Implementation method and system of virtual private network
Abstract
The present invention discloses a method and system for implementing a virtual private network, which stores a VPN-dedicated mapping table for VPN in the mapping plane of an ID / locator isolated network. This VPN-dedicated mapping table effectively realizes a virtual private network in an ID / locator separated network by determining whether or not communication between VPN end host users in the VPN is realized. This method and system will meet the user's demand for virtual private networks, and the technology proposal to separate the ID and locator will remove the impact on the conventional VPN business and change to existing equipment and software by implementing VPN. To reduce. [Selection diagram] Fig. 1

Term
Projected expiry 10 September 2030.
- Priority
- Filed
- Published
- Today
- Projected expiry
12 claims: 4 independent, 8 dependent
- 1バーチャル・プライベート・ネットワーク(VPN)の実現方法であって、前記VPNはID/ロケータ分離ネットワークに基づき実現し、該方法は、ID/ロケータ分離ネットワークのマッピングプレーンは、VPNのVPN専用マッピングテーブルと普通マッピングテーブルを設置し、前記VPN専用マッピングテーブルは、同じVPNのVPNエンドホストのID識別子とロケータ識別子とのマッピング関係を含み、前記普通マッピングテーブルは、普通エンドホストのID識別子とロケータ識別子とのマッピング関係を含み、 前記マッピングプレーンは、目的エンドホストID識別子によって、ソースエンドホストのプロパティと一致するVPN専用マッピングテーブル或は普通マッピングテーブルを検索し、目的エンドホストのマッピング関係を見つければ、ID/ロケータ分離ネットワークは、ソースエンドホストと目的エンドホストと間の通信を実現し、目的エンドホストのマッピング関係を見つけなければ、通信が失敗してしまうことが含まれることを特徴とする。
- 2前記プロパティはエンドホストがVPNエンドホストに属するかどうかを示し、前記マッピングプレーンが目的エンドホストのID識別子によって、ソースエンドホストのプロパティと一致するVPN専用マッピングテーブル或は普通マッピングテーブルを検索するステップにおいて、ソースエンドホストのプロパティが、前記ソースエンドホストがVPNエンドホストであることを示すと、前記マッピングプレーンは、前記VPN専用マッピングテーブルを検索し、ソースエンドホストのプロパティが、前記ソースエンドホストがVPNエンドホストではないと示すと、前記マッピングプレーンは、前記普通マッピングテーブルを検索する 請求項1に記載の前記方法。
- 3前記マッピングプレーンは複数のVPN専用マッピングテーブルを含み、異なるVPN専用マッピングテーブルが異なるVPNに対応し、異なるVPN識別子を有し、 前記プロパティとはエンドホストがVPNエンドホストに属すかどうか及びVPNエンドホストに属する時、所属するVPN識別子を指し、 前記マッピングプレーンは目的エンドホストのID識別子によって、ソースエンドホストのプロパティと一致するVPN専用マッピングテーブル或は普通マッピングテーブルを検索するステップにおいて、ソースエンドホストのプロパティは、前記ソースエンドホストがVPNエンドホストであることを示すと、前記マッピングプレーンがVPN識別子と対応するVPN専用マッピングテーブルを検索し、ソースエンドホストのプロパティは、前記ソースエンドホストがVPNエンドホストではないと示すと、前記マッピングプレーンが前記普通マッピングテーブルを検索する 請求項1に記載の前記方法。
- 4前記マッピングプレーンが目的エンドホストのID識別子によって、ソースエンドホストのプロパティと一致するVPN専用マッピングテーブル或は普通マッピングテーブルを検索するステップの前に、前記方法は、 アクセスサービスノード(ASN) はソースエンドホストが送信したメッセージを受信し、その中にソースエンドホストID識別子と目的エンドホストID識別子が載せられ、 前記ASNはソースエンドホストID識別子によって、プロパティテーブルを検索し、ソースエンドホストのプロパティを獲得し、且つ、マッピングプレーンにメッセージを転送し、或は検索リクエストを送信し、その中にソースエンドホストのプロパティ及び目的エンドホストのID識別子が載せられ、 ID/ロケータ分離ネットワークにおいて、ソースエンドホストと目的エンドホストとの通信を実現するステップにおいて、前記ASN或はマッピングプレーンは前記目的ロケータ識別子が対応する目的アクセスサービスノードにメッセージを転送し、通信を実現することが更に含まれる 請求項1~3の何れか1項に記載の前記方法。
- 5前記ASN又はマッピングプレーンは、前記目的ロケータ識別子が対応する目的アクセスサービスノードにメッセージを転送し、通信を実現するステップの後に、前記方法は、 前記目的アクセスサービスノードが前記メッセージを受信し、且つ、目的エンドホストに転送するのと同時に、ソースエンドホストのID識別子とロケータ識別子のマッピング関係及びソースエンドホストのVPNプロパティをローカルマッピングテーブルに記録し、目的アクセスサービスノードは前記目的エンドホストが返却したメッセージを受信した後、ローカルマッピングテーブルを検索し、ソースホストと目的エンドホストのプロパティが一致すると判断すると、直接にメッセージの転送を行うことが更に含まれる 請求項4に記載の方法。
- 6バーチャル・プライベート・ネットワーク(VPN)の実現方法であって、前記VPNがID/ロケータ分離ネットワークに基づき実現し、該方法は、 ID/ロケータ分離ネットワークのマッピングプレーンはVPN専用マッピングテーブルを設置し、前記VPN専用マッピングテーブルは同じVPNのVPNエンドホストID識別子とロケータ識別子とのマッピング関係を含み、 前記マッピングプレーンは前記VPN専用マッピングテーブルを検索し、目的エンドホストのマッピング関係を見つけると、ID/ロケータ分離ネットワークはソースエンドホストと目的エンドホストとの通信を実現し、目的エンドホストのマッピング関係を見つけないと、通信が失敗することが含まれることを特徴とする。
- 7前記マッピングプレーンは同時に複数のVPN専用マッピングテーブルを設置し、異なるVPN専用マッピングテーブルが異なるVPNに対応し、異なるVPN識別子を有し、 前記マッピングプレーンは目的エンドホストID識別子によって、ソースエンドホストのVPN識別子と一致するVPN専用マッピングテーブルを検索し、目的エンドホストのマッピング関係を見つけると、ID/ロケータ分離ネットワークはソースエンドホストと目的エンドホスト間の通信を実現し、目的エンドホストのマッピング関係を見つけないと、通信が失敗する請求項6に記載の方法。
- 8前記マッピングプレーンが目的エンドホストのID識別子によって、ソースエンドホストのVPN識別子と一致するVPN専用マッピングテーブルを検索するステップの前に、前記方法は、 アクセスサービスノード(ASN) はソースエンドホストが送信したメッセージを受信し、その中にソースエンドホストID識別子と目的エンドホストID識別子が載せられ、 前記ASNはソースエンドホストID識別子によって、設置したプロパティテーブルを検索し、ソースエンドホストのプロパティを獲得し、且つ、マッピングプレーンにメッセージを転送し、或は検索リクエストを送信し、その中にソースエンドホストのプロパティ及び目的エンドホストのID識別子が載せられ、 ID/ロケータ分離ネットワークがソースエンドホストと目的エンドホストとの通信を実現するステップにおいて、前記ASN或はマッピングプレーンは前記目的ロケータ識別子が対応する目的アクセスサービスノードにメッセージを転送し、通信を実現することが更に含まれる請求項7に記載の前記方法。
- 9前記ASN又はマッピングプレーンは前記目的ロケータ識別子が対応する目的アクセスサービスノードにメッセージを転送し、通信を実現するステップの後に、前記方法は、 前記目的アクセスサービスノードが前記メッセージを受信し、且つ、目的エンドホストに転送するのと同時に、ソースエンドホストのID識別子とロケータ識別子のマッピング関係及びソースエンドホストのVPNプロパティをローカルマッピングテーブルに記録し、目的アクセスサービスノードは前記目的エンドホストが返却したメッセージを受信した後、ローカルマッピングテーブルを検索し、ソースホストと目的エンドホストのプロパティが一致すると判断すると、直接にメッセージの転送を行うことが更に含まれる 請求項8に記載の方法。
- 10バーチャル・プライベート・ネットワーク(VPN)の実現システムであって、前記システムはID/ロケータ分離アーキテクチャネットワークに基づき実現し、ネットワークで接続するサービスアクセスノード(ASN)とマッピングプレーンを含み、前記ASNは第1送受信モジュール、プロパティテーブル及びプロパティテーブル検索モジュールを含み、その中に、 前記第1送受信モジュールはソースエンドホストが送信したメッセージを受信し、その中にソースエンドID識別子と目的エンドホストID識別子が載せられ、且つ、プロパティテーブル検索モジュールに通知し、及びマッピングプレーンにメッセージを転送し、或は検索リクエストを送信し、その中に、ソースエンドホストのプロパティ及び目的エンドホストのID識別子が載せられるように設置され、前記マッピングプレーンに検索リクエストを送信する時、前記マッピングプレーンが送信した検索結果を受信し、目的エンドホストのマッピング関係を見つけると、検索結果によってメッセージを転送し、目的エンドホストのマッピング関係を見つけないと、通信が失敗するように更に設置され、 前記プロパティテーブルはエンドホストとそのプロパティの対応する関係を保存するように設置され、 前記プロパティテーブル検索モジュールは前記第1送受信モジュール、プロパティテーブルと接続し、前記ソースエンドホストID識別子によって、前記プロパティテーブルを検索し、ソースエンドホストのプロパティを獲得し、且つ、前記第1送受信モジュールに通知するように設置され、 前記マッピングプレーンは第2送受信モジュール、マッピングデータベース及びデータベース検索モジュールを含み、その中に、 前記第2送受信モジュールは、前記ASNが転送したメッセージ或は送信した検索リクエストを受信し、且つ、データベース検索モジュールに通知するように設置され、検索リクエストを受信する時、前記ASNに検索結果を転送するように更に設置され、転送したメッセージを受信する時、目的エンドホストのマッピング関係を見つけると、検索結果によって、メッセージを転送し、目的エンドホストのマッピング関係を見つけないと、通信が失敗し、 前記マッピングデータベースはVPN専用マッピングテーブルと普通マッピングテーブルを保存し、前記VPN専用マッピングテーブルが同じVPNのVPNエンドホストID識別子とロケータ識別子のマッピング関係を含み、前記普通マッピングテーブルが普通エンドホストID識別子とロケータ識別子のマッピング関係を含むように設置され、 前記データベース検索モジュールは前記第2送受信モジュール及びマッピングデータベースと接続し、目的エンドホストのID識別子によって、ソースエンドホストのプロパティと一致するVPN専用マッピングテーブル或は普通マッピングテーブルを検索し、且つ、検索結果を前記第2送受信信モジュールに通知するように設置される バーチャル・プライベート・ネットワーク(VPN)の実現システム。
