Communication Method, Device, Electronic Device and Readable Storage Medium

By generating and exchanging token information, a session channel between intranet devices and external network devices is established, which solves the problem of difficulty in deploying public springboard machines and limited number of intranet devices, and achieves more flexible and efficient intranet equipment maintenance.

CN113726521BActive Publication Date: 2025-06-27TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110998097.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-08-27
Publication Date
2025-06-27
Estimated Expiration
2041-08-27

AI Technical Summary

Technical Problem

In the prior art, it is difficult to deploy public network springboard machines, and the number of server ports is limited, which limits the number of maintainable intranet devices and increases the difficulty of equipment maintenance.

Method used

By generating and exchanging token information, a session channel between the intranet device and the external network device is established to realize data transmission, and the access process through the public network springboard machine is avoided.

Benefits of technology

It reduces the deployment difficulty, expands the number of intranet devices that can be accessed by external network devices, and simplifies the equipment maintenance process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113726521B_ABST
    Figure CN113726521B_ABST
Patent Text Reader

Abstract

The present application discloses a communication method, device, equipment and readable storage medium, belonging to the technical field of Internet of Things. The method includes: in response to obtaining an access request sent by an external network device for an internal network device, generating first token information corresponding to the internal network device and second token information corresponding to the external network device; sending the first token information to the internal network device and sending the second token information to the external network device; obtaining a first session request carried with the first token information sent by the internal network device, and based on the first token information, establishing a first session channel with the internal network device; obtaining a second session request carried with the second token information sent by the external network device, and based on the second token information, establishing a second session channel with the external network device, and performing data transmission between the internal network device and the external network device based on the first session channel and the second session channel. The present application does not limit the number of internal network devices that the external network device can access, reducing the deployment difficulty and the difficulty of device maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of the Internet of Things, and particularly to a communication method, device, electronic device and readable storage medium. Background Art

[0002] In the Internet of Things scenario, the internal network devices are distributed in various working conditions, making it extremely difficult for the operation and maintenance entity to maintain the internal network devices. To facilitate the operation and maintenance entity to maintain the internal network devices, the Secure Shell (SSH) technology is usually used to implement the remote control of the internal network devices by the external network devices (i.e., the devices of the operation and maintenance entity), so as to perform communication between the internal network devices and the external network devices. That is, data is sent from the internal network devices to the external network devices, or data is sent from the external network devices to the internal network devices.

[0003] In the related art, the internal network devices are bound to the public network jump servers, and the public network jump servers are bound to the ports of the servers. The public network jump server is a hardware device that can be used as a jump to realize the remote control of devices. When the operation and maintenance entity needs to maintain the internal network devices, the external network devices access the ports of the servers, and through the public network jump servers bound to the ports, the external network devices communicate with the internal network devices.

[0004] Since the use of public network jump servers increases the deployment difficulty and the number of ports of the servers is limited, the number of internal network devices that can be maintained by the operation and maintenance entity is limited, which is not conducive to the maintenance of the devices. Summary of the Invention

[0005] The embodiments of the present application provide a communication method, device, electronic device and readable storage medium, which can be used to solve the problems in the related art that the deployment of public network jump servers is difficult and the number of internal network devices that can be maintained is limited. The technical solutions include the following content.

[0006] On the one hand, the embodiments of the present application provide a communication method, and the method includes:

[0007] In response to obtaining an access request for an internal network device sent by an external network device, generating first token information corresponding to the internal network device and second token information corresponding to the external network device;

[0008] Sending the first token information to the internal network device and sending the second token information to the external network device;

[0009] Obtaining a first session request carried by the first token information sent by the internal network device, and based on the first token information, establishing a first session channel with the internal network device;

[0010] Obtain a second session request carrying the second token information sent by the external network device, and based on the second token information, establish a second session channel with the external network device;

[0011] Based on the first session channel and the second session channel, perform data transmission between the internal network device and the external network device.

[0012] On the other hand, an embodiment of the present application provides a communication device, and the device includes:

[0013] A generation module, configured to generate first token information corresponding to the internal network device and second token information corresponding to the external network device in response to obtaining an access request sent by the external network device for the internal network device;

[0014] A sending module, configured to send the first token information to the internal network device and send the second token information to the external network device;

[0015] A establishing module, configured to obtain a first session request carrying the first token information sent by the internal network device, and based on the first token information, establish a first session channel with the internal network device;

[0016] The establishing module is further configured to obtain a second session request carrying the second token information sent by the external network device, and based on the second token information, establish a second session channel with the external network device;

[0017] A transmission module, configured to perform data transmission between the internal network device and the external network device based on the first session channel and the second session channel.

