A data transmission method and apparatus
By combining wired and wireless links in a virtual private network and encapsulating dynamic addresses using the GRE protocol, data transmission via wireless links is achieved, solving the problem of scarce fiber optic cable resources at the end point and improving the reliability and speed of data transmission.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2023-01-05
- Publication Date
- 2026-05-12
AI Technical Summary
The scarcity of fiber optic cable resources at the end point makes it difficult to guarantee the reliability of data transmission in virtual private networks.
By combining wired and wireless links through user front-end devices, and using the GRE protocol to encapsulate dynamic source and destination addresses in data packets, data transmission is achieved through the wireless link. Load sharing and backup are performed between the wired and wireless links to ensure reliable data packet transmission.
It improves the reliability and speed of data transmission, solves the problem of scarce optical cable resources at the end, and achieves real-time and highly reliable data transmission without increasing the demand for optical cable resources.
Smart Images

Figure CN116234063B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication, in particular to a data transmission method and device. BACKGROUND
[0002] With the development of digital technology, the demand for accessing the Internet is also increasing, and the demand for transmission in various aspects is constantly improving. Enterprises, hospitals, government departments and the like also build private networks. Since the cost of building a private network with private optical cables and cables is too high and the applicability is low, the technology of building a private virtual private network on a shared network is widely used.
[0003] On this basis, the reliability of data transmission of the virtual private network is most concerned. Usually, the reliability of network transmission is guaranteed by the access of multiple routes at the end. Due to the difficulty of expanding optical cable resources due to planning and construction, the problem of tight end optical cable resources is prone to occur. SUMMARY
[0004] The present application provides a data transmission method and device for solving the problem of tight end optical cable resources.
[0005] To achieve the above purpose, the present application adopts the following technical scheme:
[0006] In a first aspect, the present application provides a data transmission method applied to a first user front-end device in a virtual private network system, the first user front-end device accessing a bearer network through a wired link and a first wireless link, comprising: receiving a data packet sent by a user terminal device, the data packet comprising a static source address and a target address, the static source address pointing to the user terminal device, and the target address pointing to a receiving end of the data packet; determining a target link for transmitting the data packet, the target link being the wired link and / or the first wireless link; in the case that the target link is the first wireless link, encapsulating a dynamic source address and a dynamic target address in the data packet based on a GRE protocol to obtain a wireless transmission data packet; the dynamic source address and the dynamic target address are allocated by a dynamic IP pool of the first wireless link, and respectively point to a starting point and an ending point of the first wireless link; and transmitting the wireless transmission data packet into the bearer network through the first wireless link.
[0007] In the above embodiments, the first user front-end device encapsulates the dynamic source address and dynamic destination address of the first wireless link, as well as the static source address and destination address, into wireless transmission data packets using the GRE protocol. Since virtual private networks (VPNs) require static source addresses to be fixed IPs, while wireless links mostly use dynamically assigned IPs, this method decouples the static source address of the data packet from the dynamic source address of the wireless link. This solves the problem that wireless links use dynamic addresses while VPNs require static addresses, enabling wireless links to also carry VPN data transmission. Introducing wireless links for VPN data transmission further alleviates the problem of limited fiber optic cable resources at the end point.
[0008] In one possible implementation, when the target link is a first wireless link, the above data transmission method further includes: encapsulating data packets into VPN data packets based on a VPN protocol; and encapsulating dynamic source addresses and dynamic destination addresses into data packets based on a GRE protocol to obtain wireless transmission data packets, including: encapsulating dynamic source addresses and dynamic destination addresses into VPN data packets based on a GRE protocol to obtain wireless transmission data packets.
[0009] In one possible implementation, the connection status of the wired link and the first wireless link is detected; the target link for transmitting data packets is determined, including: when both the wired link and the first wireless link are connected normally, the wired link is determined as the target link; when the wired link connection fails and the first wireless link connection is normal, the first wireless link is determined as the target link.
[0010] In one possible implementation, the data transmission method further includes: detecting the connection status of the wired link and the first wireless link; determining the target link for transmitting data packets, including: when both the wired link and the first wireless link are normally connected, determining both the wired link and the first wireless link as the target link.
[0011] In one possible implementation, the data transmission method further includes: when the target link is a wired link and a first wireless link, encapsulating a dynamic source address and a dynamic destination address into a data packet based on the GRE protocol to obtain a wireless transmission data packet; and encapsulating the data packet according to a VPN protocol to obtain a wired transmission data packet; the wired transmission data packet and the wireless transmission data packet have the same data packet identifier; transmitting the wireless transmission data packet to the bearer network via the first wireless link; and transmitting the wired transmission data packet to the bearer network via the wired link.
[0012] In one possible implementation, the above data transmission method further includes: when the target link is a wired link and a first wireless link, encapsulating a dynamic source address and a dynamic destination address into a portion of data packets based on the GRE protocol to obtain a wireless transmission data packet; and encapsulating another portion of data packets according to the VPN protocol to obtain a wired transmission data packet; transmitting the wireless transmission data packet to the bearer network through the first wireless link; and transmitting the wired transmission data packet to the bearer network through the wired link.
[0013] In one possible implementation, the Virtual Private Network system further includes a second user front-end device, which accesses the bearer network via a second wireless link; the first user front-end device and the second user front-end device form a VRRP backup group, having the same virtual IP address and different virtual MAC addresses; the user terminal device is configured with a virtual IP address and a target virtual MAC address, the target virtual address being the virtual MAC address of either the first or second user front-end device; data packets are sent by the user terminal device based on the virtual IP address and the target virtual MAC address to reach either the first or second user front-end device; the data transmission method further includes: updating the target virtual MAC address to the virtual MAC address of the first user front-end device when at least one of the wired link and the first wireless link is connected normally; and sending a notification message to the second user front-end device when both the wired connection and the first wireless link fail, the notification message instructing the second user front-end device to update the target virtual MAC address to the virtual MAC address of the second user front-end device.
