Movatterモバイル変換


[0]ホーム

URL:


CN105577630B - A kind of internet access method and terminal based on multisystem - Google Patents

A kind of internet access method and terminal based on multisystem
Download PDF

Info

Publication number
CN105577630B
CN105577630BCN201510220486.4ACN201510220486ACN105577630BCN 105577630 BCN105577630 BCN 105577630BCN 201510220486 ACN201510220486 ACN 201510220486ACN 105577630 BCN105577630 BCN 105577630B
Authority
CN
China
Prior art keywords
address
preset
source
segment
unit
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201510220486.4A
Other languages
Chinese (zh)
Other versions
CN105577630A (en
Inventor
关学进
李静
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Shebohui Art Exhibition Co.,Ltd.
Original Assignee
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Yulong Computer Telecommunication Scientific Shenzhen Co LtdfiledCriticalYulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority to CN201510220486.4ApriorityCriticalpatent/CN105577630B/en
Publication of CN105577630ApublicationCriticalpatent/CN105577630A/en
Application grantedgrantedCritical
Publication of CN105577630BpublicationCriticalpatent/CN105577630B/en
Activelegal-statusCriticalCurrent
Anticipated expirationlegal-statusCritical

Links

Landscapes

Abstract

Translated fromChinese

本发明实施例公开了一种基于多系统的上网方法及终端,应用于终端,其中方法包括:第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包,所述第一系统和所述第二系统为在所述终端运行的操作系统;所述第二系统接收所述访问数据包;所述第二系统从所述访问数据包中提取所述源IP地址,并判断提取的所述源IP地址是否包含于预先设置的预设IP地址段中;若提取的所述源IP地址包含于所述预设IP地址段中,则所述第二系统将所述访问数据包发送至所述目的IP地址所在终端。可见,本发明实施例能够为操作系统提供网络服务,且能够保障操作系统的安全需求。

The embodiment of the present invention discloses a multi-system-based Internet access method and terminal, which are applied to the terminal, wherein the method includes: the first system sends an access data packet including the source IP address and the destination IP address to the second system, and the second system The first system and the second system are operating systems running on the terminal; the second system receives the access data packet; the second system extracts the source IP address from the access data packet, and judging whether the extracted source IP address is included in a preset preset IP address segment; if the extracted source IP address is included in the preset IP address segment, the second system will access the The data packet is sent to the terminal where the destination IP address is located. It can be seen that the embodiment of the present invention can provide network services for the operating system and can guarantee the security requirements of the operating system.

Description

Translated fromChinese
一种基于多系统的上网方法及终端A method and terminal for accessing the Internet based on multiple systems

技术领域technical field

本发明涉及互联网技术领域,尤其涉及一种基于多系统的上网方法及终端。The invention relates to the technical field of the Internet, in particular to a multi-system-based method for surfing the Internet and a terminal.

背景技术Background technique

目前随着智能终端的发展,智能终端已成为用户生活必不可缺的物品。用户经常使用智能终端上网娱乐,例如,浏览网页、观看视频等等;用户也经常使用智能终端进行办公,例如,阅读文件、编辑文字等等。在实际应用中,为满足用户的不同需求,智能终端中可能搭载多套操作系统,例如:用于上网娱乐的娱乐操作系统、用于学习的学习操作系统和用于办公的办公操作系统等等。其中,为保证操作系统的安全,智能终端搭载的一些操作系统不提供网络服务,例如办公操作系统。但是,为保证系统安全而屏蔽网络服务,也导致在操作系统不能对远程事务进行处理,因此,提供一种能够在操作系统安全地上网方式非常重要。At present, with the development of smart terminals, smart terminals have become an indispensable item in users' lives. Users often use smart terminals to surf the Internet for entertainment, for example, to browse webpages, watch videos, etc.; users also often use smart terminals for office work, for example, to read files, edit text, and so on. In practical applications, in order to meet the different needs of users, smart terminals may be equipped with multiple sets of operating systems, such as entertainment operating systems for Internet entertainment, learning operating systems for learning, and office operating systems for office work, etc. . Among them, in order to ensure the safety of the operating system, some operating systems carried by smart terminals do not provide network services, such as office operating systems. However, shielding network services to ensure system security also results in the inability to process remote transactions in the operating system. Therefore, it is very important to provide a way to safely surf the Internet in the operating system.

发明内容Contents of the invention

本发明实施例公开了一种基于多系统的上网方法及终端,能够为操作系统提供网络服务,且能够保障操作系统的安全需求。The embodiment of the invention discloses a multi-system-based Internet access method and a terminal, which can provide network services for an operating system and can guarantee the safety requirements of the operating system.

本发明实施例公开了一种基于多系统的上网方法,应用于终端,所述方法包括:The embodiment of the present invention discloses a method for accessing the Internet based on multiple systems, which is applied to a terminal, and the method includes:

第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包,所述第一系统和所述第二系统为在所述终端运行的操作系统;The first system sends an access data packet including a source IP address and a destination IP address to a second system, and the first system and the second system are operating systems running on the terminal;

所述第二系统接收所述访问数据包;the second system receives the access packet;

所述第二系统从所述访问数据包中提取所述源IP地址,并判断提取的所述源IP地址是否包含于预先设置的预设IP地址段中;The second system extracts the source IP address from the access data packet, and determines whether the extracted source IP address is included in a preset preset IP address segment;

若提取的所述源IP地址包含于所述预设IP地址段中,则所述第二系统将所述访问数据包发送至所述目的IP地址所在终端。If the extracted source IP address is included in the preset IP address segment, the second system sends the access data packet to the terminal where the destination IP address is located.

本发明实施例还公开了一种终端,所述终端包括:第一发送单元、接收单元、判断单元和第二发送单元,其中:The embodiment of the present invention also discloses a terminal, the terminal includes: a first sending unit, a receiving unit, a judging unit and a second sending unit, wherein:

所述第一发送单元,用于控制第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包,所述第一系统和所述第二系统为在所述终端上运行的操作系统;The first sending unit is configured to control the first system to send an access data packet including the source IP address and the destination IP address to the second system, the first system and the second system are running on the terminal operating system;

所述接收单元,用于控制所述第二系统接收所述访问数据包;The receiving unit is configured to control the second system to receive the access data packet;

所述判断单元,用于控制所述第二系统从所述访问数据包中提取所述源IP地址,并判断提取的所述源IP地址是否包含于预先设置的预设IP地址段中;The judging unit is configured to control the second system to extract the source IP address from the access data packet, and judge whether the extracted source IP address is included in a preset preset IP address segment;

所述第二发送单元,用于若提取的所述源IP地址包含于所述预设IP地址段中,则控制所述第二系统将所述访问数据包发送至所述目的IP地址所在终端。The second sending unit is configured to control the second system to send the access data packet to the terminal where the destination IP address is located if the extracted source IP address is included in the preset IP address segment .

在本发明实施例中,终端同时运行有第一系统和第二系统时,当第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包之后,第二系统将从访问数据包中提取源IP地址,并判断提取的源IP地址是否包含于预先设置的预设IP地址段中;若提取的源IP地址包含于预设IP地址段中,则第二系统将访问数据包发送至目的IP地址所在终端。可见,本发明实施例能够为操作系统提供网络服务,且能够保障操作系统的安全需求。In the embodiment of the present invention, when the terminal runs the first system and the second system at the same time, after the first system sends the access packet containing the source IP address and the destination IP address to the second system, the second system will access the Extract the source IP address from the data packet, and judge whether the extracted source IP address is included in the preset IP address segment; if the extracted source IP address is included in the preset IP address segment, the second system will access the data The packet is sent to the terminal where the destination IP address is located. It can be seen that the embodiment of the present invention can provide network services for the operating system and can guarantee the security requirements of the operating system.

附图说明Description of drawings

为了更清楚地说明本发明实施例中的技术方案,下面将对实施例中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings that need to be used in the embodiments. Obviously, the drawings in the following description are some embodiments of the present invention. Those of ordinary skill in the art can also obtain other drawings based on these drawings without any creative effort.