- 11前記プロパティはエンドホストがVPNエンドホストに属するかどうかを示し、 前記マッピングプレーンのデータベース検索モジュールは、ソースエンドホストのプロパティは前記ソースエンドホストがVPNエンドホストであると示すと、前記VPN専用マッピングテーブルを検索し、ソースエンドホストのプロパティは前記ソースエンドホストがVPNエンドホストではないと示すと、前記普通マッピングテーブルを検索するように設置される 請求項10に記載のシステム。
- 12前記マッピングプレーンのマッピングデータベースは複数のVPN専用マッピングテーブルを含み、異なるVPN専用マッピングテーブルが異なるVPNと対応し、異なるVPN識別子を有し、 前記プロパティとはエンドホストがVPNエンドホストに属するかどうか、及びVPNエンドホストに属する時、所属するVPN識別子を示し、 前記マッピングプレーンのデータベース検索モジュールは、ソースエンドホストのプロパティは前記ソースエンドホストがVPNエンドホストであると示すと、VPN識別子と対応するVPN専用マッピングテーブルを検索し、ソースエンドホストのプロパティは前記ソースエンドホストがVPNエンドホストではないと示すと、前記普通マッピングテーブルを検索するように設置される請求項10に記載の前記システム。
Independent claims12
84 paragraphs, as filed
The present invention relates to an ID / locator separation technology, and more particularly to a method and system for realizing a virtual private network in an ID / locator separation network.
Research on next-generation information network architectures is one of the most popular challenges today. The basic direction of these research subjects is to seamlessly integrate telecommunications networks represented by voice services, television networks represented by video services, and the Internet represented by data services. , The feature is that the network carrier is converted to IP. Typical examples are, for example, VOIP (Voice over Internet Protocol) networks that provide voice services and IPTV networks that provide TV services, 3rd generation mobile communication networks in which IP core networks are carriers, and a large number of supermarkets. There are research items for 3G or 4G networks.
4G is an abbreviation for 4th generation mobile communication system. 4G aims to provide voice, data and streaming media services with solutions based on IP carrier networks, giving users a faster communication environment at any time, any place, any service. To do.
NGN (Next Generation Network) is a next-generation network established on the basis of telecommunications networks, and is intended to establish a transport layer based on unified IP packet switching. In the unified transport layer, the development of various application programs can be independent of the specific transmission technology, expanding the application range of the application programs.
Today's IP packet carrier networks are based on IPv4 and have evolved. Since IP technology was originally born in the United States, a large amount of IPv4 is available in developed countries such as the United States. The addresses are distributed. On the other hand, very few IP addresses are distributed to developing countries with a large population, which limits the development of IP packet carrier networks and various communication networks in developing countries to a shortage of IP addresses. For example, the current number of Internet users in Japan exceeds the number of IPv4 addresses that Japan already has. And since the number of network users in Japan is increasing at a high speed, there is no choice but to increase the duplicate use of IP addresses with other technologies and equipment. Therefore, the problem of insufficient IP address space severely hinders the future development of IP carrier networks and communication networks in Japan. The most ideal way to solve this problem is to use IPV6. However, this drastic change to network architecture technology will require the payment of a large amount of costs associated with constructing a new IPv6 carrier network and the replacement of a number of terminals calculated at 100 million. From there, it turned out that this was not a good idea for the current situation.
From the above technical studies, it was found that the problems and difficulties faced are the same, although there are major differences in the research focus and direction selection for the next-generation network architecture due to differences in technical foundations, profit backgrounds, etc. It was.
In 3G and 4G, the field of wireless communication is the research center for next-generation networks, and it is intended to improve the quality of wireless mobile communication based on the entire IP packet core network, NGN and NGI (Next-Generation Internet, next). The telecommunications network and the Internet field are researches for next-generation network integration, respectively, and CNGI (China's Next Generation) Internet, China's next-generation Internet) intends to build a next-generation Internet based on IPv6, and Beijing Jiaotong University's "Basic Research on Integrated Reliable Network and Extensive Service System" builds a unified new packet network. I hope I can do it. Although there are major differences between the various studies, the common point of view is that the future network will be a unified carrier network based on packets. For this reason, researching the next-generation .NET framework makes the Internet a major reference. Since its birth, the Internet has been developing at a much higher speed and has already become the most successful and most vibrant communication network. Features such as its flexible expandability, highly efficient packet switching, and the powerful functions of terminals. Is well suited to the design demands of new generation networks. The Internet will be the main reference model for new generation network design. However, the structure of the Internet has not yet been optimized, and there are many serious design problems. In addition to the fact that the IP address space cannot satisfy the application demand, the following directions have appeared.
