A system and method for supporting port sharing and IP binding of WireGuard devices

By supporting port sharing and IP binding of WireGuard devices, the management and security complexity problems caused by limited UDP ports on the server and the device listening to any address are solved, and port saving and multi-tenant support are achieved.

CN117834753BActive Publication Date: 2025-06-27CHINA TELECOM CLOUD TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202311712699.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-13
Publication Date
2025-06-27
Estimated Expiration
2043-12-13

AI Technical Summary

Technical Problem

The existing WireGuard protocol creates a limited UDP port on the server, resulting in a limited number of devices, and the device listens to any address, which makes other applications unable to share ports, increasing management complexity and security policy configuration complexity.

Method used

By supporting port sharing and IP binding of WireGuard devices, multiple WireGuard devices are allowed to share the same listening port, and the device is supported to bind a specific IP address, and enable the SO_REUSEPORT attribute to allow multiple applications to share the port.

Benefits of technology

Save a large number of UDP ports, reduce management complexity and security policy configuration complexity, avoid the problem that other applications cannot share ports, and meet the multi-tenant and high-availability needs of WireGuard devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117834753B_ABST
    Figure CN117834753B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of computer network security and network communication technologies, and is a system and method for supporting port sharing and IP binding of WireGuard devices. The specific method includes: S1: The WireGuard driver provides a Netlink interface to the management tool or application to configure the IP address and SO_REUSEPORT; create a UDP socket according to the configured listening port, configure a unique identifier WNI for the WireGuard device, and associate multiple WireGuard devices with the UDP socket; the sender sends the encrypted and encapsulated packets to the peer through the UDP socket; when the receiver receives the packets on the UDP socket, it obtains the WiregGuard device from the UDP socket and delivers the packets to the WiregGuard device for decapsulation and decryption processing. The present invention solves the problems of port waste and easy conflict with other applications or services in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of computer network security and network communication, and is a system and method that supports port sharing and IP binding of WireGuard devices. Background Art

[0002] WireGuard is a modern, high-performance, and secure VPN protocol. Compared with traditional VPN protocols (such as OpenVPN and IPsec), WireGuard has the following advantages: High performance: WireGuard uses the latest encryption algorithms and a more lightweight protocol design, making it have higher performance and lower latency, which enables WireGuard to perform excellently on high-speed networks and low-power devices. Security: WireGuard uses the most advanced encryption algorithms (such as ChaCha20, Poly1305, Curve25519, etc.), and also adopts various security measures (such as integrity checks, key rotation, etc.) to ensure the security and reliability of VPN connections; in addition, the WireGuard protocol design is simple, avoiding many security vulnerabilities. Easy to use: The WireGuard protocol design is simple, with less implementation code volume, and is easy to deploy and maintain. At the same time, WireGuard also provides a set of easy-to-use command-line tools and APIs, enabling users to easily create and manage VPN connections. Cross-platform support: WireGuard supports multiple operating systems such as Linux, Windows, macOS, iOS, Android, etc., and can run on various types of devices, including embedded devices, routers, servers, etc.

[0003] In the existing publicly disclosed invention technologies, for example, the patent with the application publication number CN114285697A discloses a multi-network single-entry VPN system based on WireGuard and OpenVPN. The system is as follows: Users access through OpenVPN for single-entry access, create a tunnel through Wireguard at the third layer of the network to connect different networks. User traffic is transmitted from the tun0 network interface of OpenVPN through the SSL secure tunnel to the VPN gateway, the data packets are filtered by nftables and forwarded to the network interface of Wireguard, and the data is sent to the destination network through the tunnel, and the Lightweight Directory Access Protocol LDAP protocol is used to authenticate and control access permissions for enterprise-level users.