图1是本发明实施例公开的一种基于多系统的上网方法的流程示意图;FIG. 1 is a schematic flow diagram of a method for accessing the Internet based on multiple systems disclosed in an embodiment of the present invention;

图2是本发明实施例公开的另一种基于多系统的上网方法的流程示意图;FIG. 2 is a schematic flowchart of another method for accessing the Internet based on multiple systems disclosed in an embodiment of the present invention;

图3是本发明实施例公开的另一种基于多系统的上网方法的流程示意图;FIG. 3 is a schematic flowchart of another method for accessing the Internet based on multiple systems disclosed in an embodiment of the present invention;

图4是本发明实施例公开的一种终端的结构示意图;FIG. 4 is a schematic structural diagram of a terminal disclosed in an embodiment of the present invention;

图5是本发明实施例公开的另一种终端的结构示意图;FIG. 5 is a schematic structural diagram of another terminal disclosed in an embodiment of the present invention;

图6是本发明实施例公开的另一种终端的结构示意图。Fig. 6 is a schematic structural diagram of another terminal disclosed in an embodiment of the present invention.

具体实施方式detailed description

下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some of the embodiments of the present invention, but not all of them. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.

本发明实施例公开了一种基于多系统的上网方法及终端,能够为操作系统提供网络服务,且能够保障操作系统的安全需求。以下分别进行详细说明。The embodiment of the invention discloses a multi-system-based Internet access method and a terminal, which can provide network services for an operating system and can guarantee the safety requirements of the operating system. Each will be described in detail below.

请参见图1,图1为本发明实施例公开的一种基于多系统的上网方法的流程示意图。如图1所示,该基于多系统的上网方法可以包括以下步骤。Please refer to FIG. 1 . FIG. 1 is a schematic flowchart of a method for accessing the Internet based on multiple systems disclosed in an embodiment of the present invention. As shown in Fig. 1, the method for accessing the Internet based on multiple systems may include the following steps.

S101、第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包,该第一系统和该第二系统为在终端运行的操作系统。S101. The first system sends an access data packet including a source IP address and a destination IP address to a second system, where the first system and the second system are operating systems running on a terminal.

本发明实施例中,终端可包括多个运行的操作系统,该终端至少包括一个第一系统和一个第二系统。该终端可包括但不仅限于智能手机(如Android手机、iOS手机等)、平板电脑、掌上电脑、移动互联网设备(MID,Mobile Internet Devices)或穿戴式智能设备等包含多个系统的终端设备。In the embodiment of the present invention, the terminal may include multiple running operating systems, and the terminal includes at least one first system and one second system. The terminal may include, but not limited to, smart phones (such as Android phones, iOS phones, etc.), tablet computers, palmtop computers, mobile Internet devices (MID, Mobile Internet Devices) or wearable smart devices that include multiple systems.

本发明实施例中,第一系统和第二系统同时运行于该终端。该第一系统可包括但不限于用于办公的办公操作系统,该第二系统可包括但不限于用于上网娱乐的娱乐操作系统,如Android操作系统、IOS操作系统等等。当第一系统为终端前台运行的操作系统,第二系统为终端后台运行的操作系统时,用户可以使用第一系统进行上网。当用户在第一系统输入针对目标IP地址的访问请求时,第一系统将响应该访问请求,获取在第一系统下终端的IP地址作为源IP地址,并根据该访问请求生成包括源IP地址和目的IP地址的访问数据包。第一系统生成访问数据包之后,将向在终端后台运行的第二系统发送该访问数据包;具体地,第一系统可以以广播的形式向第二系统发送该访问数据包。In the embodiment of the present invention, the first system and the second system run on the terminal at the same time. The first system may include but not limited to an office operating system used for office work, and the second system may include but not limited to an entertainment operating system used for Internet entertainment, such as Android operating system, IOS operating system and so on. When the first system is the operating system running in the foreground of the terminal and the second system is the operating system running in the background of the terminal, the user can use the first system to surf the Internet. When the user enters an access request for the target IP address in the first system, the first system will respond to the access request, obtain the IP address of the terminal under the first system as the source IP address, and generate an IP address containing the source IP address according to the access request. and destination IP address access packets. After the first system generates the access data packet, it will send the access data packet to the second system running in the background of the terminal; specifically, the first system may send the access data packet to the second system in the form of broadcast.

S102、第二系统接收访问数据包。S102. The second system receives the access data packet.

S103、第二系统从访问数据包中提取源IP地址,并判断提取的源IP地址是否包含于预先设置的预设IP地址段中。S103. The second system extracts the source IP address from the access data packet, and judges whether the extracted source IP address is included in a preset preset IP address segment.

本发明实施例中,用户可在第二系统预先设置预设IP地址段,该预设IP地址段为一个或多个IP地址的集合。在第二系统接收到访问数据包之后,第二系统将从访问数据包中提取源IP地址,并且判断从访问数据包中提取的源IP地址是否包含于预设IP地址段中。若提取的源IP地址包含于预设IP地址段中,则执行步骤S104;若提取的源IP地址不包含于预设IP地址段中,则第二系统丢弃访问数据包并结束流程。In the embodiment of the present invention, the user can preset a preset IP address segment in the second system, and the preset IP address segment is a collection of one or more IP addresses. After the second system receives the access data packet, the second system will extract the source IP address from the access data packet, and judge whether the source IP address extracted from the access data packet is included in the preset IP address segment. If the extracted source IP address is included in the preset IP address segment, step S104 is executed; if the extracted source IP address is not included in the preset IP address segment, the second system discards the access data packet and ends the process.

本发明实施例中,用户可在第二系统设置安全性较高的网络的IP地址集合为预设IP地址段;例如VPN(Virtual Private Network,虚拟专用网络)相较于其他无线网络具有安全性高的优点,因此,用户可在第二系统设置VPN网络的IP地址集合为预设IP地址段。只有当源IP地址包含于预先设置的VPN网络IP地址集合中时,第二系统才将访问数据包发送至目的IP地址所在终端;当第二系统开启GPRS(General Packet Radio Service,通用分组无线服务)或其他WIFI无线网络时,将不能进行网络数据访问。因此,在本发明实施例中,通过第二系统判断源IP地址是否为预设IP地址段中的IP地址,若是,则第二系统才将访问数据包发送至目的IP地址所在终端,从而保障了第一系统访问网络的安全性。In the embodiment of the present invention, the user can set the IP address set of the network with higher security as the preset IP address segment in the second system; for example, VPN (Virtual Private Network, virtual private network) has security compared to other wireless networks High advantage, therefore, the user can set the IP address set of the VPN network as a preset IP address segment in the second system. Only when the source IP address is included in the preset VPN network IP address set, the second system sends the access data packet to the terminal where the destination IP address is located; when the second system opens GPRS (General Packet Radio Service, general packet radio service ) or other WIFI wireless network, network data access will not be available. Therefore, in the embodiment of the present invention, the second system judges whether the source IP address is an IP address in the preset IP address segment, and if so, the second system sends the access data packet to the terminal where the destination IP address is located, thereby ensuring It ensures the security of the first system to access the network.

S104、第二系统将访问数据包发送至目的IP地址所在终端。S104. The second system sends the access data packet to the terminal where the destination IP address is located.

本发明实施例中,若第二系统判断源IP地址包含于预设IP地址段中,则第二系统根据目的IP地址将访问数据包发送至目的IP地址所在终端。In the embodiment of the present invention, if the second system determines that the source IP address is included in the preset IP address segment, the second system sends the access data packet to the terminal where the destination IP address is located according to the destination IP address.

在图1所描述的方法中,终端同时运行有第一系统和第二系统时,当第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包之后,第二系统将从访问数据包中提取源IP地址,并判断提取的源IP地址是否包含于预先设置的预设IP地址段中;若提取的源IP地址包含于预设IP地址段中,则第二系统将访问数据包发送至目的IP地址所在终端。可见,本发明实施例能够为操作系统提供网络服务,且能够保障操作系统的安全需求。In the method described in Figure 1, when the terminal runs the first system and the second system at the same time, after the first system sends the access data packet containing the source IP address and the destination IP address to the second system, the second system will Extract the source IP address from the access data packet, and determine whether the extracted source IP address is included in the preset IP address segment; if the extracted source IP address is included in the preset IP address segment, the second system will The access data packet is sent to the terminal where the destination IP address is located. It can be seen that the embodiment of the present invention can provide network services for the operating system and can guarantee the security requirements of the operating system.

请参见图2,图2为本发明实施例公开的另一种基于多系统的上网方法的流程示意图。如图2所示,该基于多系统的上网方法可以包括以下步骤。Please refer to FIG. 2 . FIG. 2 is a schematic flowchart of another method for accessing the Internet based on multiple systems disclosed in an embodiment of the present invention. As shown in Figure 2, the method for accessing the Internet based on multiple systems may include the following steps.

