Reference station network, reference station network node public network security access method and device

By using IPSec VPN tunnels and source address translation mechanisms, the problems of high operating costs and insufficient security in the base station network are solved, achieving high scalability, strong security, and simple configuration of the base station network, and ensuring the security of the data center intranet.

CN116192411BActive Publication Date: 2025-11-25QIANXUN SPATIAL INTELLIGENCE INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111420715.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-26
Publication Date
2025-11-25
Estimated Expiration
2041-11-26

AI Technical Summary

Technical Problem

Existing technologies in base station networks suffer from high operating costs, insufficient security, and complex configuration. In particular, when accessing a large number of branch sites, VPN encryption methods are difficult to meet the needs of edge computing.

Method used

An IPSec VPN tunnel is used to connect the base station and the data center. Source address translation is performed through the data center VPN gateway to ensure that when the data center server initiates access, devices within the site cannot directly access the data center. By combining VPN interest flow and address translation mechanisms, secure connections and redundancy switching between sites are achieved.

Benefits of technology

It achieves high scalability, strong security, and simple configuration of the base station network, enabling flexible redundancy switching, ensuring the security of the data center intranet, and reducing operating costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116192411B_ABST
    Figure CN116192411B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of reference station network, and discloses a reference station network and a node public network security access method and device thereof, wherein a reference station is connected with a reference station gateway, the reference station gateway is connected with a data center VPN gateway through a VPN encryption tunnel on a public network, and multiple in-station devices of the reference station are connected with a data center server through the VPN encryption tunnel; the method comprises the following steps: a data center server initiates an access request for a specified in-station device; a data center VPN gateway performs network address translation on an original source address of the data center server in an access request data packet according to preconfiguration; the data center VPN gateway judges whether an address pair of a new source address of the data packet and a destination address of the specified in-station device matches a preconfigured VPN interest flow, and sends the access request data packet to the specified in-station device; wherein the preconfigured VPN interest flow does not contain the original source address of the data center server.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network communication, in particular to large reference station network technology. BACKGROUND

[0002] The Beidou satellite navigation system is an important part of the Beidou satellite navigation system. Through the satellite navigation signal repeater carried by the geostationary satellite, various correction information such as ephemeris error, satellite clock error, and ionospheric delay can be broadcast to users, and the positioning accuracy of the original satellite navigation system can be improved. However, although the ground-based enhancement reference station is widely distributed, the operation cost is high in some application scenarios.

[0003] On the other hand, the remote access technology (VPN, Virtual Private Network) has developed rapidly in recent years. VPN belongs to remote access technology, which is simply a private network built using public networks. For example, a company employee goes on a business trip to a foreign place and wants to access the server resources of the enterprise intranet. This access belongs to remote access. However, although VPN has the advantages of security and convenience, it is complex in some application scenarios, consumes a large amount of computing resources, and affects its further more widespread application. SUMMARY

[0004] The purpose of the present application is to provide a reference station network and its node public network security access method and device, and an access device and site number scale with better scalability, stronger access capability, higher security, simpler configuration, and more flexible redundant switching.

[0005] The present application discloses a reference station network node public network security access method, wherein the reference stations in the reference station network are connected with the reference station gateway, the reference station gateway is connected with the data center VPN gateway through the VPN encryption tunnel on the public network, the data center VPN gateway is connected with the data center server, so that the multiple in-station devices of the reference station are connected with the data center server through the VPN encryption tunnel, and the method comprises the following steps:

[0006] The data center server initiates an access request to a specified in-station device, wherein the access request data packet contains the original source address of the data center server and the destination address corresponding to the specified in-station device;

[0007] The data center VPN gateway translates the original source address of the data center server in the access request data packet according to the pre-configuration to generate a new source address in the access request data packet;

[0008] The data center VPN gateway judges whether the address pair of the new source address of the data message to the destination address of the specified in-station device matches a pre-configured VPN interest flow, and if so, the data center VPN gateway sends the access request data message to the specified in-station device; wherein the pre-configured VPN interest flow does not contain the original source address of the data center server.

[0009] In a preferred example, the method further comprises the following steps:

[0010] After receiving the access request data message, the specified in-station device returns a corresponding data message to the data center server according to the access request, wherein the return source address of the returned data message is the destination address of the request data message, and the return destination address of the returned data message is the new source address of the request data message.

[0011] In a preferred example, in the step of the data center VPN gateway translating the original source address of the data center server in the access request data message according to a pre-configuration to generate the new source address in the access request data message,

[0012] The data center VPN gateway matches the original source address with a pre-set network address translation configuration file, and translates the source address according to the matching result to translate the original source address of the data message into a corresponding new source address set in advance, while retaining the source address translation session information of the address translation in the data center VPN gateway, wherein the source address translation session information contains the original source address before translation, the destination address before translation, the port information before translation, the new source address after translation, the destination address after translation, and the port information after translation, and the destination address before translation and the destination address after translation are the same.

[0013] In a preferred example, in the step of the specified in-station device receiving the access request data message and returning a corresponding data message to the data center server according to the access request,

[0014] When the in-station device returns a response data message, the data center VPN gateway checks whether the return source address and the return destination address match the translated new source address and the translated destination address in the stored source address translation session information, and if so, modifies the return destination address to be the same as the original source address in the request data message and continues to send, and if not, discards.

[0015] In a preferred example, in the step of the data center VPN gateway judging whether the address pair of the new source address of the data message to the destination address of the specified in-station device matches a pre-configured VPN interest flow, comprises:

[0016] determining that a new source address preset by the data center VPN gateway matches a destination address preset by the reference station gateway, and a destination address preset by the data center VPN gateway matches a source address preset by the reference station gateway.