The Internet was invented in the 70s of the 20th century, but it was difficult for people at that time to predict the existence of a large number of mobile terminals and multihoming terminals in today's world. For this reason, the Internet Protocol stack at the time was primarily designed for terminals connected in a "fixed" manner. Under the network environment at that time, terminals basically do not move from one locator to another, so the sending address is the receiving address, and the reversible route creates dual properties of ID and locator. The IP address I had worked well and there was no conflict between the ID property and the locator property of the IP address. IP addresses that represent IDs and locators at the same time just meet the demands of networks at the time. From the perspective of the network environment of the time, such a design proposal is simple and effective, and simplifies the hierarchical structure of the protocol stack. It is natural that there is an internal contradiction between the ID property of the IP address and the locator property. The ID property of an IP address requires that any two IP addresses be equal, and IP addresses can be distributed by organizational structure, but there is an inevitable relationship between consecutively coded IP addresses. There is no, or at least in the topology locator, there is no inevitable relationship. The IP address locator property requires that IP addresses be distributed based on the network topology (not the organizational structure), and all IP addresses located within the same subnet are placed in one contiguous IP address block. In this way, the IP address prefixes in the network topology are aggregated, thereby reducing the items in the routing table of the router equipment and ensuring the scalability of the router system.
With the scale of networks and the development of technology, a technology for dynamically distributing IP addresses is gradually appearing. For example, the Dynamic Host Configuration Protocol (DHCP) breaks the assumption that the IP address displays the only terminal. Use of private IP address space and network address translation (NAT, Network Address) The birth of Translator) technology exacerbates the situation. Under these circumstances, IP addresses that have ID and locator properties at the same time continue to play no role, and the dual property problem of IP addresses has already emerged. In addition to the obvious changes in technology demand, there have also been huge changes in Internet user conditions. In the first few years after the Internet was born, it was used by mutually trusted personnel who were basically in the same group, and traditional Internet Protocol stacks were also designed based on this type of assumption. However, today's Internet users are in a very "cobblestone mixed" situation, and people are no longer able to trust each other. Under these circumstances, the Internet, which lacks embedded security measures, also needs to be transformed.
In summary, internal inconsistencies in the dual properties of IP addresses cause the following problems:
1. Router expandable problem There are basic assumptions about the scalability of Internet router systems. That is, the assumption is that "addresses are distributed by topology, or topology is distributed by address, and one is selected from the two." The ID property of the IP address requires that the IP address be distributed based on the organizational structure (not the network topology) to which the terminal belongs. Such distributions, while maintaining a certain degree of stability, cannot be easily changed. The IP address locator property requires that the IP address be distributed based on the network topology to ensure the scalability of the router system. This causes a conflict between the two properties of the IP address, which ultimately leads to the scalability problem of the Internet router system.
2. Mobility problem The ID property of the IP address requires that the IP address does not change as the terminal locator changes. As a result, it is possible to guarantee that the communication bound to the ID is not interrupted, and further, after the terminal moves, another terminal can use the ID and establish a communication communication with it. The IP address locator property requires that the IP address change as the terminal locator changes, thus allowing the IP address to be aggregated into a new network topology. Otherwise, the network must always hold a single router information for the terminal after the move, which leads to a rapid increase in the routing table items.
3. Multihoming problem Multihoming usually means that a terminal or network accesses the Internet through the networks of multiple ISPs (Internet Service Providers) at the same time. Benefits of multihoming technology include increasing network reliability, helping equalize network traffic loads across multiple ISPs, and increasing overall available bandwidth. However, the internal contradiction of the dual properties of IP addresses makes it difficult to realize multihoming technology. The ID property of an IP address requires that one multihoming terminal always show another terminal an immutable ID, no matter how many ISPs this multihoming terminal accesses the Internet. The IP address locator property requires one multihoming terminal to communicate using different IP addresses in different ISP networks, thus ensuring that the terminal's IP addresses are aggregated into the topology of the ISP network.
4. Safety and locator privacy issues Since the IP address includes the terminal ID information and the locator information at the same time, the respondent node and the malicious eavesdropper simultaneously acquire the terminal ID information and the topology locator information by the IP address of one terminal. be able to.
In general, since the establishment of the conventional systematic structure of the Internet, extremely large changes have occurred in both the technical environment of the Internet and the user group. The Internet needs to innovate accordingly. The IP address dual property problem is one of the basic problems that hinders the continuous development of the Internet, and separating the ID property and locator property of the IP address is a problem facing the Internet. Is a good idea to solve. The new network is designed based on this idea, providing a network structure that separates and maps ID information and locator information, and solves some serious harmful effects existing on the existing Internet.
Much research and exploration has been done in the industry to solve the ID and locator problem, and the basic idea of separating all IDs and locators is to bind them all to their original IP address. Separating the ID and locator dual properties. One idea is the URL of the application layer (Uniform Resource Locator, URL is an identifier method that completely draws the addresses of web pages and other resources on the Internet) or FQDN (Fully Qualified Domain). Name, pass domain name) is adopted as the ID identifier of the terminal, for example, IPNL (IP Next Layer, belongs to the method of NAT extended architecture), TRIAD (A Scalable Deployable NAT-based Internet Architecture, expandable and (It is a network architecture based on NAT that is easy to deploy), etc., and some proposals introduce a new namespace as an ID identifier, for example, HIP (Host Identity). In the network layer where the IP address is the locator identifier in Protocol (Host Identification Protocol), the host identifier is increased, and some proposals classify the IP address, part of the IP is the ID identifier, and part of the IP is the locator identifier. , For example LISP (Locator / ID Separation) The Chinese patent claim CN1801764 disclosed on July 12, 2006, such as Protocol, locator ID separation protocol), is an "Internet access method based on ID and locator separation" applied by a person such as Zhang Hong Department of Northern Jiaotong University. The method solves the problem of separating the ID and the locator by using the IP address as the host locator identifier and the host identifier at the introduction end as the ID identifier. In these solutions above, the host-based solution needs to improve the host's protocol stack, for example the HIP, network-based solution needs to improve the router of the identified locator. And, similarly, as a network-based solution, not all locators that have a router that has completed the ID and locator mapping function in the network are the same. One idea is to clarify where the router that has completed the mapping function is located on the boundary of the user network, that is, the router with the mapping function belongs to the user network, and one idea (LISP, TIDR (Tunneled Inter-domain)) Routing (routing between tunnel domains) and Ivip (Internet Vastly Improved Plumbing)) do not limit the existence locators in the network by the router that has completed the mapping function, and one idea is that the router can be expanded. Clarify that the mapping information to be resolved and guarantee the ID and locator can be obtained only by the network administrator, and strictly limit that the router that has completed the mapping function is the core network access router, that is, the mapping function router is the core network. Belongs to. In the solution where the ID identifier and the locator identifier are located at the same time in the network layer, for example, in LISP, there is a design difference in which the ID and the locator are completely separated by strictly dividing the network topology. The current version of the LISP protocol always uses an EID (Endpoint Identifier) before the network provides a mapping analysis service, routes the first data package to the other end, and is a two-way communication tunnel router. RLOC (Routing) Require students to study the mapping relationship between Locator (Router Locator Identifier) and EID, so that at least some router nodes in the network simultaneously hold router items based on RLOC and EID, and LISP can extend the router. It will affect your ability to solve problems.
Since the submission goals of the proposal to separate various IDs and locators are different, the functions to be finally realized are also different. The design objective of IPNL is to gain longer life in IPv4 networks and avoid the total reconstruction challenges posed by redeeming the IPv4 protocol with the IPv6 protocol. The purpose of TRIAD's design is to solve various problems that NAT has brought to the Internet, and at the same time, to provide mobility and a certain amount of support for strategic routers and the like. The initial purpose of submitting the HIP is to solve safety issues, and then to do a lot of work in mobility support and to study multihoming support. SHIM6 (Level 3 Shim for IPv6) was submitted mainly to solve the problem that IPv6 networks can support multihoming. The design objective of LIN6 (Location Independent Networking for IPv6) is to provide mobility and multihoming solutions that can be selected for the IPv6 protocol. ILNP (Identifier Locator Network) The design goal of Protocol) is to provide an IPv6 extension mechanism that can solve mobility and multihoming problems. GSE (Global, Site and End-System Designator) intends to change the structure of IPv6 addresses, and therefore controls the increase of global routing table items and flexibly supports multihoming technology. TIDR's design goal is to strengthen existing Internet routers and transmission capabilities to solve problems such as overall routing table expansion, interdomain routing security and multihoming. LISP is primarily designed for router extensible problems.