S201、第一系统获取源IP地址。S201. The first system acquires a source IP address.

本发明实施例中,作为一种可选的实施方式,第一系统获取源IP地址的具体实施方式包括以下步骤:In the embodiment of the present invention, as an optional implementation manner, the specific implementation manner in which the first system obtains the source IP address includes the following steps:

11)第一系统向目标服务器发送拨号请求;11) The first system sends a dial request to the target server;

12)第一系统接收目标服务器响应拨号请求发送的IP地址;12) The first system receives the IP address sent by the target server in response to the dial-up request;

13)第一系统将该IP地址确认为源IP地址。13) The first system confirms the IP address as the source IP address.

在该实施方式中,用户可以通过点击第一系统的用于连接网络的功能按钮以触发第一系统向目标服务器发送拨号请求,该目标服务器为待连接网络对应的服务器。例如,若用户想要在第一系统连接VPN网络,在用户在第一系统输入VPN账号和密码之后,用户点击用于连接VPN网络的功能按钮可触发第一系统向VPN服务器发送携带VPN账号和密码的拨号请求;VPN服务器接收到该拨号请求之后,若判断VPN账号和密码相匹配,则VPN服务器将为第一系统分配一个IP地址,并将该IP地址返回给第一系统;第一系统将接收的VPN服务器返回的IP地址确认为源IP地址。In this embodiment, the user can trigger the first system to send a dialing request to the target server by clicking the function button of the first system for connecting to the network, and the target server is a server corresponding to the network to be connected. For example, if the user wants to connect to the VPN network in the first system, after the user enters the VPN account number and password in the first system, the user clicks on the function button for connecting to the VPN network to trigger the first system to send the VPN account and password to the VPN server. A dial-up request for a password; after the VPN server receives the dial-up request, if it judges that the VPN account number and password match, the VPN server will assign an IP address to the first system and return the IP address to the first system; Confirm the received IP address returned by the VPN server as the source IP address.

S202、第一系统向第二系统发送该源IP地址。S202. The first system sends the source IP address to the second system.

本发明实施例中,在第一系统获取到源IP地址之后,第一系统将向第二系统发送该源IP地址;具体地,第一系统可以以广播的形式向第二系统发送该源IP地址。In the embodiment of the present invention, after the first system obtains the source IP address, the first system will send the source IP address to the second system; specifically, the first system can send the source IP address to the second system in the form of broadcast address.

S203、第二系统判断该源IP地址是否包含于预先设置的预设IP地址段中。S203. The second system judges whether the source IP address is included in a preset preset IP address segment.

本发明实施例中,第二系统接收到第一系统发送的源IP地址之后,将判断源IP地址是否包含于预先设置的预设IP地址段中。若第二系统判断源IP地址包含于预先设置的预设IP地址段中,则执行步骤S204。可选的,若第二系统判断源IP地址不包含于预先设置的预设IP地址段中,则第二系统将该源IP地址添加进禁出列表中。In the embodiment of the present invention, after receiving the source IP address sent by the first system, the second system will judge whether the source IP address is included in the preset preset IP address segment. If the second system determines that the source IP address is included in the preset IP address segment, step S204 is performed. Optionally, if the second system judges that the source IP address is not included in the preset IP address segment, the second system adds the source IP address into the forbidden list.

S204、第二系统将该源IP地址添加进准出列表中。S204. The second system adds the source IP address into the pass-out list.

S205、第一系统向第二系统发送包含有该源IP地址和目的IP地址的访问数据包。S205. The first system sends an access data packet including the source IP address and the destination IP address to the second system.

S206、第二系统接收访问数据包。S206. The second system receives the access data packet.

S207、第二系统从访问数据包中提取该源IP地址,并判断提取的该源IP地址是否包含于准出列表中。S207. The second system extracts the source IP address from the access data packet, and judges whether the extracted source IP address is included in the allow-out list.

本发明实施例中,第二系统从访问数据包中提取该源IP地址之后,将判断提取的源IP地址是否包含于准出列表中。因为准出列表中的IP地址一定包含于预先设置的IP地址段中,因此,当第二系统判断提取的该源IP地址包含于准出列表中时,可确定该源IP地址一定包含于预先设置的预设IP地址段中。当第二系统判断提取的该源IP地址不包含于准出列表中时,可确定该源IP地址一定不包含于预先设置的预设IP地址段中。当第二系统判断提取的该源IP地址包含于准出列表中时,执行步骤S208;当第二系统判断提取的该源IP地址不包含于准出列表中时,第二系统丢弃该访问数据包以结束该流程。In the embodiment of the present invention, after the second system extracts the source IP address from the access data packet, it will judge whether the extracted source IP address is included in the allow-out list. Because the IP address in the allowed-out list must be included in the preset IP address segment, therefore, when the second system judges that the extracted source IP address is included in the allowed-out list, it can be determined that the source IP address must be included in the preset IP address segment. In the preset IP address segment set. When the second system determines that the extracted source IP address is not included in the pass-out list, it may determine that the source IP address must not be included in the preset preset IP address segment. When the second system judges that the extracted source IP address is included in the quasi-exit list, step S208 is executed; when the second system judges that the extracted source IP address is not included in the quasi-exit list, the second system discards the access data package to end the process.

S208、第二系统将访问数据包发送至目的IP地址所在终端。S208. The second system sends the access data packet to the terminal where the destination IP address is located.

在图2所描述的方法中,终端同时运行有第一系统和第二系统时,当第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包之后,第二系统将从访问数据包中提取源IP地址,并判断提取的源IP地址是否包含于准出列表中;若提取的源IP地址包含于准出列表中,则第二系统将访问数据包发送至目的IP地址所在终端。可见,本发明实施例能够为操作系统提供网络服务,且能够保障操作系统的安全需求。In the method described in FIG. 2, when the terminal runs the first system and the second system at the same time, after the first system sends the access data packet containing the source IP address and the destination IP address to the second system, the second system will Extract the source IP address from the access data packet, and judge whether the extracted source IP address is included in the quasi-exit list; if the extracted source IP address is included in the quasi-exit list, the second system sends the access data packet to the destination IP The terminal where the address resides. It can be seen that the embodiment of the present invention can provide network services for the operating system and can guarantee the security requirements of the operating system.

请参见图3,图3为本发明实施例公开的另一种基于多系统的上网方法的流程示意图。如图3所示,该基于多系统的上网方法可以包括以下步骤。Please refer to FIG. 3 . FIG. 3 is a schematic flowchart of another method for accessing the Internet based on multiple systems disclosed in an embodiment of the present invention. As shown in Fig. 3, the method for accessing the Internet based on multiple systems may include the following steps.

S301、第二系统接收用户输入的用于设置预设IP地址段的设置指令,该设置指令携带IP地址段。S301. The second system receives a setting instruction input by a user for setting a preset IP address segment, where the setting instruction carries an IP address segment.

本发明实施例中,用户可在第二系统预先设置预设IP地址段。该IP地址段可以是一个或多个IP地址的集合,本发明实施例不做限定。In the embodiment of the present invention, the user can pre-set a preset IP address segment in the second system. The IP address segment may be a collection of one or more IP addresses, which is not limited in this embodiment of the present invention.

S302、第二系统输出待校验信息输入口。S302. The second system outputs an input port of information to be verified.

本发明实施例中,第二系统接收到用户输入的设置指令之后,将输出待校验信息输入口,用户可在待校验信息输入口输入待校验信息。该待校验信息可包括但不限于待校验密码、待校验指纹信息、待校验脸形信息、待校验虹膜信息、待校验视网膜信息以及待校验声纹信息中的任意一种和几种的组合。In the embodiment of the present invention, after the second system receives the setting instruction input by the user, it will output the input port of the information to be verified, and the user can input the information to be verified at the input port of the information to be verified. The information to be verified may include, but not limited to, passwords to be verified, fingerprint information to be verified, face shape information to be verified, iris information to be verified, retina information to be verified, and voiceprint information to be verified and several combinations.

S303、第二系统获取通过待校验信息输入口输入的待校验信息。S303. The second system acquires the information to be verified input through the input port of the information to be verified.

S304、第二系统判断待校验信息是否与预先设置的预设校验信息相匹配。S304. The second system judges whether the information to be verified matches the preset verification information set in advance.

