A network access method, device, system and storage medium for an SSL VPN client

By building the sslvpn module as middleware in the network server, the complex browser access problem in the existing sslvpn technology is solved, and a simple connection between the sslvpn client and the server is realized, which improves system stability and simplifies the operation process.

CN116232787BActive Publication Date: 2025-07-22BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211631255.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-19
Publication Date
2025-07-22
Estimated Expiration
2042-12-19

AI Technical Summary

Technical Problem

The existing sslvpn technology requires complex transformation and development of computer clients when implementing browser access, which is time-consuming and labor-intensive, and requires high device stability, making it difficult to achieve simple browser access.

Method used

By building the sslvpn module as middleware in the network server, the interaction between the browser and the sslvpn client background program is realized, the dependence on the computer client is reduced, and the interactive data is directly processed through the network server, simplifying the construction of the http framework.

Benefits of technology

It realizes quick connection between the sslvpn client and the server, reduces workload, improves system stability, simplifies operation processes, and avoids complex changes to the computer client.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116232787B_ABST
    Figure CN116232787B_ABST
Patent Text Reader

Abstract

The present invention provides a network access method, device, system and storage medium for an SSLVPN client. The method is applied to a network server and includes: obtaining an SSLVPN access request sent by a browser; determining parameter information about the SSLVPN client background program based on the SSLVPN access request; establishing a network connection with the SSLVPN client background program based on the parameter information; sending the parameter information to the SSLVPN client background program based on the network connection, so that the SSLVPN client background program sends the parameter information to the SSLVPN server and receives a feedback message from the SSLVPN server, and at the same time sends the feedback message to the network server; processing the feedback message to generate a response message in a target format; and sending the response message to the browser to complete the access to the SSLVPN. The network access method for the SSLVPN client of the present invention can quickly and conveniently implement an indirect access connection between the SSLVPN client and the SSLVPN server based on the network server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of network security technology, and particularly to a network access method, device, system and storage medium for an SSLVPN client. Background Art

[0002] When using SSLVPN, it is necessary to log in through a client. For users, they need to obtain the client installation package and then install it before that, and the operation is cumbersome and complex. And the way of accessing SSLVPN through a browser does not require users to actively obtain and install the client, so the browser access solution of SSLVPN becomes particularly important. However, the existing solutions only support the transformation of the SSLVPN client on the computer client.

[0003] For example, as Figure 1 shown, the existing technical solution is to directly transform the original SSLVPN client, including developing an HTTP framework to communicate with the browser for sending and receiving interactions. In this way, the changes to the old computer-side SSLVPN client are relatively large and complex. Moreover, when the existing computer client supports the browser access of SSLVPN, the newly added HTTP parsing framework is a large and complex module. Developing this function not only takes a lot of time and effort, but also has high requirements for the integrity and stability of the device and this module, and is not easy to implement. Summary of the Invention

[0004] The present invention provides a network access method for an SSLVPN client that can quickly and conveniently realize the indirect access connection between the SSLVPN client and the SSLVPN server based on a network server.

[0005] To solve the above technical problems, an embodiment of the present invention provides a network access method for an SSLVPN client, which is applied to a network server, and the method includes:

[0006] Obtain an SSLVPN access request sent by a browser;

[0007] Determine parameter information about the SSLVPN client background program based on the SSLVPN access request;

[0008] Establish a network connection with the SSLVPN client background program based on the parameter information;

[0009] Send the parameter information to the SSLVPN client background program based on the network connection, so that the SSLVPN client background program sends the parameter information to the SSLVPN server, receives the feedback message from the SSLVPN server, and simultaneously sends the feedback message to the network server;

[0010] Process the feedback message to generate a response message in the target format;

[0011] Send the response message to the browser to complete the access to sslvpn.

[0012] As an optional embodiment, the obtaining of the sslvpn access request sent by the browser includes:

[0013] The user initiates the sslvpn access request based on the browser;

[0014] The browser sends the sslvpn access request to the network server, enabling the network server to obtain the sslvpn access request.

[0015] As an optional embodiment, the determining of the parameter information regarding the sslvpn client background program based on the sslvpn access request includes:

[0016] Perform data parsing on the sslvpn access request;

[0017] Determine the communication address and access request parameters of the sslvpn client background program based on the parsing result.

[0018] As an optional embodiment, the establishing of a network connection with the sslvpn client background program based on the parameter information includes:

[0019] Establish a TCP connection with the sslvpn client background program based on the communication address.

[0020] As an optional embodiment, the sending of the parameter information to the sslvpn client background program based on the network connection includes:

[0021] Encapsulate the parameter information based on the transport protocol of the network connection;

[0022] Send the encapsulated parameter information to the sslvpn client background program based on the network connection.

[0023] As an optional embodiment, the sending of the parameter information by the sslvpn client background program to the sslvpn server includes:

[0024] The sslvpn client background program encapsulates the parameter information and sends it to the sslvpn server.

[0025] As an optional embodiment, it is characterized in that the processing of the feedback message to generate a response message in the target format includes:

[0026] Construct an HTTP response message based on the feedback message.

[0027] Another embodiment of the present invention also provides a browser access device for an SSLVPN client, which is applied to a network server. The browser access device for the SSLVPN client is characterized in that it includes:

[0028] An obtaining module, configured to obtain an SSLVPN access request sent by a browser;

[0029] A determining module, configured to determine parameter information about the background program of the SSLVPN client based on the SSLVPN access request;

[0030] A establishing module, configured to establish a network connection with the background program of the SSLVPN client based on the parameter information;

[0031] A first sending module, configured to send the parameter information to the background program of the SSLVPN client based on the network connection, so that the background program of the SSLVPN client sends the parameter information to the SSLVPN server, and receive a feedback message from the SSLVPN server, and at the same time send the feedback message to the network server;

[0032] A processing module, configured to process the feedback message to generate a response message in a target format;

[0033] A second sending module, configured to send the response message to the browser to complete the access to the SSLVPN.

[0034] Another embodiment of the present invention also provides a browser access system for an SSLVPN client, which is characterized in that it includes:

[0035] One or more processors;

[0036] A memory, configured to store one or more programs;

[0037] When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the network access method for the SSLVPN client as described in any one of the above embodiments.

[0038] Another embodiment of the present invention also provides a storage medium, which is characterized in that a computer program is stored thereon, and when the program is executed by a processor, it implements the network access method for the SSLVPN client as described in any one of the above embodiments.

[0039] Based on the disclosure of the above embodiments, the beneficial effects of the embodiments of the present invention include that by using the network server as the middleware between the sslvpn client and the sslvpn server to perform request interactions between the two, it is possible to avoid building the cumbersome http framework in the existing solutions. Moreover, the computer client does not need to process the data of the browser and can directly obtain it based on the network server. Similarly, when interacting with the sslvpn server, there is no need to process the intermediate data, and all can be handed over to the network server for processing, greatly reducing the workload. In addition, the network server technology is mature, and its performance is more stable compared to the http framework built in the existing solutions.

[0040] Other features and advantages of the present invention will be described in the following specification, and part of them will become obvious from the specification, or be understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the structures specifically pointed out in the written specification, claims, and drawings.

[0041] Next, through the drawings and embodiments, the technical solutions of the present invention will be further described in detail. Description of the Drawings

[0042] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention, and do not constitute a limitation to the present invention. In the drawings:

[0043] Figure 1 It is the sslvpn access method in the existing solution.

[0044] Figure 2 It is the flowchart of the network access method of the sslvpn client in the embodiments of the present invention.

[0045] Figure 3 It is the flowchart of the network access method of the sslvpn client in another embodiment of the present invention.

[0046] Figure 4 It is the application flowchart of the network access method of the sslvpn client in the embodiments of the present invention.

[0047] Figure 5 It is another application flowchart of the network access method of the sslvpn client in the embodiments of the present invention.

[0048] Figure 6 It is the structural block diagram of the network access device of the sslvpn client in the embodiments of the present invention. Detailed Embodiments

[0049] Next, with reference to the drawings, the specific embodiments of the present invention will be described in detail, but it is not a limitation to the present invention.

[0050] It should be understood that various modifications can be made to the embodiments disclosed herein. Therefore, the following description should not be construed as limiting, but merely as exemplifying the embodiments. Those skilled in the art will envision other modifications within the scope and spirit of the present disclosure.

[0051] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the disclosure and, together with the general description of the disclosure given above and the detailed description of the embodiments given below, serve to explain the principles of the disclosure.

[0052] These and other features of the present invention will become apparent from the following description of the preferred forms of the embodiments, given by way of non-limiting example with reference to the accompanying drawings.

[0053] It should also be understood that although the present invention has been described with reference to some specific examples, those skilled in the art can surely implement many other equivalent forms of the present invention, which have the features as described in the claims and thus are all within the protection scope defined thereby.

[0054] When taken in conjunction with the accompanying drawings, the above and other aspects, features, and advantages of the present disclosure will become more apparent in view of the following detailed description.

[0055] Specific embodiments of the present disclosure will be described hereinafter with reference to the accompanying drawings; however, it should be understood that the disclosed embodiments are merely examples of the present disclosure, which can be implemented in various ways. Well-known and / or repetitive functions and structures have not been described in detail to avoid obscuring the present disclosure with unnecessary or redundant details. Therefore, the specific structural and functional details disclosed herein are not intended to be limiting, but merely as a basis for the claims and a representative basis for teaching those skilled in the art to use the present disclosure in substantially any suitable detailed structure in a variety of ways.

[0056] This specification may use the phrases "in one embodiment", "in another embodiment", "in yet another embodiment", or "in other embodiments", which may each refer to one or more of the same or different embodiments according to the present disclosure.

[0057] Next, embodiments of the present invention will be described in detail with reference to the accompanying drawings.

[0058] As Figure 2 shown, an embodiment of the present invention provides a network access method for an sslvpn client, which is applied to a network server, and the method includes:

[0059] Obtain an sslvpn access request sent by a browser;

[0060] Determine parameter information about the SSLVPN client background program based on the SSLVPN access request;

[0061] Establish a network connection with the SSLVPN client background program based on the parameter information;

[0062] Send the parameter information to the SSLVPN client background program based on the network connection, so that the SSLVPN client background program sends the parameter information to the SSLVPN server, and receive the feedback message from the SSLVPN server, and at the same time send the feedback message to the network server;

[0063] Process the feedback message to generate a response message in the target format;

[0064] Send the response message to the browser to complete the access of the SSLVPN.

[0065] In this embodiment, an SSLVPN module can be constructed in the network server to execute the interaction steps between the browser and the SSLVPN client background program, that is, to connect the two. And the network server can be integrated into the SSLVPN client as a middleware to execute the above steps in this embodiment.

[0066] Based on the disclosure of the above embodiment, the beneficial effects of this embodiment include that by using the network server as the middleware between the SSLVPN client and the SSLVPN server to execute the request interaction between the two, it is possible to avoid building the cumbersome http framework in the existing solution, and the computer client does not need to process the data of the browser, and can directly obtain it based on the network server. Similarly, when interacting with the SSLVPN server, there is no need to process the intermediate data, and it can be handed over to the network server for processing, which greatly reduces the workload. In addition, the network server technology is mature, and compared with the http framework built in the existing solution, the performance is more stable. Therefore, based on the method of this embodiment, it can effectively solve the technical problems that when the computer client of the existing SSLVPN realizes the browser access function, since the http framework is necessary for this function, and this framework is relatively complex to develop and has a large impact on the original client, the processing process is complex, and the client needs to process a large amount of interaction data.

[0067] Further, in this embodiment, when obtaining the SSLVPN access request sent by the browser, it includes:

[0068] The user initiates an SSLVPN access request based on the browser;

[0069] The browser sends the SSLVPN access request to the network server, so that the network server obtains the SSLVPN access request.

[0070] Such as Figure 3As shown, determine parameter information about the SSLVPN client background program based on the SSLVPN access request, including:

[0071] Perform data parsing on the SSLVPN access request;

[0072] Based on the parsing result, determine the communication address and access request parameters of the SSLVPN client background program.

[0073] Establish a network connection with the SSLVPN client background program based on the parameter information, including:

[0074] Establish a TCP connection with the SSLVPN client background program based on the communication address.

[0075] Send the parameter information to the SSLVPN client background program based on the network connection, including:

[0076] Encapsulate the parameter information based on the transport protocol of the network connection;

[0077] Send the encapsulated parameter information to the SSLVPN client background program based on the network connection.

[0078] The SSLVPN client background program sends the parameter information to the SSLVPN server, including:

[0079] The SSLVPN client background program encapsulates the parameter information and then sends it to the SSLVPN server.

[0080] Process the feedback message to generate a response message in the target format, including:

[0081] Construct an HTTP response message based on the feedback message.

[0082] Specifically, in combination with Figure 4 As shown, the user obtains the SSLVPN login page based on the browser, and the SSLVPN server responds to the login page and sends back response information. After the browser receives the response information and determines the connection established with the SSLVPN, it detects whether there is an SSLVPN client background program on the current device. If not, it obtains the SSLVPN client background program package from the SSLVPN server and installs it. If it exists, or after it has been installed, the user can input the username, password, and access request information through the SSLVPN login page of the browser. The browser obtains this information and can send it to the network server (i.e., the web server in the figure), which is located in the user device and can be regarded as a middleware for the interaction between the browser and the SSLVPN client background program.

[0083] In a web server, it is responsible for parsing http data from a browser, encapsulating the data according to the requirements of the sslvpn client background program, and then sending the encapsulated data to the sslvpn client background program.

[0084] The sslvpn client background program interacts with the sslvpn server based on the received data, sends an access request, receives the response result returned by the sslvpn server, and then returns the result to the web server.

[0085] After obtaining the response result returned by the sslvpn client background program, the web server processes the result, constructs an http response message, and finally returns the http response message to the browser to complete the user's sslvpn access.

[0086] Furthermore, to better elaborate on the execution process of the web server, the following is a specific description in combination with Figure 4 :

[0087] As Figure 5 shown, the user initiates an sslvpn access request through a browser, and then the browser sends the request data (here it is http request data) to the local web server (i.e., the web server in the figure). The web server here can be understood as a middleware in the sslvpn system;

[0088] After receiving the http request data, the web server parses the data using its own http framework to obtain the sslvpn access request parameters carried and the communication address of the sslvpn client background program, specifically including the ip, port of the sslvpn virtual gateway, the username, and password of the user;

[0089] According to the framework process of the web server, it enters the newly added sslvpn module. Through this module, it establishes a tcp connection with the sslvpn client background program in combination with the communication address of the sslvpn client background program, and then encapsulates the obtained access request parameters and sends them to the sslvpn client background program based on the tcp connection;

[0090] The sslvpn client background program encapsulates the access data sent by the web server, then initiates an access request to the sslvpn server, that is, sends the encapsulated information to the sslvpn server, receives the information returned by the sslvpn server, and forwards it to the web server at the same time;

[0091] The sslvpn module of the web server constructs the returned result into a response message, and then the http framework of the web server returns the data to the browser to complete the sslvpn access.

[0092] As shown Figure 6 in the figure, another embodiment of the present invention further provides a browser access device 100 for an sslvpn client, which is applied to a network server. The browser access device for the sslvpn client includes:

[0093] An obtaining module, configured to obtain an sslvpn access request sent by a browser;

[0094] A determining module, configured to determine parameter information about an sslvpn client background program based on the sslvpn access request;

[0095] A establishing module, configured to establish a network connection with the sslvpn client background program based on the parameter information;

[0096] A first sending module, configured to send the parameter information to the sslvpn client background program based on the network connection, so that the sslvpn client background program sends the parameter information to an sslvpn server, receives a feedback message from the sslvpn server, and simultaneously sends the feedback message to the network server;

[0097] A processing module, configured to process the feedback message to generate a response message in a target format;

[0098] A second sending module, configured to send the response message to the browser to complete the access to the sslvpn.

[0099] As an optional embodiment, obtaining the sslvpn access request sent by the browser includes:

[0100] A user initiates the sslvpn access request based on the browser;

[0101] The browser sends the sslvpn access request to the network server, so that the network server obtains the sslvpn access request.

[0102] As an optional embodiment, determining the parameter information about the sslvpn client background program based on the sslvpn access request includes:

[0103] Performing data parsing on the sslvpn access request;

[0104] Determining a communication address and access request parameters of the sslvpn client background program based on the parsing result.

[0105] As an optional embodiment, establishing a network connection with the sslvpn client background program based on the parameter information includes:

[0106] Establish a TCP connection with the sslvpn client background program based on the communication address.

[0107] As an optional embodiment, the sending the parameter information to the sslvpn client background program based on the network connection includes:

[0108] Encapsulate the parameter information based on the transport protocol of the network connection;

[0109] Send the encapsulated parameter information to the sslvpn client background program based on the network connection.

[0110] As an optional embodiment, the sslvpn client background program sending the parameter information to the sslvpn server includes:

[0111] The sslvpn client background program encapsulates the parameter information and then sends it to the sslvpn server.

[0112] As an optional embodiment, it is characterized in that the processing the feedback message to generate a response message in a target format includes:

[0113] Construct an http response message based on the feedback message.

[0114] Another embodiment of the present invention further provides a browser access system, including:

[0115] One or more processors;

[0116] A memory configured to store one or more programs;

[0117] When the one or more programs are executed by the one or more processors, the one or more processors implement the above-mentioned network access method of the sslvpn client.

[0118] Furthermore, an embodiment of the present invention further provides a storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the network access method of the sslvpn client as described above. It should be understood that each solution in this embodiment has the corresponding technical effects in the above method embodiment, and will not be elaborated here.

[0119] Furthermore, an embodiment of the present invention further provides a computer program product, the computer program product is tangibly stored on a computer-readable medium and includes computer-readable instructions, and when the computer-executable instructions are executed, at least one processor is caused to execute a device log processing method such as that in the above-mentioned embodiment.

[0120] It should be noted that the computer storage medium of the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable medium can, for example but is not limited to, be an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access storage medium (RAM), a read-only storage medium (ROM), an erasable programmable read-only storage medium (EPROM or flash memory), an optical fiber, a portable compact disk read-only storage medium (CD-ROM), an optical storage medium, a magnetic storage medium, or any suitable combination of the above. In the present invention, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, apparatus, or device. And in the present invention, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which the computer-readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program configured to be used by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: wireless, antenna, optical cable, RF, etc., or any suitable combination of the above.

[0121] In addition, those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage and optical storage, etc.) that contain computer-usable program code.

[0122] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate for implementing in the process Figure 1one or more processes and / or blocks Figure 1 a system of functions specified in one or more blocks

[0123] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including an instruction system that implements the functions specified in the process Figure 1 one or more processes and / or blocks Figure 1 specified in one or more blocks

[0124] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the process Figure 1 one or more processes and / or blocks Figure 1 specified in one or more blocks

[0125] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention also intends to include these changes and modifications therein

[0126] The above embodiments are only exemplary embodiments of the present invention and are not used to limit the present invention. The protection scope of the present invention is defined by the claims. Those skilled in the art can make various modifications or equivalent replacements within the essence and protection scope of the present invention, and such modifications or equivalent replacements should also be regarded as falling within the protection scope of the present invention

Claims

1. A network access method for an SSLVPN client, applied to a network server, characterized in that The method includes: Obtaining an SSLVPN access request sent by a browser; Determining parameter information about the SSLVPN client background program based on the SSLVPN access request; Establishing a network connection with the SSLVPN client background program based on the parameter information; Sending the parameter information to the SSLVPN client background program based on the network connection, causing the SSLVPN client background program to send the parameter information to the SSLVPN server, receiving a feedback message from the SSLVPN server, and simultaneously sending the feedback message to the network server; Processing the feedback message to generate a response message in a target format; the response message in the target format is an HTTP response message; Sending the response message to the browser to complete the access to SSLVPN; wherein, The network server is used to parse the HTTP data from the browser, encapsulate the HTTP data according to the requirements of the SSLVPN client background program, and send the encapsulated data to the SSLVPN client background program.

2. The network access method of the sslvpn client according to claim 1, characterized in that, The obtaining of the SSLVPN access request sent by the browser includes: A user initiating the SSLVPN access request based on the browser; The browser sending the SSLVPN access request to the network server, causing the network server to obtain the SSLVPN access request.

3. The network access method of the sslvpn client according to claim 1, characterized in that, The determining of the parameter information about the SSLVPN client background program based on the SSLVPN access request includes: Performing data parsing on the SSLVPN access request; Determining the communication address and access request parameters of the SSLVPN client background program based on the parsing result.

4. The network access method of the SSLVPN client according to claim 3, characterized in that, The establishing of the network connection with the SSLVPN client background program based on the parameter information includes: Establishing a TCP connection with the SSLVPN client background program based on the communication address.

5. The network access method of the SSLVPN client according to claim 3, characterized in that, The sending of the parameter information to the SSLVPN client background program based on the network connection includes: Encapsulating the parameter information based on the transport protocol of the network connection; Sending the encapsulated parameter information to the SSLVPN client background program based on the network connection.

6. The network access method of the sslvpn client according to claim 1, wherein The sending of the parameter information by the SSLVPN client background program to the SSLVPN server includes: The SSLVPN client background program encapsulating the parameter information and sending it to the SSLVPN server.

7. A network access device for an SSLVPN client, which is applied to a network server, and is characterized in that, The browser access device of the SSLVPN client includes: An obtaining module, used to obtain an SSLVPN access request sent by a browser; A determining module, used to determine parameter information about the SSLVPN client background program based on the SSLVPN access request; An establishing module, used to establish a network connection with the SSLVPN client background program based on the parameter information; A first sending module, configured to send the parameter information to the sslvpn client background program based on the network connection, so that the sslvpn client background program sends the parameter information to the sslvpn server, and receive a feedback message from the sslvpn server, and at the same time send the feedback message to the network server; A processing module, configured to process the feedback message to generate a response message in a target format; the response message in the target format is an http response message; A second sending module, configured to send the response message to the browser to complete the access to the sslvpn; where The network server is configured to parse http data from the browser, encapsulate the http data according to the requirements of the sslvpn client background program, and send the encapsulated data to the sslvpn client background program.

8. A network access system for an SSLVPN client, characterized in that, Comprising: One or more processors; A memory, configured to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the network access method of the sslvpn client according to any one of claims 1-6.

9. A storage medium, characterized in that, A computer program is stored thereon, and when the program is executed by a processor, the network access method of the sslvpn client according to any one of claims 1-6 is implemented.

Citation Information

Patent Citations

  • SSL VPN (Secure Socket Layer Virtual Private Network) authentication method, device and gateway

    CN114070585A

  • SSL VPN resource access method and device

    CN114666186A