[go: up one dir, main page]

CN1561040A - Transmission method of universal radio transparent VPN network bridge system based on GRPS/CDMA 2000 1X - Google Patents

Transmission method of universal radio transparent VPN network bridge system based on GRPS/CDMA 2000 1X Download PDF

Info

Publication number
CN1561040A
CN1561040A CNA2004100127615A CN200410012761A CN1561040A CN 1561040 A CN1561040 A CN 1561040A CN A2004100127615 A CNA2004100127615 A CN A2004100127615A CN 200410012761 A CN200410012761 A CN 200410012761A CN 1561040 A CN1561040 A CN 1561040A
Authority
CN
China
Prior art keywords
vpn
wireless
data
terminal
network
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
CNA2004100127615A
Other languages
Chinese (zh)
Inventor
吴玲琦
魏莎
胡士毅
刘凯
赵勋
徐杰
余勋林
彭巍
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Wuhan Hongxin Telecommunication Technologies Co Ltd
Original Assignee
Wuhan Hongxin Telecommunication Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Wuhan Hongxin Telecommunication Technologies Co Ltd filed Critical Wuhan Hongxin Telecommunication Technologies Co Ltd
Priority to CNA2004100127615A priority Critical patent/CN1561040A/en
Publication of CN1561040A publication Critical patent/CN1561040A/en
Pending legal-status Critical Current

Links

Images

Landscapes

  • Data Exchanges In Wide-Area Networks (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

This invention relates to a general radio transparent VPN mail bridge system composed of radio VPN terminals and gate ways taking GPRS/CDMA2000 1X OF 2.5G public radio packet data transmission exchange platform provided by current mobile communication merchants as the transmission basis, both the two equipments work on the Ether net link layer, so it can realize IP data remote transparent radio transmission and interaction of different Ether nets. It's not necessary to use special VPN to set up network or developing extra softwares or mounting software at customer ends and all the top layer applied systems are the original softwares without improvement to set up network by this invented system.