本发明实施例中,当第二系统判断待校验信息与预设校验信息相匹配时,执行步骤S305;当第二系统判断待校验信息与预设校验信息不匹配时,结束该流程或输出用于提示用户待校验信息与预设校验信息不匹配的错误提示信息,以提示用户重新通过待校验信息输入口输入待校验信息。In the embodiment of the present invention, when the second system judges that the information to be verified matches the preset verification information, step S305 is executed; when the second system judges that the information to be verified does not match the preset verification information, the process ends. The process or output is used to prompt the user that the information to be verified does not match the preset verification information, so as to prompt the user to re-enter the information to be verified through the input port of the information to be verified.

本发明实施例中,该预设校验信息可包括但不限于预设校验密码、预设校验指纹信息、预设校验脸形信息、预设校验虹膜信息、预设校验视网膜信息以及预设校验声纹信息中的任意一种和几种的组合。In the embodiment of the present invention, the preset verification information may include but not limited to preset verification password, preset verification fingerprint information, preset verification face shape information, preset verification iris information, preset verification retina information As well as any one or combination of preset verification voiceprint information.

可选的,上述的预设校验信息可以包括指纹串信息以及每一个指纹对应的输入时间;那么相应地,判断待校验信息是否与预设校验信息相匹配可以包括以下步骤:Optionally, the above-mentioned preset verification information may include fingerprint string information and the input time corresponding to each fingerprint; then correspondingly, judging whether the information to be verified matches the preset verification information may include the following steps:

判断指纹串是否与预设校验信息包括的指纹串相同,并且相同指纹的输入时间的差值是否均小于预设值,如果校验指纹串与预设校验信息包括的指纹串相同,并且相同指纹的输入时间的差值均小于预设值,那么可以确定待校验信息与预设校验信息相匹配;反之,确定待校验信息与预设校验信息不一致。其中,通过实施该实施方式,可以防止非法用户在第二系统设置预设IP地址段,保障了系统的安全性。Judging whether the fingerprint string is the same as the fingerprint string included in the preset verification information, and whether the difference between the input time of the same fingerprint is less than the preset value, if the verification fingerprint string is the same as the fingerprint string included in the preset verification information, and If the difference between the input times of the same fingerprint is less than the preset value, then it can be determined that the information to be verified matches the preset verification information; otherwise, it is determined that the information to be verified is inconsistent with the preset verification information. Wherein, by implementing this implementation manner, illegal users can be prevented from setting a preset IP address segment in the second system, thereby ensuring system security.

S305、第二系统响应设置指令,将设置指令携带的IP地址段设置为预设IP地址段。S305. The second system responds to the setting instruction, and sets the IP address segment carried in the setting instruction as a preset IP address segment.

S306、第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包,该第一系统和该第二系统为在终端运行的操作系统。S306. The first system sends an access data packet including the source IP address and the destination IP address to the second system, where the first system and the second system are operating systems running on the terminal.

S307、第二系统接收访问数据包。S307. The second system receives the access data packet.

S308、第二系统从访问数据包中提取源IP地址,并判断提取的源IP地址是否包含于预先设置的预设IP地址段中。S308. The second system extracts the source IP address from the access data packet, and judges whether the extracted source IP address is included in a preset preset IP address segment.

S309、第二系统将访问数据包发送至目的IP地址所在终端。S309. The second system sends the access data packet to the terminal where the destination IP address is located.

在图3所描述的方法中,终端同时运行有第一系统和第二系统时,当第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包之后,第二系统将从访问数据包中提取源IP地址,并判断提取的源IP地址是否包含于预先设置的预设IP地址段中;若提取的源IP地址包含于预设IP地址段中,则第二系统将访问数据包发送至目的IP地址所在终端。可见,本发明实施例能够为操作系统提供网络服务,且能够保障操作系统的安全需求。In the method described in FIG. 3, when the terminal runs the first system and the second system at the same time, after the first system sends the access data packet containing the source IP address and the destination IP address to the second system, the second system will Extract the source IP address from the access data packet, and determine whether the extracted source IP address is included in the preset IP address segment; if the extracted source IP address is included in the preset IP address segment, the second system will The access data packet is sent to the terminal where the destination IP address is located. It can be seen that the embodiment of the present invention can provide network services for the operating system and can guarantee the security requirements of the operating system.

请参阅图4,图4是本发明实施例公开的一种终端的结构示意图。其中,图4所示的终端可以包括第一发送单元401、接收单元402、判断单元403和第二发送单元404,其中:Please refer to FIG. 4 . FIG. 4 is a schematic structural diagram of a terminal disclosed in an embodiment of the present invention. Wherein, the terminal shown in FIG. 4 may include a first sending unit 401, a receiving unit 402, a judging unit 403, and a second sending unit 404, wherein:

第一发送单元401,用于控制第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包,所述第一系统和所述第二系统为在所述终端上运行的操作系统。The first sending unit 401 is configured to control the first system to send an access data packet including the source IP address and the destination IP address to the second system, the first system and the second system are running on the terminal operating system.

本发明实施例中,终端可包括多个运行的操作系统,该终端至少包括一个第一系统和一个第二系统。该终端可包括但不仅限于智能手机(如Android手机、iOS手机等)、平板电脑、掌上电脑、移动互联网设备(MID,Mobile Internet Devices)或穿戴式智能设备等包含多个系统的终端设备。In the embodiment of the present invention, the terminal may include multiple running operating systems, and the terminal includes at least one first system and one second system. The terminal may include, but not limited to, smart phones (such as Android phones, iOS phones, etc.), tablet computers, palmtop computers, mobile Internet devices (MID, Mobile Internet Devices) or wearable smart devices that include multiple systems.

本发明实施例中,第一系统和第二系统同时运行于该终端。该第一系统可包括但不限于用于办公的办公操作系统,该第二系统可包括但不限于用于上网娱乐的娱乐操作系统,如Android操作系统、IOS操作系统等等。当第一系统为终端前台运行的操作系统,第二系统为终端后台运行的操作系统时,用户可以使用第一系统进行上网。当用户在第一系统输入针对目标IP地址的访问请求时,第一系统将响应该访问请求,获取在第一系统下终端的IP地址作为源IP地址,并根据该访问请求生成包括源IP地址和目的IP地址的访问数据包。第一系统生成访问数据包之后,第一发送单元401将控制第一系统向在终端后台运行的第二系统发送该访问数据包;具体地,第一系统可以以广播的形式向第二系统发送该访问数据包。In the embodiment of the present invention, the first system and the second system run on the terminal at the same time. The first system may include but not limited to an office operating system used for office work, and the second system may include but not limited to an entertainment operating system used for Internet entertainment, such as Android operating system, IOS operating system and so on. When the first system is the operating system running in the foreground of the terminal and the second system is the operating system running in the background of the terminal, the user can use the first system to surf the Internet. When the user enters an access request for the target IP address in the first system, the first system will respond to the access request, obtain the IP address of the terminal under the first system as the source IP address, and generate an IP address containing the source IP address according to the access request. and destination IP address access packets. After the first system generates the access data packet, the first sending unit 401 will control the first system to send the access data packet to the second system running in the background of the terminal; specifically, the first system can send the access data packet to the second system in the form of broadcast The access packet.

接收单元402,用于控制所述第二系统接收第一发送单元401控制第一系统发送的访问数据包。The receiving unit 402 is configured to control the second system to receive the access data packet that the first sending unit 401 controls to send from the first system.

判断单元403,用于控制所述第二系统从所述访问数据包中提取所述源IP地址,并判断提取的所述源IP地址是否包含于预先设置的预设IP地址段中。The judging unit 403 is configured to control the second system to extract the source IP address from the access data packet, and judge whether the extracted source IP address is included in a preset preset IP address segment.

本发明实施例中,用户可在第二系统预先设置预设IP地址段,该预设IP地址段为一个或多个IP地址的集合。在接收单元402控制第二系统接收到访问数据包之后,判断单元403将控制第二系统将从访问数据包中提取源IP地址,并且判断从访问数据包中提取的源IP地址是否包含于预设IP地址段中。若提取的源IP地址包含于预设IP地址段中,则由第二发送单元404控制第二系统将访问数据包发送至目的IP地址所在终端;若提取的源IP地址不包含于预设IP地址段中,则第二系统丢弃访问数据包。In the embodiment of the present invention, the user can preset a preset IP address segment in the second system, and the preset IP address segment is a collection of one or more IP addresses. After the receiving unit 402 controls the second system to receive the access data packet, the judging unit 403 will control the second system to extract the source IP address from the access data packet, and judge whether the source IP address extracted from the access data packet is included in the preset Set the IP address segment. If the extracted source IP address is included in the preset IP address segment, the second sending unit 404 controls the second system to send the access data packet to the terminal where the destination IP address is located; if the extracted source IP address is not included in the preset IP address address segment, the second system discards the access data packet.

