WO2017000355A1 - 一种网络连接方法及电子设备 - Google Patents

一种网络连接方法及电子设备 Download PDF

Info

Publication number
WO2017000355A1
WO2017000355A1 PCT/CN2015/085857 CN2015085857W WO2017000355A1 WO 2017000355 A1 WO2017000355 A1 WO 2017000355A1 CN 2015085857 W CN2015085857 W CN 2015085857W WO 2017000355 A1 WO2017000355 A1 WO 2017000355A1
Authority
WO
WIPO (PCT)
Prior art keywords
network
electronic device
connection
data
data packet
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2015/085857
Other languages
English (en)
French (fr)
Inventor
成厚富
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Original Assignee
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Yulong Computer Telecommunication Scientific Shenzhen Co Ltd filed Critical Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Publication of WO2017000355A1 publication Critical patent/WO2017000355A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W48/00Access restriction; Network selection; Access point selection
    • H04W48/17Selecting a data network PoA [Point of Attachment]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/02Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W40/00Communication routing or communication path finding
    • H04W40/24Connectivity information management, e.g. connectivity discovery or connectivity update

Definitions

  • the present application relates to the field of electronic information, and in particular, to a network connection method and an electronic device.
  • VPDN Virtual Private Dial-up Networks
  • Existing electronic devices can only guarantee to remain connected to the VPDN or to maintain a connection with a public network (such as a mobile data network or a WIFI public network), and cannot simultaneously connect the VPDN to the public network.
  • a public network such as a mobile data network or a WIFI public network
  • the present application provides a network connection method and an electronic device, and aims to solve the problem of how to realize the simultaneous online connection between the VPDN of the electronic device and the public network.
  • a network connection method includes:
  • the first system controlling the electronic device is controlled to access the private network based on the network currently registered by the electronic device, and the second system controlling the electronic device is controlled to access the public network.
  • the first system shares a physical communication module with the second system, where the physical communication module is disposed in the first system or the second system;
  • the controlling the first system of the electronic device to access the private network, and controlling the second system of the electronic device to access the public network includes:
  • the network connection data packet is sent through the physical communication module according to a routing table corresponding to each of the two systems.
  • the first system is preferentially connected to the private network.
  • it also includes:
  • the first rule is started, where the first rule is to prohibit an application in the second system from sending a data packet to the network;
  • the second rule is started, where the second rule is to prohibit the application in the first system from sending a data packet to the network;
  • the current network connection status is that the first system is connected to the private network and the second system is connected to the public network, the first rule and the second rule are cleared.
  • controlling the second system of the electronic device to access the public network includes:
  • the second system is connected to the public network through the WIFI channel, and if the WIFI channel of the second system is not enabled, the mobile data channel is used to move the data channel.
  • the second system is connected to the public network.
  • An electronic device comprising:
  • connection control module configured to receive a network connection instruction, and control a first system accessing the private network of the electronic device according to a condition that the network currently registered by the electronic device meets a condition for supporting multiple PDNs, and control the electronic device
  • the second system accesses the public network.
  • the first system includes a first data connection manager, a first virtual network interface module, and a first routing management module
  • the second system includes a second data connection manager and a second virtual network interface.
  • Module and second route management module ;
  • the connection control module includes a first data connection manager, the first route management module, the first virtual network interface module, the second data connection manager, a second route management module, and a second virtual network interface Module
  • the first data connection manager is configured to establish or tear down a data connection of the first system and the private network, and notify and maintain a data connection state, where the first route management module is used by the first system.
  • Data packet routing and after matching the corresponding routing information, sending the data packet of the first system to the second system by using the first virtual network interface module;
  • the second data connection manager is used for Establishing or dismantling data connection of the second system and the private network, and notification and maintenance of a data connection state, where the second route management module is used for data packet routing of the second system, and is matched to corresponding After routing the information, the data packet of the second system is sent to the first system by using the second virtual network interface module.
  • the first system shares a physical communication module with the second system, where the physical communication module is disposed in the first system or the second system;
  • connection control module is configured to control the first system of the electronic device to access the private network, and the second system that controls the electronic device to access the public network includes:
  • the virtual network interface module of the system where the physical communication module is located is configured to receive a network connection data packet sent by another system;
  • the route management module of the system in which the physical communication module is located tags the received network connection data packet sent by another system; generates a first routing table according to the data packet with the mark; and according to the physical communication module a data packet sent by the system that does not have the tag, and generates a second routing table;
  • the second data connection manager sends a network connection data packet through the physical communication module according to a routing table corresponding to each of the two systems.
  • connection control module is further configured to:
  • the first system is preferentially connected to the private network.
  • connection control module is configured to: after receiving the network connection instruction, preferentially use the first system to connect to the private network, including:
  • the first data connection manager is configured to send a connection state of the first system to the second data connection manager;