[0014] In one possible implementation, detecting the connection status of the wired link and the first wireless link includes: establishing a BFD session between the wired link and the first wireless link, periodically sending and receiving BFD messages; if no BFD message is received from the wired link and / or the first wireless link within the detection time, it is considered that the wired link and / or the first wireless link that has not received a BFD message has experienced a connection failure.
[0015] Secondly, the present invention provides a data transmission device applied to a Virtual Private Network (VPN) system. This data transmission device is communicatively connected to user-end devices within the VPN system and accesses a bearer network via a wired link and a first wireless link. The device includes: a data receiving module for receiving data packets sent by the user-end devices, the data packets including a static source address and a destination address, the static source address pointing to the user-end device and the destination address pointing to the receiving end of the data packet; a link selection module for determining a target link for transmitting the data packets, the target link being a wired link and / or a first wireless link; a data encapsulation module for encapsulating a dynamic source address and a dynamic destination address into a data packet based on the GRE protocol, when the target link is the first wireless link, to obtain a wireless transmission data packet; the dynamic source address and dynamic destination address are allocated by a dynamic IP pool of the first wireless link, and the dynamic source address and dynamic destination address respectively point to the start and end points of the first wireless link; and a data sending module for transmitting the wireless transmission data packet to the bearer network via the first wireless link, when the target link is the first wireless link.
[0016] Thirdly, the present invention provides a Virtual Private Network (VPN) system, including a user terminal device and a first user front-end device. The user terminal device and the first user front-end device are communicatively connected. The first user front-end device accesses the bearer network via a wired link and a first wireless link. The user terminal device is used to send data packets to the first user front-end device. The data packets include a static source address and a destination address. The static source address points to the user terminal device, and the destination address points to the receiving end of the data packets. The first user front-end device is used to receive the data packets sent by the user terminal device. A target link for transmitting the data packets is determined. The target link is a wired link and / or a first wireless link. When the target link is the first wireless link, a dynamic source address and a dynamic destination address are encapsulated in the data packets based on the GRE protocol to obtain wireless transmission data packets. The dynamic source address and the dynamic destination address are allocated by the dynamic IP pool of the first wireless link and point to the start and end points of the first wireless link, respectively. The wireless transmission data packets are transmitted to the bearer network through the first wireless link.
[0017] For a detailed description of the second to third aspects and their various implementations in this application, please refer to the detailed description in the first aspect and its various implementations; and for a detailed description of the beneficial effects of the second to third aspects and their various implementations, please refer to the beneficial effect analysis in the first aspect and its various implementations, which will not be repeated here.
[0018] These or other aspects of this application will become more readily apparent in the following description. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0020] Figure 1 This is a schematic diagram of a system architecture for connecting a user front-end device using the data transmission method of this application embodiment;
[0021] Figure 2 This is a schematic diagram of a system architecture for connecting two user front-end devices using the data transmission method of this application embodiment;
[0022] Figure 3 This is a schematic diagram of the hardware structure of the CPE according to an embodiment of this application;
[0023] Figure 4 This is a flowchart illustrating the data transmission method according to an embodiment of this application;
[0024] Figure 5 This is a schematic diagram illustrating the transmission of different data via a wired link and a first wireless link in an embodiment of this application.
[0025] Figure 6 This is a schematic diagram illustrating the simultaneous transmission of the same data by a wired link and a first wireless link in an embodiment of this application.
[0026] Figure 7 This is a schematic diagram of a data transmission device according to an embodiment of this application. Detailed Implementation
[0027] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0028] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature. In the description of this invention, unless otherwise stated, "a plurality of" means two or more.
[0029] To facilitate understanding of the technical solutions of the embodiments of this application, before introducing the identity authentication method of the embodiments of this application, some of the terms and technologies involved will be briefly introduced as follows.
[0030] Customer Premise Equipment (CPE)
[0031] A CPE (Content Premises Equipment) is a new type of wireless terminal access device. Like a mobile phone, it can obtain mobile network access by inserting a SIM card, directly act as a wired network interface, or convert it into a Wi-Fi signal to provide device connectivity in scenarios such as home or office.
[0032] Generic Routing Encapsulation (GRE)
[0033] GRE is a protocol used to encapsulate packets that use one routing protocol within packets that use another protocol.
[0034] Bidirectional Forwarding Detection (BFD)
[0035] BFD (Bidirectional Forwarding Detection) is a network protocol used to detect faults between two forwarding points, enabling millisecond-level rapid link detection. By working in conjunction with upper-layer routing protocols, BFD can achieve rapid route convergence, ensuring service continuity.
[0036] Virtual Router Redundancy Protocol (VRRP)
[0037] VRRP is a routing protocol that addresses the single point of failure issue that occurs when configuring a static gateway in a local area network.
[0038] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.
[0039] This application provides a data transmission method and apparatus, which can be applied to, for example... Figure 1 The system architecture shown is as follows. This system architecture includes a user terminal device 101 and a first user front-end device 102. The user terminal device 101 and the first user front-end device 102 can communicate, and the user terminal device 102 can access the bearer network through a wired link and / or a wireless link of the first user front-end device 102. For ease of explanation, in this embodiment, the wireless link connected to the first user front-end device 102 is referred to as the first wireless link.
[0040] It should be noted that in the system architecture of this application, the number of user terminal devices 101 and first user front-end devices 102 is not limited, and user terminal devices 101 are connected to at least one first user front-end device 102.Figure 1 The following explanation uses a user terminal device 101 and a first user front-end device 102 as an example.
