A method and apparatus for establishing a VPN tunnel based on traffic triggering

By sending negotiation probe packets between VPN encryption devices to trigger the Internet key exchange process, and automatically configuring or expanding interoperability policies, the problem of complex interoperability policies between VPN encryption devices is solved, and efficient VPN tunnel establishment is achieved.

CN119382970BActive Publication Date: 2025-12-02WUHAN SHIP COMM RES INST (NO 722 RES INST OF CHINA STATE SHIPBUILDING CORP)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411500509.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-25
Publication Date
2025-12-02
Estimated Expiration
2044-10-25

AI Technical Summary

Technical Problem

In existing technologies, the configuration of interoperability strategies between VPN encryption devices is complex and error-prone, especially in environments with multiple communication terminals or multiple networks, requiring a large amount of manual configuration.

Method used

By sending a negotiation probe packet to the first terminal, the Internet key exchange process is triggered, the interoperability policy is configured or expanded, a VPN tunnel is established, and automatic negotiation between VPN encryption devices is achieved.

Benefits of technology

It reduces the complexity of manual configuration, improves configuration efficiency, enables configuration-free interoperability policies between VPN encrypted devices, and enhances the universality of negotiation protocols.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119382970B_ABST
    Figure CN119382970B_ABST
Patent Text Reader

Abstract

This application belongs to the field of network encryption technology, specifically disclosing a VPN tunnel establishment method and apparatus based on traffic triggering. This application, through minor modifications to the existing IKE negotiation process, sends a first negotiation probe packet to a first terminal, enabling a second VPN encryption device to intercept the first negotiation probe packet and initiate an Internet Key Exchange (IKEY) process with the first VPN encryption device. The first VPN encryption device, by responding to the IKEY process, configures its interoperability policy with the second VPN encryption device or extends the interoperability policy, obtaining a third negotiation probe packet. This allows the second VPN encryption device to obtain its session key with the first VPN encryption device based on the third negotiation probe packet, completing the VPN tunnel establishment. This achieves configuration-free interoperability policy configuration between VPN encryption devices, reducing the complexity of manual configuration and improving configuration efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of network encryption technology, and more specifically, relates to a method and apparatus for establishing a VPN tunnel based on traffic triggering. Background Technology

[0002] Virtual Private Network (VPN) technology uses the Internet Key Exchange process to exchange negotiated keys. In accordance with security policies, it uses the established VPN tunnel to encrypt and transmit network layer data, enabling secure and reliable message transmission over insecure open networks, effectively reducing the cost of secure transmission of private information over the network.

[0003] Typically, both parties in a communication connection have a unique public IP address when accessing the internet via dial-up or broadband. VPN encryption devices can establish a VPN tunnel between them. However, implementing VPN functionality between these devices often requires extensive manual configuration of interoperability policies, especially in environments with multiple communication terminals or networks, making the configuration complex and prone to errors. Summary of the Invention

[0004] To address the shortcomings of existing technologies, the purpose of this application is to provide a VPN tunnel establishment method and apparatus based on traffic triggering, aiming to solve the problem that in the prior art, to implement VPN functionality between VPN encrypted devices, a large amount of manual configuration of interoperability policies is often required, especially in environments with multiple communication terminals or multiple networks, where the configuration is complex and prone to errors.

[0005] To achieve the above objectives, in a first aspect, this application provides a traffic-triggered VPN tunnel establishment method, applied to a first VPN encryption device, wherein no interoperability policy is configured between the first VPN encryption device and a second VPN encryption device, comprising:

[0006] Send a first negotiation probe packet to the first terminal that is connected to the network where the second VPN encryption device is located, so that the second VPN encryption device receives the first negotiation probe packet and initiates an Internet key exchange process to the first VPN encryption device;

[0007] In response to the Internet key exchange process;

[0008] Receive the second negotiation probe packet sent by the second VPN encryption device, and obtain the third negotiation probe packet by configuring the interoperability policy or extending the configured interoperability policy according to the second negotiation probe packet;

[0009] The third negotiation probe packet is sent to the second VPN encryption device so that the second VPN encryption device can obtain the session key between the first VPN encryption device and the second VPN encryption device based on the third negotiation probe packet.

[0010] In some embodiments, configuring an interoperability policy based on a second negotiation probe packet includes:

[0011] If it is determined that no communication policy is configured between the first VPN encryption device and the second VPN encryption device, a communication policy is established according to the IP address of the network IP packet.

[0012] In some embodiments, the configured interoperability policy is extended according to the second negotiation probe packet, including:

[0013] If it is determined that an interoperability policy has been configured between the first VPN encryption device and the second VPN encryption device, the interoperability policy is extended.

[0014] In some embodiments, before sending the first negotiation probe packet to a first terminal communicating with the second VPN encryption device, the method further includes:

[0015] Based on the network IP packets received from the third terminal accessing the network where the first VPN encryption device is located, which are sent to the first terminal accessing the network where the second VPN encryption device is located, the negotiation and detection function of the first VPN encryption device is triggered.

