Method for accessing intranet service and management system
By interacting with public network devices and jump nodes, login information for jump servers and internal network devices is allocated to user terminals, solving the security and process simplification issues of public network users accessing the internal network laboratory, and realizing secure and efficient access to internal network services.
Patent Information
- Application Number
- CN202410879293.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-01
- Publication Date
- 2026-01-06
AI Technical Summary
In existing technologies, users in public network environments face the risk of network environment exposure when accessing intranet laboratory services. At the same time, strict review mechanisms lead to user churn. How to simplify the access process while ensuring security has become an urgent technical problem to be solved.
By interacting with public network devices and jump nodes, the system allocates the first jump server and the first internal network device to the user terminal and provides corresponding login information, simplifying the user access process and improving security and resource allocation efficiency.
While ensuring security, the process of users accessing the intranet lab has been simplified, improving the user experience and making the allocation of resources in the intranet lab more reasonable and efficient.
Smart Images

Figure CN121284026A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network communication, and more particularly to a method and management system for accessing intranet services. Background Technology
[0002] Nowadays, cutting-edge products and applications from enterprises are often deployed as services on intranet devices in intranet labs.
[0003] When a user in the public network environment wants to use any service in the intranet lab, the access method for the relevant intranet service is often to assign a jump server and a fixed account to the user. The user can then log in to the intranet device in the intranet lab through the designated jump server using the fixed account to access the service.
[0004] Because users in the public network environment use fixed accounts to access designated jump servers, the network environment of the internal network lab is at risk of exposure. Therefore, services in the internal network lab are usually limited to internal personnel or a specific group of people who have undergone strict review for access and testing.
[0005] However, overly strict review mechanisms can lead to the loss of potential users in the public network environment. Therefore, how to ensure the security of the intranet lab while enabling users in the public network environment to easily experience the services of the intranet lab has become an urgent technical problem to be solved. Summary of the Invention
[0006] This application provides a method and management system for accessing intranet services. This method enables users in public network environments to experience intranet laboratory services more conveniently and securely.
[0007] In a first aspect, embodiments of this application provide a method for accessing intranet services. The method is applied to a public network device located within the public network. The method includes: providing an access page to a user terminal; receiving an access request sent by the user terminal through the access page, the access request including an identifier of a target service; receiving status information of multiple jump servers sent by a jump node, the jump node being located in the intranet network and communicatively connected to the public network device, the jump node including multiple jump servers; and receiving status information of multiple intranet devices sent by the jump node, the multiple intranet devices being located within the intranet network; and according to the access request, the status information of the multiple jump servers... Based on the status information of the jump server and the status information of the multiple intranet devices, a first jump server and a first intranet device are identified, and the target service runs on the first intranet device. A first instruction is sent to the jump node, including the device identifier of the first jump server and the device identifier of the first intranet device. First login information is received from the jump node, and the remote desktop of the first jump server is provided to the user terminal through the first login information. Second login information is received from the jump node, and the second login information is provided to the user terminal so that the user can log in to the first intranet device and access the target service based on the second login information.
[0008] In this solution, the user terminal and the jump node are interacted through public network equipment to allocate a first jump server and a first internal network device to the user terminal, as well as the first login information and second login information required for the user terminal to access the target service on the first internal network device. This simplifies the user access process and improves the user experience while ensuring security, and makes the resource allocation of the internal network laboratory more reasonable.
[0009] In some embodiments, the status information of the plurality of jump servers includes the online status, CPU utilization, memory utilization, and number of online users of the plurality of jump servers; the status information of the plurality of intranet devices includes the online status, CPU utilization, memory utilization, and number of online users of the plurality of intranet devices.
[0010] In this solution, public network devices can reasonably allocate the first jump server to the user based on the status information of the multiple jump servers, and reasonably allocate the first internal network device to the user based on the status information of the multiple internal network devices, making the allocation of access resources for internal network services more reasonable and efficient.
[0011] In some embodiments, receiving the first login information returned by the jump node and providing the remote desktop of the first jump server to the user terminal through the first login information includes: receiving the first login information returned by the jump node, wherein the first login information includes the access account identifier and password of the first jump server; logging into the remote desktop of the first jump server through the first login information; and providing the logged-in remote desktop to the user terminal.
[0012] In this solution, the public network device logs into the remote desktop of the first jump server through the first login information and provides the remote desktop to the user, which simplifies the access process for the user and improves the access efficiency of the target service.
[0013] In some embodiments, the second login information includes the access account identifier and password of the first intranet device. Providing the second login information to the user terminal so that the user terminal can access the first intranet device according to the second login information includes: providing the second login information to the user terminal through the access page; in response to the second login information input by the user terminal, sending the second login information to the redirection node, receiving the target service data of the first intranet device sent by the redirection node, and providing the target service to the user terminal.
[0014] In this solution, the public network device responds to the second login information entered by the user through the access page and provides the target service to the user. This can improve the security of the user's access to the target service.
[0015] In some embodiments, the method for determining the first jump server and the first intranet device based on the access request, the status information of the plurality of jump servers and the plurality of intranet devices further includes: determining whether there is an abnormal connection status of the jump server and / or intranet device based on the status information, and if so, sending an abnormal notification to the user terminal.
[0016] In this solution, the public network device can monitor the connection status of multiple jump servers and / or internal network devices in real time through the status information of these multiple jump servers and internal network devices. When a connection anomaly is detected, an anomaly notification is sent to the user terminal, thus improving the stability of the user terminal when accessing the target service.
[0017] Secondly, embodiments of this application provide a method for accessing intranet services, characterized in that the method is applied to a jump node, the jump node being located in the intranet network and communicatively connected to multiple intranet devices located in the intranet network, the jump node including multiple jump servers, the method comprising: acquiring status information of the multiple jump servers and the multiple intranet devices, and sending the status information of the multiple jump servers and the multiple intranet devices to a public network device, the public network device being located in the public network and communicatively connected to the jump node; receiving a first instruction from the public network device, and in response to the first instruction, allocating first login information and second login information, the first instruction including a device identifier of a first jump server and a device identifier of a first intranet device, the first login information being used to log in to the first jump server, and the second login information being used to log in to the first intranet device; sending the first login information to the public network device to enable the public network device to log in to the first jump server; and sending the second login information to the public network device to enable a user terminal to log in to the first intranet device according to the second login information and access services on the first intranet device.
[0018] In this solution, the jump node assigns first and second login information to the user terminal based on the first instruction sent by the public network device. Web remote desktop technology is used to enable the public network device to log in to the first jump server and the first internal network device. This avoids the risk of data leakage caused by network attacks on internal network devices. Furthermore, the jump node handles the communication connection between the user terminal and the internal network device without requiring additional hardware support, making access to internal network services more convenient and improving compatibility.
[0019] In some embodiments, the status information of the plurality of jump servers includes the online status, CPU utilization, memory utilization, and number of online users of the plurality of jump servers; the status information of the plurality of intranet devices includes the online status, CPU utilization, memory utilization, and number of online users of the plurality of intranet devices.
[0020] In some embodiments, when the user accesses a service on the first intranet device, the method includes: deleting the assigned first login information and second login information.
[0021] In some embodiments, when the user accesses a service on the first intranet device, the method further includes: performing device initialization on the first jump server and the first intranet device.
[0022] In this solution, after each user experience session, the jump node restores the intranet devices and jump servers to their initial state or deletes the user information, effectively ensuring the security of intranet service access.