本发明实施例中,用户可在第二系统设置安全性较高的网络的IP地址集合为预设IP地址段;例如VPN(Virtual Private Network,虚拟专用网络)相较于其他无线网络具有安全性高的优点,因此,用户可在第二系统设置VPN网络的IP地址集合为预设IP地址段。只有当源IP地址包含于预先设置的VPN网络IP地址集合中时,第二发送单元404才控制第二系统才将访问数据包发送至目的IP地址所在终端;当第二系统开启GPRS(General PacketRadio Service,通用分组无线服务)或其他WIFI无线网络时,将不能进行网络数据访问。因此,在本发明实施例中,通过判断单元403控制第二系统判断源IP地址是否为预设IP地址段中的IP地址,若是,则第二发送单元404才控制第二系统将访问数据包发送至目的IP地址所在终端,从而保障了第一系统访问网络的安全性。In the embodiment of the present invention, the user can set the IP address set of the network with higher security as the preset IP address segment in the second system; for example, VPN (Virtual Private Network, virtual private network) has security compared to other wireless networks High advantage, therefore, the user can set the IP address set of the VPN network as a preset IP address segment in the second system. Only when the source IP address is included in the preset VPN network IP address set, the second sending unit 404 controls the second system to send the access data packet to the terminal where the destination IP address is located; when the second system opens the GPRS (General Packet Radio Service, General Packet Wireless Service) or other WIFI wireless networks, network data access will not be available. Therefore, in the embodiment of the present invention, the judgment unit 403 controls the second system to judge whether the source IP address is an IP address in the preset IP address segment, and if so, the second sending unit 404 controls the second system to access the data packet It is sent to the terminal where the destination IP address is located, thus ensuring the security of the first system's access to the network.

第二发送单元404,用于若提取的所述源IP地址包含于所述预设IP地址段中,则控制所述第二系统将所述访问数据包发送至所述目的IP地址所在终端。The second sending unit 404 is configured to control the second system to send the access data packet to the terminal where the destination IP address is located if the extracted source IP address is included in the preset IP address segment.

请一并参阅图5,图5是本发明实施例公开的另一种终端的结构示意图。其中,图5所示的终端是由图4所示的终端进行优化得到的。与图4所示的终端相比较,图5所示的终端除包括图4所示的终端的所有单元外,还可以包括第一获取单元405和添加单元406,其中:Please refer to FIG. 5 together. FIG. 5 is a schematic structural diagram of another terminal disclosed in an embodiment of the present invention. Wherein, the terminal shown in FIG. 5 is obtained by optimizing the terminal shown in FIG. 4 . Compared with the terminal shown in FIG. 4, the terminal shown in FIG. 5 may include not only all units of the terminal shown in FIG. 4, but also a first acquiring unit 405 and an adding unit 406, wherein:

第一获取单元405,用于控制第一系统获取源IP地址。The first obtaining unit 405 is configured to control the first system to obtain the source IP address.

可选的,第一获取单元405包括:发送子单元4051、接收子单元4052和确认子单元4053,其中:Optionally, the first acquiring unit 405 includes: a sending subunit 4051, a receiving subunit 4052, and a confirming subunit 4053, wherein:

发送子单元4051,用于控制第一系统向目标服务器发送拨号请求;a sending subunit 4051, configured to control the first system to send a dial request to the target server;

接收子单元4052,用于控制所述第一系统接收所述目标服务器响应所述拨号请求发送的IP地址;a receiving subunit 4052, configured to control the first system to receive the IP address sent by the target server in response to the dialing request;

确认子单元4053,用于控制所述第一系统将所述IP地址确认为源IP地址。The confirmation subunit 4053 is configured to control the first system to confirm the IP address as the source IP address.

在该实施方式中,用户可以通过点击第一系统的用于连接网络的功能按钮以触发发送子单元4051控制第一系统向目标服务器发送拨号请求,该目标服务器为待连接网络对应的服务器。例如,若用户想要在第一系统连接VPN网络,在用户在第一系统输入VPN账号和密码之后,用户点击用于连接VPN网络的功能按钮可触发发送子单元4051控制第一系统向VPN服务器发送携带VPN账号和密码的拨号请求;VPN服务器接收到该拨号请求之后,若判断VPN账号和密码相匹配,则VPN服务器将为第一系统分配一个IP地址,并将该IP地址返回给第一系统;确认子单元4053控制第一系统将接收的VPN服务器返回的IP地址确认为源IP地址。In this embodiment, the user can click the function button of the first system for connecting to the network to trigger the sending subunit 4051 to control the first system to send a dial request to the target server, which is the server corresponding to the network to be connected. For example, if the user wants to connect to the VPN network in the first system, after the user enters the VPN account number and password in the first system, the user clicks the function button for connecting to the VPN network to trigger the sending subunit 4051 to control the first system to send the VPN server Send a dial-up request carrying a VPN account number and password; after the VPN server receives the dial-up request, if it judges that the VPN account number and password match, the VPN server will assign an IP address to the first system and return the IP address to the first system. System; the confirmation subunit 4053 controls the first system to confirm the received IP address returned by the VPN server as the source IP address.

第一发送单元401,还用于控制所述第一系统向第二系统发送所述源IP地址。The first sending unit 401 is further configured to control the first system to send the source IP address to the second system.

本发明实施例中,在第一获取单元405控制第一系统获取到源IP地址之后,第一发送单元401将控制第一系统将向第二系统发送该源IP地址;具体地,第一系统可以以广播的形式向第二系统发送该源IP地址。In the embodiment of the present invention, after the first obtaining unit 405 controls the first system to obtain the source IP address, the first sending unit 401 will control the first system to send the source IP address to the second system; specifically, the first system The source IP address may be sent to the second system in a broadcast form.

接收单元402,还用于控制所述第二系统接收第一发送单元401控制第一系统发送的源IP地址。The receiving unit 402 is further configured to control the second system to receive the source IP address that the first sending unit 401 controls to send from the first system.

判断单元403,还用于控制所述第二系统判断所述源IP地址是否包含于预先设置的预设IP地址段中。The judging unit 403 is further configured to control the second system to judge whether the source IP address is included in a preset preset IP address segment.

本发明实施例中,接收单元402控制第二系统接收到第一系统发送的源IP地址之后,判断单元403将控制第二系统判断源IP地址是否包含于预先设置的预设IP地址段中。若第二系统判断源IP地址包含于预先设置的预设IP地址段中,则添加单元406控制第二系统将源IP地址添加进准出列表中。可选的,若第二系统判断源IP地址不包含于预先设置的预设IP地址段中,则添加单元406控制第二系统将该源IP地址添加进禁出列表中。In the embodiment of the present invention, after the receiving unit 402 controls the second system to receive the source IP address sent by the first system, the judging unit 403 controls the second system to judge whether the source IP address is included in the preset preset IP address segment. If the second system judges that the source IP address is included in the preset preset IP address segment, the adding unit 406 controls the second system to add the source IP address into the pass-out list. Optionally, if the second system judges that the source IP address is not included in the preset IP address segment, the adding unit 406 controls the second system to add the source IP address into the forbidden list.

添加单元406,用于若所述第二系统判断所述源IP地址包含于所述预设IP地址段中,则控制所述第二系统将所述源IP地址添加进准出列表中。The adding unit 406 is configured to control the second system to add the source IP address into the pass-out list if the second system judges that the source IP address is included in the preset IP address segment.

判断单元403控制所述第二系统判断提取的所述源IP地址是否包含于预先设置的预设IP地址段中的具体实施方式为:The judging unit 403 controls the second system to judge whether the extracted source IP address is included in the preset preset IP address segment. The specific implementation method is as follows:

判断单元403控制所述第二系统判断提取的所述源IP地址是否包含于所述准出列表中,若提取的所述源IP地址包含于所述准出列表中,则确定提取的所述源IP地址包含于所述预设IP地址段中。The judging unit 403 controls the second system to judge whether the extracted source IP address is included in the allowed-out list, and if the extracted source IP address is included in the allowed-out list, then determine whether the extracted source IP address is included in the allowed-out list. The source IP address is included in the preset IP address segment.