[0016] Secondly, embodiments of this application provide a traffic-triggered VPN tunnel establishment method, applied to a second VPN encryption device, wherein no interoperability policy is configured between the first VPN encryption device and the second VPN encryption device, including:

[0017] Receive the first negotiation probe packet sent by the first VPN encryption device;

[0018] Initiate an Internet key exchange process with the first VPN encryption device;

[0019] Send a second negotiation probe packet to the first VPN encryption device so that the first VPN encryption device can configure an interoperability policy or extend the configured interoperability policy according to the received second negotiation probe packet, and obtain a third negotiation probe packet;

[0020] Receive the third negotiation probe packet sent by the first VPN encryption device, and obtain the session key between the first VPN encryption device and the second VPN encryption device based on the third negotiation probe packet.

[0021] Thirdly, this application provides a traffic-triggered VPN tunnel establishment apparatus, applied to a first VPN encryption device, wherein no interoperability policy is configured between the first VPN encryption device and a second VPN encryption device, including:

[0022] The first sending module is used to send a first negotiation probe packet to a first terminal that is connected to the network where the second VPN encryption device is located, so that the second VPN encryption device receives the first negotiation probe packet and initiates an Internet key exchange process to the first VPN encryption device.

[0023] The negotiation response module is used to respond to the Internet key exchange process;

[0024] The first receiving module is used to receive the second negotiation probe packet sent by the second VPN encryption device, and to obtain the third negotiation probe packet by configuring the interoperability policy or extending the configured interoperability policy according to the second negotiation probe packet.

[0025] The second sending module is used to send the third negotiation probe packet to the second VPN encryption device, so that the second VPN encryption device can obtain the session key between the first VPN encryption device and the second VPN encryption device based on the third negotiation probe packet.

[0026] Fourthly, embodiments of this application provide a traffic-triggered VPN tunnel establishment apparatus, applied to a second VPN encryption device, wherein no interoperability policy is configured between the first VPN encryption device and the second VPN encryption device, including:

[0027] The first receiving module is used to receive the first negotiation probe packet sent by the first VPN encryption device;

[0028] The negotiation initiation module is used to initiate an Internet key exchange process with the first VPN encryption device;

[0029] The second sending module is used to send a second negotiation probe packet to the first VPN encryption device, so that the first VPN encryption device can configure an interoperability policy or extend the configured interoperability policy according to the received second negotiation probe packet to obtain a third negotiation probe packet.

[0030] The second receiving module is used to receive the third negotiation probe packet sent by the first VPN encryption device, and obtain the session key between the first VPN encryption device and the second VPN encryption device based on the third negotiation probe packet.

[0031] Fifthly, this application provides an electronic device, comprising: at least one memory for storing a program; and at least one processor for executing the program stored in the memory, wherein when the program stored in the memory is executed, the processor is configured to execute the traffic-triggered VPN tunnel establishment method described in any of the embodiments of the first or second aspect.

[0032] In a sixth aspect, this application provides a computer-readable storage medium storing a computer program that, when run on a processor, causes the processor to execute the traffic-triggered VPN tunnel establishment method described in any embodiment of the first or second aspect.

[0033] In a seventh aspect, this application provides a computer program product that, when run on a processor, causes the processor to execute the traffic-triggered VPN tunnel establishment method described in any of the embodiments of the first or second aspect.

[0034] Overall, the technical solutions conceived in this application have the following beneficial effects compared with the prior art:

[0035] The VPN tunnel establishment method and apparatus based on traffic triggering provided in this application, through minor modifications to the existing IKE negotiation process, sends a first negotiation probe packet to a first terminal, enabling a second VPN encryption device to intercept the first negotiation probe packet and initiate an Internet Key Exchange (IKEY) process with the first VPN encryption device. The first VPN encryption device, in response to the IKEY process, configures its interoperability policy with the second VPN encryption device or extends the interoperability policy, obtaining a third negotiation probe packet. This allows the second VPN encryption device to obtain its session key with the first VPN encryption device based on the third negotiation probe packet, completing the VPN tunnel establishment. This achieves configuration-free interoperability policy configuration between VPN encryption devices, reducing the complexity of manual configuration and improving configuration efficiency. Furthermore, the modifications to the existing IKE negotiation protocol are minor, making it highly versatile and practically valuable. Attached Figure Description

[0036] Figure 1 This is one of the flowcharts illustrating the traffic-triggered VPN tunnel establishment method provided in this application embodiment;

[0037] Figure 2 This is a schematic diagram of the working topology of the VPN encryption device provided in the embodiments of this application;

[0038] Figure 3 This is a schematic diagram of the negotiation detection process provided in the embodiments of this application;