[0023] Thirdly, embodiments of the present invention provide a management system, which includes a public network device, a jump node, and multiple internal network devices. The jump node includes multiple jump servers. The public network device is located in the public network, and the jump node and the multiple internal network devices are located in the internal network. The public network device, the jump node, and the multiple internal network devices are communicatively connected.
[0024] The public network device is used to provide an access page to the user terminal, receive access requests sent by the user terminal through the access page, and receive status information of multiple jump servers and multiple internal network devices sent by the redirection node; based on the access request and the status information of the multiple jump servers and multiple internal network devices, determine a first jump server and a first internal network device; send a first instruction to the redirection node; receive first login information returned by the redirection node, and provide the user terminal with the remote desktop of the first jump server through the first login information; receive second login information returned by the redirection node, and provide the user terminal with the second login information; wherein, the access request includes the identifier of the target service, the The first instruction includes the device identifier of the first jump server and the device identifier of the first intranet device; the jump node is used to obtain the status information of the multiple jump servers and the multiple intranet devices, and send the status information of the multiple jump servers and the multiple intranet devices to the public network device; receive the first instruction from the public network device, and in response to the first instruction, allocate first login information and second login information; send the first login information to the public network device so that the public network device can log in to the first jump server; send the second login information to the public network device so that the user terminal can log in to the first intranet device according to the second login information; the target service available to the user is running on the first intranet device.
[0025] It should be understood that the beneficial effects of the technical solution of the third aspect of the embodiments of this application and the corresponding possible implementation methods can be referred to the above-described technical effects of the first and second aspects, and will not be repeated here. Attached Figure Description
[0026] Figure 1 This is a schematic diagram of an interaction scenario for accessing an intranet laboratory provided in an embodiment of this application;
[0027] Figure 2a This is a schematic diagram of the architecture of the user management module in the software program of a public network device;
[0028] Figure 2b This is a schematic diagram of the architecture of the jump server management module of the software program for public network devices;
[0029] Figure 2c This is a schematic diagram of the architecture of the laboratory management module of the software program for public network devices;
[0030] Figure 2d This is a schematic diagram of the architecture of the laboratory management module of the software program for public network devices;
[0031] Figure 3 This is a schematic diagram of the software program for jump nodes;
[0032] Figure 4 This is a flowchart of the method for accessing intranet services from the public network device side disclosed in this application;
[0033] Figure 5 This is a schematic diagram of an interaction scenario where a user accesses a service on the first intranet device.
[0034] Figure 6 This is a flowchart of the method for accessing intranet services on the jump node side disclosed in this application;
[0035] Figure 7 This is a schematic diagram of the architecture of a management system disclosed in this application;
[0036] Figure 8 This is a schematic diagram of the scaffolding machine provided in the embodiments of this application;
[0037] Figure 9 This is a schematic diagram of the structure of the intranet device provided in the embodiments of this application. Detailed Implementation
[0038] The terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such terms are interchangeable where appropriate; this is merely a way of distinguishing objects with the same attributes in the embodiments of this application. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion, so that a process, method, system, product, or apparatus that comprises a series of elements is not necessarily limited to those elements, but may include other elements not explicitly listed or inherent to those processes, methods, products, or apparatuses.
[0039] To facilitate understanding of the technical solution of this application, the relevant terms used in this document are explained below.
[0040] The public network refers to the internet, a network accessible to anyone. It consists of many interconnected computer networks. Through the public network, one can connect to any networked device on a private network.
[0041] An intranet (IV) is a network established within a limited scope, consisting of multiple internal network devices and other network equipment, accessible only within that specific area. IVs are typically enterprise-internal office networks established to achieve specific functions. Multiple internal network devices cannot directly access other devices on the internet; they can only connect to the public network through specific methods, such as port forwarding, via a Web-RDP (Web-Remote Desktop Protocol) service deployed on a jump server.
[0042] Port mapping refers to mapping a port on a host within an internal network to a port on a public network host, providing corresponding services. When a user accesses this port on a public IP address, the server automatically maps the request to a jump server within the corresponding local area network, which then provides the user with application services from the internal network lab.
[0043] A jump server is a security device used to manage and control remote access to a protected network. Its function is to provide an isolated access method, preventing external users from directly connecting to the internal network, thereby enhancing the security of the internal network.
[0044] An intranet lab refers to an experimental environment deployed within an intranet that can provide users with service experiences and operations. These services can include different types such as online education, software testing, product demonstrations, remote work, and cloud gaming. Depending on the experimental environment, an intranet lab can be deployed on one or more intranet devices.
[0045] Web-RDP (Web-Remote Desktop Protocol) service refers to a web-based remote desktop protocol service. Users can access the remote desktop of a jump server through a browser to remotely experience and operate the intranet laboratory.
[0046] Nowadays, enterprises typically deploy their cutting-edge products and applications as services on intranet devices in intranet labs.
[0047] When a user in the public network environment wants to use any service in the intranet lab, the access method for the relevant intranet service will assign the user a jump server and a fixed account for that jump server. The user can log in to the intranet device in the intranet lab through the designated jump server using the fixed account to access the service.
[0048] Because users in the public network environment use fixed accounts to access designated jump servers, the network environment of the internal network lab faces the risk of exposure. Therefore, services in the internal network lab are usually limited to internal personnel or a specific group of people who have undergone strict review for access and testing.
[0049] However, overly strict review mechanisms can lead to the loss of potential users in the public network environment. Therefore, how to ensure the security of the intranet lab while enabling users in the public network environment to easily experience the intranet lab's products and services has become an urgent technical problem to be solved.
[0050] To simplify the access process for intranet services while ensuring the security of the intranet laboratory's network environment, this application provides a method and management system for accessing intranet services. This method provides access pages to user terminals through public network devices on the public network and receives access requests from user terminals. It receives status information of the jump server and intranet devices sent by the jump node through the public network device, and assigns login information of the first intranet device to the user terminal based on different user experience requests and the device information of the jump server and intranet device. This allows users to access the target service on the first intranet device through the first jump server and the login information of the first intranet device. Compared to known intranet service access methods, this method manages the user side on the public network, the jump server and the intranet device side on the intranet simultaneously, simplifying the user access process while ensuring security, improving user experience, and making the resource allocation of the intranet laboratory more reasonable.
[0051] To facilitate understanding of the technical solution of this application, an application scenario of an embodiment of this application will be introduced first below.
[0052] For example, Figure 1 This diagram illustrates an interactive scenario for accessing an intranet laboratory, as provided in an embodiment of this application. Figure 1 As shown, the public network includes at least one user terminal 100 and a public network device 200, while the internal network includes a jump node 300 and laboratories 410 to Nth laboratories 420. The public network device 200 is communicatively connected to the jump node 300.
[0053] Among them, the jump node 300 includes multiple jump machines, such as jump machine 301 and jump machine 302, and each laboratory in the first laboratory 410 to the Nth laboratory 420 includes multiple intranet devices, such as intranet device 411 and intranet device 412 in the first laboratory.
[0054] A jump server is used to enable cross-network communication between user terminals and internal network devices. Illustratively, in some possible implementations, one jump server can connect to one internal network device, allowing one user terminal to access that device. Alternatively, one jump server can connect to multiple internal network devices, or multiple jump servers can connect to one internal network device, allowing multiple user terminals to access multiple internal network devices. Each internal network device runs services available to the user terminal.