The above proposals and proposals provide solutions to separate IDs and locators from problematic locals under existing network architectures, and separating locators and IDs is a future data communication network, especially mobile data communication networks. Is the core technology of.
A VPN (virtual private network) can provide interconnection between components and resources in different networks. VPNs utilize the infrastructure of Internet networks or other public networks to create new tunnels for users and provide the same security and functional security as dedicated networks.
VPN has various realization methods, and specifically, it is divided into a VPN solution managed by a user (CPE-VPN) and a VPN solution implemented by a telecommunications carrier (PP-VPN).
The feature of the user-managed VPN solution (CPE-VPN plan) is that the user self-installs, manages and maintains the VPN gateway equipment, and the public IP network makes it a standard VPN tunnel between each branch mechanism and the parent company. Establishing a based connection, tunnel protocols are typically Layer 2 Tunneling Protocol (L2TP), Point-to-Point Tunneling Protocol (PPTP), IPsec (Secure IP), IP in IP (IP Encapsulation) and GRE (Generic). Use Routing Encapsulation, etc., and use various encryption technologies and NAT technologies to ensure the security of data transmission.
The establishment and management of the VPN tunnel connection is entirely up to the user and the supplier does not need to adjust or change the structure and performance of the network. Such a method is usually called the "VPN self-establishment" method.
VPN supports companies to establish connections with branching mechanisms or other companies via public networks such as the Internet for secure communication. Such a VPN connection established via the Internet is theoretically equivalent to a connection established in a wide area network between two locations. VPN communication has been established on the basis of public networks, but when using a VPN, users feel that they are communicating using a dedicated network, so the name of a virtual private network is obtained. By using VPN technology, the current telecommunications volume is increasing day by day, and in the situation where the global operation of the company is widely distributed, it is necessary for employees to access the central resource, and it is necessary for the company to access the central resource. It is possible to solve the problem of prompt and effective communication.
Basic use of VPN: VPNs provide long-distance user access and support VPNs to access corporate resources over long distances through public networks in a secure manner, for example, VPN users first network of local access service providers (ISPs). Dial an access server (BRAS), then use VPN software, and use an established connection with your local ISP to create a VPN across one Internet or other public network between a long-distance user and your corporate VPN server. Is newly created.
Using VPN to connect long-distance local area networks, without using expensive long-distance dedicated circuits, branching mechanisms and corporate routers use their local dedicated lines to connect local ISPs. Connect to the Internet via or access the ISP's broadband access server through dial-up and connect to the internet. Using VPN software, create a new VPN between the branching mechanism and the corporate router using the connection established with the local ISP and the Internet network.
The VPN solution (PP-VPN) implemented by the telecommunications carrier is to install a VPN gateway facility in the telecommunications carrier's public data communication network and access the user by a dedicated line or by dial-up over a long distance. Used for access. Using the gateway equipment, a VPN can be established in the entire network network by technologies such as channel encapsulation, virtual router or MPLS (multiprotocol label switching) according to the specific demand of the VPN network, and Adopt encryption technology to ensure the security of data transmission. The establishment of the VPN connection is entirely done by the carrier and disclosed to the user. Such a method is what is often referred to as an "outsourcing VPN" method.
With the rapid development of broadband access networks, the problem that carriers have to solve in order to develop quality operations is how to make a rational stratification plan for the network structure. So, it is to realize measurement for users and control of business. Since a large amount of Ethernet (registered trademark) technology has been adopted for the access network layer surface, the technology for realizing network division based on the current Ethernet (registered trademark) is mainly virtual local area network (VLAN, Virtual Local Area Network). ) Technology. VLAN is an emerging technology that realizes virtual workgroups by logically dividing equipment in a local area network into individual segments rather than physically. IEEE (IEEE (The Institute of Electrical and Electronics) Engineers, International Association of Electrical and Electronic Engineers)) will publish in 1999 a draft 802.1Q protocol standard used to standardize the VLAN implementation strategy. In the traditional Ethernet (registered trademark) frame format, 4096 VLANs are defined, and the VLAN is submitted to solve the broadcasting problem and safety of Ethernet (registered trademark), which is the Ethernet (registered trademark) frame. Increase VLAN heads on top, divide users into smaller workgroups by VLAN ID, limit user two-tier mutual access between different workgroups, and each workgroup has one virtual local area network Is. The advantage of a virtual local area network is that the broadcast range can be limited, virtual workgroups can be formed, and the network can be controlled dynamically. Since the VLANs separate the broadcast storm and the communication between the different VLANs, the communication between the different VLANs is completed by the router.
There are mainly several methods for dividing VLANs. The first is to divide the VLAN by port. The method of dividing VLANs by port in this way is the most commonly used method. The second is MAC (Media Access) (Control, medium access control) VLANs are divided by address. The biggest advantage of this method of partitioning VLANs is that when the user's physical locator moves, that is, when moving from one switch to another, the VLAN does not need to be reconfigured. is there. The flaw is that the switch runs inefficiently because it is always configured by all users when it is initialized. The third is to divide the VLAN by the network layer. In this way, the method of dividing VLAN is not by router but by network layer address or protocol type (for example, supporting multiple protocols) of each host, so even if the physical locator of the user changes, it belongs again. It is not necessary to configure the VLAN to be used. The flaw is that re-analyzing the frame header reduces efficiency. Fourth, the VLAN is divided by IP multicast. Consider that IP multicast is actually the definition of VLAN, that is, one multicast group is one VLAN. The method of dividing in this way extends the VLAN to a wide area network. For this reason, such methods have greater flexibility and are easily extended by routers.
VLAN has been extensively applied to broadband access as a VPN technology in certain Ethernet® communication environments, and is often applied in core or wide area networks based on Multiprotocol Label Switching (MPLS). It is a VPN.
The advent of Multiprotocol Label Switching (MPLS) technology is changing the entire systematic structure of the Internet. The proposed technology to realize VPN by adopting MPLS technology provides the same security guarantee as Frame Relay or ATM (Asynchronous Transfer Mode) network while significantly improving the defects of conventional IP networks. However, it can adapt to the demand of VPN business well.
The network model for MPLS VPNs may be routers or Layer 2 switches, with customer edge (CE, Customer Edge) equipment located at the client and providing access to network suppliers, and transfers primarily associated with nodes. Maintains tables, exchanges VPN router information with other PE routers, and forwards VPN operations using Label Switched Paths (LSPs) in the MPLS network, which is the Label Edge Router (LSP) in the MPLS network. Using a provider edge (PE, Provider Edge) router that is a LER, Label Edge Router) and an already established LSP, transparent transfer is performed for VPN data, and routing information related to VPN is not maintained. This includes supplier routers (PR, Provider Routers), which are Label Switching Routers (LSRs) in MPLS networks.
Benefits of MPLS VPN: Security: MPLS VPNs provide a means of preventing attacks and label fraud by adopting a variety of measures such as routing isolation, address isolation and information hiding. Therefore, MPLS VPNs can provide a security guarantee that is completely similar to ATM / FR VPNs.
Scalability: MPLS has very strong extensibility. One has a large number of VPN points that can be stored in the MPLS network, and the other has BGP (Border Gateway Protocol) in the number of nodes of the user, and the same VPN is distributed and managed by the members. The number of nodes of the user in the above is not limited, it is easy to expand, and direct communication between any node and any other node can be realized. In particular, when realizing network-like communication between user nodes, there is no need to configure the circuit between user nodes item by clause, and the user side only has one port / one line to access the network. Well, it avoids the scalability problem of N squares.