[0018] In a possible implementation manner, the generation module is configured to generate identification information of the internal network device and identification information of the external network device in response to obtaining an access request sent by the external network device for the internal network device; perform encryption processing on the identification information of the internal network device to obtain first token information corresponding to the internal network device; perform encryption processing on the identification information of the external network device to obtain second token information corresponding to the external network device.

[0019] In a possible implementation manner, the establishing module is configured to parse the first token information to obtain first identification information; in response to the first identification information being consistent with the identification information of the internal network device, establish a first session channel with the internal network device.

[0020] In a possible implementation, the establishing module is configured to parse the second token information to obtain second identification information; and in response to the second identification information being consistent with the identification information of the external network device, establish a second session channel with the external network device.

[0021] In a possible implementation, the apparatus further includes:

[0022] A receiving module, configured to receive a long connection request sent by the internal network device;

[0023] The establishing module is further configured to, in response to the long connection request, establish a long connection channel with the internal network device;

[0024] The sending module is configured to send the first token information to the internal network device based on the long connection channel.

[0025] In a possible implementation, the apparatus further includes:

[0026] A disconnecting module, configured to, in response to establishing a first session channel with the internal network device and not obtaining the second session request within a target duration, disconnect the first session channel; or, in response to establishing a second session channel with the external network device and not obtaining the first session request within the target duration, disconnect the second session channel.

[0027] In a possible implementation, the sending module is further configured to send a notification message to the internal network device and the external network device, where the notification message is used to notify that the first session channel and the second session channel have been successfully established.

[0028] On the other hand, an embodiment of the present application provides a communication system, which is applied to a server cluster, and the server cluster includes a target server, a first server, and a second server;

[0029] The target server is configured to, in response to obtaining an access request sent by the external network device for the internal network device, generate a first token information corresponding to the internal network device and a second token information corresponding to the external network device; send the first token information to the internal network device, and send the second token information to the external network device;

[0030] The target server is further configured to obtain a first session request sent by the internal network device and carrying the first token information, and establish a first session channel with the internal network device through the first server based on the first token information;

[0031] The target server is further configured to obtain a second session request sent by the external network device and carrying the second token information, and establish a second session channel with the external network device based on the second token information through the second server;

[0032] The first server and the second server are configured to perform data transmission between the internal network device and the external network device based on the first session channel and the second session channel.

[0033] In a possible implementation manner, the target server is configured to, in response to obtaining an access request sent by an external network device for an internal network device, generate identification information of the internal network device and identification information of the external network device; perform encryption processing on the identification information of the internal network device to obtain first token information corresponding to the internal network device; and perform encryption processing on the identification information of the external network device to obtain second token information corresponding to the external network device.

[0034] In a possible implementation manner, the target server is configured to parse the first token information to obtain first identification information; and in response to the first identification information being consistent with the identification information of the internal network device, establish a first session channel with the internal network device.

[0035] In a possible implementation manner, the target server is configured to parse the second token information to obtain second identification information; and in response to the second identification information being consistent with the identification information of the external network device, establish a second session channel with the external network device.

[0036] In a possible implementation manner, the target server is further configured to receive a long connection request sent by the internal network device; in response to the long connection request, establish a long connection channel with the internal network device; and based on the long connection channel, send the first token information to the internal network device.

[0037] In a possible implementation manner, the target server is further configured to, in response to establishing the first session channel with the internal network device and not obtaining the second session request within a target duration, disconnect the first session channel; or, in response to establishing the second session channel with the external network device and not obtaining the first session request within the target duration, disconnect the second session channel.

[0038] In a possible implementation manner, the target server is further configured to send notification information to the internal network device and the external network device, where the notification information is used to notify that the first session channel and the second session channel have been successfully established.

[0039] In a possible implementation, the first server is configured to receive data sent by the intranet device based on the first session channel, and store the data sent by the intranet device in the queue of the second server;

[0040] The second server is configured to read the data sent by the intranet device from the queue of the second server, and send the data sent by the intranet device to the extranet device based on the second session channel.