[0055] It is worth noting that in this embodiment, the public network device 200 can connect to the jump node 300 via port mapping. It can also connect to the jump node 300 via a Virtual Private Network (VPN). In other words, this application does not restrict the connection method between the public network device 200 and the jump node 300.
[0056] User terminal 100 can initiate access requests to the first laboratory 410 to the Nth laboratory 420 through the access page provided by public network device 200. These access requests include an identifier for a specific service (target service).
[0057] For example, the access page includes an operation prompt field for providing operation tips and instructions, a user login field for receiving user information, and access interfaces for the first laboratory 410 to the Nth laboratory 420. In some possible implementations, the user can send the identifier of a service from the first laboratory 410 to the Nth laboratory 420 to the public network device 200 through the aforementioned access interface. This service identifier is used to distinguish services running on the internal network device.
[0058] It is worth noting that users can also provide feedback on any issues encountered during the experience by accessing the page. Accordingly, the management node 200 can optimize the services in the first laboratory 410 to the Nth laboratory 420 based on the issues reported by users.
[0059] The public network device 200 includes a software program 210, which, when executed, can implement the method for accessing intranet services proposed in this application.
[0060] The public network device 200 can provide access pages to users of the client 100 and receive user information and access requests sent by users of the client 100 through the access pages.
[0061] The public network device 200 is used to receive the status information of multiple jump servers sent by the jump server node 300, as well as multiple intranet devices in the first laboratory 410 to the Nth laboratory 420. Based on the identifier of the target service and the device information of the jump server and the intranet device, it allocates the jump server (first jump server) and intranet device (first intranet device) corresponding to the access request to the user terminal 100.
[0062] The public network device 200 is also used to send a first instruction to the jump node. The first instruction includes the device identifiers of the first jump server and the first internal network device.
[0063] The following content will explain the status information and device identification of the jump server and the internal network devices.
[0064] The status information of the jump server may include at least one of the following: whether the device is online, CPU utilization, memory utilization, number of online users, or access duration of online users.
[0065] Among them, the number of online users represents the number of users logged in simultaneously on a certain jump server, and the access duration of online users represents the access duration of a certain user on that jump server.
[0066] The device identifier of a scaffolding machine is used to represent the identity information of a scaffolding machine, serving as a unique identifier for that scaffolding machine.
[0067] The status information of intranet devices may include at least one of the following: whether the device is online, CPU utilization, memory utilization, number of online users, and access duration of online users.
[0068] The number of online users indicates the number of users logged in simultaneously on a certain intranet device, and the access duration of online users indicates the access duration of a certain user on that intranet device.
[0069] The device identifier of an intranet device is used to represent the identity information of a certain intranet device, serving as a unique identifier for that intranet device.
[0070] The public network device 200 is also used to receive the first login information returned by the jump node 300, and provide the user terminal 100 with the remote desktop of the first jump machine through the first login information. It also receives the second login information returned by the jump node 200, and provides the second login information to the user terminal 100 so that the user terminal 100 can log in to the first intranet device and access the target service based on the second login information.
[0071] The following will explain the first and second login information.
[0072] The initial login information includes the access account identifier and password for the first jump server.
[0073] The second login information includes the access account identifier and password of the first intranet device.
[0074] The jump node 300 may include a software program 310, which, when executed, can implement the method for accessing intranet services proposed in this application.
[0075] Jump node 300 is used to obtain the status information of multiple jump servers and multiple intranet devices, and send the status information of multiple jump servers and multiple intranet devices to public network device 200.
[0076] The jump node 300 is also used to receive the first instruction from the public network device 200, and in response to the first instruction, allocate the first login information and the second login information.
[0077] The first instruction includes the device identifier of the first jump server and the device identifier of the first intranet device; the first login information is used to log in to the first jump server, and the second login information is used to log in to the first intranet device.
[0078] The jump node 300 sends first login information to the public network device 200 so that the public network device 200 can log in to the first jump server. It also sends second login information to the public network device 200 so that the user terminal 100 can log in to the first intranet device based on the second login information and access the services on the first intranet device.
[0079] It is worth noting that, in some possible implementations, the jump node 300 can also perform device initialization operations on multiple jump servers and multiple intranet devices.
[0080] As an example rather than a limitation, the above device initialization may include the installation and restoration of operating systems for multiple jump servers and multiple intranet devices, and may also include the setting of access permissions for multiple jump servers and multiple intranet devices. This application does not limit this.
[0081] After the user completes access to the service on the first jump server, the jump node 300 can also perform device initialization operations on the first jump server and the first intranet device, as well as delete the first login information and the second login information assigned to the user 100.
[0082] It is worth noting that, Figure 1 The public network device 200, the multiple jump servers in the jump node 300, and the multiple intranet devices in the intranet laboratory shown are only functional divisions. In actual deployment, they may include one or more jump servers and intranet devices located in the same or different areas. The public network device 200, the multiple jump servers in the jump node 300, and the multiple intranet devices in the intranet laboratory can be computing devices capable of providing data processing, computing, and / or storage functions, etc., and this application does not limit them in this regard.
[0083] As mentioned above, the public network device 200 includes a software program 210, which, when executed, enables the method for accessing intranet services proposed in this application. The software program 210 includes a user management module 211, a jump server management module 212, a laboratory management module 213, and a system information management module 214.
[0084] For example, Figure 2a This diagram illustrates the architecture of the user management module in the software program of a public network device. Figure 2a As shown, the user management module 211 is used to receive access requests sent by the user terminal 100 and send the access requests to the jump server management module 212 and the laboratory management module 213. In some possible implementations, the user management module 211 is also used to provide the user terminal 100 with... Figure 1 The access interface shown receives access requests sent by client 100 through the access page.
[0085] User management module 211 is used to receive the first login information returned by jump server management module 212, receive the first jump server remote desktop returned by jump node 300, log in to the remote desktop of the first jump server through the first login information, and provide the remote desktop after login to user terminal 100.
[0086] User management module 211 is also used to receive the second login information returned by laboratory management module 213 and provide the second login information to user terminal 100 through access page; in response to the second login information input by user terminal 100, it receives the target service data of the first intranet device sent by jump node 300 and provides the target service to user terminal through access page.
[0087] In some possible implementations, the user management module 211 is also used to receive customer information sent by the user terminal 100, and determine the corresponding access permissions and access policies for the customer based on the user information, the device information of the jump server and the device information of the intranet device.
[0088] In one possible implementation, user access permissions can include three levels: high, medium, and low. High-privilege users have complete control over the jump server and intranet devices, such as the power on / off control. Medium-privilege users can utilize the jump server and intranet devices to perform most of the operations required for daily work, such as data processing control. Low-privilege users only have access to the most basic information and functions of the jump server and intranet devices.
[0089] User access permissions can also include unrestricted access to the intranet lab, or adding users to a blacklist or whitelist. Unrestricted access to the intranet lab means there are no access restrictions; a whitelist allows access from user IDs or IP addresses that are on the list; a blacklist allows access from user IDs or IP addresses that are not on the list.
[0090] In one possible implementation, user access policies include single-access and unlimited-access. Single-access means that users must apply for access permission before each visit. Only after the application is approved can the user access the corresponding intranet lab within a specified time period. Each user can only access the intranet lab once; if the visit ends, the user has no further access. Unlimited-access means that within a certain time limit, the user can access the designated intranet lab an unlimited number of times.