本发明实施例中,判断单元403控制第二系统从访问数据包中提取该源IP地址之后,将判断提取的源IP地址是否包含于准出列表中。因为准出列表中的IP地址一定包含于预先设置的IP地址段中,因此,当第二系统判断提取的该源IP地址包含于准出列表中时,可确定该源IP地址一定包含于预先设置的预设IP地址段中。当第二系统判断提取的该源IP地址不包含于准出列表中时,可确定该源IP地址一定不包含于预先设置的预设IP地址段中。当第二系统判断提取的该源IP地址包含于准出列表中时,第二发送单元404控制第二系统将访问数据包发送至目的IP地址所在终端;当第二系统判断提取的该源IP地址不包含于准出列表中时,第二系统丢弃该访问数据包。In the embodiment of the present invention, after the judging unit 403 controls the second system to extract the source IP address from the access data packet, it will judge whether the extracted source IP address is included in the pass-out list. Because the IP address in the allowed-out list must be included in the preset IP address segment, therefore, when the second system judges that the extracted source IP address is included in the allowed-out list, it can be determined that the source IP address must be included in the preset IP address segment. In the preset IP address segment set. When the second system determines that the extracted source IP address is not included in the pass-out list, it may determine that the source IP address must not be included in the preset preset IP address segment. When the second system judges that the extracted source IP address is included in the quasi-exit list, the second sending unit 404 controls the second system to send the access data packet to the terminal where the destination IP address is located; when the second system judges that the extracted source IP address When the address is not included in the allow-out list, the second system discards the access data packet.

请一并参阅图6,图6是本发明实施例公开的另一种终端的结构示意图。其中,图6所示的终端是由图4所示的终端进行优化得到的。与图4所示的终端相比较,图6所示的终端除包括图4所示的终端的所有单元外,还可以包括设置单元407、输出单元408和第二获取单元409,其中:Please refer to FIG. 6 together. FIG. 6 is a schematic structural diagram of another terminal disclosed by an embodiment of the present invention. Wherein, the terminal shown in FIG. 6 is obtained by optimizing the terminal shown in FIG. 4 . Compared with the terminal shown in FIG. 4, the terminal shown in FIG. 6 may include a setting unit 407, an output unit 408, and a second acquiring unit 409 in addition to all the units of the terminal shown in FIG. 4, wherein:

所述接收单元402,还用于控制所述第二系统接收用户输入的用于设置预设IP地址段的设置指令,所述设置指令携带IP地址段。The receiving unit 402 is further configured to control the second system to receive a setting instruction input by a user for setting a preset IP address segment, where the setting instruction carries an IP address segment.

本发明实施例中,用户可在第二系统预先设置预设IP地址段。该IP地址段可以是一个或多个IP地址的集合,本发明实施例不做限定。In the embodiment of the present invention, the user can pre-set a preset IP address segment in the second system. The IP address segment may be a collection of one or more IP addresses, which is not limited in this embodiment of the present invention.

所述输出单元408,用于控制所述第二系统在所述接收单元402接收所述设置指令之后,输出待校验信息输入口。The output unit 408 is configured to control the second system to output an input port of information to be verified after the receiving unit 402 receives the setting instruction.

本发明实施例中,接收单元402控制第二系统接收到用户输入的设置指令之后,输出单元408将控制第二系统输出待校验信息输入口,用户可在待校验信息输入口输入待校验信息。该待校验信息可包括但不限于待校验密码、待校验指纹信息、待校验脸形信息、待校验虹膜信息、待校验视网膜信息以及待校验声纹信息中的任意一种和几种的组合。In the embodiment of the present invention, after the receiving unit 402 controls the second system to receive the setting instruction input by the user, the output unit 408 will control the second system to output the input port of the information to be verified, and the user can input the input port of the information to be verified. test information. The information to be verified may include, but not limited to, passwords to be verified, fingerprint information to be verified, face shape information to be verified, iris information to be verified, retina information to be verified, and voiceprint information to be verified and several combinations.

所述第二获取单元409,用于控制所述第二系统获取通过所述待校验信息输入口输入的待校验信息。The second obtaining unit 409 is configured to control the second system to obtain the information to be verified input through the input port of the information to be verified.

所述判断单元403,还用于控制所述第二系统判断所述待校验信息是否与预先设置的预设校验信息相匹配。The judging unit 403 is further configured to control the second system to judge whether the information to be verified matches the preset verification information set in advance.

本发明实施例中,当第二系统判断待校验信息与预设校验信息相匹配时,设置单元407控制第二系统响应设置指令,将设置指令携带的IP地址段设置为预设IP地址段;当第二系统判断待校验信息与预设校验信息不匹配时,结束该流程或输出用于提示用户待校验信息与预设校验信息不匹配的错误提示信息,以提示用户重新通过待校验信息输入口输入待校验信息。In the embodiment of the present invention, when the second system judges that the information to be verified matches the preset verification information, the setting unit 407 controls the second system to respond to the setting instruction, and set the IP address segment carried by the setting instruction as the preset IP address section; when the second system judges that the information to be verified does not match the preset verification information, it ends the process or outputs an error message for prompting the user that the information to be verified does not match the preset verification information, so as to remind the user Input the information to be verified through the input port of the information to be verified again.

本发明实施例中,该预设校验信息可包括但不限于预设校验密码、预设校验指纹信息、预设校验脸形信息、预设校验虹膜信息、预设校验视网膜信息以及预设校验声纹信息中的任意一种和几种的组合。In the embodiment of the present invention, the preset verification information may include but not limited to preset verification password, preset verification fingerprint information, preset verification face shape information, preset verification iris information, preset verification retina information As well as any one or combination of preset verification voiceprint information.

可选的,上述的预设校验信息可以包括指纹串信息以及每一个指纹对应的输入时间;那么相应地,判断待校验信息是否与预设校验信息相匹配可以包括以下步骤:Optionally, the above-mentioned preset verification information may include fingerprint string information and the input time corresponding to each fingerprint; then correspondingly, judging whether the information to be verified matches the preset verification information may include the following steps:

判断指纹串是否与预设校验信息包括的指纹串相同,并且相同指纹的输入时间的差值是否均小于预设值,如果校验指纹串与预设校验信息包括的指纹串相同,并且相同指纹的输入时间的差值均小于预设值,那么可以确定待校验信息与预设校验信息相匹配;反之,确定待校验信息与预设校验信息不一致。其中,通过实施该实施方式,可以防止非法用户在第二系统设置预设IP地址段,保障了系统的安全性。Judging whether the fingerprint string is the same as the fingerprint string included in the preset verification information, and whether the difference between the input time of the same fingerprint is less than the preset value, if the verification fingerprint string is the same as the fingerprint string included in the preset verification information, and If the difference between the input times of the same fingerprint is less than the preset value, then it can be determined that the information to be verified matches the preset verification information; otherwise, it is determined that the information to be verified is inconsistent with the preset verification information. Wherein, by implementing this implementation manner, illegal users can be prevented from setting a preset IP address segment in the second system, thereby ensuring system security.

所述设置单元407,用于控制所述第二系统响应所述设置指令,将所述设置指令携带的IP地址段设置为所述预设IP地址段。The setting unit 407 is configured to control the second system to respond to the setting instruction, and set the IP address segment carried in the setting instruction as the preset IP address segment.

在图4~6所描述的终端中,当第一发送单元控制第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包之后,判断单元将控制第二系统将从访问数据包中提取源IP地址,并判断提取的源IP地址是否包含于预先设置的预设IP地址段中;若提取的源IP地址包含于预设IP地址段中,则第二发送单元控制第二系统将访问数据包发送至目的IP地址所在终端。可见,本发明实施例能够为操作系统提供网络服务,且能够保障操作系统的安全需求。In the terminals described in Figures 4-6, after the first sending unit controls the first system to send the access data packet containing the source IP address and the destination IP address to the second system, the judging unit will control the second system to access the Extract the source IP address in the data packet, and judge whether the extracted source IP address is included in the preset preset IP address segment; if the extracted source IP address is included in the preset IP address segment, the second sending unit controls the first The second system sends the access data packet to the terminal where the destination IP address is located. It can be seen that the embodiment of the present invention can provide network services for the operating system and can guarantee the security requirements of the operating system.