Description

The transparent VPN bridge system of wireless universal transmission method based on GPRS/CDMA2000 1X
Technical field
The present invention relates to public mobile communication field, field of data networks and information security field, specifically, be the general packet radio service gprs/code division multiple access CDMA2000 1X bag exchanges data transmission platform that provides by each mobile operator, finish transparent, wireless, the safe transmission of strange land mechanism and local mechanism ethernet network data.
Background technology
For cost consideration, also do not set up the IP data transmission link between now a lot of medium-sized and small enterprises various places offices and the enterprise headquarters.The general fashion of their information interchange is following three kinds probably at present: phone, fax, Email.1) the liaison mode price is expensive, and often can not say clearly problem and situation fully; 2) fax mode is often because the problem of related personnel or facsimile equipment causes information in time not transmit or to lose, and same data can form fax original text identical more than 2 parts in office and corporate HQ, causes the office paper waste; Whether 3) the information transmission of E-mail mode exists than long time delay, and because the mail network problem causes losing of Email E-mail through regular meeting, by Email information is sent also and can't be investigated for the related personnel simultaneously.And for the existing electric network office platform of the office of enterprise that has also can't with corporate HQ's Intranet networking, can not accomplish that the various information of office and corporate HQ is in time shared.
In addition because the develop rapidly of IP data network, the inside data of enterprise networking of various enterprise groups with good conditionsi is at present closely finished, and various Enterprise Resources Plan ERP, customer relation management CRM, supply chain management SCM, management information system mis system all are based upon on the inside IP data network of these enterprise groups.For grasp at any time business event dynamically, carry out business information transmission/interchanges, each branch of enterprise group/professional site just needs long-rangely at any time carry out information data with inside IP data network enterprise headquarters and exchange.The mode of the inner IP data network of long-range access enterprise headquarters of traditional branch comprises digital data service DDN special line, data microwave, utility wired telephone network PSTN dial-up access etc., but it is cumbersome that these modes are opened, communication cost is generally higher, and the utilance of respective communication resource is very low.
Summary of the invention
At current telecommunication network transfer of data situation, need the long-range transparent network connected mode of a kind of new high performance-price ratio and substitute data transfer modes such as original special line or dialing, purpose of the present invention is in order to overcome the problem and shortage of above-mentioned existence, a kind of wireless transparent VPN bridge system transmission method based on GPRS/CDMA2000 1X is provided, wireless transparent VPN bridge system has been realized on long-range strange land mechanism ethernet link layer, the public packet radio transfer of data of the 2.5G switching plane GPRS/CDMA2000 1X that provides with present mobile communication carrier is the transmission basis, carries out the long-range transparent wireless transmission of strange land network ethernet ip data and mutual function.Adopt the wireless transparent VPN bridge system of this method to form by wireless VPN terminal and vpn gateway, it all is operated in ethernet link layer, this wireless vpn system has the transparency to the original ethernet ip network of user, utilize this system group network not need additionally to develop software or client software is installed, all upper layer application systems of user are the original software of enterprise, simultaneously enterprise's original system or network are not needed to do any change yet.And this system has the transmission of data and highly encrypt and authentication mechanism, and is similar with the wired VPN that sets up on the Internet Internet, is enterprise's universal transparent wireless transmission vpn system of setting up on the wireless public network platform.
The bag data transmission channel of wireless transparent VPN bridge technology utilization ethernet data link layer bag data processing mechanism, the 2.5G public radio communication GPRS of system or CDMA2000 1X, obtain to be transferred to the packet of local mechanism at strange land mechanism ethernet data link layer, by the bag data transmission service of public radio communication system, be wirelessly transmitted to the data link layer of local mechanism Ethernet; Obtain to be transferred to the packet of strange land mechanism simultaneously in the local ethernet data link layer,, be wirelessly transmitted to the data link layer of strange land Ethernet by the bag data transmission service of public radio communication system.Realize the long-range transparent wireless transmission and the real-time, interactive of ethernet ip data between the network of strange land.
Wireless transparent VPN bridge system is made up of wireless VPN terminal and vpn gateway, and wireless VPN terminal works is at ethernet data link layer and GPRS/CDMA2000 1X wireless access network.Terminal ethernet line RJ45 interface receives the data that branch office network need send to main office network from ethernet link layer, converts GPRS/CDMA2000 1X transmission form and wireless launching to; Receiving GPRS/CDMA2000 1X downlink wireless data simultaneously, whether be information that vpn gateway send, if this information is the information that vpn gateway sends, then converts thereof into the Ethernet interface mode and export, otherwise this information is abandoned if analyzing this information.The VPN terminal is landed GPRS/CDMA2000 1X wireless network automatically, and the call treatment of real-time response wireless access network guarantees that terminal is always online.Wireless vpn gateway is operated in ethernet data link layer and GPRS/CDMA2000 1X Data packet network, to carry out the corresponding routing management for the network packet that the legal wireless VPN terminal that receives sends, guarantee that the data of a plurality of terminals can correctly arrive the purpose network.Intercepting and capturing the data that need send to branch office network,, send to the branch office network of VPN terminal seat simultaneously by GPRS/CDMA2000 1X Data packet network by link layer.Vpn gateway is implemented remote tracing to all wireless VPN terminals of reaching the standard grade, and understands the presence of VPN data terminal in real time, reaches the standard grade and rolls off the production line the time.Vpn gateway can concurrently carry out a large amount of wireless VPN terminal datas to be handled.