[0091] User management module 211 provides a user information management page a. Administrators can manage users based on user information and access requests sent by user terminals 100, and input user information into user management page a for administrator query. Administrators can also manage users through user management page a.
[0092] In one possible implementation, the user information management page a includes a user management field a1 and an access policy field a2.
[0093] The following sections will explain the user management field a1 and the access policy field a2.
[0094] The user management field a1 is used to provide user information to the administrator, who can then manage users based on this information. Specifically, user management field a1 includes the following fields: user identifier, user information, target service, access permissions, allocated resources, and access time limit.
[0095] The user identifier field is used to represent the user's identity information obtained by accessing the page, serving as a unique identifier for the user.
[0096] The user information field is used to represent information obtained by accessing the page, such as the user's IP address, name, phone number, email address, company, and city. Based on the above user information, the user's access permissions can be determined.
[0097] The Target Service field is used to identify the target service of Laboratory 410 to Laboratory 420 obtained by accessing the page.
[0098] The access permission field is used to indicate a user's access permissions.
[0099] The resource allocation field is used to represent the device information of the jump server and intranet device allocated according to the user's access request, such as the access account and password of the jump server and intranet device, IP address, CPU utilization, memory utilization, and the number of online users.
[0100] The access duration field is used to indicate the user's experience duration, experience start time, and experience end time.
[0101] The access policy field a2 is used to indicate that the administrator sets access policies for users, and can also modify the access permissions determined by the user management module 211.
[0102] It is worth noting that, Figure 2a The field information and layout of the user information management page a shown are only for the purpose of understanding this application and are not intended to limit this application. In actual implementation, other field information and layout may be included, and this application does not limit them.
[0103] For example, Figure 2b This diagram illustrates the architecture of the jump server management module in the software program of a public network device. Figure 2b As shown, the jump server management module 212 is used to receive status information of multiple jump servers sent by the jump node 300, as well as access requests sent by the user management module 211. It is worth noting that when the connection status of the jump server device is abnormal, the jump server management module 212 will also send an abnormality notification to the user terminal 100.
[0104] The jump server management module 212 is also used to allocate a jump server (first jump server) corresponding to the access request to the user terminal 100 based on the status information of multiple jump servers and the access request.
[0105] The scaffolding machine management module 212 is also used to send the device identifier of the first scaffolding machine in the first instruction to the scaffolding node 300, receive the first login information returned by the scaffolding node 300, and send the first login information to the user management module 211.
[0106] The jump server management module 212 is also used to provide a jump server management page b, through which the administrator can also manage multiple jump servers in the jump server node 300.
[0107] In one possible implementation, the scaffolding machine management page b includes a scaffolding machine working status field b1.
[0108] The following content will explain the working status field b1 of the scaffolding machine.
[0109] The jump server working status field b1 is used to provide the administrator with the working status of each jump server in the jump node 300. The jump server working status b1 specifically includes the device identification field, environment information field, device status field, online user field, multi-user information field, and virtual machine information field.
[0110] The device identification field is used to represent the identity information of a jump server, serving as a unique identifier for the jump server.
[0111] The environment information field is used to represent the IP address, CPU utilization, and memory utilization of a certain jump server detected by the jump server management module 212.
[0112] The online status field is used to indicate the online status of a certain jump server detected by the jump server management module 212, and whether it can be accessed.
[0113] The online users field is used to indicate the number of online users on a given jump server.
[0114] The multi-user information field is used to represent the status information of access accounts assigned to multiple users on a certain jump server, as well as the user's access account, password, and access permissions.
[0115] The virtual machine information field is used to indicate the number of virtual machines on a certain jump host, as well as the status information of multiple virtual machines, such as whether they are in the initial state, and the user's access account, password and access permissions.
[0116] It is worth noting that, Figure 2b The field information and layout of the scaffolding machine management page b shown are only for the purpose of understanding this application and are not intended to limit this application. In actual implementation, other field information and layout may be included, and this application does not limit them.
[0117] For example, Figure 2c This diagram illustrates the architecture of the laboratory management module of the public network device's software program. Figure 2c As shown, the laboratory management module 213 receives status information of multiple intranet devices sent by the jump node 300, as well as access requests sent by the user management module 211. It is worth noting that when the connection status of an intranet device is abnormal, the laboratory management module 213 will also send an abnormality notification to the user terminal 100.
[0118] The laboratory management module 213 is also used to allocate the corresponding intranet device (first intranet device) to the user terminal 100 based on the status information of multiple intranet devices and the access request.
[0119] Laboratory management module 213 is also used to send the device identifier of the first intranet device in the first instruction to the jump node 300, receive the second login information returned by the jump node 300, and send the second login information to user management module 211.
[0120] Laboratory management module 213 is also used to provide intranet laboratory management page c.
[0121] In one possible implementation, the intranet laboratory management page c includes an intranet device working status field c1 and a laboratory management field c2.
[0122] Next, the working status field c1 of the intranet device and the laboratory management field c2 will be explained through the following content.
[0123] The intranet device working status field c1 is used to provide the administrator with device information for multiple intranet devices in the first laboratory 410 to the Nth laboratory 420. The administrator can also manage multiple intranet devices in the first laboratory 410 to the Nth laboratory 420 based on the above working status.
[0124] To illustrate, taking the First Laboratory as an example, the intranet device working status field c1 specifically includes the device identifier field, environment information field, device status field, online user field, multi-user information field, and container information field.
[0125] The device identifier field is used to represent the identity information of a certain intranet device in the first laboratory, serving as a unique identifier for that intranet device.
[0126] The environmental information field is used to represent the IP address, CPU utilization, and memory utilization of a certain intranet device detected by the laboratory management module 213.
[0127] The online status field is used to indicate the online status of a certain intranet device detected by the laboratory management module 213, and whether it can be accessed.
[0128] The online users field is used to represent the number of online users on a specific intranet device.
[0129] The multi-user information field is used to represent the status information of access accounts assigned to multiple users on a certain intranet device, as well as the user's access account, password, and access permissions.
[0130] The container information field is used to indicate the number of containers on a certain intranet device and the status information of multiple containers, such as whether they are in the initial state, as well as the user's access account, password and access permissions.
[0131] It is understandable that the intranet device working status field c1 also includes the same information used to describe the device information of multiple intranet devices in Laboratory N 420, which will not be elaborated here.
[0132] The laboratory management field c2 is used to manage the environmental characteristics and operation guidance information of a certain laboratory provided to the user terminal 100. The above information is displayed in the operation prompt field of the aforementioned access page.
[0133] To illustrate, taking the User Experience First Lab as an example, the Lab Management Module 213 displays the environmental characteristics and operation guidance information of the First Lab in the operation prompt field of the access page. When a user experiences the First Lab through the user terminal 100, the user can follow the steps of the service operation experience by using the laboratory environmental characteristics and operation guidance displayed in the operation prompt field.
[0134] It is worth noting that, Figure 2c The field information and layout of the intranet laboratory management page c shown are only for the purpose of understanding this application and are not intended to limit this application. In actual implementation, other field information and layout may be included, and this application does not limit them.
[0135] For example, Figure 2d This diagram illustrates the architecture of the laboratory management module of the public network device's software program. Figure 2d As shown, the system information management module 214 is used to provide the system information management page d.