[0004] For another example, the patent with the application publication number CN115225493A discloses the configuration generation of a networking node based on WireGuard. The UI platform end in the WireGuard network responds to the operation of the maintenance personnel on the operation interface to update the topology structure of the networking node in the WireGuard network, obtains the change result, and sends a change request carrying the change result to the central control server; the central control server calls the target configuration generation policy corresponding to the change type, determines at least one target networking node in the WireGuard network that is associated with the change result, generates the latest WireGuard configuration information, and sends it to at least one target networking node respectively, so that each of the target networking nodes updates its own WireGuard configuration information according to the latest WireGuard configuration information.

[0005] The WireGuard protocol in the above patent is an end-to-end connection implemented through the UDP protocol. A WireGuard device will create two UDP sockets (IPv4 and IPv6), and the listening port of the UDP socket can be specified, or a kernel can randomly select an available port, while the listening address (IP address) is any address (i.e., the all-zero address, 0.0.0.0 for IPv4 and :: for IPv6), which has the problems described in the background art. Summary of the Invention

[0006] The purpose of this part is to outline some aspects of the embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this part, as well as in the abstract and title of the present application, to avoid obscuring the purpose of this part, the abstract, and the title of the invention, but such simplifications or omissions shall not be used to limit the scope of the present invention.

[0007] The current WireGuard protocol is an end-to-end connection implemented through the UDP protocol. A WireGuard device will create two UDP sockets (IPv4 and IPv6), and the listening port of the UDP socket can be specified, or a kernel can randomly select an available port, while the listening address (IP address) is any address (i.e., the all-zero address, 0.0.0.0 for IPv4 and :: for IPv6). This brings two problems:

[0008] 1. When more and more WireGuard devices are created on a server, more and more UDP ports will be occupied. Since there are at most 65535 available UDP ports, it limits that a server can create at most 65535 WireGuard devices (without considering the scenario of network namespace). At the same time, since each WireGuard device needs to exclusively occupy a UDP port, it is necessary to manage UDP ports well to avoid the devices from malfunctioning due to UDP port conflicts, which increases the complexity of the management aspect. On the other hand, too many ports also make it difficult to set security policies, and security policies need to be configured for each port.

[0009] 2. The WireGuard device listens on any address and does not enable port reuse (SO_REUSEPORT). Therefore, other applications cannot listen on the ports listened by the WireGuard device. For example, if the listening port configured for the WireGuard device is 12345, then other applications cannot listen on UDP port 12345 at any IP address. This will affect the availability of other applications or services.

[0010] The technical problems to be solved by the present invention are the following three problems in the prior art:

[0011] 1. Support port sharing for WireGuard devices, where multiple WireGuard devices share the same listening port, that is, support multiple WireGuard devices to create only two UDP sockets (IPv4 and IPv6), saving ports.

[0012] 2. Support IP binding for WireGuard devices, that is, support WireGuard devices to listen on a specific IP address in addition to any address, such as 127.0.0.1 (IPv4) and 2001::1 (IPv6), etc., to avoid conflicts with other applications or services.

[0013] 3. Support the WireGuard device to enable SO_REUSEPORT (port reuse) for the created UDP socket, that is, allow the WireGuard device and other applications / services to listen on the same port simultaneously when both enable SO_REUSEPORT, where one listens on any address and the other listens on a specific IP address. For example, WireGuard listens on 127.0.0.1:12345 and the gateway service listens on 0.0.0.0:12345.

[0014] To achieve the above object, the technical solution of a method for supporting port sharing and IP binding of WireGuard devices according to the present invention includes the following steps:

[0015] S1: The WireGuard driver provides a Netlink interface to the management tool or application to configure the IP address and SO_REUSEPORT;

[0016] S2: Create a UDP socket according to the configured listening port, configure a unique identifier WNI for the WireGuard device, and associate multiple WireGuard devices with the UDP socket;

[0017] S3: The sender sends the encrypted and encapsulated packet to the peer through the UDP socket;

[0018] S4: When the receiver receives a packet on the UDP socket, obtain the WiregGuard device from the UDP socket and deliver the packet to the WiregGuard device for decapsulation and decryption processing;

[0019] In S1, the IP address includes: specific IPv4 and IPv6 listening addresses, combined with port sharing, supporting multiple WireGuard devices to use the same UDP socket;