Wireless transparent VPN bridge system has highly encryption and authentication mechanism to the transmission of data, and is similar with the wired VPN that sets up on Internet, is enterprise's universal transparent wireless transmission vpn system of setting up on 2.5G wireless public network platform.Wireless VPN terminal and vpn gateway carry out the high strength encrypting processing to the data that needs send with block encryption algorithm, and the data that receive are made corresponding decryption processing, and the data of transmitting in GPRS/CDMA2000 1X network are data encrypted.The international mobile subscriber identity of wireless VPN terminal and link address must terminal can use after the gateway registration of center.The VPN terminal need be carried out the terminal identity authentication by the authentication service of vpn gateway, not by authenticated device, does not allow it to insert intranet; And can be with a VPN terminal and the binding of computing machine, prevent from that the VPN terminal from being usurped by other people to enter corporate intranet.Simultaneously wireless VPN terminal in line process, the real-time update by vpn gateway control VPN terminal key has realized system's high strength fail safe.
Wireless universal VPN bridge system does not need the wireless VPN networking of the enterprise-specific of commmunication company or CHINAUNICOM, just can easily realize the wireless transparent intercommunication of inner private network data between the enterprise strange land, by the wireless transparent bridge technology, a public network IP address that uses the common GSM subscriber identification module SIM card of opening packet data services or CDMA subscriber identification module UIM card and enterprise headquarters with regard to transparent the interconnecting that can realize IP data between branch's internal network and the general headquarters' internal network (as with regard to commmunication company, then not needing or not the special line of access point APN to enterprise headquarters with SIM card and certain special-purpose access point APN binding of moving certain inner IP and moving yet).
The present invention is desirable selection of low expense of realizing that strange land mechanism of enterprise, middle small data quantity internal information visit, Internet resources share.Native system has highly encryption and authentication mechanism to the transmission of data, and it is similar with the wired VPN that sets up on Internet, is enterprise's universal transparent wireless transmission vpn system of setting up on the wireless public network platform.This system is made up of wireless VPN terminal and vpn gateway, be applicable to the sector application that service access authority, Information Security, access protocol is had requirement, as the long-range transparent networking of branch of enterprise group, the transparent networking of the various electronics gathering POS machine of retail trade, the transparent networking of the various terminating machines of financial industry, the interim mobile office occasion of every profession and trade etc.
Description of drawings
Fig. 1: the protocol stack schematic diagram of wireless transparent VPN bridge technology.
Fig. 2: wireless transparent VPN bridge system structure chart.
Fig. 3: wireless VPN terminal data process chart.
Fig. 4: wireless vpn gateway communication process structure chart.
Embodiment
Next step accompanying drawings implementation method of the present invention.
Fig. 1: the protocol stack structure that wireless transparent VPN bridge technology is described.The general packet radio service gprs standard of Europe Electricity Federation ETSI is defined as the mode that the IP general transmission is carried all upper layer application protocol with the protocol stack of GPRS support node gateway, the IP-based flexibility that puts everything to its best use, the general transmission bearing function that is carried in simultaneously on the GPRS support node is finished the transfer of data that really is independent of data content; And according to the regulation of interoperability standard IOS V4.1, the A8 interface of CDMA2000 1X adopts the conventional data encapsulation to all kinds of business datums of user, transmits by IP network then, has equally also realized being independent of the transmission of user service data; Therefore take GPRS/CDMA2000 1X all kinds business datum not to be had the transmission process of Context resolution.After the link layer data by ethernet data link layer bag data processing mechanism acquisition strange land network, bag data transmission channel by 2.5G public radio communication GPRS of system or CDMA2000 1X carries out data packet transmission, after receiving the packet that is transferred to local mechanism, send it to the data link layer of the Ethernet of local mechanism, thereby realize the long-range transparent wireless transmission and the real-time, interactive of ethernet ip data between the network of strange land.
Fig. 2: the concrete network structure that general VPN bridge system is described.Vpn system is made up of wireless VPN terminal and vpn gateway, owing to adopt transparent VPN bridge technology, utilize the VPN equipment network, user's do not need additionally to develop software interface or client software is installed, all upper layer application systems are enterprise's original system application software, and the original software of enterprise, system or network are not needed to do any change.Enterprise branch office can receive wireless VPN transmission terminal on the hub or data switching exchane of office, some the affiliate computer or the network equipment that are connected to this moment on this hub (are assigned with Intranet IP address, corporate HQ, as: 172.16.3.168 etc.) can the long-range transparent internal network that has been connected to the corporate HQ (as the IP network section: 172.16.1.*), carry out inside data of enterprise transmission with corporate HQ's inner-mesh network equipment, actual effect etc. coexist and carry out information exchange on the same enterprise local area network.
Fig. 3: the wireless VPN terminal data process chart in the VPN bridge system is described.Wireless VPN terminal obtains configuration parameter earlier, carries out Ethernet interface and the initialization of GPRS/CDMA2000 1X network interface then.If receive the Ethernet data that need send to total portion mechanism after initialization is finished, send to GPRS/CDMA2000 1X network after then it being encrypted; If receive the data that vpn gateway is sent by GPRS/CDMA2000 1X network, carry out analyzing and processing after then data being decrypted processing, if network data then sends to the Ethernet of branch,, transmission security key then carries out the respective transmissions key updating if upgrading.
Fig. 4: the wireless vpn gateway communication process structure in the VPN bridge system is described.The vpn gateway mobile terminal receive after processing such as deciphering, decomposition and authentication, obtains branch's packet by the packet that GPRS support node gateway GGSN or bag data, services contact PDSN send, and sends to general headquarters' link layer of local area network then; The packet that general headquarters' local area network (LAN) main frame is responded waits the processing back to send to GGSN or PDSN by vpn gateway through encrypting.Vpn gateway carries out upgrading relevant operation with transmission security key simultaneously.