[0039] Figure 4 This is the second flowchart illustrating the traffic-triggered VPN tunnel establishment method provided in this application embodiment;

[0040] Figure 5 This is the third flowchart of the VPN tunnel establishment method based on traffic triggering provided in the embodiments of this application;

[0041] Figure 6This is one of the structural schematic diagrams of the traffic-triggered VPN tunnel establishment device provided in the embodiments of this application;

[0042] Figure 7 This is a second schematic diagram of the structure of the VPN tunnel establishment device based on traffic triggering provided in the embodiments of this application;

[0043] Figure 8 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application. Detailed Implementation

[0044] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0045] In this article, the term "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The symbol " / " in this article indicates that the related objects are in an "or" relationship; for example, A / B means A or B.

[0046] The terms "first" and "second," etc., used in the specification and claims herein are used to distinguish different objects, not to describe a specific order of objects. For example, "first terminal" and "second terminal," etc., are used to distinguish different terminals, not to describe a specific order of terminals.

[0047] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0048] In the description of the embodiments in this application, unless otherwise stated, "multiple" means two or more.

[0049] The embodiments of this application are described below with reference to the accompanying drawings.

[0050] See Figure 1 This application provides a method for establishing a VPN tunnel based on traffic triggering, which may include steps 110 to 140.

[0051] Step 110 sends a first negotiation probe packet to the first terminal accessing the network where the second VPN encryption device is located, so that the second VPN encryption device receives the first negotiation probe packet and initiates an Internet key exchange process to the first VPN encryption device;

[0052] Step 120 responds to the Internet key exchange process;

[0053] Step 130: Receive the second negotiation probe packet sent by the second VPN encryption device, and configure the interoperability policy or extend the configured interoperability policy according to the second negotiation probe packet to obtain the third negotiation probe packet;

[0054] Step 140 sends a third negotiation probe packet to the second VPN encryption device so that the second VPN encryption device can obtain the session key between the first VPN encryption device and the second VPN encryption device based on the third negotiation probe packet.

[0055] The VPN tunnel establishment method based on traffic triggering provided in this application embodiment can be applied to a first VPN encryption device. By making appropriate modifications to the negotiation IKE process, it is suitable for automatically negotiating and establishing a VPN tunnel by traffic triggering when no interoperability policy is configured between the first VPN encryption device and a second VPN encryption device that is interconnected, so as to enable subsequent encrypted transmission of network data. The specific implementation is as follows.

[0056] In this embodiment of the application, the first VPN encryption device and the second VPN encryption device are generally deployed at the network egress point. They encrypt data on the outgoing network according to the interoperability policy and decrypt data entering the network according to the interoperability policy.

[0057] like Figure 2 As shown, VPN encryption devices are deployed at the network egress points of networks A and B, respectively. For example, a first VPN encryption device is deployed at the network egress point of network A, and a second VPN encryption device is configured at the network egress point of network B. Furthermore, no interoperability policy is configured between the first and second VPN encryption devices. The two VPN encryption devices transparently transmit routing protocols, establish interoperability policies for network IP data based on traffic triggers, and process the data according to these policies.

[0058] Furthermore, in some embodiments, before sending the first negotiation probe packet to the first terminal communicating with the second VPN encryption device in step 110, the above method may further include:

[0059] Based on the network IP packets received from the third terminal accessing the network where the first VPN encryption device is located, which are sent to the first terminal accessing the network where the second VPN encryption device is located, the negotiation and detection function of the first VPN encryption device is triggered.

[0060] In this embodiment of the application, when an interoperability policy is configured between the first VPN encryption device and the second VPN encryption device, when a third terminal in network A where the first VPN encryption device is located needs to communicate with the first terminal in network B where the second VPN encryption device is located, the network IP packets sent by the third terminal should be transmitted from network A to network B under the control of the router, and finally transmitted to the first terminal.

[0061] When no interoperability policy is configured between the first and second VPN encryption devices, network IP packets sent by the third terminal will be dropped by the first VPN encryption device at the network egress point (A) because they cannot find the interoperability policy. This triggers the negotiation probe function of the first VPN encryption device. The first VPN encryption device will initiate a negotiation probe towards the destination address of the triggering network IP packet (i.e., the IP address of the first terminal), sending a negotiation probe packet, i.e., the first negotiation probe packet, to the first terminal. This negotiation probe packet includes device information configured by the first VPN encryption device to establish a VPN tunnel based on the IKE process. Examples include its own source IP address, the IP address of the second VPN encryption device, authentication information, encryption algorithm, and security parameters used for key exchange.