本发明实施例方法中的步骤可以根据实际需要进行顺序调整、合并和删减。The steps in the method of the embodiment of the present invention can be adjusted, merged and deleted according to actual needs.

本发明实施例终端的单元或子单元可以根据实际需要进行合并、划分和删减。Units or subunits of the terminal in the embodiment of the present invention can be combined, divided and deleted according to actual needs.

本领域普通技术人员可以理解上述实施例的各种方法中的全部或部分步骤是可以通过程序来指令终端设备相关的硬件来完成,该程序可以存储于一计算机可读存储介质中,存储介质可以包括:闪存盘、只读存储器(Read-Only Memory,ROM)、随机存取器(RandomAccess Memory,RAM)、磁盘或光盘等。Those skilled in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, and the storage medium can be Including: a flash disk, a read-only memory (Read-Only Memory, ROM), a random access device (Random Access Memory, RAM), a magnetic disk or an optical disk, and the like.

以上对本发明实施例公开的一种基于多系统的上网方法及终端进行了详细介绍,本文中应用了具体个例对本发明的原理及实施方式进行了阐述,以上实施例的说明只是用于帮助理解本发明的方法及其核心思想;同时,对于本领域的一般技术人员,依据本发明的思想,在具体实施方式及应用范围上均会有改变之处,综上所述,本说明书内容不应理解为对本发明的限制。The above is a detailed introduction of a multi-system-based Internet access method and terminal disclosed in the embodiment of the present invention. In this paper, specific examples are used to illustrate the principle and implementation of the present invention. The description of the above embodiment is only for helping understanding The method of the present invention and its core idea; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation and scope of application. In summary, the content of this specification should not be construed as a limitation of the invention.

Claims (10)

Translated fromChinese
1.一种基于多系统的上网方法,应用于终端,其特征在于,所述方法包括:1. A method for accessing the Internet based on multiple systems, applied to a terminal, characterized in that the method comprises:第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包,所述第一系统和所述第二系统为在所述终端运行的操作系统;The first system sends an access data packet including a source IP address and a destination IP address to a second system, and the first system and the second system are operating systems running on the terminal;所述第二系统接收所述访问数据包;the second system receives the access packet;所述第二系统从所述访问数据包中提取所述源IP地址,并判断提取的所述源IP地址是否包含于预先设置的预设IP地址段中;The second system extracts the source IP address from the access data packet, and determines whether the extracted source IP address is included in a preset preset IP address segment;若提取的所述源IP地址包含于所述预设IP地址段中,则所述第二系统将所述访问数据包发送至所述目的IP地址所在终端。If the extracted source IP address is included in the preset IP address segment, the second system sends the access data packet to the terminal where the destination IP address is located.2.根据权利要求1所述的方法,其特征在于,所述第一系统向所述第二系统发送包含有源IP地址和目的IP地址的访问数据包之前,所述方法还包括:2. The method according to claim 1, wherein before the first system sends the access data packet including the source IP address and the destination IP address to the second system, the method further comprises:第一系统获取源IP地址;The first system obtains the source IP address;所述第一系统向第二系统发送所述源IP地址;The first system sends the source IP address to the second system;所述第二系统判断所述源IP地址是否包含于预先设置的预设IP地址段中;The second system judges whether the source IP address is included in a preset preset IP address segment;若所述源IP地址包含于所述预设IP地址段中,则所述第二系统将所述源IP地址添加进准出列表中;If the source IP address is included in the preset IP address segment, then the second system adds the source IP address to an entry-exit list;所述第二系统判断提取的所述源IP地址是否包含于预先设置的预设IP地址段中包括:The second system judging whether the extracted source IP address is included in the preset preset IP address segment includes:所述第二系统判断提取的所述源IP地址是否包含于所述准出列表中,若提取的所述源IP地址包含于所述准出列表中,则确定提取的所述源IP地址包含于所述预设IP地址段中。The second system judges whether the extracted source IP address is included in the allowed-out list, and if the extracted source IP address is included in the allowed-out list, then determines that the extracted source IP address includes in the preset IP address segment.3.根据权利要求2所述的方法,其特征在于,所述第一系统获取源IP地址包括:3. The method according to claim 2, wherein obtaining the source IP address by the first system comprises:第一系统向目标服务器发送拨号请求;The first system sends a dial request to the target server;所述第一系统接收所述目标服务器响应所述拨号请求发送的IP地址;The first system receives the IP address sent by the target server in response to the dial request;所述第一系统将所述IP地址确认为源IP地址。The first system identifies the IP address as a source IP address.4.根据权利要求1所述的方法,其特征在于,在所述第二系统判断提取的所述源IP地址是否包含于预先设置的预设IP地址段中之前,所述方法还包括:4. The method according to claim 1, wherein, before the second system judges whether the extracted source IP address is included in a preset preset IP address segment, the method further comprises:所述第二系统接收用户输入的用于设置预设IP地址段的设置指令,所述设置指令携带IP地址段;The second system receives a setting instruction input by a user for setting a preset IP address segment, and the setting instruction carries an IP address segment;所述第二系统响应所述设置指令,将所述设置指令携带的IP地址段设置为所述预设IP地址段。In response to the setting instruction, the second system sets the IP address segment carried in the setting instruction as the preset IP address segment.5.根据权利要求4所述的方法,其特征在于,所述第二系统接收用户输入的用于设置预设IP地址段的设置指令之后,所述方法还包括:5. The method according to claim 4, wherein, after the second system receives the setting instruction input by the user for setting the preset IP address segment, the method further comprises:所述第二系统输出待校验信息输入口;The second system outputs an input port for information to be verified;所述第二系统获取通过所述待校验信息输入口输入的待校验信息;The second system acquires the information to be verified input through the input port of the information to be verified;所述第二系统判断所述待校验信息是否与预先设置的预设校验信息相匹配;The second system judges whether the information to be verified matches the preset verification information set in advance;若所述待校验信息与所述预设校验信息相匹配,则执行所述第二系统响应所述设置指令,将所述设置指令携带的IP地址段设置为所述预设IP地址段的步骤。If the information to be verified matches the preset verification information, execute the second system to respond to the setting instruction, and set the IP address segment carried by the setting instruction as the preset IP address segment A step of.6.一种终端,其特征在于,所述终端包括:第一发送单元、接收单元、判断单元和第二发送单元,其中:6. A terminal, characterized in that the terminal comprises: a first sending unit, a receiving unit, a judging unit and a second sending unit, wherein:所述第一发送单元,用于控制第一系统向第二系统发送包含有源IP地址和目的IP地址的访问数据包,所述第一系统和所述第二系统为在所述终端上运行的操作系统;The first sending unit is configured to control the first system to send an access data packet including the source IP address and the destination IP address to the second system, the first system and the second system are running on the terminal operating system;所述接收单元,用于控制所述第二系统接收所述访问数据包;The receiving unit is configured to control the second system to receive the access data packet;所述判断单元,用于控制所述第二系统从所述访问数据包中提取所述源IP地址,并判断提取的所述源IP地址是否包含于预先设置的预设IP地址段中;The judging unit is configured to control the second system to extract the source IP address from the access data packet, and judge whether the extracted source IP address is included in a preset preset IP address segment;所述第二发送单元,用于若提取的所述源IP地址包含于所述预设IP地址段中,则控制所述第二系统将所述访问数据包发送至所述目的IP地址所在终端。The second sending unit is configured to control the second system to send the access data packet to the terminal where the destination IP address is located if the extracted source IP address is included in the preset IP address segment .7.根据权利要求6所述的终端,其特征在于,所述终端还包括:第一获取单元、添加单元,其中:7. The terminal according to claim 6, further comprising: a first obtaining unit and an adding unit, wherein:所述第一获取单元,用于控制第一系统获取源IP地址;The first obtaining unit is configured to control the first system to obtain the source IP address;所述第一发送单元,还用于控制所述第一系统向第二系统发送所述源IP地址;The first sending unit is further configured to control the first system to send the source IP address to the second system;所述判断单元,还用于控制所述第二系统判断所述源IP地址是否包含于预先设置的预设IP地址段中;The judging unit is also used to control the second system to judge whether the source IP address is included in a preset preset IP address segment;所述添加单元,用于若所述判断单元判断所述源IP地址包含于所述预设IP地址段中,则控制所述第二系统将所述源IP地址添加进准出列表中;The adding unit is configured to control the second system to add the source IP address into the quasi-exit list if the judging unit judges that the source IP address is included in the preset IP address segment;所述判断单元控制所述第二系统判断提取的所述源IP地址是否包含于预先设置的预设IP地址段中的具体实施方式为:The specific implementation manner in which the judging unit controls the second system to judge whether the extracted source IP address is included in the preset preset IP address segment is as follows:所述判断单元控制所述第二系统判断提取的所述源IP地址是否包含于所述准出列表中,若提取的所述源IP地址包含于所述准出列表中,则确定提取的所述源IP地址包含于所述预设IP地址段中。The judging unit controls the second system to judge whether the extracted source IP address is included in the allowed-out list, and if the extracted source IP address is included in the allowed-out list, then determine whether the extracted source IP address is included in the allowed-out list. The source IP address is included in the preset IP address segment.8.根据权利要求7所述的终端,其特征在于,所述第一获取单元包括:发送子单元、接收子单元和确认子单元,其中:8. The terminal according to claim 7, wherein the first obtaining unit comprises: a sending subunit, a receiving subunit and a confirmation subunit, wherein:所述发送子单元,用于控制第一系统向目标服务器发送拨号请求;The sending subunit is configured to control the first system to send a dialing request to the target server;所述接收子单元,用于控制所述第一系统接收所述目标服务器响应所述拨号请求发送的IP地址;The receiving subunit is configured to control the first system to receive the IP address sent by the target server in response to the dialing request;所述确认子单元,用于控制所述第一系统将所述IP地址确认为源IP地址。The confirming subunit is configured to control the first system to confirm the IP address as the source IP address.9.根据权利要求6所述的终端,其特征在于,所述终端还包括设置单元,其中:9. The terminal according to claim 6, further comprising a setting unit, wherein:所述接收单元,还用于控制所述第二系统接收用户输入的用于设置预设IP地址段的设置指令,所述设置指令携带IP地址段;The receiving unit is further configured to control the second system to receive a setting instruction input by a user for setting a preset IP address segment, where the setting instruction carries an IP address segment;所述设置单元,用于控制所述第二系统响应所述设置指令,将所述设置指令携带的IP地址段设置为所述预设IP地址段。The setting unit is configured to control the second system to respond to the setting instruction, and set the IP address segment carried in the setting instruction as the preset IP address segment.10.根据权利要求9所述的终端,其特征在于,所述终端还包括:输出单元、第二获取单元,其中:10. The terminal according to claim 9, further comprising: an output unit and a second acquisition unit, wherein:所述输出单元,用于控制所述第二系统在所述接收单元接收所述设置指令之后,输出待校验信息输入口;The output unit is configured to control the second system to output an input port of information to be verified after the receiving unit receives the setting instruction;所述第二获取单元,用于控制所述第二系统获取通过所述待校验信息输入口输入的待校验信息;The second obtaining unit is configured to control the second system to obtain the information to be verified input through the input port of the information to be verified;所述判断单元,还用于控制所述第二系统判断所述待校验信息是否与预先设置的预设校验信息相匹配;The judging unit is further configured to control the second system to judge whether the information to be verified matches the preset verification information set in advance;若所述待校验信息与所述预设校验信息相匹配,则所述设置单元控制所述第二系统响应所述设置指令,将所述设置指令携带的IP地址段设置为所述预设IP地址段。If the information to be verified matches the preset verification information, the setting unit controls the second system to respond to the setting instruction, and sets the IP address segment carried in the setting instruction as the preset Set the IP address segment.
CN201510220486.4A2015-04-302015-04-30A kind of internet access method and terminal based on multisystemActiveCN105577630B (en)