[0041] In a possible implementation, the first server is configured to, based on the identification information of the extranet device, look up the corresponding third identification information of the identification information of the extranet device from the first form information, where the corresponding relationship between the identification information of the extranet device and the third identification information is stored in the first form information; store the data sent by the intranet device in the queue of the second server corresponding to the third identification information.

[0042] In a possible implementation, the second server is configured to receive data sent by the extranet device based on the second session channel, and store the data sent by the extranet device in the queue of the first server;

[0043] The first server is configured to read the data sent by the extranet device from the queue of the first server, and send the data sent by the extranet device to the intranet device based on the first session channel.

[0044] In a possible implementation, the second server is configured to, based on the identification information of the intranet device, look up the corresponding fourth identification information of the identification information of the intranet device from the second form information, where the corresponding relationship between the identification information of the intranet device and the fourth identification information is stored in the second form information; store the data sent by the extranet device in the queue of the first server corresponding to the fourth identification information.

[0045] On the other hand, an embodiment of the present application provides an electronic device, which includes a processor and a memory. At least one program code is stored in the memory, and the at least one program code is loaded and executed by the processor to enable the electronic device to implement the communication method described in any one of the above.

[0046] On the other hand, a computer-readable storage medium is further provided. At least one program code is stored in the computer-readable storage medium, and the at least one program code is loaded and executed by a processor to enable a computer to implement the communication method described in any one of the above.

[0047] On the other hand, a computer program or a computer program product is also provided. At least one computer instruction is stored in the computer program or the computer program product, and the at least one computer instruction is loaded and executed by a processor to enable a computer to implement any one of the above communication methods.

[0048] The technical solutions provided in the embodiments of the present application at least bring the following beneficial effects:

[0049] The technical solutions provided in the embodiments of the present application establish a first session channel with an intranet device based on the first token information carried in the first session request, and establish a second session channel with an extranet device based on the second token information carried in the second session request. Through the first session channel with the intranet device and the second session channel with the extranet device, the data sent by the intranet device is forwarded to the extranet device, or the data sent by the extranet device is forwarded to the intranet device. The extranet device no longer accesses the intranet device through a public network jump server, reducing the deployment difficulty, not limiting the number of intranet devices that the extranet device can access, and reducing the difficulty of device maintenance. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0051] Figure 1 is a schematic diagram of the implementation environment of a communication method provided in an embodiment of the present application;

[0052] Figure 2 is a flowchart of a communication method provided in an embodiment of the present application;

[0053] Figure 3 is a schematic framework diagram of communication between an intranet device and an extranet device provided in an embodiment of the present application;

[0054] Figure 4 is a schematic flowchart of communication between an intranet device and an extranet device provided in an embodiment of the present application;

[0055] Figure 5 is a schematic diagram of communication between an intranet device and an extranet device through a server cluster provided in an embodiment of the present application;

[0056] Figure 6 is a schematic structural diagram of a communication device provided in an embodiment of the present application;

[0057] Figure 7It is a schematic structural diagram of a terminal device provided by an embodiment of the present application;

[0058] Figure 8 It is a schematic structural diagram of a server provided by an embodiment of the present application. Detailed implementation manners

[0059] To make the objectives, technical solutions, and advantages of the present application clearer, the following will further describe in detail the embodiments of the present application with reference to the accompanying drawings.

[0060] The following will introduce in detail the terms involved in the embodiments of the present application.

[0061] High availability: Describes that a system is specially designed to reduce downtime and maintain high availability of services.

[0062] Internet of Things: The Internet of Things is an information carrier based on the Internet, traditional telecommunications networks, etc. It enables all ordinary physical objects that can be independently addressed to form an interconnected network.

[0063] Edge computing: On the side close to the object or the data source, an open platform integrating network, computing, storage, and application core capabilities is adopted to provide the nearest-end services nearby.

[0064] The communication methods in various alternative embodiments of the present application are applicable to the field of Internet of Things technology. The Internet of Things (IOT) refers to the use of various information sensors, radio frequency identification technologies, global positioning systems, infrared sensors, laser scanners and other devices and technologies to collect in real time any objects or processes that need to be connected and interacted, collect various required information such as their sound, light, heat, electricity, mechanics, chemistry, biology, location, etc., and through various possible network accesses, realize the ubiquitous connection of things to things and things to people, and realize the intelligent perception, identification and management of items and processes. The Internet of Things is an information carrier based on the Internet, traditional telecommunications networks, etc. It enables all ordinary physical objects that can be independently addressed to form an interconnected network.