[0136] The system information management module 214 is also used to collect statistics on the information of accessing users, as well as the status of multiple jump servers and multiple intranet devices, and input the above statistical information into the system information management page d for the administrator to query.
[0137] In one possible implementation, the system information management page d includes a user information statistics field d1, a scaffolding machine information statistics field d2, and a laboratory information statistics field d3.
[0138] The following sections will explain the user information statistics field d1, the scaffolding machine information statistics field d2, and the laboratory information statistics field d3.
[0139] The user information statistics field d1 specifically includes the access information field and the user distribution field.
[0140] The access information field is used to collect statistics on user visits, monthly visits, experience duration, and new user access time.
[0141] The user distribution field is used to statistically analyze the distribution of users by city, industry, occupation, and company.
[0142] The jump server information statistics field d2 specifically includes the log information field and the audit information field.
[0143] The log information field is used to statistically analyze the distribution of multiple jump servers in jump server node 300 and the log information of important operations.
[0144] The audit information field is used to compile statistics on the deployment time and equipment change information of multiple jump servers in jump node 300.
[0145] The laboratory information statistics field d3 specifically includes the log information field and the audit information field.
[0146] The log information field is used to statistically analyze the operation prompts for different versions of the first laboratory 410 to the Nth laboratory 420 within a certain time period, as well as the log information of important operations of intranet devices in each intranet laboratory.
[0147] The audit information field is used to compile statistics on the deployment time and equipment change information of multiple intranet devices in Laboratory 1 410 to Laboratory N 420.
[0148] When users encounter problems accessing the intranet laboratory, administrators can trace the problem based on the statistical information in the user information statistics field d1, the jump server information statistics field d2, and the laboratory information statistics field d3.
[0149] It is worth noting that, Figure 2d The field information and layout of the system information management page d shown are only for the purpose of understanding this application and are not intended to limit this application. In actual implementation, other field information and layout may be included, and this application does not limit them.
[0150] As mentioned above, the jump node 300 includes a software program 310. When the software program 310 is executed, it can implement the method for accessing intranet services proposed in the embodiments of this application.
[0151] For example, Figure 3 The diagram shows a module diagram of the software program for the jump node, such as... Figure 3 As shown, the software program 310 includes a data processing module 311, a scaffolding machine management module 312, and a laboratory management module 313.
[0152] The data processing module 311 is used to obtain the status information of multiple jump servers sent by the jump server management module 312 and the status information of multiple intranet devices sent by the laboratory management module 313, and send the status information of multiple jump servers and multiple intranet devices to the public network device 200.
[0153] The data processing module 311 is also used to receive a first instruction from the public network device 200, and in response to the first instruction, allocate first login information and second login information to the user terminal 100, and send the first login information and second login information to the public network device 200. Illustratively, the jump server allocated by the public network device to the user terminal is the first jump server 301, and the intranet device is the first intranet device 411. Therefore, the first instruction includes the device identifier of the first jump server 301 and the device identifier of the first intranet device 411, the first login information includes the access account identifier and password of the first jump server 301, and the second login information includes the access account identifier and password of the first intranet device 411.
[0154] The data processing module 311 is used to receive the first login information sent by the public network device 200, log in to the remote desktop of the first jump server 301 through the first login information, and send the logged-in remote desktop to the public network device 200.
[0155] The data processing module 311 uses the second login information to access the first intranet device 411 and sends the target service data of the first intranet device 411 to the public network device 200.
[0156] The jump server management module 312 is used to obtain the status information of multiple jump servers and send the status information of multiple jump servers to the data processing module 311. Before or after the user accesses the service, the jump server management module 312 is also used to perform an initialization task on the first jump server 301.
[0157] For example, depending on the type, a jump server can include multi-user type and multi-virtual machine type jump servers.
[0158] A multi-user type bastion host refers to a bastion host that supports multiple users simultaneously. Multiple independent access accounts are created on a single bastion host, and these accounts are automatically deleted after each user's access is complete. If bastion node 300 includes multiple multi-user bastion hosts, users are evenly distributed across each bastion host based on the number of online users on each host. Correspondingly, when executing the initialization command for this type of bastion host, an access account and password are automatically assigned to each user. Once the user's experience is complete, these access accounts and passwords are deleted.
[0159] A multi-virtual machine jump host refers to a jump host on which multiple identical virtual machines are deployed, with restore points set according to the initial state of the virtual machines. Accordingly, when initialization instructions are executed on this type of jump host, an independent virtual machine is assigned to the user. After the user experience is complete, the virtual machine is restored to its initial state based on the aforementioned restore points.
[0160] The laboratory management module 313 is used to obtain the status information of multiple intranet devices in the first laboratory 410 to the Nth laboratory 420, and send the status information of the multiple intranet devices to the data processing module 311. Before or after the user accesses the service, the laboratory management module 313 is also used to perform an initialization task on the first intranet device 411.
[0161] For example, depending on the type, multiple intranet devices may include intranet devices of multi-user type and multi-container type.
[0162] Multi-user intranet devices refer to intranet devices with only one trial environment deployed on them. Multiple independent access accounts are created on this trial environment, and these accounts are automatically deleted after the user's use, based on their access permissions. If the First Laboratory 410 includes multiple multi-user access intranet devices, the users are evenly distributed across the intranet devices according to the number of online users on each device. Correspondingly, when executing the initialization command for this type of intranet device, an access account and password are automatically assigned to each user. After the user's experience is complete, these access accounts and passwords are deleted.
[0163] Multi-container type intranet devices refer to intranet devices that deploy multiple identical containers within a single intranet device, with each container hosting its own user experience environment. Correspondingly, when executing initialization instructions for this type of jump host, a separate container, along with its access username and password, is assigned to the user. After the user experience is complete, the user experience environment on that container is restored to its initial state. For the next user experience, the access username and password are recreated.
[0164] It is worth noting that, Figure 2a ~Figure 2 and Figure 3 The embodiments shown are merely illustrative. For example, the division of modules in a software program is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. The functional modules in the various embodiments of this application may be integrated into one processing module, or each module may exist physically separately, or two or more modules may be integrated into one module.
[0165] Next, based on the content described above, a method for accessing intranet services provided by an embodiment of this application will be introduced. It is understood that this method is proposed based on the content described above, and some or all of the content of this method can be found in the description above.
[0166] Please see Figure 4 , Figure 4The diagram shown is a flowchart of a method for accessing intranet services from a public network device side, as disclosed in an embodiment of this application. Figure 4 As shown, access to intranet services can be achieved through S410 to S430. It can be understood that when accessing the target service, this method is executed by the public network device 200.
[0167] S410: Provides an access page to the user and receives access requests sent by the user through the access page.
[0168] As mentioned earlier, the public network device 200 located on the public network can provide an access page to the user terminal 100. The access page includes access interfaces for the first laboratory 410 to the Nth laboratory 420. The user can send the identifier of a service from the first laboratory 410 to the Nth laboratory 420 to the public network device 200 through the above access interfaces. The service identifier is used to distinguish services running on the internal network device.
[0169] In some possible implementations, different access rules need to be defined for different types of services. For example, users may be allowed unlimited access to a service or only be allowed one access to a service at a time.