[0020] S1 includes the following specific steps:

[0021] S11: Perform uniqueness confirmation to ensure that the WNI of the WireGuard device under the same IP address is unique;

[0022] S12: When creating a UDP socket through the WireGuard driver, use the configured IP address;

[0023] S13: Determine the device status. The WireGuard driver provides a Netlink interface to the management tool or application to configure the WireGuard device to determine whether to enable SO_REUSEPORT;

[0024] In S13, the device status is the DOWN state;

[0025] In S13, the determination of whether to enable SO_REUSEPORT includes: when the WireGuard driver creates a UDP socket, determine the enable status of SO_REUSEPORT. If the status is enabled, call the setsockop interface to set SO_REUSEPORT;

[0026] In S3, the sender includes: encapsulate the WNI in the header of the WireGuard packet, and use the lower 16 bits of the Reserved field in the WireGuard protocol header to carry the WNI;

[0027] The receiving party includes: parsing the lower 16 bits of the Reserved field in the WireGuard protocol header to obtain the WNI, and then obtaining the corresponding WireGuard device according to the WNI.

[0028] Specifically, in S2, the UDP socket supports being bound to specific IPv4 and IPv6 addresses.

[0029] Specifically, in S2, the unique identifier of the WireGuard device includes: WireGuard Network Identifier, WNI, where the configuration steps of the WNI are as follows:

[0030] S21: Add a structure, where wg_sock points to a UDP socket and a hash table, and under the hash table are WireGuard devices (referred to as wg_device) sharing the same port (i.e., socket);

[0031] S22: Using wg_sock as a bridge, make wg_device and sock point to wg_sock;

[0032] S23: Find the device through the socket or find the socket through the device to realize the mutual association of multiple WireGuard devices and UDP sockets.

[0033] In addition, a system for supporting port sharing and IP binding of WireGuard devices according to the present invention includes the following modules:

[0034] Configuration module, association module, message sending module, message receiving module;

[0035] The configuration module is provided by the WireGuard driver with a Netlink interface to the management tool or application to configure the IP address and SO_REUSEPORT;

[0036] The association module creates a UDP socket according to the configured listening port, configures the unique identifier WNI for the WireGuard device, and associates multiple WireGuard devices and UDP sockets with each other;

[0037] The message sending module is used for the sender to send the encrypted and encapsulated message to the peer through the UDP socket;

[0038] The message receiving module is used to obtain the WiregGuard device from the UDP socket when the receiving party receives a message through the UDP socket, and deliver the message to the WiregGuard device for decapsulation and decryption processing.

[0039] Compared with the prior art, the technical effects of the present invention are as follows:

[0040] 1. The present invention supports multiple WireGuard devices to use the same listening port, which can save a large number of UDP ports, avoid the situation that other applications or services have no available ports, and reduce the complexity of the management side. On the other hand, it also reduces the complexity of the security policy configuration for opening ports.

[0041] 2. The present invention supports binding a specific IP address to the WireGuard device, avoiding the situation that other applications or services cannot listen on the same port at a specific IP address due to the WireGuard device being bound to an arbitrary address.

[0042] 3. The present invention supports setting the SO_REUSEPORT (port reuse) attribute for the WireGuard device, which allows the WiregGuard device and other applications or services to listen on the same port, and one of them uses an arbitrary address while the other uses a specific address to meet the business requirements. Description of the Drawings

[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. Among them:

[0044] Figure 1 It is a schematic flowchart of a method for supporting port sharing and IP binding of WireGuard devices according to the present invention;

[0045] Figure 2 It is a schematic diagram of the first 4 bytes of the WireGuard protocol message header according to the present invention;

[0046] Figure 3 It is a schematic diagram of the relationship between a socket and a WireGuard device according to the present invention;

[0047] Figure 4 It is a schematic structural diagram of a system for supporting port sharing and IP binding of WireGuard devices according to the present invention. Detailed Embodiments

[0048] To make the above objects, features, and advantages of the present invention more apparent and understandable, the following provides a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification.

