Method and system for data communication between network devices

By selecting clouds, data packets are transmitted from the first network device to the second network device and applying VPN ID, the problem of streaming service providers blocking VPN connections is solved, and stable access to designated terminal devices is achieved.

CN120113221APending Publication Date: 2025-06-06PISMO LABS TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380036526.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-10-05
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

Streaming service providers prevent a large number of users from connecting to the same host using the same source IP address by detecting the IP address of the VPN connection, resulting in the VPN connection being blocked.

Method used

The packet is transmitted from the first network device to the second network device by the selected cloud, the edge server is located in the second location such that the received packet is considered to be transmitted from the second network device and the VPN ID is applied.

Benefits of technology

It is implemented to access the designated terminal device through a VPN connection without being blocked by the streaming service provider, so that the data packets received from the designated terminal device are considered a local connection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120113221A_ABST
    Figure CN120113221A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a system for transmitting a data packet between first network equipment and second network equipment. The second network device first establishes at least one first connection with a first node of a selected cloud, and the first network device may establish at least one second connection with a second node of the selected cloud using an access code. The access code is generated locally by the second network device when the at least one first connection is established. When a first data packet is transmitted from the first network device to the second network device through the cloud, the data packet is regarded as a data packet sent by the second network device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to the transmission of data packets through a virtual private network (VPN) connection. More specifically, the present invention relates to accessing a terminal device through a VPN connection without being blocked. SUMMARY OF THE INVENTION

[0002] An exemplary embodiment of the present invention discloses a method and system for transmitting a data packet from a first network device located at a first location to a second network device located at a second location through a selected cloud. An edge server is located at the second location so that the data packet received by the edge server is regarded as transmitted from the second network device.

[0003] In one embodiment, the first network device and the second device are connected to different available nodes of the selected cloud.

[0004] In another embodiment, the first network device and the second device are connected to the same available node of the selected cloud.

[0005] According to one embodiment of the present invention, access control is applied on the second network device so that not all devices having an access code can establish a connection with the node of the selected cloud.

[0006] According to the present invention, a method and system for selecting a cloud and selecting a node are disclosed herein. The node selection may be performed by the network device or the cloud.

[0007] According to one embodiment of the present invention, the VPN ID is applied during data packet transmission. Technical issues

[0008] Tunneled Traffic Network ("TTN") refers to a network architecture in which data is encapsulated within another packet and transmitted over a public or untrusted network. VPNs are a common example of TTN. They were developed to allow companies with multiple physical locations to create a secure single enterprise network that is transparent to users.

[0009] Some service providers, including streaming service providers, take various measures to prevent a large number of users from trying to connect to the same host using the same source Internet Protocol ("IP") address for network security, licensing agreements with third parties, geo-blocking restrictions, server load management, and commercial reasons. By using a VPN for the streaming service, the streaming service provider can detect and block the same source IP address if a large number of users try to connect to the same host through the same proxy server.

[0010] For example, if a streaming service provider offers a TV show that is only available in the United States, a user located in France can establish a VPN connection to watch the TV show even though they are not in the United States. If the service provider detects the IP address of the connection and concludes that a VPN is used, the VPN connection will be blocked. VPN connections can be detected in various ways, such as IP address blacklists, DNS mismatches, and traffic patterns.

[0011] Some VPN providers try to solve the problem by constantly updating the IP addresses of the servers to circumvent the streaming service provider's blocks and allow their users to access overseas content. However, this is not a panacea for the problem as service providers tend to constantly update their blacklists.

[0012] The present invention discloses a method and system for accessing a designated terminal device at another location, so that the data packet received from the designated terminal device is regarded as transmitted from the IP address of the network interface of the relay server. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1A A schematic block diagram illustrates an exemplary network environment that may be used to establish at least one tunnel between two network devices.

[0014] Figure 1B A schematic block diagram of an exemplary network environment showing three clouds.

[0015] Figure 2A A block diagram of a network device according to an embodiment of the present invention is shown.

[0016] Figure 2B A block diagram of a network device according to an embodiment of the present invention is shown.

[0017] Figure 2C A block diagram of a network device according to an embodiment of the present invention is shown.

[0018] Figure 3 is a process flow diagram illustrating a method for establishing a tunnel with a cloud and generating an access code according to one embodiment of the present invention.

[0019] 4 is a process flow diagram illustrating a method for establishing a tunnel with a cloud using an access code according to one embodiment of the present invention.

[0020] Figure 5 is a process flow chart showing a method for implementing access control according to one embodiment of the present invention.

[0021] Figure 6is a timing diagram illustrating a connection between two network devices according to an exemplary embodiment of the present invention.

[0022] Fig. 7A A data packet according to an embodiment of the present invention is shown.

[0023] Figure 7B A data packet according to an embodiment of the present invention is shown. Specific embodiments

[0024] The terms used herein are only used to describe specific embodiments and are not intended to limit the exemplary embodiments of the present invention. The singular forms "one", "an" and "said" used herein are also intended to include plural forms, unless the context clearly states otherwise. The terms "and / or" and "at least one" used herein include any and all combinations of one or more related listed items. When expressions such as "at least one" appear before a list of elements, what it modifies is the entire list of elements, rather than a single element in the list. The terms "include" and "comprising" used herein are intended to specify the presence of the features, integers, steps, operations, elements and / or components, but do not exclude the presence or additional presence of one or more other features, integers, steps, operations, elements, and / or components. In addition, the term "exemplary" is intended to refer to an example or illustration.

[0025] When an element is referred to as being “on,” “connected to,” “coupled to,” or “adjacent to” another element, the element may be directly on, connected to, coupled to, or adjacent to the other element, or one or more other intervening elements may be present. On the other hand, when an element is referred to as being “directly on,” “directly connected to,” “directly coupled to,” or “directly adjacent to” another element, no intervening elements may be present.

[0026] The terms "computer-readable medium," "primary memory," "secondary storage medium," or "other storage medium" as used herein refer to any medium that participates in providing instructions to a processing unit for execution. The processing unit reads data written to the primary storage medium and writes data to the secondary storage medium. Therefore, even if the data written to the primary storage medium is lost due to a momentary power outage, etc., the data can be recovered by transferring the data saved in the secondary storage medium to the primary storage medium. Computer-readable media is just one example of a machine-readable medium that carries instructions for implementing any of the methods and / or techniques described herein. Such media can take a variety of forms, including but not limited to non-volatile media, volatile media, and transmission media. Non-volatile media include, for example, optical or magnetic disks. Volatile storage includes dynamic memory. Transmission media include coaxial cables, copper wires, and optical fibers. Transmission media can also take the form of sound waves or light waves, such as those generated during radio wave and infrared data communications.