[0170] In some possible implementations, the public network device 200 can also receive user information sent by the user terminal 100 through an access page, and determine the user terminal 100's access permissions based on this user information. For example, the public network device 200 can assign corresponding access permissions to the user terminal 100 based on the user's IP address, name, telephone number, email address, company, city, and other information. These access permissions may include one of high, medium, or low permissions; alternatively, the user terminal 100 may have unrestricted access to the intranet laboratory, or the user may be added to a whitelist or blacklist.
[0171] S420: Receives status information of multiple jump servers sent by the jump node.
[0172] The public network device 200 is connected to the jump node 300 and can receive status information of multiple jump servers sent by the jump node 300.
[0173] The status information of the jump server includes at least one of the following: whether the device is online, CPU utilization, memory utilization, number of online users, and access duration of online users.
[0174] Jump node 300 is located on the internal network, and multiple jump servers within jump node 300 are also located on the internal network, for example... Figure 1 The springboard machine 301 and springboard machine 302 are shown.
[0175] In one possible implementation, the jump node 300 periodically sends the status information of the jump server to the public network device.
[0176] S430: Receives status information of multiple intranet devices sent by the jump node.
[0177] The public network device 200 is communicatively connected to the jump node 300, and the jump node 300 is communicatively connected to multiple internal network devices in the internal network. The public network device 200 can receive status information of multiple internal network devices sent by the jump node 300.
[0178] The status information of multiple intranet devices includes at least one of the following: online status of multiple intranet devices, CPU utilization, memory utilization, and number of online users.
[0179] In one possible implementation, the jump node 300 periodically sends the status information of the internal network devices to the public network devices.
[0180] In one possible implementation, the jump node 300 can simultaneously send status information of the jump server and status information of the internal network devices.
[0181] S440: Determine the first jump server and the first internal network device based on the access request, the status information of multiple jump servers, and the status information of multiple internal network devices.
[0182] When only one internal network device provides the target service, the public network device can identify that internal network device as the first internal network device based on the identifier of the target service in the access request. When multiple internal network devices provide the target service, the public network device can identify the first internal network device from among the multiple devices providing the target service based on at least one of the following conditions: online status, CPU utilization, memory utilization, and the number of online users. For example, an online internal network device can be identified as the first internal network device; or, an internal network device with low CPU utilization and / or low memory utilization can be identified as the first internal network device; or, an internal network device with a small number of online users can be identified as the first internal network device. It is understandable that the public network device can make a comprehensive judgment based on multiple conditions and the actual situation.
[0183] Furthermore, after identifying the first intranet device, when only one jump server is connected to the first intranet device, the public network device can designate that jump server as the first jump server. When multiple jump servers are connected to the first intranet device, the public network device can determine the first jump server from among the multiple jump servers connected to the first intranet device based on at least one of the following conditions: whether the jump server is online, CPU utilization, memory utilization, the number of online users, and the access duration of online users. For example, an online jump server can be designated as the first jump server, or a jump server with low CPU utilization and / or low memory utilization can be designated as the first jump server, or a jump server with a small number of online users can be designated as the first jump server. It is understandable that the public network device can make a comprehensive judgment based on multiple conditions and the actual situation.
[0184] In one possible implementation, the public network device 200 can consider the status information of the jump server and the status information of the internal network device together to determine the first jump server and the first internal network device, so that the user can access the target service on the first internal network device through the first jump server.
[0185] In one possible implementation, the public network device 200 can determine the service access policy based on the service identifier in the user's access request. Then, the public network device 200 determines the type of jump server based on the access policy, such as a multi-user jump server or a multi-virtual machine jump server. Finally, the public network device 200 determines the first jump server based on its CPU utilization, memory utilization, number of online users, and online status, and establishes a communication path between the client and the first jump server using the first jump server's IP address.
[0186] In one possible implementation, the public network device 200 can determine the service access policy based on the service identifier in the user's access request. Then, the public network device 200 determines the type of the internal network device based on the access policy, such as a multi-user type jump server or a multi-container type internal network device. Finally, the public network device 200 determines a first internal network device based on the CPU utilization, memory utilization, number of online users, and online status of this type of internal network device, and connects the client to the first internal network device via the first internal network device's IP address. In some possible implementations, the first internal network device determined by the public network device 200 is typically an internal network device with a relatively small number of online users.
[0187] In one possible implementation, if the access policy determined by the access request is unlimited access to services on an intranet device in one of the first laboratories 410 to the Nth laboratory, the public network device 200 can allocate multi-user type jump servers and multi-user type intranet devices to the user terminal 100.
[0188] If the access policy determined by the access request is a single access to a service on an intranet device in one of the first laboratories 410 to the Nth laboratories, the public network device 200 can allocate multiple virtual machine type jump servers and multiple container type intranet devices to the user terminal 100.
[0189] For illustrative purposes, when the access policy is unlimited access, the public network device 200, based on the access request and, among the multi-user type jump server and the multi-user type intranet device, allocates a jump server 301 (first jump server) and an intranet device 411 (first intranet device) to the user terminal according to the status information of the jump server and the intranet device.
[0190] It is understandable that when the access policy is single access, the public network device 200 can allocate the jump server 302 and the internal network device 412 to the user terminal based on the access request, and based on the status information of the jump server and the internal network device among the multiple virtual machine type jump server and the multiple container type internal network device.
[0191] S450: Send the first instruction to the jump node.
[0192] After the public network device 200 determines the first jump server 301 and the first internal network device 411 through step S420, it sends a first instruction to the jump node 300. The first instruction includes the device identifier of the first jump server and the device identifier of the first internal network device.
[0193] In one possible implementation, after receiving the first instruction sent by the public network device 200, the jump node 300 will perform initialization operations on the first jump server and the first internal network device depending on the situation.
[0194] As an illustration, when the first jump server is a multi-user type jump server 301, the jump node 300 will perform an initialization task on the jump server 301, establish an independent access account and password for the user terminal 100 in the jump server 301, and send the first login information to the public network device 200. The first login information includes the access account identifier and password of the first jump server.
[0195] When the first jump server is a multi-virtual machine type jump server 302, the jump node 300 will allocate an independent virtual machine for the user terminal 100 in the jump server 302 and send the first login information of the virtual machine to the public network device 200. In some possible implementations, the public network device 200 can also restore the running environment of the virtual machine to the initial state.
[0196] When the first intranet device is a multi-user intranet device 411, the jump node 300 will perform an initialization task on the intranet device 411, assign an access account and password for the intranet device 411 to the user terminal 100, and send the second login information to the public network device 200. The second login information includes the access account identifier and password of the first intranet device.
[0197] When the first intranet device is a multi-container type intranet device 412, the jump node 300 will perform an initialization task on the intranet device 411, allocate a container in the intranet device 412 to the client 100, and send the second login information of the container to the public network device 200. In some possible implementations, the public network device 200 can also restore the experience environment of the container to the initial state.
[0198] S460: Receives the first login information returned by the jump node, and provides the user with the remote desktop of the first jump server through the first login information.
[0199] After receiving the first login information returned by the jump node 300, the public network device 200 can log in to the remote desktop of the first jump server using the first login information and provide the logged-in remote desktop to the user terminal 100. The first login information may include the access account identifier and password of the first jump server.
[0200] Taking the first scaffolding machine, scaffolding machine 301, as an example, Figure 5 This diagram illustrates an interactive scenario where a user accesses services from a first intranet device. For example... Figure 5 As shown, in the public network, user terminal 100 is communicatively connected to public network device 200. In the intranet network, jump node 300 is communicatively connected to the first computing device. Public network device 200 in the public network is communicatively connected to jump node 300 in the intranet network.