Reliability: The MPLS VPN business naturally has a large bandwidth, many nodes, many routers, sufficient network and transmission resources, and guarantees the reliability of the network. When the relay line inside the Internet is interrupted, the network traffic of the MPLS VPN is diverted to other circuits by IGP (Interior Gateway Protocol) together with ordinary Internet traffic, and this process is completely by the convergence of IGP. It is automatically completed, completely transparent to the user, and there is no single failure in the transmission of wide area networks.
<p> The technology plan to separate the ID and locator affects the above VPN technology, affects the VPN solution (PP-VPN) implemented by the telecommunications carrier, and especially affects the plan related to the 3-layer IP address. Largely, separating the locator and ID is mainly related to the VPN user's ID identifier and communication protocol, and VPN access management uses the end host's ID identifier to perform certification management and upgrade the management system. It is necessary to perform processing, but after separating the locator and ID for the VPN solution (CPE-VPN plan) managed by the user, the end host stops communicating using the IP address again, and the end host ID identifier It is necessary to use EID, and communication with it has a relatively large impact, and it is necessary to upgrade the VPN software to support the ID identifier of the end host.</p><p> The problem to be solved by the present invention is to conveniently realize a virtual private network in an ID / locator separated network by providing a method and a system for realizing a virtual private network.</p>
<p> In order to solve the above technical problems, the present invention provides a method for realizing a virtual private network, and the virtual private network is based on the realization of an ID / locator separated network. A: The mapping plane of the ID / locator separated network has a VPN-dedicated mapping table and a normal mapping table of the virtual private network (VPN), and the VPN-dedicated mapping table is the ID identifier and locator of the VPN end host of the same VPN network. Includes a mapping relationship with the identifier, the normal mapping table contains a mapping relationship between the ID identifier of the normal end host and the locator identifier B: The mapping plane searches the VPN-only mapping table or the normal mapping table that matches the properties of the source end host by the target end host ID identifier, and if the mapping relationship of the target end host is found, the ID / locator separation network is It involves achieving communication between the source end host and the target end host, or the communication will fail.</p><p> The property indicates whether or not the end host belongs to the VPN end host, and in step B, when the property of the source end host indicates that the source end host is the VPN end host, the mapping plane is the VPN dedicated mapping. It is preferable to search the table and otherwise search the ordinary mapping table.</p><p> The mapping plane contains some VPN-only mapping tables, different VPN-only mapping tables correspond to different VPN networks, have different VPN identifiers, and the properties are whether the end host belongs to the VPN end host and the VPN end. When belonging to a host, it points to the VPN identifier to which it belongs, and in step B, if the property of the source end host indicates that the source end host is a VPN end host, the mapping plane corresponds to the VPN identifier in the VPN dedicated mapping table. If not, it is preferable to search the ordinary mapping table.</p><p> Step B is B1: The Access Service Node (ASN) receives the message sent by the source end host, which contains the source end host ID identifier and the target end host ID identifier. B2: The ASN searches the installed property table by the source end host ID identifier, acquires the source end host property, and forwards the message to the mapping plane, or sends a search request in it. Contains the properties of the source end host and the ID identifier of the target end host. B3: The mapping plane searches for a VPN-only mapping table or a normal mapping table that matches the properties of the source end host by the target end host ID identifier. B4: If the search result contains the locator identifier of the target end host, the ASN or mapping plane forwards the message to the target access service node to which the target locator identifier corresponds, enabling communication, otherwise communication It is preferable to include failure.</p><p> After step B4, at the same time that the target access service node receives the message and forwards it to the target end host, the mapping relationship between the source end host ID identifier and the locator identifier and the VPN property of the source end host are locally mapped. After recording in the table and receiving the message returned by the destination access service node from the destination end host, the local mapping table is searched, and if it is determined that the properties of the source end host and the destination end host match, the message is directly sent. It is preferable to carry out the transfer.</p><p> In order to solve the above technical problems, the present invention also provides a method for realizing a virtual private network, in which the virtual private network is realized based on an ID / locator separated network. A: The mapping plane of the ID / locator separated network has a virtual private network (VPN) dedicated mapping table, and the VPN dedicated mapping table includes the mapping relationship between the VPN end host ID identifier and the locator identifier of the same VPN network. , B: When the mapping plane searches the VPN-dedicated mapping table and finds the mapping relationship of the target end host, the ID / locator separation network realizes communication between the source end host and the target end host, otherwise communication. Is characterized by including failure.</p><p> The mapping plane has a plurality of VPN-dedicated mapping tables installed at the same time, and different VPN-dedicated mapping tables correspond to different VPNs and have different VPN identifiers. In step B, the mapping plane searches the VPN-dedicated mapping table that matches the VPN identifier of the source end host by the target end host ID identifier, finds the mapping relationship of the target end host, and the ID / locator isolation network is the source end. It is preferable that the communication fails unless the communication between the host and the target end host is realized and the mapping relationship of the target end host is found.</p><p> Step B is B1: The Access Service Node (ASN) receives the message sent by the source end host, which contains the ID identifiers of the source end and the destination end host. B2: The ASN searches the installed property table by the ID identifier of the source end host, acquires the properties of the source end host, and forwards the message to the mapping plane or sends a search request in it. , Source end host properties and purpose end host ID identifier B3: The mapping plane searches the VPN-only mapping table that matches the properties of the source end host by the ID identifier of the target end host. B4: If the search result includes the locator identifier of the target end host, the ASN or mapping plane forwards the message to the corresponding target access service node of the target locator identifier to achieve communication, otherwise communication fails. For example.</p><p> After step B4, at the same time that the target access service node receives the message and forwards it to the target end host, the mapping relationship between the source end host ID identifier and the locator identifier and the VPN property of the source end host are locally mapped. After receiving the message returned by the target end host, the target access service node searches the local mapping table and determines that the properties of the source and target end host match, and directly transfers the message. Is preferable.</p><p> In order to solve the above technical problems, the present invention further provides a virtual private network realization system, which is realized based on an ID / locator separation architecture network and is a service access node (ASN) connected by a network. ) And the mapping plane, the ASN contains a first transmit / receive module, a property table and a property table search module, in which: The first transmission / reception module receives the message sent by the source end host, contains the source end and the target end host ID identifier, notifies the property table search module, and transfers the message to the mapping plane. Alternatively, when a search request is sent and the properties of the source end host and the ID identifier of the target end host are placed therein, and the search request is sent to the mapping plane, the mapping plane It is further installed to receive the sent search results, and when it finds the mapping relationship of the target end host, it forwards the message according to the search results, otherwise it is further installed to fail the communication. The property table is set up to store the corresponding relationship between the end host and its properties. The property table search module is connected to the first transmission / reception module and the property table, searches the property table by the source end host ID identifier, acquires the property of the source end host, and obtains the property of the source end host, and the first transmission / reception module. Installed to notify The mapping plane includes a second transmit / receive module, a mapping database and a database search module, in which the mapping plane is included. The second transmission / reception module is installed so as to receive the message transferred by the ASN or the search request transmitted and notify the database search module, and when the search request is received, the search result is transferred to the ASN. When receiving the forwarded message, if the mapping relationship of the target end host is detected, the message will be forwarded according to the search result, otherwise the communication will fail. The mapping database stores a dedicated mapping table and a normal mapping table of a virtual private network (VPN), and the VPN dedicated mapping table includes a mapping relationship between a VPN end host ID identifier and a locator identifier of the same VPN network. The normal mapping table is set up to contain the mapping relationship between the normal end host ID identifier and the locator identifier. The database search module connects to the second transmission / reception module and the mapping database, searches for a VPN-dedicated mapping table or a normal mapping table that matches the properties of the source end host by the ID identifier of the target end host, and searches results. Is installed so as to notify the second transmission / reception module.