[0065] Cloud Internet of Things (Cloud IOT) aims to connect the information sensed by sensing devices and the received instructions in the traditional Internet of Things to the Internet, truly realizing networking, and realizing massive data storage and operation through cloud computing technology. Due to the characteristic of the Internet of Things that things are connected to each other and the current operating states of each "object" are sensed in real time, a large amount of data information will be generated in this process. How to summarize this information and how to screen useful information from the massive information for decision-making support in subsequent development have become key issues affecting the development of the Internet of Things. Therefore, the Internet of Things cloud based on cloud computing and cloud storage technologies has also become a powerful support for Internet of Things technology and applications.

[0066] Figure 1 It is a schematic diagram of the implementation environment of a communication method provided by an embodiment of the present application. As Figure 1 shown, this implementation environment includes: an intranet device 101, an extranet device 102, and a server 103. The intranet device 101 can be a terminal device or a server, and the extranet device 102 is a terminal device. Among them, both the terminal device and the server are electronic devices.

[0067] The terminal device can be at least one of a smart phone, a game console, a desktop computer, a tablet computer, an e-book reader, an MP3 (Moving Picture Experts Group Audio Layer III) player, an MP4 (Moving Picture Experts Group Audio Layer IV) player, and a laptop computer. Both the intranet device 101 and the extranet device 102 are communicatively connected to the server 103 through a wired network or a wireless network, so as to realize data transmission between the intranet device 101 and the extranet device 102 through interaction with the server 103.

[0068] The intranet device 101 and the extranet device 102 can generally refer to one of multiple electronic devices. This embodiment only uses the intranet device 101 and the extranet device 102 as examples for illustration. Those skilled in the art can know that the number of the above-mentioned intranet device 101 and extranet device 102 can be more or less. For example, the above-mentioned intranet device 101 and extranet device 102 can each be only one, or the above-mentioned intranet device 101 and extranet device 102 can each be dozens or hundreds, or more. The embodiments of the present application do not limit the number and type of electronic devices.

[0069] The server 103 can be a single server, a server cluster composed of multiple servers, or any one of a cloud computing platform and a virtualization center. The embodiments of the present application do not limit this.

[0070] Those skilled in the art should understand that the above-mentioned intranet device 101, extranet device 102, and server 103 are only examples. Other existing or future terminal devices or servers that can be applied to the present application should also be included in the protection scope of the present application and are hereby incorporated by reference.

[0071] Based on the above implementation environment, an embodiment of the present application provides a communication method to Figure 2 take the flowchart of a communication method provided by an embodiment of the present application shown as an example. This method can be executed by Figure 1 the server 103 inFigure 2 As shown, the method includes steps 201 to 205.

[0072] Step 201, in response to obtaining an access request sent by an external network device for an internal network device, generate first token information corresponding to the internal network device and second token information corresponding to the external network device.

[0073] In the embodiments of the present application, the internal network refers to a local area network, and the external network refers to a network that does not include this local area network. That is to say, a network is divided into two parts: inside the local area network and outside the local area network. The part inside the local area network is the internal network, and the part outside the local area network is the external network. Optionally, the internal network device is an electronic device within a local area network, and the external network device is an electronic device outside this local area network. Among them, a local area network is a private network, generally within a building or near a building, such as a home, office, or factory. The local area network is used to connect multiple electronic devices so that the electronic devices can share resources and exchange information.

[0074] Optionally, the access request sent by the external network device for the internal network device is a Secure Shell (SSH) request. SSH is formulated by the Network Working Group of the Internet Engineering Task Force (IETF). SSH is a security protocol based on the application layer. SSH is a relatively reliable protocol that provides security for remote login sessions and other network services.

[0075] Optionally, the access request sent by the external network device for the internal network device includes, but is not limited to, a Hyper Text Transfer Protocol (HTTP) request. HTTP is a request-response protocol that usually runs on top of the Transmission Control Protocol (TCP). HTTP specifies what kind of messages the client may send to the server and what kind of responses it will receive.