  • the second data connection manager is configured to, after receiving an instruction that the second system is connected to the public network, if a connection status of the first system indicates that the first system is connected to the private network, The second system is prohibited from connecting to the public network; otherwise, the second system is controlled to access the public network.
  • the first system further includes a first firewall
  • the second system further includes a second firewall
  • the first firewall is configured to start a second rule if the current network connection status is that the second system is connected to the public network, where the second rule is only forbidding applications in the first system to send to the network a data packet; and, if the current network connection status is that the first system is connected to the private network and the second system is connected to the public network, clearing the second rule;
  • the second firewall is configured to: if the current network connection status is only that the first system is connected to the private network, start a first rule, where the first rule is to prohibit an application in the second system from being in a network Transmitting the data packet; and, if the current network connection status is that the first system is connected to the private network and the second system is connected to the public network, the first rule is cleared.
  • controlling the connection module to control the second system of the electronic device to access the public network includes:
  • the second data connection manager is specifically configured to: if the WIFI channel of the second system is enabled, access the second system to the public network through the WIFI channel, if the second system is WIFI If the channel is not turned on, the second system is connected to the public network by moving the data channel.
  • the network connection method and the electronic device if receiving the network connection instruction, control the first system of the electronic device to access the private network, and control the electronic device based on the condition that the network currently registered by the electronic device satisfies the condition of supporting multiple PDNs.
  • the second system is connected to the public network. It can be seen that the method and the electronic device in the embodiment can use the network to support the characteristics of multiple PDNs, and can implement simultaneous online of the private network and the public network through the dual system.
  • FIG. 1 is a flowchart of a network connection method according to an embodiment of the present application
  • FIG. 2 is a flowchart of still another network connection method according to an embodiment of the present application.
  • FIG. 3 is a flowchart of still another network connection method according to an embodiment of the present application.
  • FIG. 4 is a schematic structural diagram of an electronic device according to an embodiment of the present disclosure.
  • FIG. 5 is a schematic structural diagram of still another electronic device disclosed in an embodiment of the present application.
  • the embodiment of the present application discloses a network connection method, which can be applied to an electronic device (for example, a mobile terminal), where the electronic device includes a first system and a second system, where the first system is used to connect to a dedicated network, and the second The system is used to connect to a public network.
  • an electronic device for example, a mobile terminal
  • the electronic device includes a first system and a second system, where the first system is used to connect to a dedicated network, and the second The system is used to connect to a public network.
  • a network connection method disclosed in the embodiment of the present application, as shown in FIG. 1 includes the following steps:
  • the network connection command may be triggered by a user's operation, for example, an operation of the user selecting a network connection option on the electronic device.
  • S102 The first system that controls the electronic device accesses the private network, and controls the second system of the electronic device to access the public network, based on the condition that the network currently registered by the electronic device meets the condition of supporting multiple PDNs.
  • Supporting multiple PDNs means that the currently registered network type supports two or more PDNs simultaneously initiating connections, and the two PDNs may be based on the same APN (access point) or different APNs.
  • the WIFI channel is prioritized, that is, if the WIFI channel of the second system is enabled, the second system is connected to the public network through the WIFI channel, if the second If the WIFI channel of the system is not turned on, the second system is connected to the public network by moving the data channel.
  • the method in this embodiment can implement the simultaneous online operation of the private network and the public network based on the condition that the network supports multiple PDNs, thereby providing a better network usage experience for the user.
  • the private network and the public network may both be LTE-based networks. Therefore, the method described in this embodiment can implement dual-networking of the same-type private network and public network, which is The usual dual-line of multimode terminals has an essential difference.
  • a network connection method is disclosed in the embodiment of the present application.
  • the first system and the second system share a physical communication module.
  • the physical communication module is set in the second system as an example for description.
  • the method in this embodiment includes the following steps:
  • S203 Mark the network connection data packet sent by the first system received by the second system.
  • the route forwarding policy may be formed according to the data packet with the tag, and the first routing table is generated by combining the link information of the IP, the gateway, and the DNS corresponding to the first system.
  • S205 Generate a second routing table according to the routing table that is not marked by the second system.
  • S206 Send a network connection data packet by using the physical communication module according to a routing table corresponding to each of the two systems.
  • S207 The first system is preferentially connected to the private network.
  • the first system opens the connection channel, the first system is controlled to access the private network, and if the first system does not open the connection channel, the second system is controlled to access the public network.
  • different routing tables are set respectively for connecting the private network and the connected public network, so that when the private network and the public network are simultaneously connected, the two do not interfere with each other. Moreover, the security of the private network can be guaranteed.
  • the physical system is disposed in the second system as an example. If the physical communication module is disposed in the first system, the implementation principle is the same as the foregoing process, and details are not described herein again.
  • Another network connection method disclosed in the embodiment of the present application, as shown in FIG. 3, includes the following steps:
  • S303 Control the first system to access the private network, and control the second system to access the public network;
  • S304 Clear the first rule and the second rule.
  • the first rule is to prohibit the application in the second system from sending a data packet to the network