[0041] In one possible embodiment, the user terminal device 101 can communicate with the first user front-end device 102 and send data packets to the first user front-end device 102.
[0042] The first user front-end device 102 can receive data packets sent by the user terminal device 101 and determine the target link for transmitting the data packet to the bearer network. The target link can be a wired link and / or a first wireless link. The first user front-end device 102 transmits the data packets sent by the user terminal device 101 to the bearer network through the wired link and / or the first wireless link. When the target link is the first wireless link, the first user front-end device 102 can encapsulate the dynamic source address and dynamic destination address into the data packet based on the GRE protocol to obtain a wireless transmission data packet, and then transmit the wireless transmission data packet to the bearer network through the first wireless link.
[0043] Optionally, the first user front-end device 102 may also establish a BFD session on the wired link and / or the first wireless link, and detect the connection status of the connected wired link and / or the first wireless link by sending and receiving BFD messages.
[0044] Optional, such as Figure 2 As shown, in the system architecture of this application, the user terminal device 101 can also be connected to the second user front-end device 112. The second user front-end device 112 and the first user front-end device 102 are two devices with different configurations. The second user front-end device 112 can receive data packets sent by the user terminal device 101, and the second user front-end device can transmit the data packets to the bearer network only through the second wireless link. Specifically, based on the GRE protocol, the dynamic source address and dynamic destination address are encapsulated in the data packet to obtain the wireless transmission data packet, and then the wireless transmission data packet is transmitted to the bearer network through the second wireless link. The first user front-end device 102 can also form a VPPR backup group with the second user front-end device 112, forming a logical routing gateway and sharing a virtual IP address. When the connection status of both the wired link and the first wireless link on the first user front-end device 102 fails, the second user front-end device 112 will refresh the MAC address corresponding to the virtual IP address on the user terminal device 101, causing the user terminal device 101 to send data packets to the second user front-end device 112.
[0045] In some embodiments, the first user front-end device 102 may carry a data transmission method for accessing the bearer network via the user terminal device 101, or a data transmission method for accessing the bearer network via the user terminal device 101 via the controller connected to the first user front-end device 102, which is executed by the controller controlling the first user front-end device 102.
[0046] The user terminal device 101 in this application embodiment can be a network-connected electronic device such as a switch, desktop computer, tablet computer, laptop computer, mobile phone, handheld computer, wearable electronic device, handheld computer, super mobile personal computer, netbook, etc. This application embodiment does not impose any restrictions on this.
[0047] In this embodiment, the first user front-end device 102 and the second user front-end device 112 can be wireless CPE devices or 4G / 5G CPE devices.
[0048] The first user front-end device 102 and the second user front-end device 112 have similar basic hardware structures, both including Figure 3 The electronic device shown includes the following components. Figure 3 Taking the electronic device shown as an example, the hardware structure of the first user front-end device 102 and the second user front-end device 112 will be introduced.
[0049] like Figure 3 As shown, the system includes a Router module and a Modem module. The Router module comprises a user-side transmission interface unit 301, a network-side transmission interface unit 302, a user configuration management unit 303, a routing management unit 304, and a service forwarding unit 305. The Modem module comprises an operation and maintenance center unit 306, an air interface protocol stack processing unit 307, a mid-frequency front-end unit 308, and an antenna feeder processing unit 309. These different modules and units are interconnected.
[0050] User-side transmission interface unit 301 is responsible for data forwarding from WAN (Wide Area Network) to WLAN / LAN (Width Area Network). Together with other modules, it performs DHCP (Dynamic Host Configuration Protocol) and supports at least one IGdps high-speed LAN port, enabling terminal devices to access mobile networks through WLAN-related standards.
[0051] The network-side transmission interface unit 302 is responsible for data forwarding between the 5G network and WLAN / LAN, and supports access via the WLAN port.
[0052] User configuration management unit 303 manages the configuration of user front-end devices through WebUI / TR069 (TechnicalReport-069, TR069 is the communication protocol between CPE and ACS).
[0053] The routing management unit 304 provides the configuration and management of routing information necessary for data forwarding.
[0054] Service forwarding unit 305 forwards service data between the user side and the network side and performs NAT (Network Address Translation).
[0055] Operation and maintenance center unit 306 is responsible for the configuration, maintenance and equipment management of the modem module.
[0056] The air interface protocol stack processing unit 307 is responsible for processing the air interface protocol of the mobile network NSA (5GNon-Standalone Architecture).
[0057] The RF front-end unit 308 is responsible for sampling the baseband signal and RF modulation and demodulation.
[0058] The antenna feeder processing unit 309 is responsible for transmitting and receiving air interface signals, and works with other modules to complete beam alignment.
[0059] It should be pointed out that, Figure 3 The structure shown does not constitute a limitation on the device, except Figure 3 In addition to the components shown, the computing device may include more or fewer components than illustrated, or combine certain components, or have different component arrangements.
[0060] The technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention.
[0061] like Figure 4 As shown, this application provides a data transmission method applied to a first user front-end device 102 in a virtual private network system. The first user front-end device 102 accesses the bearer network through a wired link and a first wireless link, and may include the following steps S401 to S404:
[0062] S401: Receive data packets sent by user terminal device 101. The data packets include a static source address and a destination address. The static source address points to user terminal device 101, and the destination address points to the receiving end of the data packets.
[0063] S402: Determine the target link for transmitting data packets, the target link being a wired link and / or a first wireless link.
[0064] It should be understood that if the user terminal device 101 can use the first user front-end device 102 as a gateway, then all data packets of the user terminal device 101 will be sent through the first user front-end device 102. When using wired link transmission, the user front-end device 102 can be assigned a static gateway address, while the address of the user terminal device 101 is a static IP address under the network segment of the user front-end device 102. This static IP address can be used as the source address for sending data packets, hence it is a static source address.