Claims (7)

1, wireless universal transparent virtual private network bridge transmission method based on packet wireless business GPRS/ code division multiple access CDMA2000 1X, be to serve as transmission basis with the public packet radio transfer of data of the 2.5G switching plane GPRS/CDMA2000 1X that present mobile communication carrier provides, it is characterized in that: this wireless transparent VPN bridge system mainly is made up of wireless VPN terminal and vpn gateway, wireless VPN terminal and vpn gateway all are operated in ethernet link layer, the transparent VPN bridge system of wireless universal adopts ethernet data link layer bag data processing mechanism, 2.5G the bag data transmission channel of the GPRS/CDMA2000 1X of public radio communication system, obtain required business data packet at the strange land ethernet data link layer by wireless VPN terminal, by the bag data transmission service of public radio communication system, be wirelessly transmitted to the data link layer of local ethernet; Vpn gateway obtains required business data packet in the local ethernet data link layer simultaneously, bag data transmission service by the public radio communication system, be wirelessly transmitted to the data link layer of strange land Ethernet, the long-range transparent wireless transmission that realizes Ethernet Internet protocol IP data between the network of strange land is with mutual.
2, wireless transparent VPN bridge system transmission method according to claim 1, it is characterized in that: wireless VPN terminal works is at ethernet data link layer and GPRS/CDMA2000 1X wireless access network, wireless VPN terminal receives branch office network by Ethernet RJ45 interface from ethernet link layer need send to the data of main office network, and converts GPRS/CDMA2000 1X transmission form to and go out with wireless transmission; Wireless VPN terminal receives the data of GPRS/CDMA2000 1X downlink wireless simultaneously, and whether analyze this information be the information that vpn gateway sends, and export if then convert thereof into the Ethernet interface mode, otherwise the VPN portable terminal abandons this information.
3, wireless transparent VPN bridge system transmission method according to claim 2, it is characterized in that: wireless VPN terminal is landed GPRS/CDMA2000 1X wireless network automatically, real-time response wireless access network service call is handled, and guarantees that wireless VPN terminal is really always online.
4, wireless transparent VPN bridge system transmission method according to claim 1, it is characterized in that: wireless vpn gateway is operated in ethernet data link layer and GPRS/CDMA2000 1X Data packet network, to carry out the corresponding routing management for the network packet that the legal wireless VPN terminal that receives sends, guarantee that the data of a plurality of terminals can correctly arrive the purpose network; Intercept and capture the business datum that need send to branch office network by link layer simultaneously,, send to the branch office network at wireless VPN terminal place by GPRS/CDMA2000 1X Data packet network.
5, wireless transparent VPN bridge system transmission method according to claim 4 is characterized in that: vpn gateway is implemented remote tracing to all wireless VPN terminals of reaching the standard grade, and understands the presence of VPN data terminal, the time of reaching the standard grade and rolling off the production line in real time.
6, according to the described wireless transparent VPN of claim 1 bridge system transmission method, it is characterized in that: wireless transparent VPN bridge system has highly encryption and authentication mechanism to the transmission of data, it is enterprise's universal transparent wireless transmission vpn system of on 2.5G wireless public network platform, setting up, the data that wireless VPN terminal and vpn gateway send needs are carried out high strength encrypting with block encryption algorithm and are handled, the data that receive are made corresponding decryption processing, wireless VPN terminal does not need China Mobile specific authorisation subscriber identification module SIM card or CHINAUNICOM's specific authorisation subscriber identification module UIM card just can insert vpn system, but the international mobile subscriber identity of VPN terminal and link address must terminal can use after the gateway registration of center, VPN terminal in actual the use need be carried out the terminal identity authentication by the authentication service of vpn gateway,, do not allow to insert intranet by authenticated device; But also can be with a VPN terminal and the binding of computing machine, prevent from that the VPN terminal from being usurped by other people to enter corporate intranet.
7, according to the described wireless transparent VPN of claim 6 bridge system transmission method, it is characterized in that: wireless VPN terminal in line process, by the real-time update of vpn gateway control VPN terminal key.
CNA2004100127615A 2004-02-24 2004-02-24 Transmission method of universal radio transparent VPN network bridge system based on GRPS/CDMA 2000 1X Pending CN1561040A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNA2004100127615A CN1561040A (en) 2004-02-24 2004-02-24 Transmission method of universal radio transparent VPN network bridge system based on GRPS/CDMA 2000 1X