[0017] In a preferred embodiment, the reference station network comprises a plurality of sets of corresponding connected reference stations and reference station gateways, a plurality of sets of corresponding connected data centers and data center VPN gateways, and the addresses contained in the VPN interest flows to which the plurality of reference stations and the plurality of data center VPN gateways are respectively connected are different.

[0018] In a preferred embodiment, the in-station device is one or any combination of the following: a meteorological instrument, an Internet of Things gateway, a sensor, and a computing server.

[0019] In a preferred embodiment, the reference station network comprises a first data center server and a first data center VPN gateway connected in correspondence, and a second data center server and a second data center VPN gateway connected in correspondence, and the first data center VPN gateway and the second data center VPN gateway are connected, and when a first VPN tunnel between the first data center VPN gateway of the first data center server and the reference station gateway is interrupted,

[0020] the second data center VPN gateway performs network address translation on the original source address of the first data center server in the access request data packet according to a pre-configuration to generate a new source address in the request data packet.

[0021] The application also discloses a reference station network node public network secure access device, wherein the reference station and the reference station gateway in the reference station network are connected, the reference station gateway is connected with a data center VPN gateway through a VPN encryption tunnel on a public network, the data center VPN gateway is connected with a data center server, and multiple in-station devices of the reference station are connected with the data center server through the VPN encryption tunnel, and the device comprises:

[0022] An access request initiation module is configured to initiate an access request for a specified in-station device, wherein the access request data packet contains an original source address of a data center server and a corresponding destination address of the specified in-station device.

[0023] A network address translation module is configured to perform network address translation on the original source address of the data center server in the access request data packet according to a pre-configuration to generate a new source address in the access request data packet.

[0024] The judging and sending module is configured to judge whether an address pair of a new source address of the data packet and a destination address of the in-station device matches a pre-configured VPN interest flow, and if yes, the data center VPN gateway sends the access request data packet to the in-station device; wherein the pre-configured VPN interest flow does not contain the original source address of the data center server.

[0025] The application also discloses a reference station network, wherein reference stations and a reference station gateway in the reference station network are connected, the reference station gateway is connected with a data center VPN gateway through a VPN encryption tunnel on a public network, and the data center VPN gateway is connected with a data center server, so that multiple in-station devices of the reference station are connected with the data center server through the VPN encryption tunnel, wherein the reference station network uses the reference station network node public network security access method as described above.

[0026] In the embodiment of the application, all devices in the same station can be accessed through the IPSec VPN tunnel, and the number of devices is not limited, so that the purpose of station-to-station connection is achieved; when the data center server accesses the station, the source address is translated by the VPN gateway into a specified network segment; the IPSec interest flow of the VPN gateway of the station matches the source translated address of the data center server.

[0027] It should be noted that each reference station station in the above embodiments can be regarded as a small branch center, and all devices in the station can access the data center through the VPN tunnel; data access can only be initiated from the data center to access the devices in the branch, and the branch devices cannot directly access the intranet of the data center through the VPN tunnel, so that the intranet security of the data center is ensured, and the configuration is simple and does not require complex policy configuration entries; the branch VPN gateway can be connected with multiple VPN gateways (the VPN gateway can be deployed in a single / multiple data centers) at the same time, so that the purpose of link redundancy switching is achieved.

[0028] Therefore, in general, the application has the following advantages: the number of access devices and stations has better scalability, the access capacity is stronger, the security is higher, the configuration is simpler, and the redundancy switching can be more flexibly realized.

[0029] A large number of technical features are described in the specification of the present application, which are distributed in various technical solutions. If all possible combinations of technical features (i.e. technical solutions) of the present application are listed, the specification will be too long. In order to avoid this problem, each technical feature disclosed in the above summary of the present application, each technical feature disclosed in the following various embodiments and examples, and each technical feature disclosed in the drawings can be freely combined with each other to form various new technical solutions (which are considered to have been described in the specification), unless such combination of technical features is technically infeasible. For example, features A+B+C are disclosed in one example, features A+B+D+E are disclosed in another example, features C and D are equivalent technical means that play the same role, and can only be used alternatively, and feature E can be combined with feature C technically. Therefore, the solution of A+B+C+D should not be considered to have been described because it is technically infeasible, and the solution of A+B+C+E should be considered to have been described. BRIEF DESCRIPTION OF DRAWINGS

[0030] Figure 1 is a schematic diagram of a network architecture according to the base station network node public network security access method of the first embodiment of the present application;

[0031] Figure 2 is a schematic diagram of the flow of the base station network node public network security access method according to the first embodiment of the present application;

[0032] Figure 3 is a schematic diagram of one example of the base station network node public network security access method according to the first embodiment of the present application;

[0033] Figure 4 is a schematic diagram of the system structure of the base station network node public network security access method according to the second embodiment of the present application;

[0034] Figure 5 is a schematic diagram of the flow of the base station network node public network security access method according to the second embodiment of the present application.

[0035] Figure 6 is a schematic diagram of the structure of the base station network node public network security access device according to the third embodiment of the present application. DETAILED DESCRIPTION

[0036] In the following description, many technical details are presented in order to make the reader better understand the present application. However, those skilled in the art can understand that the technical solutions claimed by the present application can be implemented even without these technical details and based on various changes and modifications of the following embodiments.