[0049] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present invention. However, the present invention may be practiced in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the spirit of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0050] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation manner of the present invention. The appearances of "in one embodiment" in different places in this specification do not all refer to the same embodiment, nor are they separate or selectively exclusive embodiments from other embodiments.

[0051] Embodiment 1:

[0052] As Figure 1 shown, a method for supporting port sharing and IP binding of WireGuard devices according to an embodiment of the present invention, as Figure 1 shown, includes the following specific steps:

[0053] S1: The WireGuard driver provides a Netlink interface to the management tool or application to configure the IP address and SO_REUSEPORT;

[0054] In S1, the IP address includes: specific IPv4 and IPv6 listening addresses. Combining port sharing, it supports multiple WireGuard devices to use the same UDP socket.

[0055] S1 includes the following specific steps:

[0056] S11: Perform uniqueness confirmation to ensure that the WNI of the WireGuard devices under the same IP address is unique;

[0057] S12: When creating a UDP socket through the WireGuard driver, use the configured IP address;

[0058] S13: Determine the device state. The WireGuard driver provides a Netlink interface to the management tool or application to configure the WireGuard device to determine whether to enable SO_REUSEPORT.

[0059] Among them, in S13, the device state is the DOWN state;

[0060] In S13, determining whether to enable SO_REUSEPORT includes: when the WireGuard driver creates a UDP socket, determining the enabling status of SO_REUSEPORT. If the status is enabled, the setsockop interface is called to set SO_REUSEPORT.

[0061] S2: Create a UDP socket according to the configured listening port, configure a unique identifier WNI for the WireGuard device, and associate multiple WireGuard devices with the UDP socket;

[0062] Among them, in S2, the UDP socket supports binding to specific IPv4 and IPv6 addresses.

[0063] In S2, the unique identifier of the WireGuard device includes: WireGuardNetworkIdentifier, WNI. Among them, the configuration steps of the WNI are as follows:

[0064] S21: Add a structure, where wg_sock points to a UDP socket and a hash table. Under the hash table, WireGuard devices sharing the same port (i.e., socket) are hung; (referred to as wg_device);

[0065] S22: Using wg_sock as a bridge, make wg_device and sock point to wg_sock;

[0066] S23: Find the device through the socket or find the socket through the device to realize the association between multiple WireGuard devices and the UDP socket.

[0067] S3: The sender sends the encrypted and encapsulated message to the peer through the UDP socket;

[0068] Among them, as Figure 4 shown, in S3, the sender includes: encapsulating the WNI in the header of the WireGuard message and using the lower 16-bit bits of the Reserved field in the WireGuard protocol header to carry the WNI.

[0069] S4: When the receiver receives the message on the UDP socket, obtain the WiregGuard device from the UDP socket and deliver the message to the WiregGuard device for decapsulation and decryption processing.

[0070] The receiver includes: parsing the lower 16 bits of the Reserved field of the WireGuard protocol header, obtaining the WNI, and then obtaining the corresponding WireGuard device according to the WNI.

[0071] Embodiment 2:

[0072] like Figure 2 , 3 As shown in , 4, a system supporting port sharing and IP binding of WireGuard devices according to an embodiment of the present invention includes:

[0073] The following is a specific embodiment of the present invention, and its application scenario is a security acceleration scenario (such as zero trust combined with CDN acceleration). Figure 4 As an example diagram:

[0074] 1. This embodiment supports multiple tenants. Tenants are distinguished by WNI. The WNI configurations of WireGuard interfaces of different tenants are different. For example, the WNI of tenant 1 is 1 and the WNI of tenant 2 is 2. In this way, multiple tenants can access using the same port, such as port 6666 in the figure. Tenants can be placed in the Network Namespace.

[0075] 2. The edge node may be connected to multiple back-to-source nodes, that is, different back-to-source nodes will be selected for tenants based on the link and the service quality of the back-to-source node. On the other hand, there may be acceleration nodes (or relay nodes) between the edge node and the back-to-source node.