[0065] S403: When the target link is the first wireless link, based on the GRE protocol, the dynamic source address and dynamic destination address are encapsulated in the data packet to obtain the wireless transmission data packet; the dynamic source address and dynamic destination address are allocated by the dynamic IP pool of the first wireless link and point to the start and end points of the first wireless link, respectively.
[0066] In practice, the first user front-end device 102 first encapsulates the data packets into VPN data packets based on the VPN protocol; then, based on the GRE protocol, it encapsulates the dynamic source address and dynamic destination address into the data packets to obtain wireless transmission data packets.
[0067] For example, based on the GRE protocol, the received data packet is encapsulated by adding a GRE header. On top of this, a data packet header with a dynamic address is added to obtain a wireless transmission data packet. The data packet header with the dynamic address contains a dynamic source address and a dynamic destination address, which point to the start and end points of the first wireless link, respectively.
[0068] S404: Transmit wireless data packets to the bearer network via the first wireless link.
[0069] Generally, the GRE protocol is used to cross different network layer protocols. In this application, the main function of the GRE protocol is to encapsulate data packets with static IP addresses, add a GRE header, and then add dynamic source and destination addresses. This ensures that the source addresses of data packets transmitted via wireless and wired links are the same during data packet transmission.
[0070] In the above embodiments, this application uses the GRE protocol to encapsulate data packets that originally contained static IP addresses into wireless transmission data packets. The dynamic source address and dynamic destination address are located outside the GRE header, pointing to the start and end points of the first wireless link, respectively, and can be used for data transmission within the wireless link. This not only ensures that the data packets still contain static IP addresses but also guarantees that these static IP addresses are invisible during transmission, thus improving security.
[0071] In one possible implementation, the first wireless link is a 5G link.
[0072] In one possible implementation, when the first wireless link is a 5G link, a 5G slice ID is applied for for the user front-end device 102, and a 5QI value (5G QoS Identifier, 5G service quality identifier) is configured to match the data packet transmission volume of the first wireless link.
[0073] By implementing the above methods, configuring the first wireless link with a 5QI value that matches the data packet transmission volume can guarantee the data transmission rate of the first wireless link.
[0074] Optional, such as Figure 5 As shown, when the target link is a wired link and a first wireless link, based on the GRE protocol, the dynamic source address and dynamic destination address are encapsulated in a part of the data packet to obtain a wireless transmission data packet; and, according to the VPN protocol, another part of the data packet is encapsulated to obtain a wired transmission data packet; the wireless transmission data packet is transmitted to the bearer network through the first wireless link; and the wired transmission data packet is transmitted to the bearer network through the wired link.
[0075] Compared with the serial networking method of wired and wireless links in similar technologies, the above-described implementation method enables the wired link and the first wireless link on the first user front-end device 102 to be networked in parallel and send data packets respectively.
[0076] In one possible implementation, when the target link is a wired link and a first wireless link, the received data packets are split using packet-based load balancing or data stream-based load balancing, with some data packets being transmitted to the bearer network via the wired link and some data packets being transmitted to the bearer network via the wireless link.
[0077] In addition, there are other ways to offload data, which are only used as examples in this application and are not specifically limited thereto.
[0078] Optional, such as Figure 6 As shown, when the target link is a wired link and a first wireless link, based on the GRE protocol, the dynamic source address and dynamic destination address are encapsulated in a data packet to obtain a wireless transmission data packet; and, according to the VPN protocol, the data packet is encapsulated to obtain a wired transmission data packet; the wired transmission data packet and the wireless transmission data packet have the same data packet identifier; the wireless transmission data packet is transmitted to the bearer network through the first wireless link; and the wired transmission data packet is transmitted to the bearer network through the wired link.
[0079] For example, the first user front-end device 102 encapsulates data packet 1 and data packet 2 into wireless transmission data packet 1 and wireless transmission data packet 2, and transmits them to the bearer network through the first wireless link. The first user front-end device 102 also encapsulates data packet 1 and data packet 2 into wired transmission data packet 1 and wired transmission data packet 2, and transmits them to the bearer network through the wired link. Both wireless transmission data packet 1 and wired transmission data packet 1 have the identifier "A1", and both wireless transmission data packet 2 and wired transmission data packet 2 have the identifier "A2".
[0080] In one possible embodiment, the destination address in the data packet points to the receiving end of the data packet, and the receiving end receives wireless transmission data packets and / or wired transmission data packets with the same data packet identifier through the bearer network.
[0081] In one possible embodiment, the receiving end receives wireless transmission data packets and / or wired transmission data packets with the same data packet identifier, including: the receiving end receives the first arriving wireless transmission data packet or wired transmission data packet with the same data packet identifier; if the first arriving wireless transmission data packet or wired transmission data packet with the same data packet identifier has a bit error, the receiving end discards the wireless transmission data packet or wired transmission data packet; and then receives the subsequently arriving wireless transmission data packet or wired transmission data packet with the same data packet identifier.
[0082] In the above embodiments, the receiving end can receive two identical data sets, transmitted separately by a wired link and a first wireless link, and these two data sets have the same data identifier. The receiving end can receive the data that arrives first. Compared with data transmission via a single wired link or a first wireless link, the data transmission method of this application can improve the transmission speed.
[0083] Secondly, when the receiving end receives data with bit errors, it can discard the erroneous data and receive the subsequently delivered data as a replacement. Compared to similar technologies that only switch over when the data transmission link reaches a certain bit error rate to ensure transmission accuracy, this application transmits the same data through two data links, further ensuring a higher accuracy rate for the transmitted data.