Priority Applications (1)

Application NumberPriority DateFiling DateTitle
CN201510220486.4ACN105577630B (en)2015-04-302015-04-30A kind of internet access method and terminal based on multisystem

Applications Claiming Priority (1)

Application NumberPriority DateFiling DateTitle
CN201510220486.4ACN105577630B (en)2015-04-302015-04-30A kind of internet access method and terminal based on multisystem

Publications (2)

Publication NumberPublication Date
CN105577630A CN105577630A (en)2016-05-11
CN105577630Btrue CN105577630B (en)2017-07-14

Family

ID=55887292

Family Applications (1)

Application NumberTitlePriority DateFiling Date
CN201510220486.4AActiveCN105577630B (en)2015-04-302015-04-30A kind of internet access method and terminal based on multisystem

Country Status (1)

CountryLink
CN (1)CN105577630B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
CN107547692B (en)*2017-09-302020-12-15烽火通信科技股份有限公司Method and device for configuring IP address and port number between dual systems

Citations (5)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20060271760A1 (en)*2005-05-312006-11-30Stmicroelectronics SaTranslation look-aside buffer
CN101888401A (en)*2009-05-122010-11-17阿瓦雅公司 Virtual machine implementation for multiple use cases
CN103136052A (en)*2011-11-252013-06-05展讯通信(上海)有限公司Mobile terminal and control method of mobile terminal provided with multiple operating systems
CN103176780A (en)*2011-12-222013-06-26中国科学院声学研究所Binding system and method of multiple network interfaces
CN104506732A (en)*2014-12-292015-04-08宇龙计算机通信科技(深圳)有限公司Contact person based system switching method and contact person based system switching device

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication numberPriority datePublication dateAssigneeTitle
US20060271760A1 (en)*2005-05-312006-11-30Stmicroelectronics SaTranslation look-aside buffer
CN101888401A (en)*2009-05-122010-11-17阿瓦雅公司 Virtual machine implementation for multiple use cases
CN103136052A (en)*2011-11-252013-06-05展讯通信(上海)有限公司Mobile terminal and control method of mobile terminal provided with multiple operating systems
CN103176780A (en)*2011-12-222013-06-26中国科学院声学研究所Binding system and method of multiple network interfaces
CN104506732A (en)*2014-12-292015-04-08宇龙计算机通信科技(深圳)有限公司Contact person based system switching method and contact person based system switching device

Also Published As

Publication numberPublication date
CN105577630A (en)2016-05-11

Similar Documents

PublicationPublication DateTitle
CN104967997B (en)A kind of Wi-Fi cut-in method, Wi-Fi equipment, terminal device and system
KR102087526B1 (en) Method and apparatus, device and storage medium for data processing between terminals
CN108965250B (en)Digital certificate installation method and system
CN104580406B (en)A kind of method and apparatus of synchronous logging state
CN106850503B (en)Login-free identity authentication method and device
WO2016061769A1 (en)Verification information transmission method and terminal
CN105307287B (en)A kind of connection method and wearable device
CN105337997B (en)Login method of application client and related equipment
WO2015062243A1 (en)Information display method and device
CN106201574B (en)Application interface starting method and device
CN104618315B (en)A kind of method, apparatus and system of verification information push and Information Authentication
JP2016521899A (en) Two-factor authentication
CN106375465B (en) A data migration method and server
CN105184155B (en)Application program display control method and device in terminal
WO2017049736A1 (en)Mobile communications network access method and device
CN105610842A (en)WIFI hotspot access method and mobile device
CN105868621A (en)A password resetting method and device
CN105005724B (en) A password-based screen unlocking method and communication terminal
CN103942121A (en)Data recovery system and mobile terminal
CN106897629A (en)The control method and terminal of terminal applies
CN113961836A (en)Page jump method and device, electronic equipment and storage medium
CN106572074B (en) Verification method and device for a verification code
CN107766713A (en) Face template data entry control method and related products
CN104853030B (en)Information processing method and mobile terminal
CN105577630B (en)A kind of internet access method and terminal based on multisystem

Legal Events

DateCodeTitleDescription
C06Publication
PB01Publication
C10Entry into substantive examination
SE01Entry into force of request for substantive examination
GR01Patent grant
GR01Patent grant
TR01Transfer of patent right

Effective date of registration:20250521

Address after:100080 Beijing City Haidian District Wanliuyishui Garden Building 1 First Floor Supporting Commercial Room 03

Patentee after:Beijing Shebohui Art Exhibition Co.,Ltd.

Country or region after:China

Address before:518057, Nanshan District hi tech Industrial Park (North Zone), Guangdong, Shenzhen Province, No. 2, Mengxi Road

Patentee before:YULONG COMPUTER TELECOMMUNICATION SCIENTIFIC (SHENZHEN) Co.,Ltd.

Country or region before:China

TR01Transfer of patent right

[8]ページ先頭

©2009-2025 Movatter.jp