[0076] 3. Each tenant of the edge node creates multiple WireGuard interfaces (the number is related to the number of back-to-source nodes). Taking two back-to-source nodes as an example, three WireGuard interfaces are created (for example, tenant 1 has three interfaces: wg1-0, wg1-1, and wg1-2). One interface is used as a client access, and different tenants are configured with the same listening port (such as 6666); the other two interfaces are used as interfaces for interconnecting with the back-to-source nodes, and different interfaces are configured with different listening ports (such as 8888 and 9999). In this way, the required UDP port is independent of the number of tenants, which saves a lot of ports.

[0077] 4. The back-to-source node is similar to the edge node. WNI is used to distinguish tenants. Different tenants use the same UDP port to communicate with the edge node.

[0078] 5. Taking tenant 1 as an example, a complete user access process is described as follows:

[0079] (1) The client initiates a request. When the client encapsulates the WireGuard message, it carries a WNI of 1 and a UDP destination port of 6666.

[0080] (2) When the message arrives at the edge node, after being processed by the kernel protocol stack, it is processed by the UDP socket with port number 6666. The WNI is parsed as 1, and according to the WNI, it is found (see Appendix Figure 2 ) wg1-0, so it is delivered to wg1-0 for processing. The WireGuard driver performs operations such as decapsulation and decryption of the message, and then continues to deliver it to the kernel protocol stack for processing. After that, the application (such as a security gateway or a CDN gateway) performs relevant security or data processing, and then routes it to the corresponding WireGuard interface for forwarding according to the selected origin node. For example, it is handed over to the wg1-1 interface.

[0081] (3) After the message is routed to the wg1-1 interface, the wg1-1 interface will perform encryption and encapsulation of the message. The WNI is set to 1, the outer UDP destination port is 8888, and the message is sent to the origin node using the UDP socket with port number 8888.

[0082] (4) After the origin node receives the message, it is first processed by the UDP socket with port number 8888. After parsing the WNI, it is delivered to the corresponding interface for processing according to the WNI after finding the WireGuard interface. Then, the WireGuard driver performs decryption and decapsulation processing on the message and delivers it to the kernel protocol stack for continued processing. Finally, after the application receives the data and resends it to the source station, the source station processes it.

[0083] (5) The response message from the source station also passes through the origin node, then the edge node, and finally reaches the client.

[0084] 6. As needed, a listening address can be configured for the WireGuard interface. For those using the same socket, the same listening address needs to be configured. At the same time, SO_REUSEPORT (port multiplexing) can also be enabled.

[0085] It should be understood that in various embodiments of the present application, the magnitude of the sequence numbers of the above processes does not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0086] It should be understood that determining B according to A does not mean determining B only according to A, but also B can be determined according to A and / or other information.

[0087] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions according to the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired network or / and a wireless network. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.

[0088] Those of ordinary skill in the art will realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed in the present invention can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0089] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be repeated here.

[0090] In several embodiments provided by the present invention, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of units is only one way, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings, direct couplings, or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms.

[0091] The unit described as a separation component may or may not be physically separated. The component displayed as a unit may or may not be a physical unit, that is, it may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0092] In addition, each functional unit in various embodiments of the present invention may be integrated into a processing unit, may exist physically separately for each unit, or two or more units may be integrated into one unit.

[0093] In the description of this specification, the description with reference to terms such as "one embodiment", "example", "specific example", etc. means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0094] In summary of the above embodiments, compared with the prior art, the technical effects of the present invention are as follows:

[0095] 1. The present invention supports multiple WireGuard devices to use the same listening port, which can save a large number of UDP ports, avoid the situation that other applications or services have no available ports, and reduce the complexity of the management plane. On the other hand, it also reduces the complexity of the security policy configuration for port opening.

[0096] 2. The present invention supports the WireGuard device to bind a specific IP address, avoiding the situation that other applications or services cannot listen on the same port at a specific IP address due to the WireGuard device binding an arbitrary address.

[0097] 3. The present invention supports the WireGuard device to set the SO_REUSEPORT (port reuse) attribute, which allows the WiregGuard device and other applications or services to listen on the same port, and one of them uses an arbitrary address and the other uses a specific address to meet the business requirements.

[0098] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments. The above embodiments and the descriptions in the specification only illustrate the principles of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of the present invention claimed is defined by the appended claims and their equivalents.

Claims

1. A method for supporting port sharing and IP binding of WireGuard devices, characterized in that: The method includes the following specific steps: S1: The WireGuard driver provides a Netlink interface to the management tool or application to configure the IP address and SO_REUSEPORT; S2: Create a UDP socket according to the configured listening port, configure a unique identifier WNI for the WireGuard device, and associate multiple WireGuard devices with the UDP socket; S3: The sender sends the encrypted and encapsulated packets to the peer through the UDP socket; S4: When the receiver receives the packets on the UDP socket, obtain the WiregGuard device from the UDP socket, and deliver the packets to the WiregGuard device for decapsulation and decryption processing; In S1, the IP address includes: specific IPv4 and IPv6 listening addresses, combined with the port sharing; S1 includes the following specific steps: S11: Perform uniqueness confirmation to ensure that the WNI of the WireGuard device under the same IP address is unique; S12: When creating a UDP socket through the WireGuard driver, use the configured IP address; S13: Determine the device state. The WireGuard driver provides a Netlink interface to the management tool or application to configure the WireGuard device to determine whether to enable SO_REUSEPORT; In S13, the device state is the DOWN state; In S13, the determination of whether to enable SO_REUSEPORT includes: when the WireGuard driver creates a UDP socket, determine the enabling state of SO_REUSEPORT. If the state is enabled, call the setsockop interface to set SO_REUSEPORT; In S3, the sender includes: encapsulate the WNI in the header of the WireGuard packet, and use the lower 16 bits of the Reserved field in the WireGuard protocol header to carry the WNI; The receiver includes: parse the lower 16 bits of the Reserved field in the WireGuard protocol header to obtain the WNI, and then obtain the corresponding WireGuard device according to the WNI.

2. The method for supporting port sharing and IP binding of WireGuard devices according to claim 1, characterized in that In S2, the UDP socket supports binding to specific IPv4 and IPv6 addresses.

3. The method for supporting port sharing and IP binding of a WireGuard device according to claim 1, characterized in that, In S2, the unique identifier of the WireGuard device includes: WireGuard NetworkIdentifier, WNI. The configuration steps of the WNI are as follows: S21: Add a structure, where wg_sock points to a UDP socket and a hash table, and the hash table hangs the WireGuard devices sharing the same port; S22: Use wg_sock as a bridge to make wg_device and sock point to wg_sock; S23: Find the device through the socket or find the socket through the device to associate multiple WireGuard devices with the UDP socket.

4. A system for supporting port sharing and IP binding of WireGuard devices, which is implemented based on a method for supporting port sharing and IP binding of WireGuard devices as described in any one of claims 1-3, characterized in that, The system includes the following modules: Configuration module, association module, packet sending module, packet receiving module; The configuration module provides a Netlink interface to the management tool or application by the WireGuard driver to configure the IP address and SO_REUSEPORT; The association module creates a UDP socket according to the configured listening port, configures a unique identifier WNI for the WireGuard device, and associates multiple WireGuard devices with the UDP socket; The packet sending module is used for the sender to send the encrypted and encapsulated packet to the peer through the UDP socket; The packet receiving module is used for the receiver to obtain the WiregGuard device from the UDP socket when receiving the packet on the UDP socket, and deliver the packet to the WiregGuard device for decapsulation and decryption processing.

Citation Information

Patent Citations

  • Multi-network single-inlet VPN system based on WireGuard and OpenVPN

    CN114285697A

  • Networking node configuration generation method and equipment based on wireguide

    CN115225493A

  • Method for multiplexing a plurality of FP data frames of WCDMA Iub interface onto UDP packet

    CN101499893A

  • Connection method and device for Linux server

    CN103746977A