[0084] In addition, the same data is transmitted through two links, so if either link fails, the transmission will not be interrupted due to link switching.
[0085] Therefore, the data transmission method of this application can meet the needs of real-time and highly reliable data transmission services, improving data transmission speed, ensuring data reliability, and achieving uninterrupted data transmission. More importantly, the data transmission method of this application does not require more optical cable resources; it can improve data transmission reliability by transmitting data packets via wireless links.
[0086] Optionally, before determining the target link for transmitting data packets, the connection status of the wired link and the first wireless link is detected. Determining the target link for transmitting data packets includes: when both the wired link and the first wireless link are connected normally, the wired link is determined as the target link; when the wired link connection is faulty but the first wireless link connection is normal, the first wireless link is determined as the target link.
[0087] For example, if a wired link connection failure is detected, but the first wireless link is functioning normally, the first wireless link is used as the target link. Once the wired link connection is restored, the target link is switched back from the first wireless link to the wired link.
[0088] In the above embodiment, before determining the target link for transmitting data packets, the connection status of the wired link and the first wireless link is detected. Subsequently, the target link for transmitting data packets can be selected based on the connection status of the two links. The wired link is used as the primary target link for transmission, while the first wireless link is used only as a backup target link. This increases the number of transmission paths and avoids relying solely on end-point optical cable resources for data transmission.
[0089] In one possible implementation, a fast rerouting protocol or a tunnel-level 1+1 protection method is used to associate the switching of the target link with the connection status of the wired link and the first wireless link, so that the target link switches between the wired link and the first wireless link.
[0090] The target link switching method described above is only an example. There are other methods besides these, but they are not specifically limited in this application embodiment.
[0091] Optionally, before determining the target link for transmitting data packets, the connection status of the wired link and the first wireless link is detected; determining the target link for transmitting data packets includes: when both the wired link and the first wireless link are connected normally, both the wired link and the first wireless link are determined as the target link.
[0092] For example, if both the wired link and the first wireless link are connected normally, both the wired link and the first wireless link are designated as the target links. If either the wired link or the wireless link experiences a connection failure, the wired link or the first wireless link that is connected normally is designated as the target link. When the connection of the wired link or the wireless link that experienced a connection failure is restored, both the wired link and the first wireless link are again designated as the target links.
[0093] In one possible embodiment, both the wired link and the first wireless link are identified as target links, including: configuring a network link aggregation group on the first user front-end device 102, and configuring the wired link and the first wireless link as active links participating in data transmission in the network link aggregation group.
[0094] It should be understood that the active links in the network link aggregation group are logically the same data link. Each aggregation group uniquely corresponds to a logical interface, that is, the wired link and the first wireless link receive data through the same interface on the first front-end device 102, and the two links are then used as the same logical link for data transmission.
[0095] Through the above implementation, when the user terminal device 101 has a need for increased speed or higher transmission requirements, it can configure a network link aggregation group to simultaneously use wired and wireless links as target links for data transmission. In this way, even when the physical bandwidth of the wired link is limited, by adding a wireless link as the target link for data packet transmission, the bandwidth and speed of data transmission can be expanded, thus meeting the real-time transmission needs of the user terminal device 101.
[0096] In one possible embodiment, the user terminal device 101 or the first user front-end device 102 configures different ECMP (Equal Cost Multi-path) five-tuple hash strategies for different data packets, so that the data packets enter the bearer network through the wired link or the first wireless link and are transmitted in the core network with different routes.
[0097] Through the above implementation methods, the wired link or the first wireless link, and the transmission path of the wired link in the bearer network and the core network, and the transmission path of the first wireless link in the bearer network and the core network, may have different data transmission rates. The user terminal device 101 can select different ECMPs to transmit data packets according to the data packet transmission requirements.
[0098] Optionally, the Virtual Private Network system also includes a second user front-end device 112, which accesses the bearer network via a second wireless link. The first user front-end device 102 and the second user front-end device 112 form a VRRP backup group, having the same virtual IP address and different virtual MAC addresses. The user-end device is configured with a virtual IP address and a target virtual MAC address. The target virtual address is the virtual MAC address of either the first user front-end device 102 or the second user front-end device 112. Data packets are sent by the user-end device based on the virtual IP address and the target virtual MAC address to reach either the first user front-end device 102 or the second user front-end device 112.
[0099] It should be understood that when the first user front-end device 102 and the second user front-end device 112 form a VRRP backup group, the connection status of the wired and wireless links between the associated devices, the first user front-end device 102 and the second user front-end device 112 have the same virtual IP address and different MAC addresses. The user terminal device 101 will use this virtual IP address as the gateway address, and all data packets of the user terminal device 101 will be transmitted through this gateway address.
[0100] In some embodiments, the data transmission method further includes: updating the target virtual MAC address to the virtual MAC address of the first user front-end device 102 when at least one of the wired link and the first wireless link is connected normally; and sending a notification message to the second user front-end device 112 when both the wired link and the first wireless link are faulty, the notification message being used to instruct the second user front-end device 112 to update the target virtual MAC address to the virtual MAC address of the second user front-end device 112.
[0101] When the wired link and / or the first wireless link on the first user front-end device 102 are connected normally, the first user equipment 102 has the highest priority in the VRRP backup group, and has the right to use the virtual IP address and respond to ARP packets (Address Resolution Protocol), while the second user front-end device 102 does not have the right to use the virtual IP address and respond to ARP request packets.
[0102] When user terminal device 101 transmits a data packet to the gateway corresponding to the aforementioned virtual IP address, it sends an ARP request message using the ARP protocol to query the corresponding MAC address through the gateway's virtual IP address. At this time, the first user front-end device 102, which has the highest priority, responds to the ARP request message and acknowledges the user terminal device 101, including its virtual MAC address. When the wired link and / or the first wireless link of the first user front-end device 102 are properly connected, the first user front-end device 102 acts as the default gateway.