</p><p> The property indicates whether or not the end host belongs to the VPN end host, and when the property of the source end host indicates that the source end host is the VPN end host, the database search module of the mapping plane is the VPN dedicated mapping table. If not, it is preferable to search the ordinary mapping table.</p><p> The mapping database of the mapping plane contains some VPN-only mapping tables, different VPN-only mapping tables correspond to different VPN networks, have different VPN identifiers, and the property is whether the end host belongs to the VPN end host. , And when belonging to a VPN end host, it points to the VPN identifier to which it belongs, and if the properties of the source end host indicate that the source end host is a VPN end host, the database search module of the mapping plane corresponds to the VPN identifier. It is preferable to search the VPN-dedicated mapping table, otherwise to search the normal mapping table.</p><p> In order to solve the above technical problems, the present invention further provides a method for realizing a virtual private network, and the virtual private network is realized based on an ID / locator separated network. A: The mapping plane of the ID / locator separated network has a dedicated mapping table for the virtual private network (VPN), and the VPN dedicated mapping table shows the mapping relationship between the ID identifier and the locator identifier of the VPN end host of the same VPN network. Including B: When the source end host is a VPN end host, the ID / locator separated network includes realizing communication between the VPN end hosts in the VPN by the VPN dedicated mapping table.</p><p> The mapping plane has multiple VPN-dedicated mapping tables installed at the same time, different VPN-dedicated mapping tables correspond to different VPN networks, have different VPN identifiers, and in step B, the ID / locator separation network is the VPN of the source end host. It is preferable to realize communication between VPN end hosts in the corresponding VPN by using a VPN-dedicated mapping table that matches the identifier.</p>
<p> The present invention stores a VPN-dedicated mapping table for VPN in the mapping plane of the ID / locator-separated network, and determines whether or not communication between VPN end host users in the VPN is realized by this VPN-dedicated mapping table. So, in the ID / locator separation network, the technical proposal to effectively realize the virtual private network, meet the demand for the virtual private network by the user, and separate the ID and the locator is the conventional virtual private network. Eliminate the impact on network VPN operations.</p>
<figref num="1">FIG. 1 is a schematic diagram of a method of realizing a virtual private network according to an embodiment of the present invention.</figref><figref num="2">FIG. 2 is a schematic diagram of an ID / locator separation architecture used to realize the virtual private network of the embodiment according to the present invention.</figref><figref num="3">FIG. 3 is a schematic diagram for realizing a virtual private network in the ID / locator separated network shown in FIG.</figref><figref num="4">Fig. 4 is a flow diagram of an application example that realizes data package processing in a network architecture based on Fig. 3.</figref><figref num="5">FIG. 5 is a schematic diagram of the module structure of the virtual private network realization system according to the embodiment of the present invention.</figref>
A data communication network that separates the ID and the locator always separates the ID property and the locator property of the conventional IP address, and the IP address only has the locator property, and as the identifier of the geographical locator of the end host, the end host An ID identifier is newly established and used for the end ID identifier of communication transmission, and the locator identifier of the end host is determined by the geographical locator and network topology in which the end host is located. Although it causes a change in the locator identifier of the end host, the ID identifier of the end host belongs to the identifier used only for the terminal ID, and has a feature that it does not change in the process of moving the end host. At the same time, the mapping between the end host ID identifier and the locator identifier increases, and it is necessary to complete this mapping relationship with the functional entity, and the present invention refers to this functional entity as the mapping plane.
In the plan to separate various IDs and locators, the name of this mapping plane is also different. For example, the patent ZL200610001825.0 of Beijing Jiaotong University's patent ZL200610001825.0 interprets this, and introduced an ID analyzer to introduce an end host identifier. Responsible for parsing the mapping relationship between the EID and the IP address, and dynamically maintaining and updating the binding between the end host identifier EID and the IP address. In the LISP technical proposal, the LISP3 scene adopts a mapping database, provides a mapping relationship between the ID identifier EID and the locator identifier RLOC, and uses the distributed hash table LISPDHT (LISP Distributed Hash Tables) for mapping. The database is studying. It is also called a mapping server in other plans, and is collectively called a mapping plane in the present invention.
The main spirit of the realization method and realization system of the virtual private network of the present invention is to store the VPN-dedicated mapping table of the virtual private network (Virtual Private Network, VPN) in the mapping plane of the ID / locator separated network. When the source end host is a VPN end host, the ID / locator separated network effectively virtualizes in the ID / locator separated network by realizing communication between the VPN end hosts in the VPN by the VPN dedicated mapping table. -Achieve a private network, meet the demand for virtual private networks by users, and a technology proposal that separates IDs and locators removes the impact on traditional virtual private network VPN services.
For example, as shown in FIG. 1, the method of realizing the virtual private network according to the embodiment of the present invention is realized based on the ID / locator separated network. The mapping plane of the ID / locator separated network has a VPN dedicated mapping table and a normal mapping table of the virtual private network (VPN), and the VPN end host ID identifier and the locator identifier of the same VPN network as the above VPN dedicated mapping table are mapped. Step 101, which includes a relationship and the above normal mapping table contains a mapping relationship between a normal end host ID identifier and a locator identifier, The above mapping plane searches the VPN dedicated mapping table or normal mapping table that matches the source end host property by the target end host ID identifier, and if the mapping relationship of the target end host is detected, the ID / locator separation network is the source. Includes step 102, where communication between end hosts is achieved, otherwise communication fails.
The above embodiment realizes normal communication and one VPN network communication at the same time in the same ID / locator separated network.
To if the mapping plane having only one VPN dedicated mapping table, the property refers to whether the end host belongs to a VPN end host, the step 102 Oite, properties of the source end host the source end host VPN If it is indicated as an end host, the mapping plane searches the VPN-dedicated mapping table, otherwise it searches the normal mapping table.
In order to realize multiple virtual private networks in the same ID / locator separated network, multiple VPN dedicated mapping tables are installed on the mapping plane, different VPN dedicated mapping tables correspond to different VPN networks, and different VPN identifiers. The above property indicates whether or not the end host belongs to the VPN end host, and when it belongs to the VPN end host, the VPN identifier to which the end host belongs. In step 102, the property of the source end host indicates that the source end host belongs to the VPN end. If it is indicated as a host, the mapping plane searches the VPN-dedicated mapping table corresponding to the VPN identifier, otherwise it searches the normal mapping table.
Of course, the present invention is also applied to the realization of a plurality of different VPNs in an ID / locator separated network by installing a plurality of VPN-dedicated mapping tables instead of the mapping plane normally. If so, the virtual private network implementation method of another embodiment of the present invention is A: The mapping plane of the ID / locator separated network has multiple virtual private network (VPN) dedicated mapping tables, and the mapping relationship between the VPN end host ID identifier and the locator identifier of the same VPN network for each VPN dedicated mapping table. Including, different VPN dedicated mapping tables correspond to different VPN networks, have different VPN identifiers, B: The above mapping plane searches the VPN-dedicated mapping table that matches the source end host VPN identifier by the target end host ID identifier, and when the mapping relationship of the target end host is found, the ID / locator separation network is the source and the target end host. Communication can be achieved, or it can be organized so that communication fails.
The ID / locator isolation network includes an access service node and a mapping plane, and when step 102 and step B are specifically realized, the mapping plane realizes the transfer of the message, or the transfer plane other than the mapping plane realizes the message. Achieve the transfer of, specifically a: The Access Service Node (ASN) receives the message sent by the source end host, which contains the source end and the destination end host ID identifier. b: The above ASN searches the installed property table by the source end host ID identifier, acquires the source end host property, transfers the message to the mapping plane, or sends the search request, and the source in it. Contains end host properties and purpose end host ID identifier c: The mapping plane looks up the VPN-only mapping table that matches the properties of the source end host by the destination end host ID identifier. d: If the search result includes the locator identifier of the target end host, the ASN or mapping plane forwards the message to the corresponding destination access service node of the target locator identifier to achieve communication, otherwise communication fails. That is included.