[0062] The first negotiation probe packet will be transmitted to network B under the control of the router. At this time, the second VPN encryption device on network B will intercept the first negotiation probe packet and terminate the continued transmission of network IP packets. The second VPN encryption device responds to the first negotiation probe packet by sending a negotiation probe packet (i.e., the second negotiation probe packet) to the first VPN encryption device and initiates the IKE negotiation process with the first VPN encryption device. The second negotiation probe packet also includes the aforementioned device information configured by the second VPN encryption device to establish a VPN tunnel based on the IKE process. This includes, for example, its own source IP address, the IP address of the first VPN encryption device, authentication information, encryption algorithm, and security parameters used for key exchange.

[0063] Furthermore, in some embodiments, configuring the interoperability strategy based on the second negotiation probe packet in the above steps may include:

[0064] If it is determined that no communication policy is configured between the first VPN encryption device and the second VPN encryption device, a communication policy is established according to the IP address of the network IP packet.

[0065] In this embodiment, the first VPN encryption device responds to the Internet key exchange process initiated by the second VPN encryption device and receives the second negotiation probe packet sent by the second VPN encryption device. Based on this second negotiation probe packet, the first VPN encryption device confirms its IP address. Since no interoperability policy has been established between the two VPN encryption devices at this time, an interoperability policy is established according to the IP address triggered by the traffic. This interoperability policy is then sent to the second VPN encryption device as a negotiation probe packet (i.e., the third negotiation probe packet) to continue the subsequent IKE negotiation process.

[0066] After the second VPN encryption device receives the interoperability policy from the first VPN encryption device, the VPN encryption devices have completed the exchange of interoperability policies. The session key established by the subsequent IKE negotiation process will use this interoperability policy.

[0067] Furthermore, in some embodiments, the above steps, including expanding the configured interoperability strategy according to the second negotiation probe packet, include:

[0068] If it is determined that an interoperability policy has been configured between the first VPN encryption device and the second VPN encryption device, the interoperability policy is extended.

[0069] In the above steps, after the first VPN encryption device receives the second negotiation probe packet sent by the second VPN encryption device, if it confirms that an interoperability policy has been established between the two devices, it expands the configured interoperability policy and sends the expanded policy as a negotiation probe packet (i.e., the third negotiation probe packet) to the second VPN encryption device. Simultaneously, it sends a notification to the second VPN encryption device, informing it that the negotiation process has ended.

[0070] After the second VPN encryption device receives the extended interoperability policy from the first VPN encryption device, the VPN encryption devices have completed the exchange of interoperability policies. The session key established by the subsequent negotiation IKE process will use the extended interoperability policy.

[0071] For example, such as Figure 2As shown, VPN encryption devices are typically deployed at the network egress point. They encrypt data leaving the network according to security policies and decrypt data entering the network according to security policies. When a third terminal in network A (assuming IP address 1.0.0.10) wants to communicate with a first terminal in network B (assuming IP address 2.0.0.10), the network IP packets sent by the third terminal are transmitted from network A to network B under the control of the router, and finally reach the first terminal. When the network IP packets sent by the third terminal reach the first VPN encryption device at the network egress point of network A, the communication policy (1.0.0.10 <-> 2.0.0.10) will not be found and the packets will be discarded. At this time, the negotiation probe function of the first VPN encryption device is triggered. The first VPN encryption device will initiate a negotiation probe to the destination IP address (2.0.0.10) of the triggering network IP packets and send a first negotiation probe packet to the destination IP address (2.0.0.10). Figure 3 As shown.

[0072] like Figure 3 As shown, the first negotiation probe packet will be transmitted to network B under the control of the router. At this time, the second VPN encryption device of network B will intercept the first negotiation probe packet and terminate the continued transmission of network IP packets. The second VPN encryption device responds to the first negotiation probe packet, sends a second negotiation probe packet to the first VPN encryption device, and initiates the negotiation IKE procedure with the first VPN encryption device.

[0073] like Figure 3 As shown, the first VPN encryption device receives the second negotiation probe packet from the second VPN encryption device and confirms the IP address of the second VPN encryption device. If the first VPN encryption device finds that there is no communication policy between it and the second VPN encryption device, it establishes a communication policy according to the IP address triggered by the traffic (1.0.0.10<->2.0.0.10) and sends the communication policy to the second VPN encryption device to continue the subsequent negotiation process.

[0074] like Figure 3 As shown, the second VPN encryption device received the interoperability policy sent by the second VPN encryption device. At this time, the VPN encryption devices completed the exchange of interoperability policies, and the session key established by the subsequent negotiation IKE process will use this interoperability policy.

[0075] like Figure 3As shown, in the above steps, if the first VPN encryption device discovers that it has established an interoperability policy with the second VPN encryption device, it expands the interoperability policy so that the expanded interoperability policy includes the IP address (1.0.0.10<->3.0.0.10) of the second terminal (assuming IP address is 3.0.0.10) that triggered the negotiation probe to access the B network. At the same time, it sends a notification to the second VPN encryption device to inform it that the negotiation process has ended.

[0076] like Figure 3 As shown, if the first VPN encryption device and the second VPN encryption device have automatically established an interoperability policy negotiation, and there is out-of-policy traffic from network B to network A, it will trigger the negotiation detection function of the second VPN encryption device. Using the same method as above, the interoperability policy between the second VPN encryption device and the first VPN encryption device can be configured or the configured interoperability policy can be extended to complete the establishment of the VPN tunnel.

[0077] The traffic-triggered VPN tunnel establishment method provided in this application, through minor modifications to the existing IKE negotiation process, sends a first negotiation probe packet to a first terminal. This allows a second VPN encryption device to intercept the first negotiation probe packet and initiate an Internet Key Exchange (IKEY) process with the first VPN encryption device. The first VPN encryption device, in response to this IKEY process, configures its interoperability policy with the second VPN encryption device or extends the interoperability policy, obtaining a third negotiation probe packet. This enables the second VPN encryption device to obtain its session key with the first VPN encryption device based on the third negotiation probe packet, completing the VPN tunnel establishment. This achieves configuration-free interoperability policy configuration between VPN encryption devices, reducing the complexity of manual configuration and improving configuration efficiency. Furthermore, the modification to the existing IKE negotiation protocol is minor, making it highly versatile and practically valuable.

[0078] See Figure 4 This application provides a method for establishing a VPN tunnel based on traffic triggering, which may include steps 210 to 240.

[0079] Step 210: Receive the first negotiation probe packet sent by the first VPN encryption device;

[0080] Step 220: Initiate an Internet key exchange process to the first VPN encryption device;

[0081] Step 230 sends a second negotiation probe packet to the first VPN encryption device, so that the first VPN encryption device can configure an interoperability policy or extend the configured interoperability policy according to the received second negotiation probe packet, and obtain a third negotiation probe packet;

[0082] Step 240 receives the third negotiation probe packet sent by the first VPN encryption device and obtains the session key between the first VPN encryption device and the second VPN encryption device based on the third negotiation probe packet.

[0083] The VPN tunnel establishment method based on traffic triggering provided in this application embodiment can be applied to a second VPN encryption device. By making appropriate modifications to the negotiation IKE process, it is suitable for automatically negotiating and establishing a VPN tunnel by traffic triggering when no interoperability policy is configured between the first VPN encryption device and the second VPN encryption device that it is interconnected with, so as to facilitate the encrypted transmission of subsequent network data. The specific implementation is as follows.

[0084] In this embodiment of the application, the first VPN encryption device and the second VPN encryption device are generally deployed at the network egress point. They encrypt data on the outgoing network according to the interoperability policy and decrypt data entering the network according to the interoperability policy.

[0085] like Figure 2 As shown, VPN encryption devices are deployed at the network egress points of networks A and B, respectively. For example, a first VPN encryption device is deployed at the network egress point of network A, and a second VPN encryption device is configured at the network egress point of network B. Furthermore, no interoperability policy is configured between the first and second VPN encryption devices. The two VPN encryption devices transparently transmit routing protocols, establish interoperability policies for network IP data based on traffic triggers, and process the data according to these policies.

[0086] When configuring an interoperability policy between the first VPN encryption device and the second VPN encryption device, when a third terminal in network A, where the first VPN encryption device is located, needs to communicate with the first terminal in network B, where the second VPN encryption device is located, the network IP packets sent by the third terminal should be transmitted from network A to network B under the control of the router, and finally transmitted to the first terminal.

[0087] When no interoperability policy is configured between the first and second VPN encryption devices, network IP packets sent by the third terminal will be dropped by the first VPN encryption device at the network egress point (A) because they cannot find the interoperability policy. This triggers the negotiation probe function of the first VPN encryption device, which will initiate a negotiation probe towards the destination address of the triggering packet (i.e., the IP address of the first terminal), sending a negotiation probe packet, the first negotiation probe packet, to the first terminal. This negotiation probe packet includes device information configured by the first VPN encryption device for establishing a VPN tunnel based on the IKE process. This information includes its own source IP address, the IP address of the second VPN encryption device, authentication information, encryption algorithm, and security parameters used for key exchange.

[0088] The first negotiation probe packet will be transmitted to network B under the control of the router. At this time, the second VPN encryption device of network B will intercept the first negotiation probe packet and terminate the continued transmission of network IP packets. The second VPN encryption device responds to the first negotiation probe packet, sends a negotiation probe packet (i.e., the second negotiation probe packet) to the first VPN encryption device, and performs the negotiation IKE procedure with the first VPN encryption device.

[0089] The second negotiation probe packet also includes the aforementioned device information required by the second VPN encryption device to establish a VPN tunnel based on the IKE process. This includes, for example, its own source IP address, the IP address of the first VPN encryption device, authentication information, encryption algorithm, and security parameters used for key exchange.

[0090] The first VPN encryption device responds to the Internet key exchange process initiated by the second VPN encryption device and receives the second negotiation probe packet sent by the second VPN encryption device. Based on this second negotiation probe packet, the first VPN encryption device confirms the IP address of the second VPN encryption device. Since no interoperability policy has been established between the two VPN encryption devices at this point, an interoperability policy is established based on the IP address triggered by the traffic. This interoperability policy is then sent to the second VPN encryption device as a negotiation probe packet (i.e., the third negotiation probe packet) to continue the subsequent IKE negotiation process.

[0091] After the second VPN encryption device receives the interoperability policy from the first VPN encryption device, the VPN encryption devices have completed the exchange of interoperability policies. The session key established by the subsequent IKE negotiation process will use this interoperability policy.

[0092] In the above steps, after the first VPN encryption device receives the second negotiation probe packet sent by the second VPN encryption device, if it confirms that an interoperability policy has been established between the first VPN encryption device and the second VPN encryption device, it expands the configured interoperability policy and uses the expanded interoperability policy as the negotiation probe packet (i.e., the third negotiation probe packet).

[0093] The second VPN encryption device receives the third negotiation probe packet (i.e., the extended interoperability policy) sent by the first VPN encryption device. At this point, the VPN encryption devices have completed the exchange of interoperability policies, and the session key established by the subsequent negotiation IKE process will use the extended interoperability policy.

[0094] See Figure 5 The VPN tunnel establishment method based on traffic triggering provided in this application embodiment may include:

[0095] Terminals in the network (assuming the first network) where the access initiator (which can be the first VPN encryption device or the second VPN encryption device) is located send network IP packets to terminals in the network (assuming the second network) where the responder (which can be the first VPN encryption device or the second VPN encryption device) is located.

[0096] When a network IP packet sent by a terminal in the initiator's network is transmitted to the VPN encryption device at the first network exit, the interoperability policy will not be found and the packet will be discarded. At this time, the negotiation probe function of the VPN encryption device is triggered, and the first negotiation probe packet is sent to the VPN encryption device corresponding to the responder.

[0097] The VPN encryption device corresponding to the responder intercepts the first negotiation probe packet and terminates the continued transmission of network IP packets. It then sends a second negotiation probe packet to the VPN encryption device corresponding to the initiator and initiates the negotiation IKE process.

[0098] The VPN encryption device corresponding to the initiator receives the second negotiation probe packet, and when it confirms that there is no interoperability policy configured between it and the VPN encryption device corresponding to the responder, it establishes an interoperability policy according to the IP address triggered by the traffic, and sends it to the responder as the third negotiation probe packet;

[0099] When the responder receives the third negotiation probe packet, the two VPN encryption devices have completed the exchange of interoperability policies. The session key established by the subsequent IKE negotiation process will use this interoperability policy.

[0100] When the VPN encryption device of the initiating party confirms that it has an interoperability policy configured with the VPN encryption device of the responding party, it expands the interoperability policy and sends the expanded interoperability policy to the VPN encryption device of the responding party. At the same time, it sends a notification to the VPN encryption device of the responding party, informing it that the negotiation process has ended.

[0101] The traffic-triggered VPN tunnel establishment method provided in this application makes minor modifications to the existing IKE negotiation process. It receives a first negotiation probe packet from a first VPN encryption device and initiates an Internet Key Exchange (IKEY) process with the first VPN encryption device. The first VPN encryption device, by responding to the IKEY process, configures or extends its interoperability policy, thus obtaining a third negotiation probe packet. The second VPN encryption device obtains its session key with the first VPN encryption device based on the third negotiation probe packet, completing the VPN tunnel establishment. This method eliminates the need for configuration of interoperability policies between VPN encryption devices, reducing the complexity of manual configuration and improving configuration efficiency. Furthermore, it requires minimal modification to the existing IKE negotiation protocol, has strong versatility, and possesses practical value.

[0102] The traffic-triggered VPN tunnel establishment apparatus provided in this application is described below. The traffic-triggered VPN tunnel establishment apparatus described below can be referred to in correspondence with the traffic-triggered VPN tunnel establishment method described above.

[0103] See Figure 6 This application provides a traffic-triggered VPN tunnel establishment device, applied to a first VPN encryption device, wherein no interoperability policy is configured between the first VPN encryption device and a second VPN encryption device, and may include:

[0104] The first sending module 610 is used to send a first negotiation probe packet to a first terminal that is connected to the network where the second VPN encryption device is located, so that the second VPN encryption device receives the first negotiation probe packet and initiates an Internet key exchange process to the first VPN encryption device.

[0105] Negotiation response module 620 is used to respond to the Internet key exchange process;

[0106] The first receiving module 630 is used to receive the second negotiation probe packet sent by the second VPN encryption device, and to obtain the third negotiation probe packet by configuring an interoperability policy or extending the configured interoperability policy according to the second negotiation probe packet.

[0107] The second sending module 640 is used to send a third negotiation probe packet to the second VPN encryption device, so that the second VPN encryption device can obtain the session key between the first VPN encryption device and the second VPN encryption device based on the third negotiation probe packet.

[0108] The traffic-triggered VPN tunnel establishment device provided in this application, through minor modifications to the existing IKE negotiation process, sends a first negotiation probe packet to a first terminal. This allows a second VPN encryption device to intercept the first negotiation probe packet and initiate an Internet Key Exchange (IKEY) process with the first VPN encryption device. The first VPN encryption device, in response to this IKEY process, configures its interoperability policy with the second VPN encryption device or extends the interoperability policy, obtaining a third negotiation probe packet. This enables the second VPN encryption device to obtain its session key with the first VPN encryption device based on the third negotiation probe packet, completing the VPN tunnel establishment. This achieves configuration-free interoperability policy configuration between VPN encryption devices, reducing the complexity of manual configuration and improving configuration efficiency. Furthermore, the modification to the existing IKE negotiation protocol is minor, making it highly versatile and practically valuable.

[0109] See Figure 7This application provides a traffic-triggered VPN tunnel establishment device, applied to a second VPN encryption device, wherein no interoperability policy is configured between the first VPN encryption device and the second VPN encryption device, and may include:

[0110] The first receiving module 710 is used to receive the first negotiation probe packet sent by the first VPN encryption device;

[0111] Negotiation Initiation Module 720 is used to initiate an Internet key exchange process to the first VPN encryption device;

[0112] The second sending module 730 is used to send a second negotiation probe packet to the first VPN encryption device so that the first VPN encryption device can configure an interoperability policy or extend the configured interoperability policy according to the received second negotiation probe packet and obtain a third negotiation probe packet.

[0113] The second receiving module 740 is used to receive the third negotiation probe packet sent by the first VPN encryption device, and obtain the session key between the first VPN encryption device and the second VPN encryption device based on the third negotiation probe packet.

[0114] The traffic-triggered VPN tunnel establishment device provided in this application embodiment, through minor modifications to the existing IKE negotiation process, receives a first negotiation probe packet sent by a first VPN encryption device and initiates an Internet Key Exchange (IKEY) process with the first VPN encryption device. The first VPN encryption device, by responding to the IKEY process, configures or extends its interoperability policy, obtaining a third negotiation probe packet. The second VPN encryption device obtains its session key with the first VPN encryption device based on the third negotiation probe packet sent by the first VPN encryption device, completing the VPN tunnel establishment. This achieves configuration-free interoperability policies between VPN encryption devices, reducing the complexity of manual configuration and improving configuration efficiency. Furthermore, the modification to the existing IKE negotiation protocol is minimal, making it highly versatile and possessing practical value.

[0115] It is understood that the detailed functional implementation of each of the above units / modules can be found in the description in the aforementioned method embodiments, and will not be repeated here.

[0116] It should be understood that the above-described device is used to execute the methods in the above embodiments. The implementation principle and technical effect of the corresponding program modules in the device are similar to those described in the above methods. The working process of the device can be referred to the corresponding process in the above methods, and will not be repeated here.

[0117] Based on the methods in the above embodiments, this application provides an electronic device, see [link to relevant documentation]. Figure 8The electronic device may include a processor 810, a communications interface 820, a memory 830, and a communication bus 840, wherein the processor 810, the communications interface 820, and the memory 830 communicate with each other via the communication bus 840. The processor 810 may call logical instructions in the memory 830 to execute the methods described in the above embodiments.

[0118] Furthermore, the logical instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application.

[0119] Based on the methods in the above embodiments, this application provides a computer-readable storage medium storing a computer program that, when run on a processor, causes the processor to execute the methods in the above embodiments.

[0120] Based on the methods in the above embodiments, this application provides a computer program product that, when run on a processor, causes the processor to execute the methods in the above embodiments.

[0121] It is understood that the processor in the embodiments of this application can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor can be a microprocessor or any conventional processor.

[0122] The method steps in this application embodiment can be implemented in hardware or by a processor executing software instructions. The software instructions can consist of corresponding software modules, which can be stored in random access memory (RAM), flash memory, read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, portable hard disks, CD-ROMs, or any other form of storage medium known in the art. An exemplary storage medium is coupled to the processor, enabling the processor to read information from and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can reside in an ASIC.

[0123] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0124] It is understood that the various numerical designations used in the embodiments of this application are merely for the convenience of description and are not intended to limit the scope of the embodiments of this application.

[0125] Those skilled in the art will readily understand that the above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A method for establishing a VPN tunnel based on traffic triggering, characterized in that, Applied to a first VPN encryption device, where no interoperability policy is configured between the first VPN encryption device and the second VPN encryption device, including: A first negotiation probe packet is sent to a first terminal that is connected to the network where the second VPN encryption device is located, so that the second VPN encryption device receives the first negotiation probe packet and initiates an Internet key exchange process to the first VPN encryption device. In response to the Internet key exchange process; The system receives a second negotiation probe packet sent by the second VPN encryption device, and configures the interoperability policy or extends the configured interoperability policy according to the second negotiation probe packet to obtain a third negotiation probe packet. The third negotiation probe packet is sent to the second VPN encryption device so that the second VPN encryption device can obtain the session key between the first VPN encryption device and the second VPN encryption device based on the third negotiation probe packet.

2. The VPN tunnel establishment method based on traffic triggering as described in claim 1, characterized in that, The step of configuring the interoperability strategy according to the second negotiated probe packet includes: If it is determined that the interoperability policy is not configured between the first VPN encryption device and the second VPN encryption device, the interoperability policy is established according to the IP address of the network IP packet.

3. The VPN tunnel establishment method based on traffic triggering as described in claim 1, characterized in that, The interoperability strategy configured according to the second negotiated probe packet includes: If it is determined that the interoperability policy has been configured between the first VPN encryption device and the second VPN encryption device, the interoperability policy is extended.

4. The VPN tunnel establishment method based on traffic triggering as described in any one of claims 1-3, characterized in that, Before sending the first negotiation probe packet to the first terminal that communicates with the second VPN encryption device, the method further includes: Based on the network IP packets received from the third terminal accessing the network where the first VPN encryption device is located, which are sent to the first terminal accessing the network where the second VPN encryption device is located, the negotiation and detection function of the first VPN encryption device is triggered.

5. A method for establishing a VPN tunnel based on traffic triggering, characterized in that, Applied to a second VPN encryption device, where no interoperability policy is configured between the first VPN encryption device and the second VPN encryption device, including: Receive the first negotiation probe packet sent by the first VPN encryption device; Initiate the Internet key exchange process to the first VPN encryption device; A second negotiation probe packet is sent to the first VPN encryption device so that the first VPN encryption device configures the interoperability policy or extends the configured interoperability policy according to the received second negotiation probe packet, and obtains a third negotiation probe packet; The third negotiation probe packet sent by the first VPN encryption device is received, and the session key between the first VPN encryption device and the second VPN encryption device is obtained based on the third negotiation probe packet.

6. A VPN tunnel establishment device based on traffic triggering, characterized in that, Applied to a first VPN encryption device, where no interoperability policy is configured between the first VPN encryption device and the second VPN encryption device, including: The first sending module is used to send a first negotiation probe packet to a first terminal that is connected to the network where the second VPN encryption device is located, so that the second VPN encryption device receives the first negotiation probe packet and initiates an Internet key exchange process to the first VPN encryption device. The negotiation response module is used to respond to the Internet key exchange process; The first receiving module is used to receive the second negotiation probe packet sent by the second VPN encryption device, and to obtain the third negotiation probe packet by configuring the interoperability policy or extending the configured interoperability policy according to the second negotiation probe packet. The second sending module is used to send the third negotiation probe packet to the second VPN encryption device, so that the second VPN encryption device can obtain the session key between the first VPN encryption device and the second VPN encryption device based on the third negotiation probe packet.

7. A VPN tunnel establishment device based on traffic triggering, characterized in that, Applied to a second VPN encryption device, where no interoperability policy is configured between the first VPN encryption device and the second VPN encryption device, including: The first receiving module is configured to receive the first negotiation probe packet sent by the first VPN encryption device; The negotiation initiation module is used to initiate the Internet key exchange process to the first VPN encryption device; The second sending module is used to send a second negotiation probe packet to the first VPN encryption device, so that the first VPN encryption device can configure the interoperability policy or extend the configured interoperability policy according to the received second negotiation probe packet to obtain a third negotiation probe packet. The second receiving module is used to receive the third negotiation probe packet sent by the first VPN encryption device, and to obtain the session key between the first VPN encryption device and the second VPN encryption device based on the third negotiation probe packet.

8. An electronic device, characterized in that, include: At least one memory for storing computer programs; At least one processor is configured to execute a program stored in the memory, wherein when the program stored in the memory is executed, the processor is configured to execute the traffic-triggered VPN tunnel establishment method as described in any one of claims 1-4 or the traffic-triggered VPN tunnel establishment method as described in claim 5.

9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is run on the processor, it causes the processor to perform the traffic-triggered VPN tunnel establishment method as described in any one of claims 1-4 or the traffic-triggered VPN tunnel establishment method as described in claim 5.

10. A computer program product, characterized in that, When the computer program product is run on the processor, the processor performs the traffic-triggered VPN tunnel establishment method as described in any one of claims 1-4 or the traffic-triggered VPN tunnel establishment method as described in claim 5.

Citation Information

Patent Citations

  • Tunnel creation method and device and storage medium

    CN111083091A

  • Network layer security protection system and method based on IKE protocol

    CN113364811A