  • the second rule is to prohibit the application in the first system from sending a data packet to the network
  • connection rule is further used to further ensure that data packets of the system that prohibits the connection to the network are not sent to the network, thereby further ensuring the security of the system.
  • the embodiment of the present application further discloses an electronic device, as shown in FIG. 4, including:
  • the first system the second system, and the connection control module.
  • the first system is configured to be connected to the private network
  • the second system is configured to be connected to the public network
  • the connection control module is configured to: if the network connection instruction is received, the network currently registered according to the electronic device meets the condition for supporting multiple PDNs. And controlling a first system of the electronic device to access a private network, and controlling a second system of the electronic device to access the public network.
  • the second system is connected to the public network through the WIFI channel, and if the WIFI channel of the second system is not enabled, the data channel is moved. And connecting the second system to a public network.
  • connection control module is further configured to: if the network currently registered by the electronic device does not support the multiple PDN, after the network connection instruction is received, the first system is preferentially connected to the private network.
  • the electronic device described in this embodiment has two sets of systems. Based on the characteristics of the registration network supporting multiple PDNs, the purpose of simultaneously opening the private network and the public network can be achieved.
  • the electronic device is provided with a first system and a second system, and each system includes a network application (Net APP).
  • the first system of the electronic device includes a first data connection manager, a first virtual network interface module, and a first routing management module, where the second system includes a second data connection manager, a second virtual network interface module, and a Two routing management modules.
  • the first system shares the physical communication module with the second system, and the physical communication module setting may be set in the first system or the second system.
  • the physical communication module is set in the second system as an example for description. .
  • the first data connection manager is configured to establish or tear down a data connection of the first system and the private network, and notify and maintain a data connection status;
  • the first routing management module is configured to send the data packet of the first system to the first system, and after the matching to the corresponding routing information, send the data packet of the first system to the first virtual network interface module. Said second system.
  • the second data connection manager is configured to establish or tear down a data connection of the second system and the private network, and notify and maintain a data connection status;
  • the second route management module is configured to send the data packet of the second system to the second system, and after the matching to the corresponding routing information, send the data packet of the second system to the second virtual network interface module. Said the first system.
  • connection control module is composed of a first data connection manager, a first route management module, a first virtual network interface, a second data connection manager, a second route management module, and a second virtual network interface.
  • the connection control module controls the first system of the electronic device to access the private network, and the specific implementation manner of controlling the second system of the electronic device to access the public network may be:
  • the second virtual network interface in the second system receives the network connection data packet sent by the first system, and the second route management module in the second system marks the network connection data packet sent by the first system, and has The marked data packet generates a first routing table, and generates a second routing table according to the data packet sent by the system where the physical communication module is located and does not have the tag.
  • the second data connection manager in the second system sends the network connection data packet through the physical communication module according to the routing tables corresponding to the two systems respectively.
  • the specific implementation manner of using the first system to connect to the private network may be:
  • connection status of the first system indicates that the first system is connected to the private network, and the second system is prohibited from connecting to the public network; otherwise, the second system is controlled to access the public network.
  • the electronic device described in this embodiment further includes:
  • first firewall disposed in the first system and a second firewall disposed in the second system.
  • the first firewall is configured to: if the current network connection status is the second system and the public network Connected to the second rule, the second rule only prohibits the application in the first system from sending a data packet to the network; and if the current network connection status is the first system connected to the private network And the second system is connected to the public network, and the second rule is cleared;
  • the second firewall is configured to: if the current network connection status is only that the first system is connected to the private network, start a first rule, where the first rule is to prohibit an application in the second system from sending data to the network And; if the current network connection status is that the first system is connected to the private network and the second system is connected to the public network, the first rule is cleared.
  • the electronic device described in this embodiment is provided with a first system and a second system.
  • the first system is used to connect to a private network
  • the second system is used to connect to a public network
  • the dual network of the VPDN and the public network can be realized, which not only satisfies
  • the dual needs of government and enterprise users for security and Internet access have greatly improved the experience of government and enterprise users on data services.
  • the functions described in the methods of the embodiments of the present application may be stored in a computing device readable storage medium. Based on such understanding, a portion of the embodiments of the present application that contributes to the prior art or a portion of the technical solution may be embodied in the form of a software product stored in a storage medium, including a plurality of instructions for causing a
  • the computing device (which may be a personal computer, server, mobile computing device, or network device, etc.) performs all or part of the steps of the methods described in various embodiments of the present application.
  • the foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本申请提供了一种网络连接方法及电子设备,如果接收到网络连接指令,基于电子设备当前注册的网络满足支持多PDN的条件,控制电子设备的第一系统接入专用网络,并且控制电子设备的第二系统接入公共网络,可见,本实施例所述的方法及电子设备,利用网络支持多PDN的特性,能够通过双系统实现专用网络和公共网络的同时在线。