[0103] After receiving the virtual MAC address of the first user front-end device 102, the user terminal device 101 will cache the virtual MAC address in the user terminal device 101. Thereafter, data packets from the user terminal device 101 will be addressed to the first user front-end device 102 based on the virtual IP address of the gateway and the virtual MAC address of the first user front-end device 102.
[0104] When both the wired and wireless links on the first user front-end device 102 experience connection failures, the first user front-end device 102 will lower its priority and send a VRRP message with reduced priority to the second user front-end device 112. At this time, the second user front-end device 112 has the highest priority and gains the right to use the gateway's virtual IP address, while the first user front-end device 102 loses its right to use the gateway's virtual IP address. The second user front-end device 112 will then send a gratuitous ARP message to the user terminal device 101, refreshing the MAC address corresponding to the gateway's virtual IP address on the user terminal device 101, and modifying the virtual MAC address of the first user front-end device 102 to the virtual MAC address of the second user front-end device 112. Afterwards, data packets from the user terminal device 101 will be addressed to the second user front-end device 112 based on the gateway's virtual IP address and the second user front-end device 112's virtual MAC address.
[0105] Through the above embodiments, a VRRP backup group is established between the first user front-end device 102 and the second user front-end device 112, with the first user front-end device 102 as the primary transmission device and the second user front-end device 112 as the backup transmission device.
[0106] When both the wired link and the first wireless link on the first user front-end device 102 fail, the data packets are redirected to the second user front-end device 112 by refreshing the MAC address corresponding to the virtual IP address of the gateway on the user device 101, thereby achieving device-level transmission link switching.
[0107] In this way, even if both the wired link and the first wireless link of the first user front-end device 102 fail, the second wireless link on the second user front-end device 112 can still transmit data. Therefore, this application adds device-level transmission protection on top of the link-level protection on the first user front-end device 102, further ensuring the reliability of data transmission. It also meets the requirement of dual-route access at the end.
[0108] In one possible implementation, when at least one of the wired link and the first wireless link is connected, the second wireless link of the second user front-end device may be in a connected state or an idle state.
[0109] For example, the second wireless link on the second user front-end device 112 can remain continuously connected, as a connected state. Alternatively, the second user front-end device 112 can periodically send heartbeat signal data packets through the second wireless link to maintain the connection to the second wireless link, as an idle state.
[0110] In the above implementation, the second wireless link remains connected, but can respond to link switching more quickly when both the wired link and the first wireless link fail, thus better ensuring the reliability of data transmission. When the second wireless link remains idle, it consumes less bandwidth. The user device can choose between these two states to strike a balance between different reliability requirements and wireless link bandwidth consumption.
[0111] Optionally, the connection status of the wired link and the first wireless link is detected, including: establishing a BFD session between the wired link and the first wireless link, periodically sending and receiving BFD messages; if no BFD message is received on the wired link and / or the first wireless link within the detection time, it is considered that the wired link and / or the first wireless link that did not receive the BFD message has a connection failure.
[0112] The data transmission method provided in this application supports user terminal device 101 to access a virtual private network via a wired link or a first wireless link from user front-end device 102. Wireless link access is convenient and does not require end-point optical cables, thus solving the problem of scarce optical cable resources.
[0113] In the data packets transmitted on the first wireless link, in accordance with the GRE protocol, they have a dynamic address required for wireless link transmission, as well as a static source address in the inner layer, satisfying the requirement that the source address for data transmission in a virtual private network should be a static address.
[0114] Simultaneously, the first wireless link and the wired link are networked serially, each ensuring its own data transmission. Under this premise, the wireless link can serve as a backup link for the wired link, or as a data transmission link as needed. This ensures uninterrupted data transmission on the wired link and can also increase bandwidth and transmission rate as required. The first wireless link can also transmit the same data as the wired link, thereby improving the reliability of data transmission. This approach addresses the issue of limited fiber optic cable at the end point, ensures reliable and uninterrupted data transmission, and meets the data transmission rate requirements of client device 101.
[0115] In addition, the client device 101 can also connect to the second user front-end device 112. The second user front-end device 112 accesses the bearer network only through the second wireless link, serving as a backup device for the first user front-end device 102, and transmits data packets. The second user front-end device 112 meets the dual-route access requirement without requiring an end-point optical cable, providing device-level protection for the data transmission of the client 101.
[0116] like Figure 7 As shown, in some embodiments, the data transmission apparatus provided in this application may include:
[0117] The data receiving module 501 is used to receive data packets sent by the user terminal device. The data packets include a static source address and a destination address. The static source address points to the user terminal device, and the destination address points to the receiving end of the data packets.
[0118] The link selection module 502 is used to determine the target link for transmitting data packets, wherein the target link is a wired link and / or a first wireless link.
[0119] In one possible embodiment, the link selection module 502 is specifically configured to: detect the connection status of the wired link and the first wireless link, and determine the target link for transmitting data packets, including: when both the wired link and the first wireless link are normally connected, determining the wired link as the target link; and when the wired link connection fails but the first wireless link connection is normal, determining the first wireless link as the target link.
[0120] In one possible embodiment, the link selection module 502 is further configured to: detect the connection status of the wired link and the first wireless link, and determine the target link for transmitting data packets, including: when both the wired link and the first wireless link are connected normally, determining both the wired link and the first wireless link as the target link.
[0121] In one possible embodiment, the link selection module 502 is specifically used to: detect the connection status of the wired link and the first wireless link, including: establishing a BFD session between the wired link and the first wireless link, periodically sending and receiving BFD messages; if no BFD message is received from the wired link and / or the first wireless link within the detection time, it is considered that the wired link and / or the first wireless link that has not received the BFD message has a connection failure.