[0037] Explanation of some concepts:

[0038] Data center server: Internet Data Center, abbreviated as IDC, is a standard telecommunication professional room environment built by the telecommunication department using existing Internet communication lines and bandwidth resources, which provides server hosting, rental and related value-added services for enterprises and governments. By using the IDC server hosting service of the telecommunication department, enterprises or government units do not need to build their own professional room, lay expensive communication lines, or hire network engineers at high salaries, and can solve many professional needs of using the Internet. The services provided by IDC can be divided into four types: host hosting, resource rental, value-added services, and application services. The IDC server generally has significant configuration expansion compared with the standard server, such as full hard disks, large memory, and high-power fans for heat dissipation.

[0039] Reference station: a ground fixed observation station that continuously observes satellite navigation signals for a long time and transmits observation data to the data center in real time or at a fixed time through communication facilities.

[0040] In-station equipment: refers to professional application equipment in the reference station, for example, a meteorological instrument, an Internet of Things gateway, various sensors, and an edge computing server. These devices only have basic network functions and need to communicate with the data center server through the VPN gateway.

[0041] VPN gateway: in the specification and drawings of the present application, it is also referred to as a VPN gateway, and both have the same meaning.

[0042] VPN: Virtual Private Network (VPN) creates an encrypted, virtual point-to-point connection between the VPN client and the VPN gateway, ensuring the security of data when passing through the Internet.

[0043] Tunnel: Tunneling is a way of passing data between networks using the infrastructure of the Internet. The data (or payload) that is passed using tunneling can be frames or packets of different protocols. Tunneling protocols re-encapsulate the frames or packets of these other protocols in a new header. The new header provides routing information, enabling the encapsulated payload data to be passed through the Internet. The encapsulated packets are routed between the two endpoints of the tunnel through the public Internet. The logical path that the encapsulated packets take across the public Internet is called the tunnel. Once at the network endpoint, the data is de-encapsulated and forwarded to the final destination. Note that tunneling refers to the entire process, including data encapsulation, transmission, and de-encapsulation. Tunneling is the basis of VPN technology. In creating a tunnel, both the client and server must use the same tunneling protocol. Tunneling can be divided into Layer 2 and Layer 3 tunneling protocols according to the Open Systems Interconnection Reference Model (OSI).

[0044] IPSec VPN tunnel: There are three main tunneling protocols for VPN, PPTP, L2TP, and IPSec. PPTP and L2TP protocols work at Layer 2 of the OSI model, also known as Layer 2 tunneling protocols. IPSec is a Layer 3 tunneling protocol.

[0045] VPN gateway: VPN gateway is a network that can be interconnected through VPN technology, and is the best form of network interconnection between headquarters and branch offices.

[0046] Network segment: Network segment refers to a part of a computer network that can communicate directly using the same physical layer device (transmission medium, repeater, hub, etc.).

[0047] IPsec interest flow: also known as "IPsec interest flow", IPsec is a kind of encrypted tunnel technology, which establishes a secure and secure communication tunnel between different networks by using encrypted security services. Interest flow is a term of VPN, which refers to the traffic that needs to be protected, that is, the traffic that needs to enter the VPN tunnel. In some cases, the data encrypted by the IPsec tunnel has multiple different network segments as its source and destination address, so the interest flow needs to be grouped when configuring the IPsec interest flow. In a typical IPsec tunnel topology, if you need to control the intercommunication between 192.168.1.0 / 24 and 192.168.3.0 / 24, and the intercommunication between 192.168.2.0 / 24 and 192.168.4.0 / 24, you need to group the interest flow when configuring the IPsec interest flow: 192.168.1.0 / 24 and 192.168.3.0 / 24 are a group of interest flows, and 192.168.2.0 / 24 and 192.168.4.0 / 24 are a group of interest flows.

[0048] The inventors of the present application found through long-term research and analysis that the characteristics of the ground-based augmentation reference station are widely distributed, evenly distributed in various provinces across the country, and the total number of stations built across the country reaches several thousand. Each site transmits epoch data through various wide area network technologies. However, how to use this nationwide site distribution to build an edge computing network still needs to be continuously explored. In the network construction of the ground-based augmentation reference station, the security of the network access method has corresponding policies and regulations. The two general requirements are: leased line and VPN link.

[0049] Although the network can be built by using the leased line provided by the operator to meet the various access requirements of the reference station network and edge computing, the price of the leased line is high, and the operation cost of the leased line access of thousands of sites is high.

[0050] As for the VPN link, although the VPN link can perform data encryption transmission on the public network, the existing VPN encryption method still has some defects for the access requirements of edge computing. Specifically as follows:

[0051] For SSL VPN, the main role of SSL VPN is to connect between host and site. That is, the host initiating the SSL VPN can access the SSL VPN gateway through the VPN tunnel, and after obtaining the intranet address, it can connect to the server in the intranet. Although this connection method can meet the local access requirements, edge computing often introduces other professional equipment, and needs to regard the reference station as a site containing multiple devices, and needs to establish a site-site encrypted transmission tunnel, at which time the characteristics of the SSL VPN are difficult to meet the requirements.

[0052] For IPSec VPN, the main role of IPSec VPN is to establish an encrypted tunnel to meet the data encryption transmission between sites. After the establishment of the VPN tunnel, multiple devices in the site can communicate with the center node through the tunnel. From the perspective of network communication, the access demand of edge computing can be met. However, from the security perspective, after the establishment of the IPSec VPN tunnel, a direct data center tunnel is opened, and the security vulnerabilities of each branch site may have a significant impact on the data center. When a data center connected with thousands of branch sites is established, it is a very complex work to set security policies for each site in the center, and a large amount of computing resources will be consumed.

[0053] The inventors of the present application further consider that if each reference station site is regarded as a small branch center, all devices in the site can access the data center through the VPN tunnel, wherein the number of internal devices of the branch center is not limited, the number of branch sites is not limited, and the number of access devices and sites is easy to expand horizontally, so that the ability of massive edge computing resources and node access can be achieved.

[0054] Therefore, the inventors of the present application propose a method for public network security access of reference station network nodes. Wherein, all devices in the same site can be accessed through the IPSec VPN tunnel, and the number of devices is not limited, so as to achieve the purpose of site-site connection; when the data center server accesses the site, the source address is translated through the VPN gateway to a specified network segment; the IPSec interest stream of the site connected to the VPN gateway matches the source translation address of the data center server.

[0055] More specifically, the inventors of the present application construct a secure access tunnel between the data center and the branch site by combining the source address translation network segment of the center VPN gateway and the interest stream characteristics of the IPSec VPN tunnel. The specific features are that the entire VPN tunnel is an encrypted tunnel, which can use various national and internationally common encryption algorithms; the data center server can access multiple devices in the branch site through the VPN tunnel; after the establishment of the VPN tunnel, data access must be initiated by the data center server, otherwise it cannot be done, which ensures the internal security of the data center; the branch sites cannot access each other, which reduces the security risk; the center VPN gateway does not need to set complex security policy items, and the configuration is simple; the branch site can connect to a single / multiple data center through multiple links and realize redundant switching

[0056] Each base station site can be regarded as a small branch center, and all devices in the site can access the data center through a VPN tunnel; for data access, only the branch device can initiate access to the data center, and the branch device cannot directly access the intranet of the data center through the VPN tunnel, which ensures the security of the intranet of the data center and is simple to configure without complex policy configuration entries; further, the branch VPN gateway can be connected to multiple VPN gateways (the VPN gateway can be deployed in a single / multiple data centers) at the same time to achieve the purpose of link redundancy switching.

[0057] In order to make the purpose, technical solutions and advantages of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the drawings.

[0058] The first embodiment of the present application relates to a base station network node public network secure access method.

[0059] Figure 1 The system architecture of the base station network node public network secure access method is shown in FIG. 1, wherein the base station in the base station network is connected with the base station gateway, the base station gateway is connected with the data center VPN gateway through a VPN encryption tunnel on the public network, the data center VPN gateway is connected with the data center server, and the multiple station devices of the base station are connected with the data center server through the VPN encryption tunnel, and the method comprises the following steps. Figure 1

[0060] It should be pointed out that the system architecture can contain one or two or more data center servers.

[0061] The station device, it should be pointed out that the number of station devices in the system architecture can be arbitrary, and the station device can be a meteorological instrument, an Internet of Things gateway, various sensors, an edge computing server, etc.

[0062] The flow of the base station network node public network secure access method is shown in FIG. 2, and the method comprises the following steps. Figure 2

[0063] Step 110: the data center server initiates an access request for a specified station device, wherein the access request data packet contains the original source address of the data center server and the destination address corresponding to the specified station device.

[0064] Step 120: the data center VPN gateway translates the original source address of the data center server in the access request data packet according to the pre-configuration to generate a new source address in the access request data packet.

[0065] ​​Preferably, the data center VPN gateway matches the original source address with a pre-configured network address translation profile, and performs source address translation according to the matching result to translate the original source address of the data packet into a corresponding new source address, while retaining the address translation session information of the address translation in the data center VPN gateway, the address translation session information including the original source address before translation, the destination address before translation, the port information before translation, the new source address after translation, the destination address after translation, and the port information after translation, wherein the destination address before translation is the same as the destination address after translation.

[0066] Step 130: The data center VPN gateway determines whether the address pair of the new source address of the data packet and the destination address of the specified in-station device matches a pre-configured VPN interest flow, and if so, sends the access request data packet to the specified in-station device; wherein the pre-configured VPN interest flow does not contain the original source address of the data center server.

[0067] Preferably, in the step of determining whether the address pair of the new source address of the data packet and the destination address of the specified in-station device matches a pre-configured VPN interest flow, the data center VPN gateway determines whether the pre-configured new source address of the data center VPN gateway matches the pre-configured destination address of the reference station gateway, and whether the pre-configured destination address of the data center VPN gateway matches the pre-configured source address of the reference station gateway.

[0068] Step 140: After receiving the access request data packet, the specified in-station device transmits a corresponding data packet back to the data center server according to the access request, wherein the return source address of the return data packet is the destination address of the request data packet, and the return destination address of the return data packet is the new source address of the request data packet.

[0069] Preferably, when the in-station device returns a response data packet, the data center VPN gateway checks whether the return source address and the return destination address match the translated new source address and the translated destination address in the stored source address translation session information, and if so, modifies the return destination address to be the same as the original source address in the request data packet and continues to send, and if not, discards.

[0070] Specifically, in this step, the data center server (1.1.1.1) initiates an access request to a specified in-station device, such as in-station device (3.3.3.3). Wherein "1.1.1.1" is the source address of the data center server.

[0071] Thereafter, after passing through the VPN gateway, the source address (1.1.1.1) of the data center server is translated into a specified network segment according to a VPN gateway address translation policy, and the source address (1.1.1.1) of the data center server is translated into a new source address (2.2.2.2).

[0072] The new source address can also be referred to as a source translation address.

[0073] The following describes a VPN gateway network address translation (NAT) mechanism. A source address translation technology is used in the embodiments of the present application. When a data message of a data center server reaches a VPN gateway, the VPN gateway matches the source address with a translation policy configured in advance, and performs source address translation according to the matching result, to translate the source address of the data message into a corresponding new source address set in advance. Meanwhile, a session information of the address translation is reserved in the VPN gateway, and the session information includes'source / destination address and port information before translation' and'source / destination address and port information after translation'. When a data message of a response is returned by a destination device, the VPN gateway checks whether the source / destination address of the data message matches the stored source address translation session information, and if the data message matches the source address translation session information, the VPN gateway performs a related operation and sends the data message continuously. If the data message does not match the source address translation session information, the data message is discarded.

[0074] The present application uses the function of the above source address translation mechanism: only when a data center server initiates an access, the data center server can communicate with a station-in-device of a reference station.

[0075] When the station-in-device of the reference station attempts to initiate an access to the data center server first, the station-in-device can only initiate an access to the configured new source address, and the new source address is a virtual address specially used for network address translation. The data message of the reference station side can be translated to the data center side only by relying on the source address translation session information. Since the access is not initiated by the data center server, there is no corresponding address translation session information, and thus the access initiated first by the station-in-device is discarded.

[0076] Specifically, in the step 130, the corresponding destination address of the specified station-in-device is (3.3.3.3).

[0077] It should be noted that since the address pair of the translated source address (2.2.2.2) of the data center server and the corresponding destination address (3.3.3.3) of the station-in-device matches a VPN interest flow, the data message is transmitted through a VPN tunnel.

[0078] VPN tunnel interest flow matching principle: a local source address segment matches a remote destination address segment, and a local destination address segment matches a remote source address segment.

[0079] Source address Destination address VPN gateway 2.2.2.2 3.3.3.3 Intra-site device 3.3.3.3 2.2.2.2

[0080] Note: In the example, a single IP address is used as an example, which can be replaced by an IP network segment.

[0081] The VPN gateway checks the translated data packet, and when the source / destination address of the data packet matches the source / destination address of the VPN gateway in the above table, the data packet is transmitted through the VPN tunnel.

[0082] Further, in the above step 140, when the data packet containing the corresponding data is returned by the designated in-station device to the VPN gateway, the VPN gateway changes the destination address in the data packet from the translated source address of the data center server, i.e., the translated source address, to the address of the data center server, and continues to complete the transmission of the data packet according to the address of the data center server.

[0083] Specifically, after the designated in-station device (3.3.3.3) receives the access request and returns the data packet with the corresponding data to the VPN gateway, the VPN gateway changes the destination address in the data packet from the translated source address of the data center server (2.2.2.2) to the address of the data center server (1.1.1.1), and continues to complete the transmission of the data.

[0084] The above embodiment has the following characteristics: 1. All devices in the reference station can access the data center through the VPN tunnel. 2. The gateway of the reference station is connected to the VPN gateway through the VPN encrypted tunnel. 3. The destination address of the interest stream matches the source address translation network segment of the data center VPN gateway. 4. The data center VPN gateway performs source address translation on the internal servers of the center. 5. The data center server initiates access to the devices of the branch station of the reference station; the branch devices cannot initiate access to the data center server. 6. Multiple VPN gateways and multiple data center redundancy switching.

[0085] It should be noted that in the present embodiment, the source address translation network segment of the VPN gateway and the destination address network segment of the VPN interest stream are coupled together, combining the functions of address translation and VPN to form a unique security mechanism. Among them, only the source address translation segment of the VPN gateway can be accessed through the VPN tunnel, and this translation segment address is a virtual address, which must have an actual effective virtual address and branch in-station device communication after the data center server initiates an access request through the VPN gateway.

[0086] In addition, the branch in-station device cannot actively initiate access to the data center.

[0087] In addition, different VPN gateways can be configured with different source address network segments, naturally forming different VPN paths. Thus, the purpose of link redundancy and switching is achieved.

[0088] Technical effects:

[0089] In the above embodiment, all devices in the same site can be accessed by using the IPSec VPN tunnel, and the number of devices is not limited, achieving the purpose of site-site connection; when the data center server accesses the site, the VPN gateway is used for source address translation, and the specified network segment is translated; the IPSec interest stream of the site connected to the VPN gateway matches the source translation address of the data center server.

[0090] It should be pointed out that each reference station site in the above embodiment can be regarded as a small branch center, and all devices in the site can access the data center through the VPN tunnel; data access can only be initiated from the data center to access the devices in the branch, and the branch devices cannot directly access the intranet of the data center through the VPN tunnel, which ensures the security of the intranet of the data center, and the configuration is simple, without complex policy configuration entries; the branch VPN gateway can be connected to multiple data center VPN gateways (the data center VPN gateway can be deployed in a single / multiple data centers) at the same time, achieving the purpose of link redundancy switching.

[0091] In order to better understand the technical solutions of the present application, a specific example will be described below, and the details listed in the example are mainly for the purpose of understanding, and do not limit the protection scope of the present application.

[0092] As shown in Figure 3 , the source address translation is configured on the data center VPN gateway, and the specified data center server address 1.1.1.1 is changed to 2.2.2.2; the branch site sets the VPN interest stream, and the destination address is 2.2.2.2.

[0093] The data flow is introduced as follows:

[0094] The data center server initiates access to the device 3.3.3.3 in the site.

[0095] After passing through the data center VPN gateway, the data center VPN gateway address translation policy is matched, the source address of the data center server is changed to 2.2.2.2, that is, the source translation address of the data center server. Then, 2.2.2.2 is used as the source address to access 3.3.3.3.

[0096] Because the source translation address 2.2.2.2 of the data center server matches the address pair of the VPN interest stream to the device 3.3.3.3 in the site, the data is transmitted through the VPN tunnel.

[0097] After receiving the request, the device in the site returns the data.

[0098] When the returned data reaches the data center VPN gateway, the data center VPN gateway changes the destination address from 2.2.2.2 to 1.1.1.1, and continues to complete the transmission of the data.

[0099] It should be noted that the above example has the following technical effects:

[0100] The branch site is connected to the data center through a VPN tunnel after encryption; the VPN tunnel only transmits access to the branch site equipment initiated by the data center server through the data center VPN gateway; the branch site equipment has no data center internal network information and cannot directly initiate any access to the data center internal server, and the security and virus vulnerability of the branch site will not affect the data center; since different data center VPN gateways can set different source address translation network segments, link redundancy can be simply realized. That is, by connecting the same data center (the same internal network segment) through different links, the purpose of redundant switching can be achieved.

[0101] The following will be combined with a specific example to illustrate the switching process of data transmission when the system architecture contains two data center servers: a first data center server and a second data center server, and the VPN tunnel between the VPN gateway of one of the data center servers and the reference station gateway is interrupted.

[0102] Among them, the reference station network includes multiple groups of corresponding connection reference stations and reference station gateways, multiple groups of corresponding connection data centers and data center VPN gateways, and the addresses contained in the VPN interest streams connected by the multiple reference stations and the multiple data center VPN gateways are different.

[0103] Further, the reference station network includes a first data center server and a first data center VPN gateway connected in correspondence, and a second data center server and a second data center VPN gateway connected in correspondence, and the first data center VPN gateway and the second data center VPN gateway are connected, when the first VPN tunnel between the first data center VPN gateway of the first data center server and the reference station gateway is interrupted, the second data center VPN gateway translates the original source address of the first data center server in the access request data packet according to the pre-configuration to generate a new source address in the request data packet.

[0104] In the following example, as shown in Figure 4 , Figure 5 When the first VPN tunnel between the first VPN gateway of the first data center server (see S201) and the reference station gateway is interrupted (see S206), the first VPN gateway loses the routing information to the reference station network segment (see S203), and the following switching process occurs:

[0105] Step 210: The reference station network segment of the second VPN gateway of the second data center server (see S202) is injected into the core network (see S204).

[0106] Note that each data center server uses its own nearest VPN gateway as the VPN gateway. The data packet of the data center server is always sent to its own VPN gateway. The VPN gateway is responsible for selecting the optimal forwarding path. For the same route segment, the VPN access route of the VPN gateway has higher priority than the route learned from the core network.

[0107] Network switching mechanism forming conditions: the station equipment is connected to at least two data center VPN gateways through VPN tunnels. The translated virtual address segment of each data center VPN gateway is unique.

[0108] Data center VPN gateway side: the data center VPN gateway has its own VPN access route, and the route is also injected into the core network. When the VPN tunnel accessed by the data center VPN gateway is interrupted, the VPN tunnel related route disappears, and then the data center VPN gateway selects the secondary route learned from the core network. When the accessed VPN tunnel is restored, the local VPN related route is restored, and since the local VPN route has higher priority, the local VPN is selected as the available route again. Since the route state is automatically switched with the on-off state of the VPN, the switching of the network link is realized.

[0109] Station equipment side: the station equipment waits for the data center server to initiate access. When the data center packet is switched to another data center VPN gateway, the translated virtual source address is different. The station equipment automatically matches to the related VPN tunnel according to the source address, and completes the switching action.

[0110] Step 220: the first data center server initiates an access request to the reference station through the first VPN gateway and the second VPN gateway in turn, the access request data packet contains the source address of the first data center server and the destination address corresponding to the specified station equipment, and the second VPN gateway translates the source address of the first data center server in the access request data packet into a specified network segment to generate a new source address in the request data packet.

[0111] In other words, the first data center server initiates an access request to the reference station through the first VPN gateway and the second VPN gateway in turn, i.e., S203-S205-S204, the access request carries the source address of the first data center server, and the second VPN gateway translates the source address of the first data center server to generate the source translation address corresponding to the first data center server (see S204).

[0112] Step 230: The second VPN gateway determines whether the address pair of the new source address of the data packet and the destination address of the specified in-station device matches the pre-configured VPN interest flow, and if so, the second VPN gateway sends the access request data packet to the specified in-station device (see S207 and S208).

[0113] That is, the second VPN gateway determines whether the address pair of the new source address of the first data center server and the destination address corresponding to the in-station device matches the pre-configured VPN interest flow, and if so, the second VPN gateway sends an access request to the in-station device.

[0114] Step 240: The reference station gateway switches to the second VPN tunnel with the second VPN gateway according to the source address of the received data packet (see S207), and returns the data packet containing the data of the in-station device to the second VPN gateway (see S204) through the second VPN tunnel (see S207).

[0115] Step 250: The second VPN gateway returns the data packet to the first data center server via the first VPN gateway.

[0116] The above example has the following characteristics: 1. All devices in the reference station can access the data center through the VPN tunnel. 2. The reference station gateway is connected to the VPN gateway through the VPN encryption tunnel. 3. The interest flow destination address matches the data center VPN gateway source address translation segment. 4. The data center VPN gateway performs source address translation on the internal servers. 5. The data center server initiates access to the devices in the branch station of the reference station; the branch devices cannot initiate access to the data center server. 6. Multiple VPN gateway multiple data center redundancy switching.

[0117] It should be noted that in the present embodiment, the source address translation segment of the data center VPN gateway and the destination address segment of the VPN interest flow of the reference station gateway are coupled together, combining the functions of address translation and VPN to form a unique security mechanism. Among them, only the source address translation segment of the VPN gateway can be accessed through the VPN tunnel, and this translation segment address is a virtual address, which must have an actual effective virtual address and branch in-station device communication after the data center server initiates an access request through the VPN gateway.

[0118] Moreover, the branch in-station device cannot actively initiate access to the data center.

[0119] Moreover, different VPN gateways can be configured with different source address segments, naturally forming different VPN paths. Thus, the purpose of link redundancy and switching is achieved.

[0120] Technical effects:

[0121] In the above embodiments, all devices in the same site can be accessed by using the IPSec VPN tunnel, and the number of devices is not limited, achieving the purpose of site-site connection; when the data center server accesses the site, the source address is translated by the data center VPN gateway into a specified network segment; the reference station gateway connects the IPSec interest flow of the data center VPN gateway, and the destination address matches the source translated address of the data center server.

[0122] It should be pointed out that each reference station site in the above embodiments can be regarded as a small branch center, and all devices in the site can access the data center through the VPN tunnel; data access can only be initiated from the data center to access the devices in the branch, and the branch devices cannot directly access the intranet of the data center through the VPN tunnel, which ensures the security of the intranet of the data center, and the configuration is simple without complex policy configuration entries; the reference station gateway can simultaneously connect multiple data center VPN gateways (the VPN gateway can be deployed in a single / multiple data centers), achieving the purpose of link redundancy switching.

[0123] The third embodiment of the present application relates to a reference station network node public network security access device, the reference station in the reference station network and the reference station gateway are connected, the reference station gateway is connected with the data center VPN gateway through the VPN encryption tunnel on the public network, the data center VPN gateway is connected with the data center server, so that multiple in-site devices of the reference station are connected with the data center server through the VPN encryption tunnel, and the structure of the device is as shown in Figure 6 The device comprises:

[0124] An access request initiation module is configured to initiate an access request to a specified in-site device, wherein the access request data packet contains the original source address of the data center server and the destination address corresponding to the specified in-site device;

[0125] A network address translation module is configured to perform network address translation on the original source address of the data center server in the access request data packet according to a pre-configuration to generate a new source address in the access request data packet;

[0126] A judgment and sending module is configured to judge whether the address pair of the new source address of the data packet to the destination address of the specified in-site device matches a pre-configured VPN interest flow, and if yes, the data center VPN gateway sends the access request data packet to the specified in-site device; wherein the pre-configured VPN interest flow does not contain the original source address of the data center server.

[0127] The first embodiment is a method embodiment corresponding to the present embodiment, and the technical details in the first embodiment can be applied to the present embodiment, and the technical details in the present embodiment can also be applied to the first embodiment.

[0128] Further, the present application also proposes a reference station network, reference stations and a reference station gateway in the reference station network are connected, the reference station gateway is connected with a data center VPN gateway through a VPN encryption tunnel and a public network, the data center VPN gateway is connected with a data center server, so that multiple in-station devices of the reference station are connected with the data center server through the VPN encryption tunnel, wherein the reference station network uses the reference station network node public network security access method described above.

[0129] The first embodiment is a method embodiment corresponding to the present embodiment, and the technical details in the first embodiment can be applied to the present embodiment, and the technical details in the present embodiment can also be applied to the first embodiment.

[0130] The present application also provides a computer storage medium, which stores computer executable instructions, and the computer executable instructions are executed by a processor to implement the method embodiments of the present application.

[0131] In addition, the present application also provides a reference station network node public network security access system, which includes a memory for storing computer executable instructions, and a processor; the processor is used to implement the steps in the above method embodiments when executing the computer executable instructions in the memory. The processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), etc. The memory can be a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk or a solid state disk, etc. The steps of the method disclosed in the embodiments of the present application can be directly embodied as hardware processor execution, or executed by a combination of hardware and software modules in the processor.

[0132] It has to be noted that, in the present patent application, the terms first and second etc. are used only to distinguish one entity or operation from another entity or operation, without necessarily requiring or implying any actual relationship or order between such entities or operations. Moreover, the terms "comprises / comprising" or "includes / including" when used in this patent application are used to specify the presence of stated features, integers, steps or components but do not preclude the presence or addition of one or more other features, integers, steps, components or groups thereof. Furthermore, the term "figure" as used in this patent application is used to specify a figure in the drawings. The term "consisting of" is used in this patent application to specify the presence of stated features, integers, steps or components and does not permit the presence of one or more additional features, integers, steps, components or groups thereof. The term "comprising of" is used in this patent application to specify the presence of stated features, integers, steps or components and does not exclude the presence of one or more additional features, integers, steps, components or groups thereof. The term "including of" is used in this patent application to specify the presence of stated features, integers, steps or components and does not exclude the presence of one or more additional features, integers, steps, components or groups thereof. The term "one" is used in this patent application to specify the presence of one or more than one of the stated feature, integer, step or component. The term "another" is used in this patent application to specify the presence of one or more than one of the stated feature, integer, step or component. The term "plurality" is used in this patent application to specify the presence of two, two or more than two of the stated feature, integer, step or component. The term "performing" is used in this patent application to specify the performance of the stated action by at least the stated feature, integer, step or component. The term "performing" is used in this patent application to specify the performance of the stated action by at least the stated feature, integer, step or component. The term "performing" is used in this patent application to specify the performance of the stated action by at least the stated feature, integer, step or component.

[0133] All documents mentioned in this application are incorporated in their entirety by reference into the disclosure of this application in order to more fully describe the state of the art as of the filing date of this application. It should be further understood that various alterations, modifications and / or additions of the concepts described in this application can be made without departing from the scope of the application as defined in the following claims.

Claims

1. A public network security access method for a reference station network node, characterized in that, The base station in the base station network and the base station gateway are connected, the base station gateway is connected with the data center VPN gateway through the VPN encryption tunnel on the public network, the data center VPN gateway is connected with the data center server, and multiple in-station devices of the base station are connected with the data center server through the VPN encryption tunnel. The method comprises the following steps: (1) The data center server initiates an access request for a specified in-station device, wherein the access request data message contains the original source address of the data center server and the destination address corresponding to the specified in-station device; (2) The data center VPN gateway translates the original source address of the data center server in the access request data message according to the pre-configuration to generate a new source address in the access request data message; (3) After the source address translation is completed, the source address translation session information containing the original source address before translation, the destination address before translation, the port information before translation, the new source address after translation, the destination address after translation and the port information after translation is reserved; (4) When the address pair of the new source address of the data message to the destination address of the specified in-station device matches the pre-configured VPN interest flow which does not contain the original source address of the data center server, the data center VPN gateway sends the access request data message to the specified in-station device.

2. The method of claim 1, wherein, The following steps are further included; After receiving the access request data message, the specified in-station device transmits a corresponding data message to the data center server according to the access request, wherein the return source address of the return data message is the destination address of the request data message, and the return destination address of the return data message is the new source address of the request data message.

3. The method of claim 1, wherein, In the step of translating the original source address of the data center server in the access request data message according to the pre-configuration, the data center VPN gateway matches the original source address with a pre-set network address translation configuration file, and translates the source address according to the matching result to translate the original source address of the data message into a corresponding new source address set in advance, and the destination address before translation is the same as the destination address after translation.

4. The method of claim 3, wherein, In the step of transmitting a corresponding data message to the data center server according to the access request after receiving the access request data message by the specified in-station device, When the in-station device returns the response data message, the data center VPN gateway checks whether the return source address and the return destination address match the translated destination address and the new source address after translation in the stored source address translation session information, if matched, the return destination address is modified to be the same as the original source address in the access request data message, and the sending is continued, if not matched, the return data message is discarded.

5. The method of claim 1, wherein, In the step of judging whether the address pair of the new source address of the data message to the destination address of the specified in-station device matches the pre-configured VPN interest flow, the following steps are included: The new source address preset by the data center VPN gateway matches the destination address preset by the reference station gateway, and the destination address preset by the data center VPN gateway matches the source address preset by the reference station gateway.

6. The method of claim 1, wherein, The reference station network includes multiple sets of corresponding connection reference stations and reference station gateways, multiple sets of corresponding connection data centers and data center VPN gateways, and the addresses contained in the VPN interest streams connected by the multiple reference stations and the multiple data center VPN gateways are different.

7. The method of claim 1, wherein, The in-station device is one or any combination of the following: a meteorological instrument, an Internet of Things gateway, a sensor, and a computing server.

8. The method of claim 6, wherein, The reference station network includes a first data center server and a first data center VPN gateway in corresponding connection, and a second data center server and a second data center VPN gateway in corresponding connection, and the first data center VPN gateway and the second data center VPN gateway are connected, and when the first VPN tunnel between the first data center VPN gateway of the first data center server and the reference station gateway is interrupted, the second data center VPN gateway performs network address translation on the original source address of the first data center server in the access request data packet according to a pre-configuration to generate a new source address in the access request data packet.

9. A base station network node public network security access device, characterized in that, The reference station and the reference station gateway in the reference station network are connected, the reference station gateway is connected to the data center VPN gateway through a VPN encryption tunnel on the public network, the data center VPN gateway is connected to the data center server, the multiple in-station devices of the reference station are connected to the data center server through the VPN encryption tunnel, and the device comprises: An access request initiation module configured to initiate an access request for a specified in-station device by the data center server, wherein the access request data packet contains an original source address of the data center server and a destination address corresponding to the specified in-station device; A network address translation module configured to perform network address translation on the original source address of the data center server in the access request data packet by the data center VPN gateway according to a pre-configuration to generate a new source address in the access request data packet; A session information retention module configured to retain source address translation session information containing the original source address before translation, the destination address before translation, the port information before translation, the new source address after translation, the destination address after translation, and the port information after translation after the source address translation is completed; A judgment and sending module configured to judge, by the data center VPN gateway, whether the address pair of the new source address of the data packet to the destination address of the specified in-station device matches a pre-configured VPN interest stream that does not contain the original source address of the data center server, and if so, the data center VPN gateway sends the access request data packet to the specified in-station device.

10. A network of reference stations, characterized in that, The base station in the base station network and the base station gateway are connected, the base station gateway is connected with the data center VPN gateway through the VPN encryption tunnel on the public network, the data center VPN gateway is connected with the data center server, and multiple station devices of the base station are connected with the data center server through the VPN encryption tunnel, wherein the base station network uses the base station network node public network security access method in any one of claims 1-8.

Citation Information

Patent Citations

  • Method for network packet routing forwarding and address converting based on IPSec security association

    CN101499965A