
JP3490358B2 (en) Inter-network communication method, server device, and inter-network communication system
Mamakos et al. RFC2516: A Method for Transmitting PPP Over Ethernet (PPPoE)
JP2006352710A (en) Packet repeating apparatus and program
JPH1132088A (en) Network system
JP3472098B2 (en) Mobile computer device, relay device, and data transfer method
JP4180458B2 (en) VPN communication system and VPN tunnel forming method
CN117938408A (en) Method and system for implementing dynamic access control in Android device

Legal Events

Date Code Title Description
GD4A Issue of patent certificate for granted invention patent
MK4A Expiration of patent term of an invention patent