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNA2004100127615A CN1561040A (en) 2004-02-24 2004-02-24 Transmission method of universal radio transparent VPN network bridge system based on GRPS/CDMA 2000 1X

Publications (1)

Publication Number Publication Date
CN1561040A true CN1561040A (en) 2005-01-05

Family

ID=34440075

Family Applications (1)

Application Number Title Priority Date Filing Date
CNA2004100127615A Pending CN1561040A (en) 2004-02-24 2004-02-24 Transmission method of universal radio transparent VPN network bridge system based on GRPS/CDMA 2000 1X

Country Status (1)

Country Link
CN (1) CN1561040A (en)

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101218577B (en) * 2005-07-08 2010-10-06 微软公司 Unified architecture for remote network access
CN101588379B (en) * 2009-06-26 2012-04-18 迈普通信技术股份有限公司 Multi-point access method for layer two virtual private network
CN102761864A (en) * 2011-04-29 2012-10-31 中国移动通信集团公司 Data transmission method, system and device
US8713305B2 (en) 2010-01-27 2014-04-29 Huawei Technologies Co., Ltd. Packet transmission method, apparatus, and network system
CN101150601B (en) * 2007-10-17 2014-09-10 中兴通讯股份有限公司 Multi-user concurrent access system and method
CN106330653A (en) * 2016-08-30 2017-01-11 成都极玩网络技术有限公司 Intelligent shunt gateway based on lightweight secure virtual private network
CN106972974A (en) * 2017-04-18 2017-07-21 南京南瑞集团公司 The Web network management systems and its terminal authentication method of a kind of electric power LTE wireless terminals
CN110535932A (en) * 2019-08-16 2019-12-03 太原理工大学 A kind of transnational enterprise's knowledge delivery system
CN113556340A (en) * 2021-07-21 2021-10-26 国网四川省电力公司乐山供电公司 Portable VPN terminal, data processing method and storage medium