Further, as a modification of the above embodiment, the following embodiment can be provided.
It is a method of realizing a virtual private network, and the above virtual private network is realized based on an ID / locator separated network. A: The mapping plane of the ID / locator separated network has a virtual private network (VPN) dedicated mapping table, and the above VPN dedicated mapping table includes the mapping relationship between the VPN end host ID identifier and the locator identifier of the same VPN network. , B: When the source end host is a VPN end host, the ID / locator separated network includes the realization of communication between the VPN end hosts in the VPN by the VPN dedicated mapping table.
The above mapping plane can install multiple VPN dedicated mapping tables at the same time, different VPN dedicated mapping tables correspond to different VPN networks and have different VPN identifiers, and in step B, the ID / locator separated network is the source end host VPN identifier. It is preferable to realize communication between VPN end hosts in the corresponding VPN by using a VPN-dedicated mapping table that matches.
The realization method of the present invention will be described in detail by taking as an example the realization of message transfer in the mapping plane with reference to the attached figure.
A schematic of the ID / locator isolation network architecture is that the user's end hosts (ie terminals, eg, first end host 100 and second end host 110 shown in Figure 2) use the ID identifier EID, as shown in Figure 2. , Each end host has a unique ID identifier, and the network's Access Service Nodes (eg, 1st ASN200 and 2nd ASN210) are transferred or received by the terminal. Encapsulates, maps, and forwards messages, finds the mapping between the end host ID identifier and locator identifier on the mapping plane 300, and maps the data message forwarding plane (abbreviated as forwarding plane) 400 to the access service node ASN. Forwarding the message after it is done, the mapping plane 300 maintains the mapping relationship between the end host ID identifier and the locator identifier, maintains appropriate updates of the mapping relationship, provides the ASN with a mapping search, and IDs. Search for a locator identifier by identifier.
As shown in the table below, the mapping plane 300 stores the correspondence between the ID identifier EID and the locator identifier LID of all terminals in the network.<tables num="1"><img file="JP2013504960A_D0001.tif" /></tables>
The processing of the message by the access service node ASN is as follows.
The first ASN200 receives a message sent by the first end host 100 to the second end host 110, and the sent message contains the ID identifier EID (1), and at this time, the target EID (2) is used to search the local mapping relationship table. If detected, message encapsulation is performed by the target LID (2) directly searched and its own LID (1), then transferred, sent to the transfer plane, and if not detected, the LID in the mapping plane. Search for (2).
When the second ASN210 at the communication partner end receives the message encapsulated by its own LID (2) address, it decapsulates and downlinks the EID (2) message after decapsulation to the second end host 110. Transferring, and at the same time studying the mapping relationship between the message source LID (1) and EID (1), the second ASN210 receives the message sent by the second end host 110 to the first end host 100, and at the other end Since the 2nd ASN210 has already studied the mapping relationship between EID (1) and LID (1) in the above flow, if the mapping relationship is detected locally on the 2nd ASN210, it can always be detected and it is necessary to search the mapping plane 300. At this time, LID (1) is directly encapsulated and transferred in the second ASN210. When the message returns to ASN1 through the transfer plane 400, it decapsulates and then ships to the first end host 100.
The method of realizing VPN under the network architecture shown in Fig. 2 is as follows.
First, a mapping table dedicated to the virtual private network VPN is installed on the mapping plane 300, and includes the mapping relationship between the ID identifiers and locator identifiers of all user end hosts of the VPN. At this time, the mapping plane has two types of mapping tables, one is a normal mapping table and the other is a VPN-dedicated mapping table.
Next, set up a VPN property table on the access service node ASN that the VPN network user accesses, and when the ASN processes this end host message, it shows that only the VPN-dedicated mapping table of the VPN to which this user belongs can be searched. Communication between users is established, and users other than this VPN-dedicated mapping table cannot establish communication, and at the same time, users other than the VPN-dedicated mapping table cannot search the VPN-dedicated mapping table, cannot access the VPN network, and VPN. Guarantee the security of your network.
There can be multiple VPN-only mapping tables, each VPN-only mapping table has one VPN identifier VPN_ID, and one such network can support multiple VPNs, meeting the application demand of many corporate networks. Fulfill.
User-end-host mapping relationships in the VPN-only mapping table can be dynamically subscribed or deleted.
When setting the VPN property accessed by the user in the ASN so that the mapping table of the identifier VPN_ID having the VPN in the mapping plane can be conveniently searched, the identifier VPN_ID of the VPN to which the user belongs is included.
Properties for users to access the VPN in the ASN can be fixedly configured and may be captured from the mapping plane 300.
VPN technology proposals provided by existing carriers can be implemented on the transfer plane, for example, providing MPLS VPN technology, secure transfer of data flow and QOS guarantee, linking the VPN technology proposal of the present invention, and connecting the VPN technology proposal of the other party. By authenticating to the ID identifier, it is possible to prevent attack means such as forgery and tampering by the conventional method from interfering with the VPN network and provide higher security, and at the same time, the uniqueness of the ID identifier is the movement of the user. Guarantees support for access, supports roaming users to access the VPN network securely at any time, and is especially advantageous for corporate users on the road.
Figure 3 shows a schematic diagram of an application example that realizes an ID / locator separation network architecture for a VPN network.
VPN-only mapping table example: It is the first virtual private network, distributes the VPN identifier VPN_ID_ (1), and the VPN-dedicated mapping table that it has is shown below.<tables num="2"><img file="JP2013504960A_D0002.tif" /></tables>
The second virtual private network distributes the VPN identifier VPN_ID_ (2), and its VPN-dedicated mapping table is as follows.<tables num="3"><img file="JP2013504960A_D0003.tif" /></tables>
Since the VPNs must be separated and cannot communicate with each other, the table items in the mapping table of VPN identifier VPN_ID_ (1) and the table items in the mapping table of VPN identifier VPN_ID_ (2) cannot overlap.
As shown in Fig. 4, the processing flow of the data message is as follows. The first ASN receives the message sent by the first end host to the second end host, and the sent message is the ID identifier EID of the first end host. Step 401, including (a1), The 1st ASN determines from the VPN property table that the 1st end host is a VPN user and is a virtual private network belonging to the VPN identifier = VPN_ID_ (1), and the 1st ASN sends a search request to the mapping plane. Step 402 with the VPN property of the first end host (which may just include the VPN identifier) and the objective ID identifier in it, Step 403 of searching the VPN-dedicated mapping table whose VPN identifier is VPN_ID_ (1) by the target ID identifier of the mapping plane and returning the search result to the 1st ASN, The 1st ASN processes a message according to the search result, and if the target ID identifier is EID (a2) and the search result returned from the mapping plane does not have this partner end, it belongs to the invalid partner end and communication is not possible, VPN Guarantee that only internal users can communicate, if the target ID identifier is EID (b1) and the search result returned from the mapping plane is the locator identifier LID (b1), the 1st ASN performs normal transfer processing and sends a message. If the transfer plane supports the existing VPN technology, the correspondence between the VPN identifier (MPLS VPN1) of the transfer plane and the VPN identifier VPN_ID_ (1) of the present invention can be established, and the data message is transferred. Step 404, which provides security and QoS (quality of service) quality assurance in the plane, The second ASN at the communication partner receives the message encapsulated by its own LID (b1) address, decapsulates it, and downlinks the EID (b1) message after decapsulation to the second end host. At the same time, step 405 to study the mapping relationship between the message source LID (b1) and EID (b1) and VPN properties, and The second ASN receives the message sent by the second end host to the first end host in step 406, Since the 2nd ASN at the other end has already studied the mapping relationship between EID (b1) and LID (b1) and VPN properties in the above flow, if the mapping relationship is detected locally at the 2nd ASN, it can always be detected and the mapping plane. VPN identifier VPN_ID_ (1) There is no need to search the VPN dedicated mapping table, and at this time, step 407 that directly encapsulates LID (a1) in the second ASN and transfers it to the first ASN, Includes step 408, which returns to the first ASN through the transfer plane, decapsulates the first ASN, and then ships to the first end host.