[0201] First, after receiving the first login information, the public network device 200 can send the first login information to the jump node 300.
[0202] In one possible implementation, after receiving the first login information, the public network device 200 can also display the first login information to the user through the access page. The user can fill in the user login field on the access page, and the public network device 200 will then send the first login information entered by the user to the redirect node 300. This application does not limit this.
[0203] Then, the jump node 300 receives the first login information sent by the public network device 200, logs into the remote desktop of the jump server 301 using the first login information, and sends the remote desktop of the jump server 301 to the public network device 200. In some possible implementations, the jump node 300 may use Web-RDP service to send the remote desktop of the jump server 301 to the public network device 200.
[0204] Finally, the public network device 200 provides the user terminal 100 with a remote desktop after logging into the jump server 301 via the access page.
[0205] It is understandable that when the first jump server is jump server 302, the public network device 200 can also provide the user terminal 100 with a remote desktop after logging into jump server 302 through the above method.
[0206] S470: Receives the second login information returned by the jump node, provides the second login information to the user terminal, so that the user terminal can log in to the first intranet device and access the target service based on the second login information.
[0207] The public network device 200 receives the second login information returned by the redirect node 300 and provides the second login information to the user terminal 100 through the access page. The second login information may be the identifier and password of the access account of the first internal network device.
[0208] User 100 can enter the second login information through the remote desktop of the first jump server.
[0209] In response to the second login information entered by the user terminal 100, the public network device 200 receives the target service data from the first internal network device and provides the target service to the user terminal 100.
[0210] Taking the first intranet device as intranet device 411 as an example, please continue reading. Figure 5 ,like Figure 5 As shown,
[0211] First, the public network device 200 responds to the second login information entered by the user terminal 100 via the remote desktop of the jump server 301, and sends the second login information to the jump server 301 in the jump node 300. The second login information includes the access account identifier and password of the internal network device 411.
[0212] Then, the jump server 301 in the jump node 300 logs into the intranet device 411 via remote desktop using the second login information, receives the target service data of the intranet device 411, and sends the target service data of the intranet device 411 to the public network device 200.
[0213] Finally, the public network device 200 receives the data of the target service and sends the data of the target service to the access page, providing the target service to the user terminal 100.
[0214] It is understandable that when the first internal network device is internal network device 412, public network device 200 can also provide application services on internal network device 412 to user terminal 100 through the above method.
[0215] In one possible implementation, when user terminal 100 accesses a service on the first intranet device, public network device 200 can also determine whether there is an abnormal connection status of the first jump server and / or the first intranet device based on the status information of the first jump server and the first intranet device. If so, an abnormality notification is sent to user terminal 100. By monitoring the connection status of the first jump server and the first intranet device in real time, public network device 200 can promptly send an abnormality notification to user terminal when a connection abnormality is detected, thereby improving the stability of user terminal access to the target service.
[0216] Please see Figure 6 , Figure 6 The diagram shown is a flowchart of a method for accessing intranet services on the jump node side, as disclosed in an embodiment of this application. Figure 4 As shown, access to intranet services can be achieved through S610 to S640. It can be understood that when accessing the target service, this method is executed by the jump node 300. It can also be understood that this method can be executed by any of the jump machines within the jump node; when one of the multiple jump machines of the jump node manages the other jump machines, this method can also be executed by that jump machine.
[0217] S610: Obtains status information of multiple jump servers and multiple intranet devices, and sends the status information of multiple jump servers and multiple intranet devices to public network devices.
[0218] The status information of multiple jump servers includes their online status, CPU utilization, memory utilization, and number of online users; the status information of multiple intranet devices includes their online status, CPU utilization, memory utilization, and number of online users.
[0219] S620: Receives the first instruction from the public network device 200, and in response to the first instruction, allocates the first login information and the second login information.
[0220] The first instruction includes the device identifier of the first jump server and the device identifier of the first intranet device; the first login information includes the access account identifier and password of the first jump server, which can be used to log in to the first jump server; the second login information includes the access account identifier and password of the first intranet device, which can be used to log in to the first intranet device.
[0221] S630: Sends first login information to public network device 200 so that public network device 200 can log in to the first jump server.
[0222] The jump node 300 receives the first login information sent by the public network device 200, logs into the remote desktop of the first jump server through the first login information, and sends the remote desktop of the first jump server to the public network device 200 using the Web-RDP service.
[0223] S640: Send second login information to public network device 200 so that user terminal 100 can log in to the first intranet device according to the second login information and access the services on the first intranet device.
[0224] The jump node 300 uses the second login information to remotely log in to the first intranet device via the first jump server, receives the target service data from the first intranet device, and sends the target service data to the public network device 200.
[0225] After the user terminal 100 completes the access to the relevant services, the jump node 300 also needs to perform initialization tasks on the jump server 301 and the intranet device 411.
[0226] Specifically, jump node 300 respectively directs to Figure 5 The jump server 301 and the intranet device 411 send control commands, and in response to the control commands, the jump server 301 and the intranet device 411 delete the access account and password assigned to the user terminal 100.
[0227] It is worth noting that if the access policy determined based on the access request sent by the user terminal 100 is a single access, the jump node 300 sends control commands to the jump server 302 and the intranet device 412 respectively.
[0228] In response to the aforementioned control command, jump server 302 deletes the access account identifier and password assigned to client 100 and restores the virtual machine to its initial state.
[0229] In response to the above control command, intranet device 412 deletes the access account identifier and password assigned to client 100 and restores the container to its initial state.
[0230] It is understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application. In addition, in some possible implementations, each step in the above embodiments may be selectively executed according to the actual situation, and may be partially or fully executed, which is not limited here.
[0231] Compared to known methods for accessing intranet services, this method receives access requests from user terminals via public network devices on the public network. It receives status information from jump servers and intranet devices sent by the jump nodes through the public network devices. Based on different user experience requests and the device information of the jump servers and intranet devices, it assigns login information for a first jump server and a first intranet device to the user terminal. This allows users to access the target service on the first intranet device via the first jump server using this login information. This method manages both the user side on the public network and the jump servers and intranet devices on the intranet simultaneously, simplifying the user access process while ensuring security, improving the user experience, and making the resource allocation in the intranet laboratory more rational.
[0232] The above is a description of a method for accessing intranet services provided by embodiments of this application. Next, a management system provided by embodiments of this application will be described.
[0233] For example, Figure 7 The diagram shown is an architectural schematic of a management system disclosed in an embodiment of this application, such as... Figure 7 As shown, the management system includes a public network device 200, a jump node 300, and multiple internal network devices. The jump node includes multiple jump servers. The public network device 200 is located in the public network, and the jump node 300 and the multiple internal network devices are located in the internal network. The public network device 200, the jump node 300, and the multiple internal network devices are communicatively connected.
[0234] The public network device 200 is used to receive access requests sent by the user terminal and receive status information of multiple jump servers and multiple internal network devices sent by the jump node 300; based on the access request and the status information of the multiple jump servers and multiple internal network devices, it determines the first jump server 301 and the first internal network device 411; sends a first instruction to the jump node 300; receives the first login information returned by the jump node 300 and provides the user terminal with the remote desktop of the first jump server 301 through the first login information; receives the second login information returned by the jump node 300 and provides the user terminal with the second login information; wherein, the access request includes the identifier of the target service, and the first instruction includes the device identifier of the first jump server 301 and the device identifier of the first internal network device 411;
[0235] The jump node 300 is used to obtain the status information of multiple jump servers and multiple intranet devices, and send the status information of multiple jump servers and multiple intranet devices to the public network device; receive a first instruction from the public network device, respond to the first instruction, allocate first login information and second login information; send the first login information to the public network device so that the public network device can log in to the first jump server; send the second login information to the public network device so that the user terminal can log in to the first intranet device according to the second login information;
[0236] The target service available to users runs on the first intranet device 401.
[0237] Figure 8 The diagram shown is a structural schematic of the scaffolding machine provided in an embodiment of this application. Figure 8 As shown, this application embodiment provides a jump server 301, including a processor 81 and a memory 82. The memory 82 stores a computer program that can run on the processor 81, so that the processor 81 can perform the following... Figure 6 All or part of the functions described.
[0238] Figure 9 The diagram shown is a structural schematic of a public network device provided in an embodiment of this application. Figure 9 As shown, this application embodiment provides a public network device 200, including a processor 91 and a memory 92. The memory 92 stores a computer program that can run on the processor 91, so that the processor 91 can perform the following... Figure 4 All or part of the functions described.
[0239] In addition to the methods, apparatus, and electronic devices described above, embodiments of this application may also provide a computer program product, comprising computer program instructions. When executed by a processor, the computer program instructions cause the processor to perform the steps of the XXX methods in the various embodiments of this application described in the "Method" section of this specification. The computer program product can be written in any combination of one or more programming languages to perform the operations of the embodiments of this application. The programming languages include object-oriented programming languages such as Java and C++, as well as conventional procedural programming languages such as C or similar languages. The computer program code can be in source code form, object code form, executable file, or some intermediate form. The computer program code can be executed entirely on the user's intranet device, partially on the user's device, as a standalone software package, partially on the user's intranet device and partially on a remote intranet device, or entirely on a remote intranet device or server.
[0240] Furthermore, embodiments of this application may also provide a computer-readable storage medium storing computer program instructions thereon, which, when executed by a processor, cause the processor to perform the steps of the XXX method according to various embodiments of this disclosure as described in the "Method" section above. The computer-readable storage medium may be any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may, for example, include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. It should be noted that the content contained in the computer-readable medium may be appropriately added to or subtracted from the requirements of legislation and patent practice in a jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.
[0241] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0242] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0243] The basic principles of this application have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this application are merely examples and not limitations, and should not be considered as essential features of the various embodiments of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the specific details described above.
[0244] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.
[0245] It should also be noted that in the apparatus, devices, and methods of this disclosure, the components or steps can be disassembled and / or recombined. These disassemblies and / or recombinations should be considered as equivalent solutions to this disclosure.
[0246] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.
[0247] It is understood that the various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. The specific embodiments described above further illustrate the purpose, technical solutions, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
[0248] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. A method of accessing an intranet service, characterized by, The method is applied to a public network device located in a public network, and comprises the following steps: providing an access page, receiving an access request sent by a user terminal through the access page, the access request comprising an identification of a target service; receiving state information of a plurality of jump boards sent by a jump node, the jump node being located in an internal network and being in communication connection with the public network device, the jump node comprising the plurality of jump boards; receiving state information of a plurality of internal network devices sent by the jump node, the plurality of internal network devices being located in the internal network; determining a first jump board and a first internal network device according to the access request, the state information of the plurality of jump boards and the state information of the plurality of internal network devices, the target service being run on the first internal network device; sending a first instruction to the jump node, the first instruction comprising a device identification of the first jump board and a device identification of the first internal network device; receiving first login information returned by the jump node, and providing a remote desktop of the first jump board to the user terminal through the first login information; receiving second login information returned by the jump node, and providing the second login information to the user terminal, so that the user logs in the first internal network device according to the second login information and accesses the target service.
2. The method of claim 1, wherein, The state information of the plurality of jump boards comprises at least one of an online state, a CPU utilization rate, a memory usage rate or a number of online users of the plurality of jump boards; and the state information of the plurality of internal network devices comprises at least one of an online state, a CPU utilization rate, a memory usage rate or a number of online users of the plurality of internal network devices.
3. The method according to any of claims 1-2, characterized in that, The receiving of the first login information returned by the jump node and the providing of the remote desktop of the first jump board to the user terminal through the first login information comprise the following steps: receiving the first login information returned by the jump node, the first login information comprising an access account identification and a password of the first jump board; logging in the remote desktop of the first jump board through the first login information; providing the remote desktop after login to the user.
4. The method according to any one of claims 1 to 3, characterized in that, The providing of the second login information to the user terminal so that the user terminal accesses the first internal network device according to the second login information comprises the following steps: providing the second login information to the user terminal through the access page, the second login information comprising an access account identification and a password of the first internal network device; in response to the second login information input by the user terminal, sending the second login information to the jump node, and receiving data of the target service of the first internal network device sent by the jump node, and providing the target service to the user terminal.
5. The method according to any one of claims 1 to 4, characterized in that, The method of determining the first jump board and the first internal network device according to the access request, the state information of the plurality of jump boards and the plurality of internal network devices further comprises the following steps: determining whether there is an abnormal connection state of a jump board and / or an internal network device according to the state information, and if there is, sending an abnormal notification to the user terminal.
6. A method of accessing an intranet service, characterized by, The method is applied to a jump node, the jump node is located in the intranet network and is in communication connection with a plurality of intranet devices located in the intranet network, the jump node comprises a plurality of jump boards, and the method comprises: Obtaining state information of the plurality of jump boards and the plurality of intranet devices, and sending the state information of the plurality of jump boards and the plurality of intranet devices to a public network device, the public network device being located in a public network and being in communication connection with the jump node; Receiving a first instruction of the public network device, and in response to the first instruction, assigning first login information and second login information, the first instruction comprising a device identifier of a first jump board and a device identifier of a first intranet device, the first login information being used for logging into the first jump board, and the second login information being used for logging into the first intranet device; Sending the first login information to the public network device, so that the public network device logs into the first jump board; Sending the second login information to the public network device, so that the user end logs into the first intranet device according to the second login information and accesses a service on the first intranet device.
7. The method of claim 6, wherein, The state information of the plurality of jump boards comprises at least one of online state, CPU utilization, memory usage or number of online users of the plurality of jump boards; and the state information of the plurality of intranet devices comprises at least one of online state, CPU utilization, memory usage or number of online users of the plurality of intranet devices.
8. The method according to any one of claims 6-7, characterized in that, When the user end accesses the service on the first intranet device, the method comprises: Deleting the assigned first login information and second login information.
9. The method according to any one of claims 6-8, characterized in that, When the user end accesses the service on the first intranet device, the method further comprises: Performing device initialization on the first jump board and the first intranet device. 10.A management system comprising a public network device, a jump node and a plurality of intranet devices, the jump node comprising a plurality of jump boards, the public network device being located in the public network, the jump node and the plurality of intranet devices being located in the intranet network, the public network device, the jump node and the plurality of intranet devices being in communication connection, the public network device being configured to perform the method for accessing intranet services according to any one of claims 1-5, the jump node being configured to perform the method for accessing intranet services according to any one of claims 6-9, and the intranet devices being configured to run services to be accessed by users.