[0027] Volatile memory can be used to store temporary variables or other intermediate information during the execution of instructions by the processing unit. Non-volatile memory or static memory can be used to store static information and instructions for the processor, as well as various system configuration parameters.

[0028] The storage medium may include a plurality of software modules, which may be implemented in the form of software code for execution by the processing unit using any suitable computer instruction type. The software code may be stored as a series of instructions or commands, or as a program in the storage medium.

[0029] Various forms of computer readable media may be involved in transmitting one or more sequences of one or more instructions to a processor for execution. For example, the instructions may initially be carried on a disk from a remote computer. Alternatively, the remote computer may load the instructions into its dynamic memory and send the instructions to a system that executes one or more sequences of one or more instructions.

[0030] The processing unit may be a microprocessor, a microcontroller, a digital signal processor (DSP), any combination of these devices, or any other circuit configured for processing information.

[0031] The processing unit executes program instructions or code segments for implementing embodiments of the present invention. In addition, embodiments may be implemented by hardware, software, firmware, middleware, microcode, hardware description language, or any combination thereof. When embodiments are to be implemented by software, firmware, middleware, or microcode, program instructions for performing the necessary tasks may be stored in a computer-readable storage medium. The processing unit may be implemented by virtualization and may be a virtual processing unit, including a virtual processing unit in a cloud-based instance.

[0032] The technology described herein can be used in various wireless communication networks, such as code division multiple access (CDMA), time division multiple access (TDMA), frequency division multiple access (FDMA), orthogonal frequency division multiple access (OFDMA), single carrier frequency division multiple access (SC-FDMA) and other networks. The terms "network" and "system" are often used interchangeably. A CDMA network can implement radio technologies such as Universal Terrestrial Radio Access (UTRA), CDMA2000, etc. UTRA includes Wideband CDMA (WCDMA) and other variants of CDMA. CDMA2000 covers IS-2000, IS-95 and IS-856 standards. A TDMA network can implement radio technologies such as Global System for Mobile Communications (GSM). An OFDMA network can implement radio technologies such as Evolved UTRA (E-UTRA), Ultra Mobile Broadband (UMB), IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Flash-OFDM, etc. UTRA and E-UTRA are part of Universal Mobile Telecommunications System (UMTS). 3GPP Long Term Evolution (LTE) is UMTS using E-UTRA, which employs OFDMA on the downlink and SC-FDMA on the uplink. UTRA, E-UTRA, UMTS, LTE, 5G, and GSM are described in documents from an organization named "3rd Generation Partnership Project" (3GPP). CDMA 2000 and UMB are described in documents from an organization named "3rd Generation Partnership Project 2" (3GPP2).

[0033] Figure 1A is a schematic block diagram showing an exemplary network environment that can be used to establish at least one tunnel between a network device, a selected cloud, and a terminal device according to an embodiment disclosed herein. Figure 1A The device includes a relay client 101, a relay server 102, and a cloud 103, each of which is located at a different location. There may be multiple available clouds including at least one node for selection. For ease of explanation, only one cloud (e.g., cloud 103 having three available nodes 103a, 103b, and 103c) is shown as a selected cloud.

[0034] For ease of illustration, relay client 101, relay server 102, and cloud 103 are located in the United States, France, and the United Kingdom, respectively, and perform functions similar to those of network device 200, management server 210, and network device 220, respectively. Figure 2A , Figure 2B and Figure 2C shown.

[0035] Laptop 101a and mobile device 101b are locally connected to relay client 101, and relay client 101 can communicate with a first node of cloud 103 through a first interconnected network, such as interconnected network 104. Edge server 106 and relay server 102 can communicate with a second node of cloud 103 through a second interconnected network, such as interconnected network 105. The first interconnected network and the second interconnected network can be public networks, private networks, or a combination of public and private networks, such as an intranet, an extranet, and the Internet.

[0036] In one embodiment, the first node and the second node are the same node.

[0037] In another embodiment, the first node and the second node are different nodes that can communicate with each other.

[0038] In one embodiment, the first node and the second node are located on the same network subnet and communicate directly with each other.

[0039] In another embodiment, the first node and the second node are not located on the same network subnet and communicate with each other indirectly.

[0040] In one embodiment, at least one first communication link is established between at least one network interface of the relay client 101 and the interconnected network 104, and at least one second communication link is established between at least one network interface of the relay server 102 and the interconnected network 105. Therefore, the relay client 101 can establish at least one first wide area network ("WAN") connection with the interconnected network 104 through the at least one first communication link, and the relay server 102 can establish at least one second WAN connection with the interconnected network 105 through the at least one second communication link. Finally, the relay client 101 can establish at least one first connection with a first node of the cloud 103 through the interconnected network 104, and further establish at least one first tunnel with the node through the at least one established first connection; the relay server 102 can establish at least one second connection with a second node of the cloud 103 through the interconnected network 105, and further establish at least one second tunnel with the node through the at least one established second connection.

[0041] In one variation, interconnection network 104 and interconnection network 105 are the same interconnection network, such as the Internet.

[0042] To illustrate the process described in the present invention, there are some prerequisites for the location of the device. Relay server 102 should be located in the same region, county, or country (hereinafter collectively referred to as "location") as edge server 106, but in a different location from relay client 101. For example, Figure 1AAs shown, relay server 102 and edge server 106 are both located in France.

[0043] In one embodiment, node 103a is co-located with relay client 101. Figure 1A As shown, node 103a and relay client 101 are both located in the United States.

[0044] In another embodiment, the node 103a is co-located with the relay server 102 and the edge server 106. Figure 1A As shown, node 103a, relay server 102, and edge server 106 are all located in France.

[0045] To simplify, Figure 1A Only one server is shown in FIG. 1. There may be multiple servers connected to the interconnected network, so that the relay server 102 can select the management server.

[0046] There is no restriction on where the relay client 101, relay server 102 and node 103a must be located. Figure 1A References to the United States, France and the United Kingdom are purely for illustrative purposes and do not imply any specific requirements or limitations.

[0047] As described above, there may be multiple clouds for the relay server 102 to choose from. Figure 1B is a schematic diagram of an exemplary network environment, showing how the relay server 102 selects a cloud from the available clouds. Figure 1B As shown, the available clouds are clouds 103, 107, and 108, which can be reached via an interconnection network 105. For ease of illustration, cloud 103 having nodes 103a-103c, cloud 107 having nodes 107a-107c, and cloud 108 having nodes 108a-108c are clouds located in the United Kingdom, Singapore, and Canada, respectively.

[0048] In one embodiment, a user or administrator of the relay server 102 may select a cloud from the available clouds based on a first criterion and establish a connection with the second node of the selected cloud. The second node is selected based on a second criterion. The first criterion and the second criterion may be selected from one or more of the following: latency, packet size, processing rate, location, cost, time, availability, security, and functions that a node may perform, such as load balancing.

[0049] In a variant, the cloud and / or the second node are selected randomly.

[0050] For example, cloud 103 is randomly selected from clouds 103, 107 and 108, and the second node is selected based on the delay. Assuming that the delays of available nodes 103a, 103b and 103c are 3ms, 10ms and 22ms respectively, node 103a with the smallest delay will be selected as the second node.

[0051] In another variant, the first criterion may depend on the second criterion. For example, if the cloud is to be selected based on latency, the latency of the cloud is the latency of the node of the cloud having the smallest latency.

[0052] For example, the delays of clouds 103, 107 and 108 are 3ms, 10ms and 22ms respectively. If the delay is the only consideration of the first criterion, the user or administrator of relay server 102 preferably selects cloud 103 with the smallest delay to establish the at least one second tunnel.

[0053] In another embodiment, the cloud can be selected based on proximity to the relay server. For example, since clouds 103, 107, and 108 are located in the United Kingdom, Singapore, and Canada, respectively, the relay server 102 located in France can select the cloud 103 closest to the relay server 102 to establish the at least one connection.

[0054] Figure 2A A schematic block diagram of a network device 200 according to an embodiment of the present invention is shown. The network device 200 includes a processing unit 201, a main memory 202, a storage unit 203, at least one network interface, such as a local area network ("LAN") interface 204, and WAN interfaces 205a and 205b. The processing unit 201 is connected to the main memory 202.

[0055] The processing unit 201 is connected to the storage unit 203, at least one LAN interface 204, and WAN interfaces 205a and 205b via a bus 206. The processing unit 201 executes program instructions or code segments for implementing an embodiment of the network device 200. In one embodiment, the main memory 202 and the storage unit 203 are non-transitory computer-readable storage media. In another embodiment, the storage unit 203 is a non-volatile memory. Non-volatile memory or static memory can be used to store static information and instructions of the processing unit, as well as various system configuration parameters. The storage unit 203 can be configured to store firmware. The firmware can be the operating system of the network device 200.

[0056] In a variant, the network device 200 may further include at least one modem for connecting to at least one SIM to establish a cellular connection.

[0057] In another variation, the network device 200 may further include an embedded universal integrated circuit card (“eUICC”) for establishing a cellular connection by managing the eSIM within the eUICC, thereby providing the network device 200 with access to wireless services.

[0058] Figure 2B FIG. 2 shows a schematic block diagram of a management server 210 according to an embodiment of the present invention. Figure 2A Similar to the network device 200 in FIG. 2 , the management server 210 includes a processing unit 211 , a main memory 212 , a storage unit 213 , and at least one network interface, such as WAN interfaces 215 a and 215 b . The processing unit 211 is connected to the main memory 212 .

[0059] The processing unit 211 is connected to the storage unit 213 and the WAN interfaces 215a and 215b via the bus 216. The processing unit 211 executes program instructions or code segments for implementing an embodiment of the management server 210. The main memory 212 and the storage unit 213 are non-transitory computer-readable storage media. In another embodiment, the storage unit 213 is a non-volatile memory. The non-volatile memory or static memory can be used to store static information and instructions for the processing unit, as well as various system configuration parameters. The storage unit 213 can be configured to store firmware. The firmware can be the operating system of the management server 210.

[0060] In a preferred embodiment, management server 210 is managed by a person, company, or organization other than the owner of network devices 200 and 220. For example, the manufacturer manages multiple management servers in different locations, such as Japan, the United States, and the United Kingdom.

[0061] In another embodiment, management server 210 is managed by the same owner of network devices 200 and 220 .

[0062] Figure 2C 2 is a schematic block diagram of a network device 220 according to an embodiment of the present invention. The network device 220 includes a processing unit 221, a main memory 222, a storage unit 223 and at least one network interface, such as WAN interfaces 225a and 225b. The processing unit 221 is connected to the main memory 222.

[0063] The processing unit 221 is connected to the storage unit 223 and the WAN interfaces 225a and 225b via the bus 226. The processing unit 221 executes program instructions or code segments for implementing the operation of the embodiment of the network device 220. The main memory 222 and the storage unit 223 are non-transitory computer-readable storage media. In another embodiment, the storage unit 223 is a non-volatile memory. The non-volatile memory or static memory can be used to store static information and instructions for the processing unit, as well as various system configuration parameters. The storage unit 223 can be configured to store firmware. The firmware can be the operating system of the network device 220.

[0064] In a variant, the network device 220 may also include at least one modem for connecting to at least one SIM to establish a cellular connection as a connection.

[0065] In another variation, the network device 220 may further include an eUICC for establishing a cellular connection by managing the eSIM within the eUICC, thereby providing the network device 220 with access to wireless services.

[0066] There is no limit to the number of WAN interfaces on network device 200, management server 210, or network device 220. The more WAN interfaces a network device 200, management server 210, or network device is equipped with, the more connections that can be formed. For example, if network device 200 includes five WAN interfaces and management server 210 includes six WAN interfaces, thirty connections can be formed between network device 200 and management server 210. Therefore, Figure 2A , Figure 2B and Figure 2C The number of WAN interfaces shown is for illustration purposes only.

[0067] There is no limit to the number of LAN interfaces on the network device 200, the management server 210, or the network device 220. The more LAN interfaces the network device 200, the management server 210, or the network device 220 is equipped with, the more terminal devices can be connected to the network device 200, the management server 210, or the network device 220. Therefore, Figure 2A , Figure 2B and Figure 2C The number of LAN interfaces shown in is for illustration purposes only.

[0068] In one variation, the LAN interface on the network device 200 may be supported for use as a WAN interface to establish a WAN connection.

[0069] In one embodiment, the network device 220 is capable of performing a series of functions for establishing at least one first connection between the cloud and the relay server, and establishing at least one second connection between the cloud and the relay client, respectively. The series of functions include but are not limited to one or more of the following: establishing a tunnel, generating an access code, and performing access control locally and / or remotely.

[0070] In one variation, if the network device 220 is unable to perform the series of functions, an external controller may be inserted into the network device 220 to perform the series of functions.

[0071] Figure 3 The method of establishing a tunnel with the cloud and generating an access code locally on the relay server according to an embodiment of the present invention is shown. Figure 1A and Figures 2A-2C Check Figure 3 .

[0072] In process 301, the relay server 102, such as the network device 220, can determine available clouds that can be connected. Each of the available clouds can be a public cloud or a private cloud hosted by the same party. For example, the available clouds are located in the United Kingdom, France, and Brazil.

[0073] In process 302, relay server 102 may select a cloud from the available clouds. For example, relay server 102 may select a cloud, such as cloud 103 located in the United Kingdom. Details of cloud selection are described in Figure 1B Described in.

[0074] In a preferred embodiment, the selected cloud 103 may be selected by a user or administrator of the relay server 102 .

[0075] In another embodiment, the selected cloud 103 may be automatically selected by the relay server 102 according to the performance of the at least one second tunnel established between the relay server 102 and the node 103a.

[0076] In process 303, after selecting the cloud 103, the relay server 102 may send a first request to connect to a second node through the second interconnected network, thereby establishing at least one second connection, and further establishing the at least one second tunnel. The second node is a node selected from at least one available node of the selected cloud 103, such as the node 103a. The at least one available node is determined by scanning all nodes in the selected cloud one by one.

[0077] In one embodiment, the second node is selected by a node of the cloud 103, such as a third node. The third node can perform node selection similar to that performed at the relay server 102, and select the second node based on the second criterion mentioned above. When the second node is selected, the third node can send a response corresponding to the request sent by the relay server 102. There is no limitation on how the third node connects to other nodes of the cloud.

[0078] In another embodiment, the second node is randomly selected by the third node of the selected cloud 103 .

[0079] In another embodiment, the second node is selected by the relay server 102 based on the second criterion mentioned above.

[0080] In another embodiment, the second node is randomly selected by the relay server 102 .

[0081] In one embodiment, when the at least one second tunnel is established, the relay server 102 is capable of recovering the lost or discarded data packets by resending the lost or discarded data packets until the node receives the data packets and sends a corresponding acknowledgement.

[0082] In process 304, the relay server 102 may generate an access profile locally. The access profile may include one or more of the following: At least one tunnel profile having a tunnel identifier, a policy, a priority, a signature, and an expiration time.

[0083] There is no restriction on the order of performing processes 303 and 304. Process 304 may follow process 303, or vice versa.

[0084] In one variation, processes 303 and 304 may be performed simultaneously.

[0085] In process 305, the relay server 102 may generate an access code corresponding to the access profile generated in process 304. The access code is stored in a database in the storage unit of the relay server 102. There is no limitation on how the access code is stored in the storage unit of the relay server 102. The database is for illustration purposes only.

[0086] The access code includes the access information of the relay server and the selected cloud. The access information may include one or more of the following: a MAC address of the relay server, a port number associated with the relay server for establishing an IP tunnel between the relay server and the second node, a serial number of the relay server, an encryption type, a pre-shared key, a certificate, a location of the selected cloud, a specified domain name, a user name, and a password.

[0087] The access code may be in any of the following forms: a token, a one-dimensional barcode, a two-dimensional barcode (ie, a QR code), a string of characters, or a string of digits.

[0088] There is no restriction on how the access code is generated. For example, the access code may be generated by hashing the authentication information into a digital string.

[0089] Figure 4A The method for establishing the at least one first tunnel between the relay client and the first node using the access code according to an embodiment of the present invention is shown. Figure 1A and Figures 2A-2C Check Figure 4A The process 401 starts when a relay client (eg, relay client 101) holds the access code and attempts to establish the at least one first tunnel.

[0090] In process 401, the relay client 101 may connect to the selected cloud according to the information of the access code. The access code may include information about the location of the selected cloud to which the relay server 102 is connected.

[0091] In process 402, the relay client 101 may select the first node from the at least one available node of the selected cloud, so that the relay client 101 may evaluate the second node through the first node and the relay server 102. For ease of illustration, the selected cloud is a cloud located in the United Kingdom, includes three management servers, and has at least one available node. The at least one available node is determined by scanning all nodes in the selected cloud one by one.

[0092] The selection of the first node is based on a third criterion. The third criterion may be selected from one or more of: latency, packet size, processing rate, location, cost, time, availability, security, and functions that a node can perform, such as load balancing.

[0093] In another embodiment, the first node is randomly selected by the relay client 101 .

[0094] In one variation, process 402 may be performed by the cloud instead of relay client 101. Relay client 101 may send a request to the third node of the cloud, which is capable of performing node selection similar to that performed at relay client 101. The third node may select the first node based on the third criterion mentioned above, and send a response corresponding to the request sent by relay client 101.

[0095] For example, the first node is selected based on the delay. Assume that the delays of available nodes 103a, 103b and 103c are 13ms, 10ms and 22ms respectively. Therefore, node 103b with the smallest delay is selected as the first node. If node 103a is the second node that establishes at least one second tunnel with relay server 102, the data packet received by relay client 101 can be transmitted to relay server 102 through nodes 103b and 103a.

[0096] In process 403, the relay client 101 may determine whether the second node and the relay server 102 are accessible through the first node. If the second node is not accessible through the first node, the relay client 101 may perform process 402 again until another first node is found so that the second node is accessible. If the second node is accessible through the first node, process 404 is performed.

[0097] In one variation, if there is only one available node in the selected cloud, relay client 101 may attempt to connect to the same node as that connected to relay server 102 in process 403 .

[0098] In process 404, the relay client 101 may establish at least one connection with the first node via the first interconnected network. The number of the at least one connection established may be determined by the number of available network interfaces of the relay client 101 and the number of available network interfaces of the first node. For example, if there are three available WAN interfaces in the relay client 101 and only one network interface in the first node, three connections may be established between the relay client 101 and the first node.

[0099] In process 405 , the relay client 101 may attempt to establish the at least one first tunnel with the first node through the at least one first connection.

[0100] In process 406, when receiving the data packets from the local device, the relay client 101 may forward all the data packets received from the local device, together with the path to the destination indicated by the data packets, to the first node, such as node 103b. The details of the data packet transmission will be described in Figure 6and discussed in Figure 7.

[0101] In one variation, only certain packets received from the local device, rather than all packets, may be forwarded to the first node, such as node 103b, along with the path to the destination indicated by the packet. Relay client 101 may execute one or more outbound traffic policies in process 406. Therefore, process 407 may be executed after process 405 and before 406, rather than after both processes 405 and 406. The details of process 407 will be described in detail in Figure 4B discussed in.

[0102] In another variation, relay client 101 may perform process 407 between process 404 and process 405 such that the at least one first tunnel is established only when the at least one outbound traffic policy is applied.

[0103] In one embodiment, when establishing the at least one first tunnel, the relay client 101 resends the lost or discarded data packets until the node receives the data packets and sends corresponding confirmations to recover the lost or discarded data packets.

[0104] Figure 4B A method for applying an outbound traffic policy between the at least one first connection according to an embodiment of the present invention is shown. Figure 4B This is a detailed description of process 407, which should be combined with Figure 1A , Figures 2A-2C and Figure 4A Check it out for better understanding.

[0105] In process 411, a user or administrator of the relay client 101 may select at least one outbound traffic policy to be applied. The selected at least one outbound traffic policy is used to select a specific data packet from the received data packets and transmit it to the relay server 102 via the first node and / or the second node.

[0106] To optimize traffic, it is preferred to forward the specific data packet to the relay server via the cloud rather than forwarding all data packets. The specific data packet may be selected based on at least one outbound traffic policy defined by a user or administrator of the relay client 101. The conditions of the at least one outbound traffic policy may be based on, but not limited to, one or more of the following: a protocol of the data packet, a session of the data packet, an application of the data packet, a source and / or destination port number (if the data packet is a TCP or UDP segment), a source and / or destination address of the data packet (if the data packet is an IP data packet), and a time of day.

[0107] For ease of explanation, three outbound traffic policies have been selected so that the data packets that satisfy these outbound traffic policies are the specific data packets. The three outbound traffic policies are based on specific local devices; based on the local devices connected to a specific service set identifier (SSID); based on specific local devices belonging to a specific application or session.

[0108] For the outbound traffic policy based on local devices, the data packet received from at least one specific local device is the specific data packet to be forwarded to the relay server through the node of the cloud. The condition for determining whether a data packet is received from at least one specific local device may be the source and / or destination port number of the data packet, and / or the source and / or destination address of the data packet, such as the MAC address of the source device. For example, Figure 1A As shown, at least one specific local device may be a laptop computer 101a, which is connected to the relay client 101 via a LAN interface of the relay client 101. The relay client 101 may be configured to forward the data packet received from the laptop computer 101a to the first node via the interconnection network 104, and further forward it to the second node, the relay server 102, and the designated device.

[0109] For the SSID-based outbound traffic policy, a network device, such as the relay client 101, can identify packets received from a specific SSID by looking at the 802.11 header of the packet. The 802.11 header contains the SSID of the network from which the packet was sent. Therefore, the relay client 101 can forward the packets received from at least one local device connected to or associated with a specific SSID to the relay server 102 through the node of the cloud. For example, Figure 1A As shown, the laptop computer 101a is associated with the SSID named "Home", which is the SSID provided by the relay client 101. If the relay client 101 is configured to forward the data packets received from the local device via the SSID named "Home", all the specific data packets received via the SSID named "Home" will be transmitted to the first node, the second node, and further transmitted to the relay server 102 and the designated device.

[0110] For the application- or session-based outbound traffic policy, the relay client 101 has multiple ways to identify data packets of a specific application or session, such as determining the IP address and port number in the packet header, port mirroring, and using deep packet inspection (DPI) to inspect the content of the data packet. Therefore, the relay client 101 can forward the data packets belonging to a specific application or session received from at least one local device to the relay server 102 through the node of the cloud. For example, the specific data packet can be a data packet belonging to a Netflix streaming session, and Netflix streaming is the process of transmitting video content to its subscribers over the Internet. The relay client 101 can be configured to forward the data packets of Netflix streaming to the second node through the interconnected network 104, and further forward them to the relay server 102 and the designated device.

[0111] In process 412, a user or administrator of the relay client 101 may assign a priority to at least one selected outbound traffic policy. If two or more outbound traffic policies are applied, conflicts between the outbound traffic policies may be avoided. A user or administrator of the relay client 101 may adjust the priority of the at least one selected outbound traffic policy at any time and in any manner.

[0112] In one variation, if only one outbound traffic policy is available for selection, process 412 may not be performed.

[0113] In process 413 , the relay client 101 may assign the at least one selected outbound traffic policy to each of the at least one first tunnel or each of the at least one first tunnel to be established.

[0114] In one embodiment, one or more outbound traffic policies may be assigned to a connection.

[0115] In another embodiment, only one connection can be associated with one outbound traffic policy.

[0116] After process 413, when the data packet is received from the local device, the relay client 101 may forward the data packet received from the local device to the first node in process 406. The forwarding is based on the at least one selected outbound traffic policy and a priority of the at least one selected outbound traffic policy.

[0117] Generally, if the relay client has the access code, any relay client can connect to the relay server through the node of the selected cloud. Therefore, the local device connected to the relay client can connect to the relay server through the node. For security purposes, access control can be introduced on the relay server side and the node so that the access of the relay client can be controlled. Figure 5 is a flow chart showing how to implement the access control on the relay server side and the node to utilize access control lists.

[0118] The access control list may be a white list or a black list. If the access control list is implemented in a white list manner, only the relay clients listed in the white list are allowed to be accessed through the second node.

[0119] On the contrary, if the access control list is implemented in a blacklist manner, all relay clients except the relay clients listed in the blacklist are allowed to access through the second node. For ease of explanation, the access control list is implemented in a whitelist manner in the following process for easier understanding.

[0120] In process 501, a first whitelist is created at the relay server, such as the relay server 102. The first whitelist is stored on the storage unit of the relay server 102 and managed by a user or administrator of the relay server 102. The first whitelist can be implemented as any of the following: a database, a parameter and a text string or any other means that can store MAC addresses, IP addresses, domain names, ports and / or URLs.

[0121] There is no limitation on the specific implementation of the whitelist or the blacklist, and it may be any method such as MAC address filtering, IP address filtering, domain name filtering, port filtering, URL filtering, etc.

[0122] The first whitelist may record the identity of the allowed relay client, which should be a unique parameter, such as the serial number of the relay client. The serial number of the allowed relay client mentioned here is only for illustration, and the identity may be any unique parameter that can identify the allowed relay client.

[0123] The number of the allowed relay clients may be zero or greater than zero. If the number of the allowed relay clients is zero, it means that no identity is entered in the first whitelist, and no relay client is allowed to access.

[0124] In a preferred embodiment, the access control of the first whitelist can be applied to the configuration of all access codes generated by the relay server. For example, only the relay-allowed clients on the first whitelist are allowed to access the relay server through any access code generated by the relay server.

[0125] In another embodiment, the access control of the first whitelist can be applied to the configuration of the specific access code generated by the relay server. For example, if the first whitelist is applied to the specific access code generated by the relay server, only the relay clients allowed on the first whitelist are allowed to access the relay server through the specific access code generated by the relay server.

[0126] In process 502, the relay server may check whether the first whitelist has been updated. The update may include operations of creation, addition, deletion, modification and replacement.

[0127] In a preferred embodiment, a second whitelist is stored on the first node or the second node for updating or synchronizing the first whitelist. When the first whitelist is updated, the first whitelist can be synchronized with the second whitelist in real time.

[0128] In another embodiment, the first node or the second node does not store a whitelist. The first node or the second node may confirm with the first whitelist stored on the relay server as needed.

[0129] In a variant, the updating or synchronization may be performed periodically or in batches to update the second whitelist. For example, the second whitelist may be updated at a predetermined time, such as every hour, every day, or every month.

[0130] In another variant, the updating or synchronization may be performed at the first node or the second node. The first node or the second node may check whether the second whitelist on the first node or the second node has been updated. If no update to the second whitelist is received, the first node or the second node may synchronize with the relay server connected to the first node or the second node to update the second whitelist.

[0131] In step 503, at the first node or the second node, when receiving the second tunnel establishment request from the relay client, the first node or the second node may determine whether the identity of the relay client is in the second whitelist.

[0132] If the identity of the relay client is in the second whitelist stored at the first node or the second node, a tunnel is established in step 504 , and the data packet received from the relay client is forwarded to the relay server through the selected cloud in step 505 .

[0133] If the identity of the relay client is not in the second whitelist, then in step 506, the data packet received from the relay client is forwarded to the relay server via another route.

[0134] Figure 6 is a timing diagram showing how to establish the connection between the relay client and the relay server through at least one node of the selected cloud by using the access code. Figure 1A , Figure 3 and Figure 4A Check Figure 6 , to gain an overall understanding and better understand the embodiments of the present invention.

[0135] In process 601, if Figure 3 As shown in process 303, the relay server 102 may connect to the second node of the selected cloud, such as node 103a of cloud 103 located in the UK. The relay server 102 may send a first request to node 103a to establish the at least one first tunnel with node 103a.

[0136] In process 602, node 103a may send a first response to relay server 102, the first response corresponding to the first request sent by relay server 102 to node 103a in process 601. After receiving the first response, the at least one second tunnel is established between relay server 102 and node 103a, and an access code is generated locally in relay server 102. There is no limitation on how relay client 101 obtains the access code generated by relay server 102. By using the access code, relay client 101 can establish the at least one first tunnel with the first node of the selected cloud in processes 603 and 604.

[0137] In process 603, similar to Figure 4A In the process 404 shown in , the relay client 101 can establish the at least one first tunnel with the first node of the selected cloud, such as node 103a. The relay client 101 can send a second request to node 103b to establish the at least one first tunnel with node 103a. The second node is the node of the selected cloud to which the relay server 101 is connected.

[0138] For simplicity, the relay client 101 and the relay server 102 are connected to the same node, so that the first node and the second node are the same node, for example, node 103a. The first node and the second node are both capable of performing routing, decapsulation and encapsulation functions. If the first node is different from the second node, at least part of the encapsulation and decapsulation is performed on the first node or the second node, such as Figure 6 shown.

[0139] In one variant, access control may be applied when establishing the at least one first tunnel. Node 103a may check the record of the access control list before sending the second reply to relay client 101 in process 604. The access control list may be a white list or a black list stored in node 103a or relay server 102. If the identity of relay client 101 is not recorded on the white list or is recorded on the black list, establishment of the at least one first tunnel is not allowed.

[0140] In process 604, the node 103a may send a second response to the relay client 101 and then establish the at least one first tunnel. The second response corresponds to the second request sent by the relay client 101 to the node 103a in process 603.

[0141] After establishing the at least one first tunnel and the at least one second tunnel, the relay client 101 can transmit a specific data packet to the relay server 102 through the node 103a. Figure 6 The process 605-608 is shown in FIG. 605-608 and should be combined with Fig. 7A To better understand.

[0142] There is no limit to the number of tunnels of the at least one first tunnel established between the relay server 102 and the node 103a, and the number of tunnels of the at least one second tunnel established between the relay client 101 and the node 103a; the number of established tunnels may vary according to the number of network interfaces on each side and the user preference. For ease of explanation, only a single tunnel is established between the relay client and the node of the cloud and between the relay server and the node of the cloud.

[0143] Prior to process 605, a first data packet (e.g., first data packet 701) is transmitted from the laptop 101a to the edge server 106, where the first data packet may be a datagram including a third request for requesting data or information from the edge server 106. Therefore, the first data packet, e.g., first data packet 701, is encapsulated into a first encapsulated data packet, e.g., first encapsulated data packet 702.

[0144] In process 605, the first encapsulated data packet is transmitted through the at least one connection to the network interface of the relay client 101. In one embodiment, the first encapsulated data packet may be received from the laptop 101a through a wireless or wired connection through the LAN interface of the relay client 101.

[0145] In another embodiment, the first encapsulated data packet may be received from the laptop computer 101 a via a wireless or wired connection through different WAN interfaces of the relay client 101 .

[0146] In process 606, when the first encapsulated data packet is received from the local device, a second encapsulated data packet (e.g., second encapsulated data packet 703) is transmitted to node 103a. Relay client 101 may encapsulate the first encapsulated data packet to form the second encapsulated data packet, and may check whether the condition is met. The encapsulation will be in Fig. 7A and Figure 7B discussed in.

[0147] If the condition is met, the relay client 101 may transmit the second encapsulated data packet to the node 103a through the established tunnel. If the received first encapsulated data packet is a specific data packet as described above, the condition is met. For example, the specific data packet may be a data packet received from a local device connected to a specific SSID, a data packet received from a local device with a specific identifier, or a data packet received under a specific session.

[0148] If the condition is not met, the relay client 101 may transmit the second encapsulated data packet via another route. If no connection is established between the relay client and the node 103a of the selected cloud, the condition is not met. One of the possible reasons for not establishing a connection is access control. For example, the identity of the relay client 101 is not on the white list or on the black list.

[0149] In step 607, the third encapsulated data packet or the fourth encapsulated data packet is transmitted from the node 103a to the relay server 102. When the node 103a receives the second encapsulated data packet through the first interconnection network, it can decapsulate the second encapsulated data packet, then encapsulate the payload of the second encapsulated data packet into a third encapsulated data packet, and forward the third encapsulated data packet to the relay server 102 according to the destination address in the header.

[0150] In a variation, the node 103a may further encapsulate the second encapsulated data packet into the fourth encapsulated data packet, where the fourth encapsulated data packet includes the same transport protocol header as the third encapsulated data packet.

[0151] In step 608, the second data packet or the fifth encapsulated data packet is transmitted from the relay server 102 to the edge server 106. When the relay server 102 receives the third encapsulated data packet or the fourth encapsulated data packet from the node of the selected cloud through the second interconnected network, the relay server 102 may decapsulate the third encapsulated data packet or the fourth encapsulated data packet to determine which device the first data packet should be designated to according to the designated address of the first data packet, and further forward the second data packet or the fifth encapsulated data packet to the designated device. The second data packet and the fifth encapsulated data packet correspond to Fig. 7A A second data packet 706 and a fifth encapsulated data packet 707 are shown.

[0152] In order to implement the method and disclosure of the present invention, the location prerequisite of each device must be met. By applying the packet transmission process disclosed in the present invention, the packet received by the edge server 106 can be regarded as the packet from the relay server 102 instead of the relay client 101, and is regarded as a local connection.

[0153] After sending the third request to the edge server 106 , the relay server 102 should receive a response corresponding to the third request.

[0154] In process 609, a third data packet is transmitted from the edge server 106 to the relay server 102. For example, the third data packet may be a datagram including a response for responding to the third request of the notebook computer 101a.

[0155] In process 610, a sixth encapsulated data packet is transmitted from the relay server 102 to the node 103a. When the third data packet, such as the third data packet 721, is received by the relay server 102, the relay server 102 may determine whether the payload of the third data packet 721 corresponds to the payload of the first data packet 701. For example, the payload of the third data packet 721 is a response corresponding to a request, and the request is the payload of the first data packet 701. Therefore, the relay server 102 may encapsulate the third data packet into the sixth encapsulated data packet, such as the sixth encapsulated data packet 722, and transmit the sixth encapsulated data packet to the node 103a.

[0156] In process 611, the seventh or eighth encapsulated data packet is transmitted from node 103a to relay client 101. When receiving the sixth encapsulated data packet from relay server 102 through the second interconnected network, node 103a may decapsulate the third data packet from the sixth encapsulated data packet, then encapsulate the third data packet into a seventh encapsulated data packet, such as seventh encapsulated data packet 723, and forward the seventh encapsulated data packet to relay client 101 through the first node.

[0157] In another variation, decapsulation is not performed at the node 103a. Instead, the node 103a may further encapsulate the sixth encapsulated data packet to form the eighth encapsulated data packet, such as the eighth encapsulated data packet 724, which includes the same transport protocol header as the seventh encapsulated data packet.

[0158] In process 612, a ninth encapsulated data packet, such as ninth encapsulated data packet 725, is transmitted from relay client 101 to laptop computer 101a. When receiving the seventh or eighth encapsulated data packet from node 103a via the first interconnected network, relay client 101 may decapsulate the third data packet from the received encapsulated data packet. Then, relay client 101 encapsulates the third data packet to form the ninth encapsulated data packet. Then, the ninth encapsulated data packet is further forwarded to laptop computer 101a.

[0159] When the data packet is transmitted between the relay client and the relay server, the data packet is encapsulated to form an encapsulated data packet. When the encapsulated data packet reaches the end of the tunnel, the encapsulated data packet can be decapsulated and the data packet can be extracted.

[0160] Fig. 7A The relationship between the data packets and the encapsulation packets during processes 605 - 608 is shown. For illustration purposes only, when the laptop 101a sends a first data packet 701 to the edge server 106, the following process occurs.

[0161] The first data packet 701 has a header 711 and a payload 712. The header 711 is used to store the source address, the destination address, the protocol type, the packet length, and other information. The payload 712 is used to store the data that the laptop 101a intends to send to the edge server 106. In this figure, the source address is the address of the laptop 101a, and the destination address is the address of the edge server 106. Those skilled in the art will understand that the first data packet 701 can be an IP data packet, an Ethernet frame, an X.25 data packet, etc.

[0162] In process 605, laptop 101a transmits first encapsulated data packet 702 to relay client 101. First encapsulated data packet 702 has header 713 and first payload portion. Header 713 includes a destination address field set to a network interface address of relay client 101 and a source address field set to a network interface address of laptop 101a. First payload portion of first encapsulated data packet 702 is used to store first data packet 701.

[0163] In process 606, the relay client 101 may transmit the second encapsulated data packet 703 to the node 103a. The second encapsulated data packet 703 has a header 714 and a second payload portion. The header 714 includes a destination address field set to a network interface address of the first node and a source address field set to a network interface address of the relay client 101. The second payload portion is used to store the first data packet 701.

[0164] In process 607, node 103a may transmit the third encapsulated data packet to relay server 102. Similar to first encapsulated data packet 702 and second encapsulated data packet 703, third encapsulated data packet 704 has a header 715 and a payload portion. Header 715 includes a destination address field set to a network interface address of relay server 102 and a source address field set to a network interface address of node 103a. The payload portion is used to store first data packet 701.

[0165] In one variation, decapsulation is not performed at the node 103a. Instead, the node 103a may encapsulate the second encapsulated data packet 703 in the fourth encapsulated data packet 705 and transmit the fourth encapsulated data packet 705 to the relay server 102. Similar to the third encapsulated data packet 704, the fourth encapsulated data packet 705 has a header 715 and a payload portion. The header 715 is the same as the header of the third encapsulated data packet 704, but the payload is different from the third encapsulated data packet 704. The payload portion is used to store the second encapsulated data packet 703.

[0166] Before process 608 , when the relay server 102 receives the third encapsulated data packet 704 or the fourth encapsulated data packet 705 , the relay server 102 decapsulates the first data packet 701 from the third encapsulated data packet 704 or the fourth encapsulated data packet 705 .

[0167] In process 608, relay server 102 may transmit fifth encapsulated data packet 716 to edge server 106. Fifth encapsulated data packet 707 has header 716 and payload portion. Header 716 includes a destination address field set to a network interface address of edge server 106 and a source address field set to a network interface address of relay server 102. The payload of fifth encapsulated data packet 707 is used to store first data packet 701.

[0168] In one variation, the relay server 102 may transmit the second data packet, instead of the fifth encapsulated data packet 716, to the edge server 106. The second data packet 706 has the same header 716 as the fifth encapsulated data packet 707, but a different payload. The payload of the second data packet 706 is used to store the payload of the first data packet 701.

[0169] Figure 7B The relationship between the data packets and the encapsulated data packets during processes 609-612 is shown, which illustrates the data transfer from the host 106 back to the laptop 101a.

[0170] In process 610, relay server 102 may transmit sixth encapsulated data packet 722 to node 103a. Sixth encapsulated data packet 722 has header 732 and payload portion. Header 732 includes a destination address field set to a network interface address of the second node and a source address field set to a network interface address of relay server 102. The payload portion is used to store third data packet 721.

[0171] In process 611, node 103a may transmit seventh encapsulated data packet 723 to relay client 101. Seventh encapsulated data packet 723 has a header 733 and a payload portion. Header 733 includes a destination address field set to the address of relay client 101 and a source address field set to a network interface address of the second node. The payload is used to store third data packet 721. Then, the second node transmits seventh encapsulated data packet 723 to relay client 101 using the tunnel previously established through the first interconnected network.

[0172] In one variation, in process 611, node 103a may transmit eighth encapsulated data packet 724 to relay client 101. Eighth encapsulated data packet 724 has header 733 and payload portion. Header 733 is the same as the header of seventh encapsulated data packet 723. However, the payload portion is used to store sixth encapsulated data packet 722. Then, the second node transmits eighth encapsulated data packet 724 to relay client 101 using the tunnel previously established through the first interconnected network.

[0173] In process 612, relay client 101 forwards ninth encapsulated data packet 725 to laptop computer 101a. Ninth encapsulated data packet 725 has header 734 and payload portion. Header 734 includes a destination address field set to the address of laptop computer 101a and a source address field set to the network interface address of edge server 106. The payload of ninth encapsulated data packet 725 is used to store third data packet 721.

[0174] In one embodiment, a VPN ID may be introduced for data packet transmission. The VPN ID is an identification string randomly generated by a network device and is guaranteed to be unique.

[0175] One of the benefits of introducing VPN IDs is to assist in packet routing at the nodes of the cloud. If the packets are tunneled through multiple WAN connections established between the relay client 101 and the interconnected network 104 or between the relay server 102 and the interconnected network 105, the relay client 101 or the relay server 102 may send the packets through one IP address but receive the corresponding packets through another IP address.

[0176] The generated VPN ID is part of the header or part of the payload of the data packet, which is used to enable the node of the selected cloud to identify the transmission or routing method of the data packet. During the transmission of the data packet, the VPN ID can be stored in the node database of the selected cloud. The node can be the first node or the second node described in this article.

[0177] In one variation, in process 611, node 103a may transmit eighth encapsulated data packet 724 to relay client 101. Eighth encapsulated data packet 724 has header 733 and payload portion. Header 733 is the same as the header of seventh encapsulated data packet 723. However, the payload portion is used to store sixth encapsulated data packet 722. Then, the second node transmits eighth encapsulated data packet 724 to relay client 101 using the tunnel previously established through the first interconnected network.

[0178] In process 612, relay client 101 forwards ninth encapsulated data packet 725 to laptop 101a. Ninth encapsulated data packet 725 has header 734 and payload portion. Header 734 includes a destination address field set to the address of laptop 101a and a source address field set to the address of a network interface of edge server 106. The payload of ninth encapsulated data packet 725 is used to store third data packet 721.

[0179] In one embodiment, a VPN ID may be introduced for data packet transmission. The VPN ID is an identification string randomly generated by a network device and is guaranteed to be unique.

[0180] One of the benefits of introducing VPN IDs is to assist in packet routing at the nodes of the cloud. If the packets are tunneled through multiple WAN connections established between the relay client 101 and the interconnected network 104 or between the relay server 102 and the interconnected network 105, the relay client 101 or the relay server 102 may send out the packets through one IP address but receive the corresponding packets through another IP address.

[0181] The generated VPN ID is a part of the header or a part of the payload of the data packet, and is used to enable the node of the selected cloud to identify the transmission or routing mode of the data packet. During the data packet transmission process, the VPNID can be stored in a node database of the selected cloud. The node can be the first node or the second node described in this article.

Claims

1. A method for establishing at least one connection between a first network device and a second network device, include: a. At the second network device, select a cloud; b. establishing at least one first connection with the first node at the second network device; c. At the second network device, locally generating an access code; d. establishing at least one second connection with a second node by using the access code at the first network device; e. at the first network device, forwarding the first data packet received from the local device to the second node; f. At the second network device, receiving a second data packet; wherein the first data packet is a portion of the payload of the second data packet; wherein the access code includes access information of the second network device and the selected cloud; wherein each of the first node and the second node is the at least one one of the available nodes; and The first node and the second node are capable of exchanging data and information.

2. The method according to claim 1, wherein if a first condition is met, the first data packet is forwarded to the second node in step e. 3 . The method of claim 2 , wherein the first condition is satisfied if the first network device is in an access control list. The method of claim 3 , wherein the access control list is stored in the first node of the selected cloud. The method of claim 1 , wherein the first node and the second node are the same node. The method of claim 1 , wherein the second node is selected based on a criteria.

7. The method of claim 1, wherein the access code is in any of the following forms: a token, a one-dimensional barcode, a two-dimensional barcode, a character string, or a numeric string.

8. The method according to claim 1, further comprising: include: An outbound traffic policy is assigned to each of the at least one established second connection.

9. The method of claim 1, wherein the second data packet comprises an IP header, in, The IP header of the second data packet is different from the IP header of the first data packet.

10. The method of claim 1, wherein encapsulation and decapsulation are performed during forwarding in step e.

11. A system for establishing at least one connection between a first network device and a second network device, include: The second network device includes: at least one second processing unit; a plurality of second network interfaces; and at least one second non-transitory computer-readable storage medium storing the at least one The program instructions executed by the second processing unit are used to: a. Select Cloud; b. Establish at least one first connection with the first node; c. Generate access codes locally; and d. receiving a second data packet; and The first network device comprises: at least one first processing unit; a plurality of first network interfaces; and at least one first non-transitory computer-readable storage medium storing the at least one The program instructions executed by the first processing unit are used to: e. establishing at least one second connection with a second node using the access code; and f. forwarding the first data packet received from the local device to the second node; wherein the first data packet is a portion of the payload of the second data packet; wherein the access code includes access information of the second network device and the selected cloud; wherein each of the first node and the second node is the at least one one of the available nodes; and The first node and the second node are capable of exchanging data and information.

12. The system according to claim 11, wherein if a first condition is satisfied, then in step f, the first network device forwards the first data packet received from a local device to the second node.

13. The system of claim 12, wherein the first condition is satisfied if the first network device is in an access control list.

14. The system of claim 13, wherein the access control list is stored in the first node of the selected cloud.

15. The system of claim 11, wherein the first node and the second node are the same node.

16. The system of claim 11, wherein the second node is selected based on a criteria.

17. The system of claim 11, wherein the access code is in any of the following forms: a token, a one-dimensional barcode, a two-dimensional barcode, a string of characters, or a string of digits.

18. The system of claim 11, wherein the at least one first non-transitory computer-readable storage medium further stores program instructions executable by the at least one first processing unit for: An outbound traffic policy is assigned to each of the at least one second connection established.

19. The system of claim 11, wherein the second data packet includes an IP header, wherein the IP header of the second data packet is different from the IP header of the first data packet.

20. The system of claim 11, wherein encapsulation and decapsulation are performed by the first network device during forwarding in step f.