A network connection system, method, and electronic device based on network tunneling
By establishing a network tunnel between the router and wireless network devices for encryption and authentication, the problem of low router security is solved, ensuring that network connection requests are not intercepted during transmission and improving user experience.
Patent Information
- Application Number
- CN202310240796.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-14
- Publication Date
- 2026-02-13
- Estimated Expiration
- 2043-03-14
AI Technical Summary
The low security between routers and wireless network devices makes network connection requests vulnerable to malicious interception and cracking, affecting user experience.
The signal receiving module receives network connection requests, and the signal transmission module forms a network tunnel with the router for encryption, forming an encrypted network connection request. The request is then decrypted and verified in the router to ensure that the network connection request is not intercepted during transmission. The firewall blocks abnormal requests.
It improves the security of network connection requests, avoids network signal diversion issues, and enhances the user experience.
Smart Images

Figure CN116156502B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, in particular to a network connection system and method based on network tunnel and electronic equipment. BACKGROUND
[0002] With the continuous development of communication technology, people are more and more used to using wireless networks for various activities, such as watching videos, shopping and browsing web pages, etc. Usually, people use the wireless function of the router to realize wireless network connection. The wireless function of the router is to forward the broadband network signal to the nearby wireless network devices, such as notebook computers, smart phones and all devices with WIFI function, through the antenna. These wireless network devices can connect to the router to access the network by inputting the password of the wireless network and successfully authenticating, or cannot connect to the router to access the network if the authentication fails.
[0003] However, due to the low security between the router and the broadband network, and between the router and the wireless network device, some people may use some tools to maliciously intercept and crack the network connection request in the signal transmission process, so that the person can construct an abnormal network connection request to send the broadband network signal to his own device to connect to the network, resulting in the broadband network signal of the router being occupied. This situation weakens the broadband network signal received by the router holder, thereby affecting the use of the wireless network device and reducing the user experience. SUMMARY
[0004] The present application provides a network connection system and method based on network tunnel and electronic equipment.
[0005] In a first aspect, the present application provides a network connection system based on network tunnel, comprising: a signal receiving module, a signal transmission module and a router.
[0006] The signal receiving module, the signal transmission module and the router are connected in sequence.
[0007] The signal receiving module is configured to receive a network connection request sent by a wireless network device.
[0008] The signal transmission module and the router establish communication to form a network tunnel, which is configured to encrypt the received network connection request to obtain an encrypted network connection request, and transmit the encrypted network connection request to the router.
[0009] The router is configured to receive the encrypted network connection request, decrypt the encrypted network connection request to obtain a decrypted network connection request, and verify whether the decrypted network connection request meets the requirements.
[0010] The router is further configured to determine whether to allow the wireless network device to access the network according to the verification result.
[0011] Optionally, the router comprises a signal verification module and a signal feedback module; the signal transmission module comprises a data forwarding unit.
[0012] The data forwarding unit is configured to encrypt the network connection request through a secure sockets layer, to obtain an encrypted network connection request, and to transmit the encrypted network connection request through a transmission control protocol, so that the encrypted network connection request is not intercepted during transmission.
[0013] The data forwarding unit is further configured to transmit the encrypted network connection request to the signal verification module, so that the signal verification module decrypts the encrypted network connection request according to a preset decryption method to obtain a decrypted network connection request, verifies whether the decrypted network connection request meets the requirements, and transmits a verification result to the signal feedback module.
[0014] Optionally, the signal transmission module comprises a firewall configured to detect whether the network connection request is a normally transmitted request.
[0015] If it is detected that the network connection request is not a normally transmitted request, the firewall is specifically configured to block the network connection request to avoid non-normal network connection requests from accessing the network.
[0016] Optionally, the signal transmission module comprises a firewall configured to detect whether the network connection request is a normally transmitted request.
[0017] If it is detected that the network connection request is not a normally transmitted request, the firewall is specifically configured to block the network connection request to avoid non-normal network connection requests from accessing the network.
[0018] Optionally, the network connection system based on a network tunnel comprises an error connection reminding module configured to, when an input password in the decrypted network connection request is incorrect, perform error connection reminding to remind a user that there is a connection exception.
[0019] Optionally, the network connection system based on a network tunnel is specifically configured to:
[0020] When the decrypted network connection request does not meet the requirements, the router is specifically configured to obtain a to-be-verified password in the decrypted network connection request, compare the to-be-verified password with a preset password, and determine whether the to-be-verified password is consistent with the preset password.
[0021] When the to-be-verified password is inconsistent with the preset password, the router is specifically configured to compare the to-be-verified password before encryption with the to-be-verified password after decryption, and determine whether there is loss in the transmission process;
[0022] When the to-be-verified password before encryption is inconsistent with the to-be-verified password after decryption, the router transmits the comparison result to the signal transmission module;
[0023] The signal transmission module, when receiving the comparison result, is specifically configured to start a firewall to isolate abnormal network connection requests.
[0024] In a second aspect, the present application provides a network connection method based on a network tunnel, comprising:
[0025] Obtaining a network connection request of a wireless network device;
[0026] Encrypting the network connection request to obtain an encrypted network connection request to ensure that the network connection request is not intercepted in the transmission process;
[0027] Decrypting the encrypted network connection request after the transmission of the encrypted network connection request is completed to obtain a decrypted network connection request to verify whether the decrypted network connection request meets the requirements;
[0028] If the decrypted network connection request meets the requirements, the wireless network device is allowed to access the network.
[0029] Through the method provided in this embodiment, the network connection request of the wireless network device can be obtained, and the network connection request is encrypted in the transmission process to obtain an encrypted network connection request, ensuring that the network connection request is not intercepted and cracked in the transmission process. After the transmission is completed, the encrypted network connection request is decrypted and it is verified whether the decrypted network connection request meets the requirements. According to the verification result, it is determined whether the wireless network device initiating the network connection request is allowed to access the network. In this way, the problem that the network connection request is intercepted in the transmission process can be avoided, other devices cannot crack the connection method by intercepting the network connection request, the problem of network signal shunting is reduced, and the user's use experience is improved.
[0030] Optionally, the method further comprises:
[0031] If the decrypted network connection request does not meet the requirements, a to-be-verified password in the decrypted network connection request is obtained;
[0032] The to-be-verified password is compared with a preset password to determine whether the to-be-verified password is consistent with the preset password;
[0033] If the to-be-verified password before encryption is inconsistent with the decrypted to-be-verified password, it is determined whether there is loss in the transmission process by comparing the to-be-verified password before encryption with the decrypted to-be-verified password.
[0034] If the to-be-verified password before encryption is inconsistent with the decrypted to-be-verified password, a firewall is started to isolate abnormal network connection requests.
[0035] In the embodiment, when the decrypted network connection request does not meet the requirements, the to-be-verified password in the network connection request is obtained, the decrypted to-be-verified password is compared with a preset password to determine whether the problem is a password input error. If the decrypted to-be-verified password is inconsistent with the preset password, it is indicated that the user may have input an error password, but it is also possible that the related protocol of the network tunnel is cracked in the transmission process, so that the to-be-verified password is intercepted, thereby causing the to-be-verified password to be lost. At this time, the to-be-verified password before encryption is compared with the decrypted to-be-verified password to determine whether there is a problem in the decryption process. If the to-be-verified password before encryption is consistent with the decrypted to-be-verified password, it is indicated that the related protocol of the network tunnel may indeed be cracked in the transmission process, so that the to-be-verified password is intercepted. At this time, the firewall in the network tunnel is started to avoid malicious connection after the to-be-verified password is intercepted.
[0036] In a third aspect, the present application provides an electronic device applied to the network connection system based on the network tunnel in the first aspect, comprising a memory and a processor, and the memory stores a computer program capable of being loaded and executed by the processor to execute the method in the second aspect.
[0037] In a fourth aspect, the present application provides a computer readable storage medium storing a computer program capable of being loaded and executed by the processor to execute the method in the second aspect. BRIEF DESCRIPTION OF DRAWINGS
[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.
[0039] Figure 1 An application scenario schematic diagram is provided for an embodiment of the present application;
[0040] Figure 2 A structure schematic diagram of a network connection system based on a network tunnel is provided for an embodiment of the present application;
[0041] Figure 3 A flow chart of a network connection method based on a network tunnel provided by an embodiment of the present application;
[0042] Figure 4 A structural schematic diagram of an electronic device provided by an embodiment of the present application; DETAILED DESCRIPTION
[0043] To make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described below in a clear and complete manner with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some but not all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0044] In addition, the term “and / or” in the present document merely describes an association relationship of associated objects, and indicates that there can be three relationships, for example, A and / or B can represent the following three cases: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character “ / ” in the present document generally represents an “or” relationship between the front and rear associated objects unless otherwise specified.
[0045] The embodiments of the present application will be further described in detail below with reference to the drawings of the specification.
[0046] Since the security between the router and the broadband network and between the router and the wireless network device is low, some people can use some tools to maliciously crack the signal transmission process, so that the person can forward the broadband network signal to his own device through the non-normal input of the SSID, resulting in the broadband network signal of the router being occupied. This situation weakens the broadband network signal received by the router holder, thereby affecting the use of the wireless network device and reducing the user experience.
[0047] Based on this, the present application provides a network connection system and method based on a network tunnel and an electronic device.
[0048] First, the network connection request of the wireless network device is received through the signal receiving module, then the network connection request is encrypted through the network tunnel formed by the communication between the signal transmission module and the router, and the encrypted network connection request is obtained, and the encrypted network connection request is transmitted to the router. The router decrypts the encrypted network connection request and verifies whether the decrypted network connection request meets the requirements. According to the verification result, it is determined whether to allow the wireless network device to access the network.
[0049] The network connection request is encrypted in the transmission process by using the signal transmission module, the encrypted network connection request is ensured not to be intercepted and cracked in the transmission process, the router can correctly send the broadband network signal to the wireless network device, the encrypted network connection request can be decrypted by the module in the router only when the network connection request is transmitted to the corresponding signal verification module, the confidentiality of the network connection request is ensured to a certain extent, the problem that the wireless network signal is shunted due to malicious connection caused by information leakage of the network connection request is avoided, and user experience is further improved.
[0050] Figure 1 An application scenario diagram is provided for the application.
[0051] The network connection request transmitted by the wireless network device is encrypted in the transmission process, the encrypted network connection request is decrypted by the router after being received by the router, the decrypted network connection request is obtained, and then whether the decrypted network connection request meets the requirements is analyzed. If it is determined that the decrypted network connection request meets the requirements, an access signal is sent to the broadband network through the router, and the broadband network signal is sent to the wireless network device, so that the wireless network device accesses the network and can access the network.
[0052] The specific implementation manner can refer to the following embodiments.
[0053] Figure 2 A structure diagram of a network connection system based on a network tunnel is provided for an embodiment of the application, as shown in the figure. Figure 2 The network connection system based on the network tunnel 200 of the embodiment includes a signal receiving module 201, a signal transmission module 202, and a router 203.
[0054] The signal receiving module 201, the signal transmission module 202, and the router 203 are connected in sequence.
[0055] The signal receiving module 201 is configured to receive a network connection request sent by a wireless network device.
[0056] After the signal transmission module 202 and the router 203 establish communication, a network tunnel is formed, which is configured to encrypt the received network connection request to obtain an encrypted network connection request, and transmit the encrypted network connection request to the router 203.
[0057] The router 203 is configured to receive the encrypted network connection request, decrypt the encrypted network connection request to obtain a decrypted network connection request, and verify whether the decrypted network connection request meets the requirements.
[0058] The router 203 is further configured to determine whether to allow the wireless network device to access the network according to the verification result.
[0059] The wireless network device can be understood as a device with WIFI function in the present application, such as a mobile phone, a notebook computer, an iPad, etc. These devices can be connected to the network through the WIFI function.
[0060] The network connection request can be understood as a connection request sent to the corresponding router to request access to the network when the wireless network device needs to access the network.
[0061] The network tunnel used in the present application can encrypt the network connection request in the transmission process, improve the security in the transmission process, and ensure data security.
[0062] The network connection request normally passed by inputting the password of the wireless network set in advance belongs to the network connection request meeting the requirements; other cases can be classified as inputting the network connection request not meeting the requirements. The network connection request not meeting the requirements needs to be blocked in the system provided in the present application. In the specific implementation process, it can be determined which cases belong to the network connection request meeting the requirements and which do not belong to the network connection request meeting the requirements according to the problems encountered in the connection process.
[0063] In some embodiments, the router 203 includes a signal verification module 204 and a signal feedback module 205; the signal transmission module 202 includes a data forwarding unit 206; the data forwarding unit 206 is configured to encrypt the network connection request through the secure sockets layer, obtain the encrypted network connection request, and transmit the encrypted network connection request through the transmission control protocol, so that the encrypted network connection request is not intercepted in the transmission process.
[0064] The data forwarding unit 206 is further configured to transmit the encrypted network connection request to the signal verification module 204, so that the signal verification module 204 decrypts the encrypted network connection request according to a preset decryption method to obtain a decrypted network connection request, verifies whether the decrypted network connection request meets the requirements, and transmits the verification result to the signal feedback module 205.
[0065] The preset decryption method is set according to the network tunnel. In the present embodiment, the network connection request encrypted by the secure sockets layer can be directly released by configuring the release module of the secure sockets layer. In the actual implementation process, other methods can also be used to decrypt the encrypted network connection request.
[0066] In some embodiments, the signal transmission module 202 comprises a firewall 207 for detecting the network connection request to avoid abnormal network connection request accessing the network; if the network connection request is detected as not being a normal request, the firewall 207 is specifically configured to block the network connection request to avoid abnormal network connection request accessing the network.
[0067] The firewall in the present application can be used to ensure the security of the network connection request transmission, and in the process of encrypted network connection request transmission, the network connection request is detected to ensure that the transmission of abnormal network connection request is blocked. In a specific implementation, the router itself is provided with a firewall, and therefore, a secondary firewall can be set based on the firewall. The firewall continuously detects the network connection request in the on state of the router, and the secondary firewall is started after the password to be verified in the network connection request is intercepted, and is used to prevent abnormal network connection request from accessing the router by imitating normal network connection request using the password to be verified.
[0068] In some embodiments, the router 203 comprises a request storage module 208 for storing the information of the wireless network device contained in the network connection request; when the decrypted network connection request is verified successfully and the wireless network device accesses the network, the request storage module 208 is specifically configured to store the information of the wireless network device verified as the decrypted network connection request, and the information of the wireless network device is used for the next verification-free connection of the wireless network device.
[0069] When the wireless network device of the user accesses the network successfully by sending a network connection request, the information of the wireless network device can be automatically stored, and when the wireless network device wants to access the network through the router again, the information of the wireless network device can be directly retrieved and matched. If it is found that the information of the wireless network device is stored by matching the stored information, the user does not need to send a network connection request, but directly connects to the router according to the matching result to access the network and obtain the broadband network signal. In this way, the operation steps of the user in the use process can be simplified, the input error problem caused by inputting the password every time can be avoided, and the user experience is improved.
[0070] In some embodiments, the network connection system 200 based on the network tunnel further comprises an error connection reminding module 209 for reminding the user of connection abnormality when the input password in the decrypted network connection request is incorrect.
[0071] When the decrypted network connection request is determined to fail the verification, the to-be-verified password in the network connection request is obtained, and the to-be-verified password is compared with the preset password to determine whether the to-be-verified password is consistent with the preset password. If the to-be-verified password is not consistent with the preset password, it can be preliminarily determined that the reason for the verification failure is that the user password is input incorrectly. At this time, the to-be-verified password before encryption is compared with the decrypted to-be-verified password. If the to-be-verified password before encryption is consistent with the decrypted to-be-verified password, it indicates that the user password input error causes the verification failure. At this time, the error connection reminding module 208 is used to perform error connection reminding, so that the user knows that the password is input incorrectly.
[0072] The error connection reminding module 209 can avoid the situation that the user still waits when the password is input incorrectly. Meanwhile, the user can be reminded to modify in time.
[0073] In some embodiments, when the decrypted network connection request does not meet the requirements, the router 203 provided by the application is specifically used to obtain the to-be-verified password in the decrypted network connection request, compare the to-be-verified password with the preset password, and determine whether the to-be-verified password is consistent with the preset password; when the to-be-verified password is not consistent with the preset password, the router 203 is specifically used to compare the to-be-verified password before encryption with the decrypted to-be-verified password, and determine whether there is loss in the transmission process; when the to-be-verified password before encryption is not consistent with the decrypted to-be-verified password, the router 203 transmits the comparison result to the signal transmission module 202; when the signal transmission module 202 receives the comparison result, the signal transmission module 202 is specifically used to start the firewall 2087 to isolate the abnormal network connection request.
[0074] Figure 3 A flowchart of a network connection method based on a network tunnel is provided for an embodiment of the application. The method of the embodiment can be applied to the router in the above scenarios. As shown in the flowchart, Figure 3 the method includes:
[0075] S301, obtaining a network connection request of a wireless network device.
[0076] The wireless network device can be understood in the application as a device that can have a WIFI function, such as a mobile phone, a notebook computer, an iPad, and the like. These devices can be connected to a network through the self-provided WIFI function.
[0077] S302, encrypting the network connection request to obtain an encrypted network connection request to ensure that the network connection request is not intercepted in the transmission process.
[0078] The network connection request is encrypted by using a secure sockets layer (SSL) to encrypt the network connection request by a transmission control protocol, so that the network connection request is encrypted and cannot be intercepted and cracked in the transmission process.
[0079] The decryption can be to release the network connection request encrypted by the SSL, so that the network connection request can be recognized by the router.
[0080] After the encrypted network connection protocol is transmitted to the router, the router performs decryption, so that the router can recognize the content of the network connection request and perform verification.
[0081] S303, when the encrypted network connection request is transmitted, the encrypted network connection request is decrypted to obtain the decrypted network connection request to verify whether the decrypted network connection request meets the requirements.
[0082] S204, if the decrypted network connection request meets the requirements, the wireless network device is allowed to access the network.
[0083] By the method provided in the embodiment, the network connection request of the wireless network device can be obtained, the network connection request is encrypted in the transmission process to obtain the encrypted network connection request, so that the network connection request cannot be intercepted and cracked in the transmission process. After the transmission is completed, the encrypted network connection request is decrypted and the decrypted network connection request is verified. According to the verification result, it is determined whether the wireless network device initiating the network connection request is allowed to access the network. In this way, the problem that the network connection request is intercepted in the transmission process can be avoided, other devices cannot crack the connection mode by intercepting the network connection request, the problem of network signal shunting is reduced, and the user experience is improved.
[0084] In some embodiments, if the verification result of the network connection request of the receiving router is verification failure, the to-be-verified password is compared with the preset password. If the to-be-verified password is inconsistent with the preset password, the to-be-verified password before encryption is compared with the to-be-verified password after decryption to determine whether they are consistent. If they are inconsistent, the firewall is started to avoid the input of abnormal network connection request. Specifically, the to-be-verified password in the decrypted network connection request can be obtained if the decrypted network connection request does not meet the requirements. The to-be-verified password is compared with the preset password to determine whether the to-be-verified password is consistent with the preset password. If the to-be-verified password is inconsistent with the preset password, the to-be-verified password before encryption is compared with the to-be-verified password after decryption to determine whether there is loss in the transmission process. If the to-be-verified password before encryption is inconsistent with the to-be-verified password after decryption, the firewall is started to isolate the abnormal network connection request.
[0085] The preset password can be understood in the present application as a password for connecting the router, which is set by the user when installing the router. The user can connect the router by the password each time when needing to connect the network, so as to obtain the broadband network signal to access the network.
[0086] The firewall can be used in the present application to ensure the security of the network connection request transmission, and detect the network connection request in the network connection request transmission process to ensure the blocking of the transmission of abnormal network connection requests. In the specific implementation mode, the router itself can be provided with a firewall, and thus a secondary firewall can be set on the basis of the firewall. The firewall continuously detects the network connection request in the on state of the router, and the secondary firewall is started after the to-be-verified password in the network connection request is intercepted, and is used to prevent the abnormal network connection request from accessing the router by imitating the normal network connection request by using the to-be-verified password.
[0087] Specifically, if it is determined according to the above embodiment that the decrypted network connection request fails to pass the verification, the to-be-verified password in the network connection request is obtained, and the to-be-verified password is compared with the preset password to determine whether the to-be-verified password is consistent with the preset password. If the to-be-verified password is not consistent with the preset password, it can be preliminarily determined that the reason for the verification failure is that the user input the password incorrectly. Of course, it can also be that the encryption protocol is cracked in the network connection request transmission process, which leads to the interception of the to-be-verified password, thereby causing the inconsistency between the to-be-verified password and the preset password. Therefore, in order to determine whether the reason for the verification failure is the user input error or the encryption protocol cracking, the to-be-verified password before encryption is compared with the decrypted to-be-verified password. If the to-be-verified password before encryption is consistent with the decrypted to-be-verified password, it indicates that the user input error can cause the verification failure; if the to-be-verified password before encryption is not consistent with the decrypted to-be-verified password, it indicates that the encryption protocol is cracked, so that the to-be-verified password before encryption is intercepted in the transmission process, thereby causing the password loss, and thus the verification failure. If the to-be-verified password before encryption is not consistent with the decrypted to-be-verified password, the firewall is directly started to avoid the abnormal network connection request from connecting the network by using the intercepted to-be-verified password.
[0088] It should be noted that the starting of the firewall does not affect the transmission of the normal network connection request. If the user inputs the same password as the preset password to send the network connection request, the firewall detects that the network connection request is normal at this time, and the subsequent operation can be continued to connect the network.
[0089] The embodiment can acquire the to-be-verified password in the network connection request when the verification fails, compare the decrypted to-be-verified password with the preset password, and determine whether the problem is an incorrect password input. If the decrypted to-be-verified password is inconsistent with the preset password, it indicates that the user may have input an incorrect password, but it is also possible that the related protocol of the network tunnel is cracked in the transmission process, so that the to-be-verified password is intercepted, thereby causing the to-be-verified password to be missing. At this time, the to-be-verified password before encryption is compared with the decrypted to-be-verified password to determine whether there is a problem in the decryption process. If the to-be-verified password before encryption is inconsistent with the decrypted to-be-verified password, it indicates that the related protocol of the network tunnel may indeed be cracked in the transmission process, causing the to-be-verified password to be intercepted. At this time, the firewall in the network tunnel is started to avoid malicious connection after the to-be-verified password is intercepted.
[0090] The method of the embodiment can be applied to the network connection system based on the network tunnel, and the implementation principle is similar, which will not be described here.
[0091] Figure 4 A structural schematic diagram of an electronic device is provided for an embodiment of the present application, and is applied to the network connection system based on the network tunnel provided in the above embodiment. As shown in Figure 4 The electronic device 400 of the embodiment can include a memory 401 and a processor 402.
[0092] The memory 401 stores a computer program capable of being loaded and executed by the processor 402 to perform the method in the above embodiment.
[0093] The processor 402 and the memory 401 are connected, for example, through a bus.
[0094] Optionally, the electronic device 400 can further include a transceiver. It should be noted that the transceiver in actual application is not limited to one, and the structure of the electronic device 400 does not constitute a limitation on the embodiments of the present application.
[0095] The processor 402 can be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array) or other programmable logic device, transistor logic device, hardware component, or any combination thereof. It can implement or execute various exemplary logical blocks, modules and circuits described in combination with the disclosure. The processor 402 can also be a combination of computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0096] The bus can include a path for transmitting information between the above-mentioned components. The bus can be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is shown in the figure, but it does not mean that there is only one bus or only one type of bus.
[0097] The memory 401 can be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory) or other type of dynamic storage device that can store information and instructions, an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, an optical disk storage (including a compact disk, a laser disk, an optical disk, a digital versatile disk, a Blu-ray disk, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program codes in the form of instructions or data structures and can be accessed by a computer, but not limited thereto.
[0098] The memory 401 is used to store application program codes for implementing the scheme of the present application, and is controlled by the processor 402 to execute. The processor 402 is used to execute the application program codes stored in the memory 401 to realize the content shown in the foregoing method embodiments.
[0099] The electronic device includes, but is not limited to, a mobile terminal such as a mobile phone, a notebook computer, a digital broadcast receiver, a PDA (Personal Digital Assistant), a PAD (Tablet Personal Computer), a PMP (Portable Multimedia Player), a car terminal (for example, a car navigation terminal), and the like, and a stationary terminal such as a digital TV, a desktop computer, and the like. It can also be a server or the like. Figure 4 The illustrated electronic device is merely an example and should not impose any limitation on the function and use range of the embodiments of the present application.
[0100] The router of the embodiment can be used to execute the method of any of the above embodiments, and has similar implementation principles and technical effects, which will not be described here.
[0101] The present application also provides a computer readable storage medium storing a computer program capable of being loaded and executed by a processor to perform the method in the above embodiments.
[0102] Those skilled in the art can understand that all or part of the steps of the above-mentioned method embodiments can be completed by program instruction-related hardware. The foregoing program can be stored in a computer readable storage medium. When the program is executed, the steps of the above-mentioned method embodiments are executed; and the foregoing storage medium includes ROM, RAM, magnetic disk or optical disk and various media capable of storing program codes.
Claims
1. A network connection system based on network tunneling, characterized in that, include: Signal receiving module, signal transmission module, router; The signal receiving module, the signal transmission module, and the router are connected in sequence. The signal receiving module is used to receive network connection requests sent by wireless network devices. After establishing communication with the router, the signal transmission module forms a network tunnel, which is used to encrypt the received network connection request to obtain an encrypted network connection request, and then transmit the encrypted network connection request to the router. The router is used to receive the encrypted network connection request, decrypt the encrypted network connection request to obtain the decrypted network connection request, and verify whether the decrypted network connection request meets the requirements. The router is also used to determine whether to allow the wireless network device to access the network based on the verification result; When the decrypted network connection request does not meet the requirements, the router is specifically used to obtain the password to be verified in the decrypted network connection request, compare the password to be verified with the preset password, and determine whether the password to be verified is consistent with the preset password. When the password to be verified is inconsistent with the preset password, the router is specifically used to compare the password to be verified before encryption with the password to be verified after decryption to determine whether there was any loss during transmission; When the password to be verified before encryption is inconsistent with the password to be verified after decryption, the router transmits the comparison result to the signal transmission module; if the password to be verified before encryption is consistent with the password to be verified after decryption, it means that the user entered the wrong password, resulting in verification failure. When the signal transmission module receives the comparison result, it is specifically used to activate the firewall to isolate abnormal network connection requests.
2. The system according to claim 1, characterized in that, The router includes a signal verification module and a signal feedback module; the signal transmission module includes a data forwarding unit. The data forwarding unit is used to encrypt the network connection request through the Secure Sockets Protocol to obtain the encrypted network connection request, and to transmit the encrypted network connection request through the Transmission Control Protocol so that the encrypted network connection request is not intercepted during transmission. The data forwarding unit is further configured to transmit the encrypted network connection request to the signal verification module, so that the signal verification module decrypts the encrypted network connection request according to a preset decryption method, obtains the decrypted network connection request, verifies whether the decrypted network connection request meets the requirements, and transmits the verification result to the signal feedback module.
3. The system according to claim 1, characterized in that, The signal transmission module includes a firewall for detecting whether the network connection request is a normally sent request. If the network connection request is detected as not being a normally sent request, the firewall is specifically used to block the network connection request to prevent abnormal network connection requests from accessing the network.
4. The system according to claim 1, characterized in that, The router includes a request storage module for storing information about the wireless network device included in the network connection request. When the decrypted network connection request is successfully verified and the wireless network device accesses the network, the request storage module is used to: store the wireless network device information of the successfully verified decrypted network connection request so that the wireless network device can connect without verification the next time.
5. The system according to claim 1, characterized in that, It also includes an error connection alert module, which is used to alert the user of an error connection when the password entered in the decrypted network connection request is incorrect.
6. A network connection method based on network tunneling, characterized in that, include: Obtain network connection requests from wireless network devices; The network connection request is encrypted to obtain an encrypted network connection request, thereby ensuring that the network connection request is not intercepted during transmission. After the encrypted network connection request is transmitted, the encrypted network connection request is decrypted to obtain the decrypted network connection request in order to verify whether the decrypted network connection request meets the requirements. If the decrypted network connection request meets the requirements, the wireless network device is allowed to access the network; If the decrypted network connection request does not meet the requirements, then obtain the password to be verified from the decrypted network connection request; The password to be verified is compared with the preset password to determine whether the password to be verified is consistent with the preset password; If the password to be verified is inconsistent with the preset password, the password to be verified before encryption is compared with the password to be verified after decryption to determine whether there was any loss during transmission. If the password to be verified before encryption is inconsistent with the password to be verified after decryption, the firewall is activated to block abnormal network connection requests; if the password to be verified before encryption is consistent with the password to be verified after decryption, it indicates that the user entered the wrong password, resulting in verification failure.
7. An electronic device, characterized in that, The network connection system based on network tunneling as described in any one of claims 1-5 includes: a memory and a processor; The memory is used to store program instructions; The processor is configured to call and execute program instructions in the memory to perform the method as described in claim 6.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program; when the computer program is executed by a processor, it implements the method as described in claim 6.
Citation Information
Patent Citations
Encryption and decryption method, equipment and computer storage medium
CN108616878A
Sensitive file management method
CN112733188A