In order to realize the above method, the present invention further provides a virtual private network realization system, and as shown in FIG. 5, the virtual private network (VPN) realization system is a service connected by a network. The access node (ASN) 500 and the mapping plane 510 are included, and the ASN 500 includes a first transmission / reception module 501, a property table 502, and a property table search module 503.
The first transmission / reception module 501 receives a message transmitted by the source end host, contains the source end and the target end host ID identifier, notifies the property table search module 503, and maps plane 510. When sending a search request to the mapping plane 510, it is installed so that the source end host property and the target end host ID identifier can be placed in it, and when the search request is sent to the mapping plane 510. When the search result sent by 510 is received and the mapping relationship of the target end host is detected, the message is forwarded according to the search result, otherwise the communication is set to fail, and when the mapping relationship fluctuates, the above mapping It will be further installed to send a registration or cancellation request to the plane 510.
The property table 502 is set up to store the correspondence between the end host and its properties.
The property table search module 503 connects to the first transmission / reception module 501 and the property table 502, searches the property table 502 by the source end host ID identifier, acquires the source end host property, and obtains the source end host property. 1 Used to notify the send / receive module 501.
The mapping plane 510 includes a second transmission / reception module 511, a mapping database 512, a database search module 513, and a maintenance module 514.
Among them, when the second transmission / reception module 511 receives the message transferred by the ASN500 or the search request to be transmitted, notifies the database search module 513, and receives the search request, the search result is sent to the ASN500. When sending and receiving a forwarded message, if the mapping relationship of the target end host is detected, the message is forwarded according to the search result, otherwise communication is set to fail and the above ASN500 registration or cancellation request is made. Further installed to receive.
The mapping database 512 stores a VPN-dedicated mapping table and a normal mapping table, the VPN-dedicated mapping table includes a mapping relationship between a VPN end host ID identifier and a locator identifier of the same VPN network, and the normal mapping table is a normal end. It is installed so as to include the mapping relationship between the host ID identifier and the locator identifier.
The database search module 513 is installed so as to connect to the second transmission / reception module 511 and the mapping database 512 and search for a VPN-dedicated mapping table or a normal mapping table that matches the source end host property by the target end host ID identifier. It is used to notify the second transmission / reception module 511 of the search result.
In contrast to having only one VPN-only mapping table, the above property indicates whether the end host belongs to the VPN end host, and the property of the source end host indicates that the source end host is a VPN end host. The plain database search module searches the VPN-only mapping table, otherwise it searches the normal mapping table.
When having multiple VPN-dedicated mapping tables, different VPN-dedicated mapping tables correspond to different VPN networks and have different VPN identifiers, and the above properties indicate whether the end host belongs to the VPN end host and the VPN end host. When it belongs to, it points to the VPN identifier to which it belongs, and if the property of the source end host indicates that the source end host is the VPN end host, the database search module 513 of the mapping plane will set the VPN identifier and the corresponding VPN dedicated mapping table. Search, otherwise search the above normal mapping table.
The maintenance module 514 connects to the second transmission / reception module 511 of the mapping plane, the normal mapping table, and the VPN dedicated mapping table (that is, the mapping database 512), and upon registration or cancellation request of ASN500, the normal mapping table or VPN dedicated. It is installed to increase or delete the mapping relationships in the mapping table.
The present invention stores a VPN-dedicated mapping table for VPN in the mapping plane of the ID / locator separated network, and determines whether or not communication between VPN end host users in the VPN is realized by this VPN-dedicated mapping table. By doing so, in the ID / locator separation network, the technology plan to effectively realize the virtual private network, meet the demand for the virtual private network by the user, and separate the ID and the locator will be the conventional VPN service. It is a VPN solution (PP-VPN) to remove the influence of VPN, reduce changes to existing equipment and software due to VPN implementation, and implement it especially for credit operators, and the method according to the present invention is realized by the mapping plane. It is a kind of VPN solution implemented by telecommunications carriers.
A person skilled in the art can complete all or part of the steps in the above method by instructing the relevant hardware by a program, which can be stored in a computer's readable storage medium, such as a read-only memory, magnetic disk or optical disk. Can be understood. All or part of the steps of the above embodiment can be selectively implemented with one or more integrated circuits. Correspondingly, each module / unit in the above embodiment can be realized by the form of hardware, and can be realized by adopting the form of software function module. The present invention is not limited to any particular type of hardware and software combination.
The present invention will be described in connection with specific examples, which can be modified and modified by those skilled in the art under conditions that do not deviate from the gist or scope of the invention. Such modifications and modifications shall be deemed to be within the scope of the invention and the scope of the attachment.
The present invention provides a method and system for realizing a virtual private network, stores a VPN-dedicated mapping table for VPN in the mapping plane of an ID / locator-separated network, and uses this VPN-dedicated mapping table to create a VPN within the VPN. By deciding whether to realize communication between end host users, it is possible to effectively realize a virtual private network in an ID / locator separated network, and the user can meet the demand for the virtual private network and ID. The technology plan to separate the locator from the locator will remove the impact on the conventional VPN business and reduce the changes to existing equipment and software due to the implementation of VPN.
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JP2000183968A | Cites | Japan | Examiner |
| JP2003008631A | Cites | Japan | Search report |
| JP2008098881A | Cites | Japan | Examiner |
| JPN6013030519; D. Farinacci: 'Locator/ID Separation Protocol (LISP)' draft-farinacci-lisp-12.txt , 20090302 | Non-patent | – | Examiner |
| JPN6013030516; D. Farinacci: 'LISP Map Server' draft-fuller-lisp-ms-00.txt , 20090303 | Non-patent | – | Examiner |
14 members in 6 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 200910176529 | China | A | |
| 200910176529 | China | A | |
| 2009101765298 | China | – | |
| 2010076788 | China | W | |
| 2010076788 | China | W | |
| 20092009176529 | – | – | – |
| 2010076788 | – | – | – |
| CN200910176529 | – | – | – |
| CN20091176529 | – | – | – |
| WO2010CN76788 | – | – | – |
Members14
| Document | Office | Kind | |
|---|---|---|---|
| WO2011032473A1 | World Intellectual Property Organization (WIPO) | A1 | |
| CN102025589A | China | A | |
| EP2466818A1 | European Patent Office (EPO) | A1 | |
| US2012180122A1 | United States of America | A1 | |
| KR20120100927A | Republic of Korea | A | |
| KR20120100927A | Republic of Korea | A | |
| JP2013504960AThis record | Japan | A | |
| KR101340495B1 | Republic of Korea | B1 | |
| KR101340495B1 | Republic of Korea | B1 | |
| US8661525B2 | United States of America | B2 | |
| JP5579853B2 | Japan | B2 | |
| EP2466818A4 | European Patent Office (EPO) | A4 | |
| CN102025589B | China | B | |
| CN102025589B | China | B |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 |
Numbers
- Publication
- 2013504960
- Publication, DOCDB
- 2013504960
- Publication, EPODOC
- JP2013504960
- Application
- 2012529109
- Application, DOCDB
- 2012529109
- Application, EPODOC
- JP20120529109
Titles2
- Japanese
- バーチャル・プライベート・ネットワークの実現方法及びシステム
- English
- Realization method and system of virtual private network
Classification
- CPC, 5
- H04L61/103
- H04L12/4633
- H04L12/4641
- H04L2101/69
- H04L12/28
- IPC, 3
- H04L12 70
- H04L12 46
- H04L12 701
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo