A VPN networking method and system for redirecting external network access data

By setting up a VPN router in the VPN network and setting the network exit of the terminal device as the router, the problem that the existing technology cannot effectively count all data traffic of the network member equipment is solved, and the complete function use of member equipment in the network is realized and data traffic statistics are improved, and the speed, security and flexibility of data transmission are improved.

CN118523981BActive Publication Date: 2025-06-06SHANGHAI BEIRUI INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410791651.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-19
Publication Date
2025-06-06
Estimated Expiration
2044-06-19

AI Technical Summary

Technical Problem

The existing VPN networking technology cannot effectively count all data traffic of network member devices. In the Android system, if the VPN program intercepts external network access data, if there is no forwarding server, the data will not be sent and the device cannot access the Internet.

Method used

By setting up a VPN router for forwarding data in the network, setting the network exit of the terminal device as the VPN router, all traffic data can be circulated through the VPN router, realizing redirection to the external network to access data to the VPN network, supporting the complete use of the networking function of member devices within the network, and facilitating the statistics of data traffic.

Benefits of technology

It realizes the complete function of member equipment in the network, facilitates statistics of all data traffic, improves data transmission speed and security, and improves the flexibility and reliability of data transmission when setting up routers in different regions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118523981B_ABST
    Figure CN118523981B_ABST
Patent Text Reader

Abstract

A VPN networking method and system for redirecting external network access data includes the following steps: establishing a networking environment: at a networking control end, at least one VPN router supporting a network forwarding function and at least one terminal device that are not in the same network are added to the same VPN networking through VPN technology; enabling a unified network exit function: after setting the network exit of the terminal device to the VPN router at the networking control end, restarting the VPN networking program, the VPN networking program receives all network data traffic on the terminal device according to the configuration information, and circulates within the network according to the flow direction of the traffic or forwards it to the set VPN router through the VPN networking program, and then forwarded by the VPN router. The present invention can redirect all external network access data to the VPN networking, support member devices within the networking to fully use the networking function, and conveniently count the data traffic usage of members within the networking.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of VPN networking, and in particular to a VPN networking method and system for redirecting external network access data. Background Art

[0002] VPN uses the public network to build a private network. The user's data is transmitted through the logical tunnel (Tunnel) established by the ISP in the public network (Internet), that is, a point-to-point virtual private line. The corresponding encryption and authentication technology is used to ensure the safe transmission of the user's internal network data on the public network, thereby truly realizing the exclusivity of network data. VPN can simulate a point-to-point private connection to send data between two computers through a shared or public network, which can help users achieve remote access and establish a reliable point-to-point connection.

[0003] Currently, VPN networking is enabled by turning on VPN, and in the process of enabling networking, the routes of other members in the network will be added to the routing table of the device VPN. In this way, the data traffic on the devices of the networking members will only flow through this networking environment if it is in these routing tables. As for the data traffic in other non-routing tables, it cannot flow through the networking environment. This may result in: first, the networking members cannot use the complete networking functions, and second, the administrator cannot count all the data traffic of the devices of the networking members. In addition, in the Android system, when the VPN program intercepts external network access data, if there is no corresponding forwarding server, the data cannot be sent out, and the entire device cannot access the Internet. Summary of the invention

[0004] The purpose of the present invention is to overcome the shortcomings of the above-mentioned prior art and provide a VPN networking method for redirecting external network access data. The method can change the network access data outside the VPN networking on terminal devices such as mobile phones from direct access to access through the communication channel within the networking and then forwarded by the router, so that members within the networking can fully use the networking function and conveniently count all data traffic of members. The present invention also provides a VPN networking system for implementing the above-mentioned method.

[0005] The present invention is achieved through the following technical solutions:

[0006] A VPN networking method for redirecting external network access data includes the following steps:

[0007] S1. Establishing a networking environment: At the networking control end, at least one VPN router supporting network forwarding function and at least one terminal device are added to the same VPN networking through the VPN service end by using VPN technology, the terminal device is installed with a VPN networking program, and the VPN router is embedded with a corresponding VPN networking program. The terminal device and the VPN router can be in the same network or in different networks.

[0008] S2. Enable the unified network exit function: After the network exit of the terminal device is set to one of the VPN routers at the networking control end, the terminal device restarts the VPN networking program thereon. The VPN networking program receives all network data traffic on the terminal device by adding an open route according to the configuration information, and circulates the traffic within the network according to the flow direction or forwards it to the set VPN router through the VPN networking program, and then forwards it by the VPN router, completing the unified network exit function and facilitating the statistics of the traffic of each terminal device.

[0009] Furthermore, when the VPN networking program receives all network data traffic on the terminal device in step S2, it also includes: establishing an MQTT long connection, and monitoring changes in network exit configuration information in real time through the MQTT long connection. If a change in the network exit configuration information is detected, the VPN connection is disconnected, the VPN networking program is restarted, and an open route is added according to the changed network exit configuration information, all network data traffic on the terminal device is received, and the traffic is forwarded to the newly configured VPN router through the VPN networking program.

[0010] Furthermore, in step S2, the traffic flows in the network or is forwarded to the VPN router through the VPN networking program according to the flow direction of the traffic, and then forwarded by the VPN router, and the method is as follows: the VPN networking program detects whether the forwarded traffic is the traffic within the network, and if it is the traffic within the network, the traffic is forwarded within the network through the VPN server; if it is the traffic outside the network, the members within the VPN network are screened, and the VPN router member information set as the network exit is screened out, and then the data is forwarded to the VPN router member through the communication channel within the VPN network, and then the data forwarding function of the VPN router member forwards the data out.

[0011] Furthermore, it also includes the step of verifying whether the network exit setting is effective, and the method is: capturing packets on the bound VPN router to check whether the network exit setting of the terminal device is effective; or judging whether its network exit setting is effective by querying the IP address of the terminal device. If the IP address is consistent with the VPN router to which it is bound, the network exit setting is assessed to be effective.

[0012] Furthermore, querying the IP address of the terminal device may be performed on a browser of the terminal device.

[0013] Furthermore, step S1 includes: first determining the members who need to be networked; then at the networking control end, adding each networking member according to the SN / UID / SID of the networking member. If the networking member is not in the member list, the networking member is added by adding a member.

[0014] Furthermore, in step S2, the device terminal logs into the VPN networking program using an account and password, and after logging in, it actively queries the configuration information of its network exit.

[0015] Furthermore, the VPN router is bound with an account and password.

[0016] Furthermore, the terminal device is an Android phone or an Android tablet.

[0017] A VPN networking system for redirecting external network access data adopts the VPN networking method for redirecting external network access data, comprising a networking control program, a VPN server, at least one VPN router and at least one terminal device, each of the terminal devices is networked through the VPN server and the networking control program, and each of the terminal devices is installed with a VPN networking program; the networking control program can be installed on a PC, the VPN router is connected to the networking control program, the VPN router is embedded with a corresponding VPN networking program, and has a network forwarding function, and the network exit of the terminal device is set to one of the VPN routers on the networking control program.

[0018] The present invention sets a VPN router for forwarding data in a network, and sets the network exit of a terminal device such as a mobile phone to the VPN router, so that all traffic data of the terminal device flows through the VPN router. Specifically, data in the network flows directly in the network, and data outside the network is forwarded through an exit router, so as to redirect all external network access data outside the VPN network to the VPN network, and supports member devices in the network to fully use the networking function, such as ensuring data security, enjoying the alarm strategy in the network, monitoring the large screen, performing acceleration and speed limiting, limiting the access to the internal network and the external network, and conveniently counting the data traffic usage of all members in the network; at the same time, because the router is not limited to the region, routers can be set in different areas, and after these VPN routers are pulled into the same network, the terminal device can switch the exit to the router at its location at any time, thereby improving the data transmission speed; and because the communication channel in the network supports encryption operation, the data transmission from the terminal device to the router can be transmitted using an encrypted channel, thereby improving the security of data transmission, and the router itself also has a risk identification function, which can play a role in safety warning reminder. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 The figure is a schematic diagram of a networking environment of the present invention.

[0020] Figure 2 It is a schematic diagram of another networking environment of the present invention.

[0021] Figure 3 This is a schematic diagram of VPN networking redirecting external network access data in the present invention.

[0022] Figure 4 This is a schematic diagram of monitoring network egress configuration information according to the present invention.

[0023] Figure 5 This is a diagram showing the operation of networking in an embodiment of the present invention.

[0024] Figure 6 This is a diagram demonstrating the operation of the network egress configuration in an embodiment of the present invention.

[0025] Figure 7 This is another operation demonstration diagram of the network egress configuration in an embodiment of the present invention.

[0026] Figure 8 A schematic diagram of the structure of the VPN networking system of the present invention.

[0027] Fig. 9 Another structural diagram of the VPN networking system of the present invention is shown in FIG.

[0028] Fig.10This is another structural diagram of the VPN networking system of the present invention. DETAILED DESCRIPTION

[0029] A VPN networking method for redirecting external network access data includes the following steps:

[0030] S1. Establishing a networking environment: At the networking control end, VPN technology is used to add at least one VPN router supporting network forwarding function and at least one terminal device to the same VPN networking through the VPN server, so that the networking environment is established.

[0031] like Figure 1 As shown in the figure, a VPN network includes a VPN server, at least one VPN router and a terminal device. The VPN router is used for network forwarding. The router has a corresponding VPN networking program embedded in it and can be added to the VPN network environment as a member. The terminal device can be a mobile phone, tablet, etc. The VPN router and the terminal device can be in the same network or not, but the VPN can realize the interconnection between the devices. The network members can be set according to the actual situation, such as Figure 2 As shown, several mobile phones, PCs and other terminal devices are provided, which can access each other through VPN networking, and can also remotely access resource servers and intranets. The terminal devices are installed with VPN networking programs.

[0032] The specific steps of networking are as follows: determine the members that need to be networked; at the networking control end, add networking members according to their SN / UID / SID. If the networking members are not in the member list, add them by adding members.

[0033] The VPN router is bound to an account, through which the network control terminal can be logged in, and the router can also be found by the account on the network control terminal. The terminal device is also registered with an account and password, through which the VPN networking program can be logged in. After the VPN networking program is started, a virtual IP address in the network will be allocated, and the members in the network can communicate through this virtual IP. In this network, operations such as resource access and sharing can be realized.

[0034] S2. Enable the unified network export function: Perform network configuration on the network control terminal, set the network export of the terminal device to one of the VPN routers. After the configuration is completed, the terminal device restarts the VPN networking program on it, and the device terminal logs in to the VPN networking program with the account and password. After logging in, it will actively query the configuration information of its network export, and receive all network data traffic on the terminal device by adding an open route according to the configuration information, and circulate the traffic within the network or forward it to the set VPN router through the VPN networking program according to the flow direction of the traffic. Figure 3As shown, the VPN router forwards the data. Compared with the general VPN networking which can only count the traffic data within the network but cannot count the data outside the network, the present invention can unify the network exit, and the traffic outside the network will also go on the connection channel within the network, thereby completing the unified network exit function and facilitating the statistics of the traffic of each terminal device.

[0035] If there is only one VPN router in the network, the network exit of all terminal devices in the network can be set to this VPN router; if there are multiple VPN routers in the network, the network exit of each terminal device in the network can be set to any one of these VPN routers according to the situation. If the network where the terminal device is located is already connected to a router, and the network exit of the terminal device is set to another VPN router, then the network flow of the terminal device will first pass through the router of the network where the terminal device is located, and then flow to the VPN router set as the network exit, and finally the data will be forwarded.

[0036] When the VPN networking program receives all network data traffic on the terminal device in step S2, Figure 4 As shown, it also includes: establishing an MQTT persistent connection, and monitoring the changes of its network exit configuration information in real time through the MQTT persistent connection. If the network exit configuration information is detected to be changed, the VPN connection is disconnected, the VPN networking program is restarted, and an open route is added according to the changed network exit configuration information, and all network data traffic on the terminal device is received, and the traffic is forwarded to the newly configured VPN router through the VPN networking program. If there is no change, the VPN networking state is maintained.

[0037] The method for transferring the above data traffic is as follows: the VPN networking program detects whether the forwarded traffic is traffic within the network. If it is traffic within the network, the traffic is forwarded through the VPN server within the network. This process is the same as the data flow direction within the network during conventional VPN networking. If it is traffic outside the network, the members within the VPN network are screened, and the member information set as the network exit is screened out, and then the data is forwarded to the member through the communication channel within the VPN network, and then the data forwarding function on the member forwards the data out.

[0038] After the network exit is set, you can also verify whether the network exit setting is effective by the following methods: (1) Capture packets on the bound VPN router to check whether the network exit setting of the terminal device is effective. (2) Determine whether its network exit setting is effective by querying the IP address of the terminal device. If the IP address is consistent with the VPN router it is bound to, the network exit setting is effective. The IP address of the terminal device can be queried on the browser of the terminal device.

[0039] The following examples illustrate the specific settings and operation steps of the networking control terminal of the present invention, as well as the specific implementation methods of the invention.

[0040] 1. Networking: Figure 5 , there is a "remote networking" menu on the networking control platform interface, under which there is a "network member" option. A member list is displayed in the "network member" card, from which you can view the member's SN / UID / SID number, intranet IP, virtual IP, etc. When a member is not in the list, you can add a member through the "add member" function box on the interface. Members include "hardware members" and "software members". Hardware members refer to routers that can be used to forward data. A VPN network must have at least one hardware member, that is, a VPN router, and software members are terminal devices, such as mobile phones, tablets, etc. Adding these hardware and software to the same network completes the networking.

[0041] The networking control terminal platform only needs to be installed on a PC that can be connected to the Internet. The hardware member VPN router is bound to an account, and the account can be used to log in to the networking control terminal platform to complete the networking on the platform. The software member terminal device has the corresponding VPN networking program installed on it. After registering the account and password, you can log in to the VPN networking program to complete subsequent operations.

[0042] 2. Set the network exit of the software member, specifically, Figure 6 , Figure 7 As shown, on the networking control platform, select the corresponding software member, in the member operation column, select More->Network Exit option, in the pop-up window, select the corresponding VPN router in the "Specify Exit" column, which is also a hardware member of the network, and change the status to open. The terminal device does not need to connect to the network of the router, and can use the 5G network or connect to other Wi-Fi that can access the Internet.

[0043] 3. Software members take mobile phones as an example. They log in to the software members through their account and password on the VPN networking program installed on the mobile phone. After successful login, the software will actively query the configuration information of the network exit.

[0044] 4. Open the VPN networking program on the mobile phone. During the networking process, the mobile phone will check the network exit configuration information. If it detects that the network exit function has been configured, the VPN networking program will add an additional open route when the VPN is created to receive all network data traffic on the mobile device (that is, the traffic generated by all software on the mobile phone). At the same time, the VPN networking program will monitor the changes in the network exit configuration information in real time through the established mqtt long connection. If there are any changes, disconnect the VPN and re-network according to the changed information; if there are no changes, maintain the VPN networking status.

[0045] 5. When the mobile phone sends data, the VPN networking program will detect whether the data is traffic within the network. If it is traffic within the network, it will still be transmitted within the network through the VPN server. If it is traffic outside the network, the VPN members will be screened once, and the router set as the exit will be screened out. Then the data will be forwarded to the router member through the communication channel (forwarding channel, p2p channel) within the network. After that, the data forwarding function on the member will forward the data out. The specific sending process is shown in the figure. In this way, the traffic data used by the mobile phone in any network will be unified and sent out to the router within the network. The network access data outside the VPN network on the mobile phone is changed from direct access to passing through a communication channel within the network and forwarded by the router before access.

[0046] A VPN networking system for redirecting external network access data adopts the VPN networking method for redirecting external network access data, including a VPN router, a terminal device, a networking control program and a VPN server, such as Figure 8 As shown, there is at least one VPN router and terminal device, and it can also be as shown in Figure 2 , Fig. 9 , Fig.10 As shown, it includes multiple VPN routers and multiple terminal devices. Each of the terminal devices is networked through the VPN server and the networking control program. The VPN networking program is installed on each of the terminal devices. The networking control program is set on the networking control terminal. The networking control program can be installed on a PC. The VPN router is connected to the networking control program. The VPN router is embedded with a corresponding VPN networking program, which has a network forwarding function. The network exit of the terminal device is set to one of the VPN routers on the networking control program. The VPN router and the terminal device can be in the same network or in different networks. They only need to be in a network environment. The role of the VPN server is to provide the function of networking control, which can include a server. The VPN server allocates virtual IPs to each member accessing the network through the networking control program to realize the networking function, and realizes the redirection of external network access data through the above method.