Description

一种网络连接方法及电子设备
本申请要求于2015年06月29日提交中国专利局,申请号为201510369779.9、发明名称为“一种网络连接方法及电子设备”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及电子信息领域,尤其涉及一种网络连接方法及电子设备。
背景技术
目前,为了满足客户的一些需求,例如安全性需求,专用网络营运而成,例如,虚拟专用拨号网(Virtual Private Dial-up Networks,VPDN)即为一种常用的专用网络。
现有的电子设备,只能保证或者与VPDN保持连接,或者与公共的网络(例如移动数据网或者WIFI公共网络)保持连接,而无法实现VPDN与公共网络的同时在线。
可见,如何实现电子设备的VPDN与公共网络的同时在线,成为目前亟待解决的问题。
发明内容
本申请提供了一种网络连接方法及电子设备,目的在于解决如何实现电子设备的VPDN与公共网络的同时在线的问题。
为了实现上述目的,本申请提供了以下技术方案:
一种网络连接方法,包括:
接收网络连接指令;
基于电子设备当前注册的网络满足支持多PDN的条件,控制所述电子设备的第一系统接入专用网络,并且控制所述电子设备的第二系统接入公共网络。
可选地,所述第一系统与所述第二系统共用物理通信模块,所述物理通信模块设置在所述第一系统或者所述第二系统中;
所述控制所述电子设备的第一系统接入专用网络,并且控制所述电子设备的第二系统接入公共网络包括:
将所述物理通信模块所在的系统接收到的另一个系统发送的网络连接数据包进行标记;
依据具有标记的数据包,生成第一路由表;
依据所述物理通信模块所在的系统发送的、不具有所述标记的数据包,生成第二路由表;
分别依据两个系统各自对应的路由表,通过所述物理通信模块,发送网络连接数据包。
可选地:如果所述电子设备当前注册的网络不支持多PDN,则在接收到网络连接指令后,优先使用所述第一系统连接所述专用网络。
可选地,还包括:
如果当前网络连接状态仅为所述第一系统与所述专用网络相连,则启动第一规则,所述第一规则为禁止所述第二系统中的应用向网络发送数据包;
如果当前网络连接状态仅为所述第二系统与所述公共网络相连,则启动第二规则,所述第二规则为禁止所述第一系统中的应用向网络发送数据包;
并且,如果当前网络连接状态为所述第一系统与所述专用网络相连且所述第二系统与所述公共网络相连,则清除所述第一规则及所述第二规则。
可选地,所述控制所述电子设备的第二系统接入公共网络包括:
如果所述第二系统的WIFI通道已开启,则通过所述WIFI通道,将所述第二系统接入公共网络,如果所述第二系统的WIFI通道未开启,则通过移动数据通道,将所述第二系统接入公共网络。
一种电子设备,包括:
第一系统,用于与专用网络连接;
第二系统,用于与公共网络连接;
连接控制模块,用于接收网络连接指令,并基于所述电子设备当前注册的网络满足支持多PDN的条件,控制所述电子设备的第一系统接入专用网络,并且控制所述电子设备的第二系统接入公共网络。
可选地,所述第一系统中包括第一数据连接管理器、第一虚拟网络接口模块及第一路由管理模块,所述第二系统中包括第二数据连接管理器、第二虚拟网络接口模块及第二路由管理模块;
所述连接控制模块包括第一数据连接管理器、所述第一路由管理模块、所述第一虚拟网络接口模块、所述第二数据连接管理器、第二路由管理模块以及第二虚拟网络接口模块;
其中,所述第一数据连接管理器用于建立或拆除所述第一系统与所述专用网络的数据连接以及数据连接状态的通知与维护,所述第一路由管理模块用于所述第一系统的数据包路由,并在匹配到对应的路由信息后,通过所述第一虚拟网络接口模块将所述第一系统的数据包发送到所述第二系统;所述第二数据连接管理器用于建立或拆除所述第二系统与所述专用网络的数据连接以及数据连接状态的通知与维护,所述第二路由管理模块用于所述第二系统的数据包路由,并在匹配到对应的路由信息后,通过所述第二虚拟网络接口模块将所述第二系统的数据包发送到所述第一系统。
可选地,所述第一系统与所述第二系统共用物理通信模块,所述物理通信模块设置在所述第一系统或者所述第二系统中;
所述连接控制模块用于控制所述电子设备的第一系统接入专用网络,并且控制所述电子设备的第二系统接入公共网络包括:
所述物理通信模块所在的系统的虚拟网络接口模块用于接收另一个系统发送的网络连接数据包;
所述物理通信模块所在的系统的路由管理模块将接收到的另一个系统发送的网络连接数据包进行标记;依据具有标记的数据包,生成第一路由表;并依据所述物理通信模块所在的系统发送的、不具有所述标记的数据包,生成第二路由表;
所述第二数据连接管理器分别依据两个系统各自对应的路由表,通过所述物理通信模块,发送网络连接数据包。
可选地,所述连接控制模块还用于:
如果所述电子设备当前注册的网络不支持多PDN,则在接收到网络连接指令后,优先使用所述第一系统连接所述专用网络。
可选地,所述连接控制模块用于在接收到网络连接指令后,优先使用所述第一系统连接所述专用网络包括:
所述第一数据连接管理器用于向所述第二数据连接管理器发送所述第一系统的连接状态;
所述第二数据连接管理器用于,在接收到所述第二系统连接所述公共网络的指令后,如果所述第一系统的连接状态指示所述第一系统与所述专用网络已连接,则禁止所述第二系统连接所述公共网络,否则,控制所述第二系统接入所述公共网络。
可选地,所述第一系统还包括第一防火墙,所述第二系统还包括第二防火墙;
所述第一防火墙用于如果当前网络连接状态为所述第二系统与所述公共网络相连,则启动第二规则,所述第二规则仅为禁止所述第一系统中的应用向网络发送数据包;并且,如果当前网络连接状态为所述第一系统与所述专用网络相连且所述第二系统与所述公共网络相连,则清除所述第二规则;
所述第二防火墙用于,如果当前网络连接状态仅为所述第一系统与所述专用网络相连,则启动第一规则,所述第一规则为禁止所述第二系统中的应用向网络发送数据包;并且,如果当前网络连接状态为所述第一系统与所述专用网络相连且所述第二系统与所述公共网络相连,则清除所述第一规则。
可选地,所述控制连接模块用于控制所述电子设备的第二系统接入公共网络包括:
所述第二数据连接管理器具体用于,如果所述第二系统的WIFI通道已开启,则通过所述WIFI通道,将所述第二系统接入公共网络,如果所述第二系统的WIFI通道未开启,则通过移动数据通道,将所述第二系统接入公共网络。
本申请所述的网络连接方法及电子设备,如果接收到网络连接指令,基于电子设备当前注册的网络满足支持多PDN的条件,控制电子设备的第一系统接入专用网络,并且控制电子设备的第二系统接入公共网络,可见,本实施例所述的方法及电子设备,利用网络支持多PDN的特性,能够通过双系统实现专用网络和公共网络的同时在线。
附图说明
为了更清楚地说明本申请实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1为本申请实施例公开的一种网络连接方法的流程图;
图2为本申请实施例公开的又一种网络连接方法的流程图;
图3为本申请实施例公开的又一种网络连接方法的流程图;
图4为本申请实施例公开的一种电子设备的结构示意图;
图5为本申请实施例公开的又一种电子设备的结构示意图。
具体实施方式
本申请实施例公开了一种网络连接方法,可以应用在电子设备(例如移动终端)上,所述电子设备具备第一系统和第二系统,其中,第一系统用于连接专用网络,第二系统用于连接公共网络。
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
本申请实施例公开的一种网络连接方法,如图1所示,包括以下步骤:
S101:接收网络连接指令;
其中,网络连接指令可以由用户的操作触发,例如,用户在电子设备上选择网络连接选项的操作。
S102:基于电子设备当前注册的网络满足支持多PDN的条件,控制电子设备的第一系统接入专用网络,并控制电子设备的第二系统接入公共网络。
所谓支持多PDN是指当前注册的网络类型支持两个或两个以上PDN同时发起连接,这两个PDN可以基于同一个APN(接入点)或不同的APN。
具体地,如果第二系统同时具备WIFI通道和移动数据通道,则优先WIFI通道,即:如果第二系统的WIFI通道已开启,则通过WIFI通道,将第二系统接入公共网络,如果第二系统的WIFI通道未开启,则通过移动数据通道,将第二系统接入公共网络。
本实施例中,从上述步骤可以看出,本实施例所述的方法,可以基于网络支持多PDN的条件,实现专用网络和公共网络的同时在线,从而为用户提供更优的网络使用体验。
需要说明的是,本实施例中,专用网络和公共网络可以均为LTE制式的网络,因此,本实施例所述的方法,可以实现同一个制式的专用网络和公共网络的双在线,这与通常的多模终端的双在线有本质的区别。
本申请实施例公开的又一种网络连接方法,本实施例中,第一系统和第二系统共用物理通信模块,本实施例中,以物理通信模块设置在第二系统中为例进行说明。
如图2所示,本实施例所述方法包括以下步骤:
S201:接收网络连接指令;
S202:判断电子设备注册的网络是否支持多PDN,如果是,执行S203,如果否,执行S207;
S203:将第二系统接收到的第一系统发送的网络连接数据包进行标记;
S204:依据具有标记的数据包,生成第一路由表;
具体地,可以依据具有标记的数据包,形成路由转发策略,再结合第一系统对应的IP、网关及DNS等链路信息,生成第一路由表。
S205:依据第二系统发送的不具有标记的路由表,生成第二路由表;
S206:分别依据两个系统各自对应的路由表,通过所述物理通信模块,发送网络连接数据包;
S207:优先使用第一系统连接专用网络。
具体地,如果第一系统开启连接通道,则控制第一系统接入专用网络,如果第一系统没有开启连接通道,则控制第二系统接入公共网络。
本实施例所述的方法,将连接专用网络与连接公共网络分别设置不同的路由表,从而使得在同时连接专网和公网的情况下,两者互不干扰。并且,更能保证专用网络的安全性。
需要说明的是,本实施例中,以物理模块设置在第二系统为例,如果物理通信模块设置在第一系统中,实现原理与上述过程相同,这里不再赘述。
本申请实施例公开的又一种网络连接方法,如图3所示,包括以下步骤:
S301:接收网络连接指令;
S302:判断电子设备注册的网络是否支持多PDN,如果是,执行S303,如果否,执行S304;
S303:控制第一系统接入专用网络,及控制第二系统接入公共网络;
S304:清除第一规则及第二规则;
其中,第一规则为禁止所述第二系统中的应用向网络发送数据包,第二规则为禁止所述第一系统中的应用向网络发送数据包。
S305:如果第一系统开启连接通道,则控制第一系统接入专用网络;
S306:启动第一规则;
S307:如果第一系统没有开启连接通道,则控制第二系统接入公共网络;
S308:启动第二规则。
本实施例中,使用连接规则进一步保证禁止连接网络的系统的数据包不被发送到网络中,从而进一步保证系统的安全。
与上述方法实施例相对应地,本申请实施例还公开了一种电子设备,如图4所示,包括:
第一系统、第二系统以及连接控制模块。
其中,第一系统用于与专用网络相连,第二系统用于与公共网络相连,连接控制模块用于,如果接收到网络连接指令,基于所述电子设备当前注册的网络满足支持多PDN的条件,控制所述电子设备的第一系统接入专用网络,并且控制所述电子设备的第二系统接入公共网络。
具体地,如果所述第二系统的WIFI通道已开启,则通过所述WIFI通道,将所述第二系统接入公共网络,如果所述第二系统的WIFI通道未开启,则通过移动数据通道,将所述第二系统接入公共网络。
可选地,连接控制模块还可以用于:如果所述电子设备当前注册的网络不支持多PDN,则在接收到网络连接指令后,优先使用所述第一系统连接所述专用网络。
本实施例所述的电子设备,具备两套系统,基于注册网络支持多PDN的特性,可以实现专用网络和公共网络同时在线的目的。
本申请实施例公开的又一种电子设备,如图5所示,电子设备具备第一系统和第二系统,每个系统中均包括网络应用(Net APP)。所述电子设备的第一系统中包括第一数据连接管理器、第一虚拟网络接口模块及第一路由管理模块,第二系统中包括第二数据连接管理器、第二虚拟网络接口模块及第二路由管理模块。进一步地,第一系统与第二系统共用物理通信模块,物理通信模块设置可以设置在第一系统或第二系统中,本实施例中,以物理通信模块设置在第二系统中为例进行说明。
其中,所述第一数据连接管理器用于建立或拆除所述第一系统与所述专用网络的数据连接以及数据连接状态的通知与维护;
所述第一路由管理模块用于所述第一系统的数据包路由,并在匹配到对应的路由信息后,通过所述第一虚拟网络接口模块将所述第一系统的数据包发送到所述第二系统。
所述第二数据连接管理器用于建立或拆除所述第二系统与所述专用网络的数据连接以及数据连接状态的通知与维护;
所述第二路由管理模块用于所述第二系统的数据包路由,并在匹配到对应的路由信息后,通过所述第二虚拟网络接口模块将所述第二系统的数据包发送到所述第一系统。
具体地,连接控制模块由第一数据连接管理器、第一路由管理模块、第一虚拟网络接口、第二数据连接管理器、第二路由管理模块及第二虚拟网络接口组成。连接控制模块控制电子设备的第一系统接入专用网络,并且控制电子设备的第二系统接入公共网络的具体实现方式可以为:
第二系统中的第二虚拟网络接口接收第一系统发送的网络连接数据包,第二系统中的第二路由管理模块将接收到的第一系统发送的网络连接数据包进行标记,并依据具有标记的数据包,生成第一路由表,并依据所述物理通信模块所在的系统发送的、不具有所述标记的数据包,生成第二路由表。
第二系统中的第二数据连接管理器分别依据两个系统各自对应的路由表,通过所述物理通信模块,发送网络连接数据包。
具体地,连接控制模块在接收到网络连接指令后,优先使用所述第一系统连接所述专用网络的具体实现方式可以为:
第一数据连接管理器向所述第二数据连接管理器发送所述第一系统的连接状态;第二数据连接管理器在接收到所述第二系统连接所述公共网络的指令后,如果所述第一系统的连接状态指示所述第一系统与所述专用网络已连接,则禁止所述第二系统连接所述公共网络,否则,控制所述第二系统接入所述公共网络。
进一步地,本实施例中所述的电子设备还包括:
设置于第一系统中的第一防火墙以及设置于第二系统中的第二防火墙。
第一防火墙用于如果当前网络连接状态为所述第二系统与所述公共网 络相连,则启动第二规则,所述第二规则仅为禁止所述第一系统中的应用向网络发送数据包;并且,如果当前网络连接状态为所述第一系统与所述专用网络相连且所述第二系统与所述公共网络相连,则清除所述第二规则;
第二防火墙用于,如果当前网络连接状态仅为所述第一系统与所述专用网络相连,则启动第一规则,所述第一规则为禁止所述第二系统中的应用向网络发送数据包;并且,如果当前网络连接状态为所述第一系统与所述专用网络相连且所述第二系统与所述公共网络相连,则清除所述第一规则。
本实施例中所述的电子设备,具备第一系统和第二系统,第一系统用于连接专用网络,第二系统用于连接公共网络,能够实现VPDN和公共网络的双在线,不仅满足了政企用户对于安全和上网的双需求,也大大提高了政企用户对于数据业务的体验。
本申请实施例方法所述的功能如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算设备可读取存储介质中。基于这样的理解,本申请实施例对现有技术做出贡献的部分或者该技术方案的部分可以以软件产品的形式体现出来,该软件产品存储在一个存储介质中,包括若干指令用以使得一台计算设备(可以是个人计算机,服务器,移动计算设备或者网络设备等)执行本申请各个实施例所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。
本说明书中各个实施例采用递进的方式描述,每个实施例重点说明的都是与其它实施例的不同之处,各个实施例之间相同或相似部分互相参见即可。
对所公开的实施例的上述说明,使本领域专业技术人员能够实现或使用本申请。对这些实施例的多种修改对本领域的专业技术人员来说将是显而易见的,本文中所定义的一般原理可以在不脱离本申请的精神或范围的情况下,在其它实施例中实现。因此,本申请将不会被限制于本文所示的 这些实施例,而是要符合与本文所公开的原理和新颖特点相一致的最宽的范围。