[0122] The data encapsulation module 503 is used to encapsulate the dynamic source address and dynamic destination address into a data packet based on the GRE protocol when the target link is the first wireless link, so as to obtain a wireless transmission data packet. The dynamic source address and dynamic destination address are allocated by the dynamic IP pool of the first wireless link, and the dynamic source address and dynamic destination address point to the start point and end point of the first wireless link, respectively.
[0123] In one possible embodiment, the data encapsulation module 503 is specifically used for: encapsulating data packets into VPN data packets based on the VPN protocol; and encapsulating dynamic source addresses and dynamic destination addresses into data packets based on the GRE protocol to obtain wireless transmission data packets, including: encapsulating dynamic source addresses and dynamic destination addresses into VPN data packets based on the GRE protocol to obtain wireless transmission data packets.
[0124] The data encapsulation module 503 is further configured to: encapsulate the dynamic source address and dynamic destination address into a data packet based on the GRE protocol, when the target link is a wired link and a first wireless link, to obtain a wireless transmission data packet; and encapsulate the data packet according to the VPN protocol to obtain a wired transmission data packet; the wired transmission data packet and the wireless transmission data packet have the same data packet identifier, and the wireless transmission data packet is transmitted to the bearer network through the first wireless link; and the wired transmission data packet is transmitted to the bearer network through the wired link.
[0125] The data transmission module 504 is used to transmit wireless data packets to the bearer network through the first wireless link when the target link is the first wireless link.
[0126] In one possible embodiment, the data transmission module 504 is further configured to: transmit wireless transmission data packets to the bearer network via a first wireless link; and transmit wired transmission data packets to the bearer network via a wired link.
[0127] In one possible embodiment, the data transmission apparatus further includes a VRRP backup module 505, used to update the target virtual MAC address to the virtual MAC address of the first user front-end device when at least one of the wired link and the first wireless link is functioning normally. The first user front-end device and the second user front-end device form a VRRP backup group, having the same virtual IP address and different virtual MAC addresses. The user terminal device is configured with a virtual IP address and a target virtual MAC address, where the target virtual address is the virtual MAC address of either the first or second user front-end device. Data packets are sent by the user terminal device based on the virtual IP address and the target virtual MAC address to reach either the first or second user front-end device.
[0128] In one possible embodiment, the VRRP backup module 505 is further configured to: send a notification message to the second user front-end device when both the wired connection and the first wireless link fail, the notification message instructing the second user front-end device to update the target virtual MAC address to the virtual MAC address of the second user front-end device.
[0129] In some embodiments, a virtual private network system provided in this application may include:
[0130] The user terminal equipment and the first user front-end equipment are connected in communication. The first user front-end equipment accesses the bearer network through a wired link and a first wireless link.
[0131] The user terminal device is used to send data packets to the first user front-end device. The data packets include a static source address and a destination address. The static source address points to the user terminal device, and the destination address points to the receiving end of the data packets.
[0132] The first user front-end device receives data packets sent by the user terminal device; determines the target link for transmitting the data packets, which is a wired link and / or a first wireless link; if the target link is the first wireless link, it encapsulates the dynamic source address and dynamic destination address into the data packet based on the GRE protocol to obtain a wireless transmission data packet; the dynamic source address and dynamic destination address are allocated by the dynamic IP pool of the first wireless link and point to the start and end points of the first wireless link, respectively. The wireless transmission data packet is then transmitted to the bearer network through the first wireless link.
[0133] This application also provides a computer-readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps in the above method embodiments.
[0134] The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a readable storage medium (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), registers, hard disks, optical fibers, compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing, or any other form of readable storage medium in the art. An exemplary storage medium is coupled to a processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium may also be a component of the processor. The processor and the storage medium may reside in an application-specific integrated circuit (ASIC). In the embodiments of this application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0135] An embodiment of this application provides a computer program product stored in a non-volatile storage medium, which is executed by at least one processor to implement the steps shown in the above method embodiments.
[0136] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be entirely or partially in the form of a computer program product. This computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a readable storage medium or transmitted from one readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, Digital Subscriber Line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state drives (SSDs)).
[0137] Through the above description of the embodiments, those skilled in the art will clearly understand that, for the sake of convenience and brevity, only the division of the above functional units is used as an example. In practical applications, the above functions can be assigned to different functional units as needed, that is, the internal structure of the device can be divided into different functional units to complete all or part of the functions described above. The specific working process of the system, device and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0138] Since the devices, readable storage media, and computer program products in the embodiments of this application can be applied to the above methods, the technical effects they can achieve can also be referred to the above method embodiments. The embodiments of this application will not be repeated here.
[0139] It should be noted that the above-mentioned units can be separate processors, or they can be integrated into a processor of the controller. Alternatively, they can be stored in the controller's memory as program code, and called and executed by a processor of the controller. The processor mentioned here can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of this application.
[0140] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0141] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0142] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0143] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling, direct coupling, or communication connections shown or discussed may be implemented through interfaces, and these interface connections may be electrical, mechanical, or other forms.
[0144] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0145] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.
[0146] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A data transmission method, characterized in that, A first user front-end device applied in a virtual private network system, the first user front-end device accessing the bearer network via a wired link and a first wireless link, the method comprising: The system receives data packets sent by a user terminal device. The data packets include a static source address and a destination address. The static source address points to the user terminal device, and the destination address points to the receiving end of the data packets. The first wireless link only supports dynamic source addresses, so the data packets cannot be transmitted to the bearer network through the first wireless link. Determine the target link for transmitting the data packet, wherein the target link is the wired link and / or the first wireless link; When the target link is the first wireless link, the dynamic source address and dynamic destination address are encapsulated in the data packet based on the GRE protocol to obtain a wireless transmission data packet; the dynamic source address and dynamic destination address are allocated by the dynamic IP pool of the first wireless link and point to the start and end points of the first wireless link, respectively. The wireless data packets are transmitted to the bearer network via the first wireless link.