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101218577B (en) * 2005-07-08 2010-10-06 微软公司 Unified architecture for remote network access
CN101150601B (en) * 2007-10-17 2014-09-10 中兴通讯股份有限公司 Multi-user concurrent access system and method
CN101588379B (en) * 2009-06-26 2012-04-18 迈普通信技术股份有限公司 Multi-point access method for layer two virtual private network
US8713305B2 (en) 2010-01-27 2014-04-29 Huawei Technologies Co., Ltd. Packet transmission method, apparatus, and network system
CN102761864A (en) * 2011-04-29 2012-10-31 中国移动通信集团公司 Data transmission method, system and device
CN102761864B (en) * 2011-04-29 2014-12-10 中国移动通信集团公司 Data transmission method, system and device
CN106330653A (en) * 2016-08-30 2017-01-11 成都极玩网络技术有限公司 Intelligent shunt gateway based on lightweight secure virtual private network
CN106972974A (en) * 2017-04-18 2017-07-21 南京南瑞集团公司 The Web network management systems and its terminal authentication method of a kind of electric power LTE wireless terminals
CN106972974B (en) * 2017-04-18 2018-09-25 南京南瑞集团公司 A kind of the Web network management systems and its terminal authentication method of electric power LTE wireless terminals
CN110535932A (en) * 2019-08-16 2019-12-03 太原理工大学 A kind of transnational enterprise's knowledge delivery system
CN113556340A (en) * 2021-07-21 2021-10-26 国网四川省电力公司乐山供电公司 Portable VPN terminal, data processing method and storage medium
CN113556340B (en) * 2021-07-21 2023-09-26 国网四川省电力公司乐山供电公司 Portable VPN terminal, data processing method and storage medium

Similar Documents

Publication Publication Date Title
CN101360011B (en) Management system supporting different data collection service
CN101018259B (en) Telecom integrated information system and method
US6912593B2 (en) Information switching platform
US20070195803A1 (en) Method and arrangement device relating to communication network
CN101588366B (en) System and method for accessing enterprise information system based on SaaS
CN1244076A (en) Method and structure for managing a set of mobile station in wireless data network
Contreras A tale of two layers: Patents, Standardization, and the Internet
CN105119787B (en) A kind of public internet access system and method based on software definition
CN1561040A (en) Transmission method of universal radio transparent VPN network bridge system based on GRPS/CDMA 2000 1X
CN101409939B (en) End-to-end system for implementing enterprise application data real time propelling movement and method thereof
CN1197296C (en) An information switch
CN201319608Y (en) Management system supporting different data acquisition services
CN1361968A (en) System and method for local policy enforcement for internet service providers
CN1703023A (en) CHINAMDN based wireless transparent D2D system transmission method
KR20230037183A (en) The system that supports on-line access to remotly located equipment/products
CN1859339B (en) Communication system and method for realizing IP cross-domain inter communication by edge media gateway
CN102843379B (en) A kind of authenticating network towards multiple access pattern
CN1241435C (en) Mobile service system
CN101436994B (en) System and method for limiting user TCP connection information
CN105049323B (en) Smart grid unified information communication system and method based on a kind of technology by IPv6
KR20140135077A (en) Separable charge system for byod service and separable charge method for data service
EP1356654B1 (en) System and method for assigning dynamic ip-addresses
FI108904B (en) A method for establishing data network connections
CN1464649A (en) Student monitoring system
CN206674005U (en) An intelligent logistics big data processing platform

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C02 Deemed withdrawal of patent application after publication (patent law 2001)
WD01 Invention patent application deemed withdrawn after publication