Claims (12)

  1. 一种网络连接方法,其特征在于,包括:
    接收网络连接指令;
    基于电子设备当前注册的网络满足支持多PDN的条件,控制所述电子设备的第一系统接入专用网络,并且控制所述电子设备的第二系统接入公共网络。
  2. 根据权利要求1所述的方法,其特征在于,所述第一系统与所述第二系统共用物理通信模块,所述物理通信模块设置在所述第一系统或者所述第二系统中;
    所述控制所述电子设备的第一系统接入专用网络,并且控制所述电子设备的第二系统接入公共网络包括:
    将所述物理通信模块所在的系统接收到的另一个系统发送的网络连接数据包进行标记;
    依据具有标记的数据包,生成第一路由表;
    依据所述物理通信模块所在的系统发送的、不具有所述标记的数据包,生成第二路由表;
    分别依据两个系统各自对应的路由表,通过所述物理通信模块,发送网络连接数据包。
  3. 根据权利要求2所述的方法,其特征在于,还包括:如果所述电子设备当前注册的网络不支持多PDN,则在接收到网络连接指令后,优先使用所述第一系统连接所述专用网络。
  4. 根据权利要求3所述的方法,其特征在于,还包括:
    如果当前网络连接状态仅为所述第一系统与所述专用网络相连,则启动第一规则,所述第一规则为禁止所述第二系统中的应用向网络发送数据包;
    如果当前网络连接状态仅为所述第二系统与所述公共网络相连,则启动第二规则,所述第二规则为禁止所述第一系统中的应用向网络发送数据包;
    并且,如果当前网络连接状态为所述第一系统与所述专用网络相连且所述第二系统与所述公共网络相连,则清除所述第一规则及所述第二规则。
  5. 根据权利要求1至4任一项所述的方法,其特征在于,所述控制所述电子设备的第二系统接入公共网络包括:
    如果所述第二系统的WIFI通道已开启,则通过所述WIFI通道,将所述第二系统接入公共网络,如果所述第二系统的WIFI通道未开启,则通过移动数据通道,将所述第二系统接入公共网络。
  6. 一种电子设备,其特征在于,包括:
    第一系统,用于与专用网络连接;
    第二系统,用于与公共网络连接;
    连接控制模块,用于接收网络连接指令,并基于所述电子设备当前注册的网络满足支持多PDN的条件,控制所述电子设备的第一系统接入专用网络,并且控制所述电子设备的第二系统接入公共网络。
  7. 根据权利要求6所述的电子设备,其特征在于,所述第一系统中包括第一数据连接管理器、第一虚拟网络接口模块及第一路由管理模块,所述第二系统中包括第二数据连接管理器、第二虚拟网络接口模块及第二路由管理模块;
    所述连接控制模块包括第一数据连接管理器、所述第一路由管理模块、所述第一虚拟网络接口模块、所述第二数据连接管理器、第二路由管理模块以及第二虚拟网络接口模块;
    其中,所述第一数据连接管理器用于建立或拆除所述第一系统与所述专用网络的数据连接以及数据连接状态的通知与维护,所述第一路由管理模块用于所述第一系统的数据包路由,并在匹配到对应的路由信息后,通过所述第一虚拟网络接口模块将所述第一系统的数据包发送到所述第二系统;所述第二数据连接管理器用于建立或拆除所述第二系统与所述专用网络的数据连接以及数据连接状态的通知与维护,所述第二路由管理模块用于所述第二系统的数据包路由,并在匹配到对应的路由信息后,通过所述第二虚拟网络接口模块将所述第二系统的数据包发送到所述第一系统。
  8. 根据权利要求7所述的电子设备,其特征在于,所述第一系统与所 述第二系统共用物理通信模块,所述物理通信模块设置在所述第一系统或者所述第二系统中;
    所述连接控制模块用于控制所述电子设备的第一系统接入专用网络,并且控制所述电子设备的第二系统接入公共网络包括:
    所述物理通信模块所在的系统的虚拟网络接口模块用于接收另一个系统发送的网络连接数据包;
    所述物理通信模块所在的系统的路由管理模块将接收到的另一个系统发送的网络连接数据包进行标记;依据具有标记的数据包,生成第一路由表;并依据所述物理通信模块所在的系统发送的、不具有所述标记的数据包,生成第二路由表;
    所述第二数据连接管理器分别依据两个系统各自对应的路由表,通过所述物理通信模块,发送网络连接数据包。
  9. 根据权利要求7所述的电子设备,其特征在于,所述连接控制模块还用于:
    如果所述电子设备当前注册的网络不支持多PDN,则在接收到网络连接指令后,优先使用所述第一系统连接所述专用网络。
  10. 根据权利要求6所述的电子设备,其特征在于,所述连接控制模块用于在接收到网络连接指令后,优先使用所述第一系统连接所述专用网络包括:
    所述第一数据连接管理器用于向所述第二数据连接管理器发送所述第一系统的连接状态;
    所述第二数据连接管理器用于,在接收到所述第二系统连接所述公共网络的指令后,如果所述第一系统的连接状态指示所述第一系统与所述专用网络已连接,则禁止所述第二系统连接所述公共网络,否则,控制所述第二系统接入所述公共网络。
  11. 根据权利要求10所述的电子设备,其特征在于,所述第一系统还包括第一防火墙,所述第二系统还包括第二防火墙;
    所述第一防火墙用于如果当前网络连接状态为所述第二系统与所述公共网络相连,则启动第二规则,所述第二规则仅为禁止所述第一系统中的 应用向网络发送数据包;并且,如果当前网络连接状态为所述第一系统与所述专用网络相连且所述第二系统与所述公共网络相连,则清除所述第二规则;
    所述第二防火墙用于,如果当前网络连接状态仅为所述第一系统与所述专用网络相连,则启动第一规则,所述第一规则为禁止所述第二系统中的应用向网络发送数据包;并且,如果当前网络连接状态为所述第一系统与所述专用网络相连且所述第二系统与所述公共网络相连,则清除所述第一规则。
  12. 根据权利要求7至11任一项所述的电子设备,其特征在于,所述控制连接模块用于控制所述电子设备的第二系统接入公共网络包括:
    所述第二数据连接管理器具体用于,如果所述第二系统的WIFI通道已开启,则通过所述WIFI通道,将所述第二系统接入公共网络,如果所述第二系统的WIFI通道未开启,则通过移动数据通道,将所述第二系统接入公共网络。
PCT/CN2015/085857 2015-06-29 2015-07-31 一种网络连接方法及电子设备 Ceased WO2017000355A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510369779.9A CN105636151B (zh) 2015-06-29 2015-06-29 一种网络连接方法及电子设备
CN201510369779.9 2015-06-29

Publications (1)

Publication Number Publication Date
WO2017000355A1 true WO2017000355A1 (zh) 2017-01-05

Family

ID=56050508

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/085857 Ceased WO2017000355A1 (zh) 2015-06-29 2015-07-31 一种网络连接方法及电子设备

Country Status (2)

Country Link
CN (1) CN105636151B (zh)
WO (1) WO2017000355A1 (zh)

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106793156B (zh) * 2016-11-24 2020-03-17 宇龙计算机通信科技(深圳)有限公司 多系统终端及网络连接方法和装置
CN106789931B (zh) * 2016-11-29 2020-05-19 北京元心科技有限公司 多系统的网络隔离共享方法及装置
CN106535160B (zh) * 2016-11-29 2019-11-08 北京元心科技有限公司 双系统双sim卡网络隔离传输的方法及系统
KR102498866B1 (ko) 2018-08-08 2023-02-13 삼성전자주식회사 데이터 통신을 지원하는 전자 장치 및 그 방법
CN115361699A (zh) * 2022-08-30 2022-11-18 青岛海信移动通信技术股份有限公司 一种流量预警方法、装置、终端设备及介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102348210A (zh) * 2011-10-19 2012-02-08 迈普通信技术股份有限公司 一种安全性移动办公的方法和移动安全设备
CN103873444A (zh) * 2012-12-14 2014-06-18 中国电信股份有限公司 移动终端vpdn在线时访问外网业务的方法、业务转接装置
WO2015087112A1 (en) * 2013-12-12 2015-06-18 Sony Corporation Automatic internet sharing
CN104735051A (zh) * 2013-12-23 2015-06-24 三星Sds株式会社 虚拟专用网连接控制系统及方法

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100518138C (zh) * 2005-04-12 2009-07-22 华为技术有限公司 实现虚拟专用网的方法
US8725895B2 (en) * 2010-02-15 2014-05-13 Damaka, Inc. NAT traversal by concurrently probing multiple candidates
CN103152267B (zh) * 2013-02-04 2017-02-22 华为技术有限公司 路由管理方法及路由方法及网络控制器及路由器
JP6201333B2 (ja) * 2013-02-18 2017-09-27 富士ゼロックス株式会社 通信システム、中継装置及びファクシミリ送受信プログラム

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102348210A (zh) * 2011-10-19 2012-02-08 迈普通信技术股份有限公司 一种安全性移动办公的方法和移动安全设备
CN103873444A (zh) * 2012-12-14 2014-06-18 中国电信股份有限公司 移动终端vpdn在线时访问外网业务的方法、业务转接装置
WO2015087112A1 (en) * 2013-12-12 2015-06-18 Sony Corporation Automatic internet sharing
CN104735051A (zh) * 2013-12-23 2015-06-24 三星Sds株式会社 虚拟专用网连接控制系统及方法

Also Published As

Publication number Publication date
CN105636151B (zh) 2017-08-11
CN105636151A (zh) 2016-06-01

Similar Documents

Publication Publication Date Title
CN105637805B (zh) 增强移动备用信道以解决有线线路网络中的节点故障
AU2018203437B2 (en) Use of an oma management object to support application-specific congestion control in mobile networks
US8131831B1 (en) Centralized policy management framework for telecommunication networks
EP2760174A1 (en) Virtual private cloud access authentication method and related apparatus
JP2018196139A (ja) サービス層サウスバウンドインターフェースおよびサービスの質
CN104468368B (zh) 配置bgp邻居的方法及装置
CN103517266B (zh) 移动网络侧激活移动终端的方法和移动网关系统
WO2017000355A1 (zh) 一种网络连接方法及电子设备
JP2016507930A5 (zh)
US8516567B2 (en) Distributed firewalling in a wireless communication network
EP3440810B1 (en) Quality of service (qos) support for tactile traffic
JP2019519146A (ja) ルーティング確立、パケット送信
CN104780147A (zh) 一种byod访问控制的方法及装置
CN104320499A (zh) 一种业务传输链路的建立方法及装置
EP3297338B1 (en) Method for realizing network access, terminal and computer storage medium
JP6137848B2 (ja) ネットワーク通信システム
KR101977005B1 (ko) 모바일 통신 시스템에서 근접 서비스를 사용하기 위한 인증 획득
CN103731817B (zh) 一种数据传输的方法和设备
US10785165B2 (en) Method for controlling service data flow and network device
CN104521201B (zh) 转发节点的处理方法、转发节点及控制节点
CN109982311B (zh) 一种终端接入核心网设备方法及终端、mme和saegw
Nguyen et al. An SDN‐based connectivity control system for Wi‐Fi devices
CN103188657B (zh) 一种为ue分配ip地址的方法及系统
CN108377493B (zh) 连接建立方法、设备及系统
WO2013189130A1 (zh) 一种基于点对点网络的通讯系统及通讯方法

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15896885

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15896885

Country of ref document: EP

Kind code of ref document: A1