[0047] by Figure 2For example, the terminal devices (mobile phones and PCs) in the network are networked through the VPN server. The network also includes the company's intranet and resource servers connected to the network through VPN routers. The resource servers can provide data resources. After the network exit of the terminal device is set to the VPN router in the network, the terminal device (mobile phone and PC) can share the resources provided by the resource server, access the intranet, and access the external network. The data is forwarded between the terminal device and the external network through the VPN router. That is, the data traffic of the external network also goes through the VPN network, and the traffic of the terminal device can be easily counted. At the same time, since both internal and external data go through the network, the terminal device can also enjoy complete networking functions, such as ensuring data security and high data flow rate.

[0048] The above detailed description is a specific description of a feasible embodiment of the present invention. The embodiment is not intended to limit the patent scope of the present invention. Any equivalent implementation or modification that does not deviate from the present invention should be included in the patent scope of this case.

Claims

1. A VPN networking method for redirecting external network access data, characterized in that: The steps include: S1. Establishing a networking environment: At the networking control end, using VPN technology through the VPN server to add at least one VPN router supporting network forwarding function and at least one terminal device to the same VPN networking, wherein the terminal device is installed with a VPN networking program, and the VPN router is embedded with a corresponding VPN networking program; S2. Enable the unified network egress function: After the network egress of the terminal device is set to one of the VPN routers at the networking control end, the terminal device restarts the VPN networking program thereon. The VPN networking program receives all network data traffic on the terminal device by adding an open route according to the configuration information, and circulates the traffic within the network or forwards it to the set VPN router through the VPN networking program according to the flow direction of the traffic, and then forwards it by the VPN router to complete the unified network egress function, so as to facilitate the statistics of the traffic of each terminal device; the terminal device logs in to the VPN networking program with an account and password, and after logging in, it will actively query the configuration information of its network egress; the VPN router is bound to an account, and the networking control end can be logged in through the account; When the VPN networking program receives all network data traffic on the terminal device in step S2, it also includes: establishing an MQTT persistent connection, and monitoring changes in network exit configuration information in real time through the MQTT persistent connection, if changes in the network exit configuration information are detected, disconnecting the VPN connection, restarting the VPN networking program, adding an open route according to the changed network exit configuration information, receiving all network data traffic on the terminal device, and forwarding the traffic to the newly configured VPN router through the VPN networking program; In step S2, the traffic flows in the network or is forwarded to the VPN router through the VPN networking program according to the flow direction of the traffic, and then forwarded by the VPN router. The method is as follows: the VPN networking program detects whether the forwarded traffic is the traffic within the network. If it is the traffic within the network, the traffic is forwarded within the network through the VPN server; if it is the traffic outside the network, the members within the VPN network are screened, and the VPN router member information set as the network exit is screened out, and then the data is forwarded to the VPN router member through the communication channel within the VPN network, and then the data forwarding function of the VPN router member forwards the data out.

2. A VPN networking method for redirecting external network access data according to claim 1, characterized in that: It also includes the step of verifying whether the network exit setting is effective, and the method is: capturing packets on the bound VPN router to check whether the network exit setting of the terminal device is effective; or judging whether its network exit setting is effective by querying the IP address of the terminal device. If the IP address is consistent with the VPN router bound to it, the network exit setting is deemed to be effective.

3. A VPN networking method for redirecting external network access data according to claim 2, characterized in that: The IP address of a terminal device can be queried on the browser of the terminal device.

4. A VPN networking method for redirecting external network access data according to claim 1, characterized in that: Step S1 includes: first determining the members to be networked; then at the networking control end, adding each networking member according to the SN / UID / SID of the networking member. If the networking member is not in the member list, the networking member is added by adding a member.

5. A VPN networking method for redirecting external network access data according to claim 1, characterized in that: The terminal device is an Android phone or an Android tablet.

6. A VPN networking system for redirecting external network access data, using the VPN networking method for redirecting external network access data as claimed in any one of claims 1 to 5, characterized in that: The invention comprises a networking control program, a VPN server, at least one VPN router and at least one terminal device. Each terminal device is networked through the VPN server and the networking control program. The VPN networking program is installed on each terminal device. The VPN router is connected to the networking control program. The VPN router is embedded with a corresponding VPN networking program and has a network forwarding function. The network exit of the terminal device is set to one of the VPN routers on the networking control program.

Citation Information

Patent Citations

  • Data transmission system

    CN113765765A