2. The data transmission method according to claim 1, characterized in that, When the target link is the first wireless link, the method further includes: The data packets are encapsulated into VPN data packets based on the VPN protocol; The method, based on the GRE protocol, encapsulates dynamic source and destination addresses within the data packet to obtain a wireless transmission data packet, including: Based on the GRE protocol, the dynamic source address and dynamic destination address are encapsulated in the VPN data packet to obtain a wireless transmission data packet.
3. The data transmission method according to claim 2, characterized in that, The method further includes: Detect the connection status of the wired link and the first wireless link; Determining the target link for transmitting the data packet includes: When both the wired link and the first wireless link are connected normally, the wired link is identified as the target link; When the wired link connection fails but the first wireless link connection is normal, the first wireless link is identified as the target link.
4. The data transmission method according to claim 2, characterized in that, The method further includes: Detect the connection status of the wired link and the first wireless link; Determining the target link for transmitting the data packet includes: When both the wired link and the first wireless link are connected normally, both the wired link and the first wireless link are identified as the target link.
5. The data transmission method according to claim 4, characterized in that, The method further includes: When the target link is the wired link and the first wireless link, the dynamic source address and dynamic destination address are encapsulated in the data packet based on the GRE protocol to obtain a wireless transmission data packet; and the data packet is encapsulated according to the VPN protocol to obtain a wired transmission data packet; the wired transmission data packet and the wireless transmission data packet have the same data packet identifier; The wireless data packets are transmitted to the bearer network via the first wireless link; and the wired data packets are transmitted to the bearer network via the wired link.
6. The data transmission method according to claim 4, characterized in that, The method further includes: When the target link is the wired link and the first wireless link, based on the GRE protocol, the dynamic source address and the dynamic destination address are encapsulated in a portion of the data packet to obtain a wireless transmission data packet; and, according to the VPN protocol, another portion of the data packet is encapsulated to obtain a wired transmission data packet. The wireless data packets are transmitted to the bearer network via the first wireless link; and the wired data packets are transmitted to the bearer network via the wired link.
7. The data transmission method according to claim 3 or 4, characterized in that, The virtual private network system further includes a second user front-end device, which accesses the bearer network through a second wireless link; the first user front-end device and the second user front-end device form a VRRP backup group, having the same virtual IP address and different virtual MAC addresses; The user terminal device is configured with the virtual IP address and the target virtual MAC address, wherein the target virtual address is the virtual MAC address of the first user front-end device or the second user front-end device. The data packet is sent by the user terminal device according to the virtual IP address and the target virtual MAC address to reach the first user front-end device or the second user front-end device; the method further includes: When at least one of the wired link and the first wireless link is connected normally, the target virtual MAC address is updated to the virtual MAC address of the first user front-end device; When both the wired connection and the first wireless link fail, a notification message is sent to the second user front-end device. The notification message is used to instruct the second user front-end device to update the target virtual MAC address to the virtual MAC address of the second user front-end device.
8. The data transmission method according to claim 3 or 4, characterized in that, The detection of the connection status between the wired link and the first wireless link includes: A BFD session is established between the wired link and the first wireless link, and BFD messages are sent and received periodically. If no BFD message is received from the wired link and / or the first wireless link within the detection time, it is considered that the wired link and / or the first wireless link that did not receive the BFD message has a connection failure.
9. A data transmission device, characterized in that, The data transmission device is applied to a virtual private network (VPN) system. The data transmission device is communicatively connected to user terminal equipment within the VPN system and accesses the bearer network via a wired link and a first wireless link, comprising: The data receiving module is used to receive data packets sent by the user terminal device. The data packets include a static source address and a destination address. The static source address points to the user terminal device, and the destination address points to the receiving end of the data packets. The first wireless link only supports dynamic source addresses, so the data packets cannot be transmitted to the bearer network through the first wireless link. A link selection module is used to determine a target link for transmitting the data packet, wherein the target link is a wired link and / or a first wireless link; The data encapsulation module is used to encapsulate the dynamic source address and dynamic destination address into the data packet based on the GRE protocol when the target link is the first wireless link, so as to obtain a wireless transmission data packet; the dynamic source address and dynamic destination address are allocated by the dynamic IP pool of the first wireless link and point to the start and end points of the first wireless link, respectively. The data transmission module is used to transmit the wireless data packet to the bearer network through the first wireless link when the target link is the first wireless link.
10. A Virtual Private Network system, characterized in that, It includes a user terminal device and a first user front-end device, wherein the user terminal device is communicatively connected to the first user front-end device, and the first user front-end device accesses the bearer network through a wired link and a first wireless link; The user terminal device is used to send data packets to the first user front-end device. The data packets include a static source address and a destination address. The static source address points to the user terminal device, and the destination address points to the receiving end of the data packets. The first user front-end device is used to receive data packets sent by the user terminal device; Determine the target link for transmitting the data packet, wherein the target link is the wired link and / or the first wireless link; When the target link is the first wireless link, the dynamic source address and dynamic destination address are encapsulated in the data packet based on the GRE protocol to obtain a wireless transmission data packet; the dynamic source address and dynamic destination address are allocated by the dynamic IP pool of the first wireless link and point to the start and end points of the first wireless link, respectively; the wireless transmission data packet is transmitted to the bearer network through the first wireless link.