[0076] It should be noted that the access request carries the identity document (ID) of the internal network device, and this ID is unique. That is to say, there is a one-to-one correspondence between the internal network device and the ID. In the embodiments of the present application, the access request also carries information such as the host and computer port.

[0077] An application program facilitating operation and maintenance operations for operation and maintenance objects is installed on the external network device. This application program is not limited in this application. Exemplarily, the application program is a browser. Through this application program, the processing flow of operation and maintenance objects is simplified, facilitating device maintenance anytime and anywhere.

[0078] A display page of the application program is shown on the external network device, facilitating the operation and maintenance object to select the internal network device to be controlled on the display page of the application program. In response to the selection operation of the internal network device by the operation and maintenance object on the display page, the external network device sends an access request for the internal network device to the server, and the ID of the internal network device is carried in the access request. After receiving the access request, the server creates a pair of token information and stores this pair of token information. Among them, one token information in this pair of token information is recorded as the first token information corresponding to the internal network device, and the other token information is recorded as the second token information corresponding to the external network device. By creating and storing this pair of token information, the corresponding relationship between the internal network device and the external network device is stored, providing a basic guarantee for the communication between the internal network device and the external network device.

[0079] Among them, the first token information is a string generated by the server. The first token information serves as a token (Token) for the internal network device to send a request to the server and has timeliness. The first token information can reduce the data processing pressure of the server and lower the frequency of querying the database. Based on the same principle, the second token information is another string generated by the server and corresponds to the first token information. The second token information serves as a token (Token) for the external network device to send a request to the server and also has timeliness.

[0080] In a possible implementation manner, in response to obtaining an access request for an internal network device sent by an external network device, generating the first token information corresponding to the internal network device and the second token information corresponding to the external network device includes: in response to obtaining an access request for an internal network device sent by an external network device, generating the identification information of the internal network device and the identification information of the external network device; performing encryption processing on the identification information of the internal network device to obtain the first token information corresponding to the internal network device; performing encryption processing on the identification information of the external network device to obtain the second token information corresponding to the external network device.

[0081] Based on the access request for the internal network device sent by the external network device, the identification information of the internal network device and the identification information of the external network device are generated. The identification information of the internal network device is a temporary ID of the internal network device generated by the server, and the temporary ID of the internal network device is different from the ID of the internal network device carried in the access request. Based on the same principle, the identification information of the external network device is also a temporary ID of the external network device generated by the server, different from the ID of the external network device, and the ID of the external network device is also unique, that is, there is a one-to-one correspondence between the external network device and the ID.

[0082] Using a symmetric encryption method or an asymmetric encryption method, encrypt the identification information of the intranet device carried in the access request to obtain the first token information corresponding to the intranet device. The symmetric encryption method uses the same key for encryption and decryption, and is also called single-key encryption. The asymmetric encryption method uses a public key and a private key for encryption and decryption. The specific implementation manners of the symmetric encryption method and the asymmetric encryption method are not limited in the embodiments of the present application. Based on the same principle, use a symmetric encryption method or an asymmetric encryption method to encrypt the identification information of the extranet device carried in the access request to obtain the second token information corresponding to the extranet device.

[0083] Step 202: Send the first token information to the intranet device and send the second token information to the extranet device.

[0084] In the embodiments of the present application, since the extranet device sends an access request for the intranet device to the server, the server can feedback the second token information of the extranet device generated in response to the access request to the extranet device. Since the first token information of the intranet device is also generated in response to the access request, the server needs to actively send the first token information of the intranet device to the intranet device. The embodiments of the present application provide a method for the server to actively send the first token information to the intranet device. The method is as follows.

[0085] In a possible implementation manner, before sending the first token information to the intranet device, it further includes: receiving a long connection request sent by the intranet device; in response to the long connection request, establishing a long connection channel with the intranet device; and sending the first token information to the intranet device, including: based on the long connection channel, sending the first token information to the intranet device.

[0086] A long connection means that multiple data packets can be continuously sent on a connection. During the connection maintenance period, if no data packets are sent, both parties need to send link detection packets. Among them, the long connection is a connection for control signaling, and the signaling is a signal for controlling a circuit.

[0087] To facilitate the server to actively send the first token information to the intranet device, the intranet device sends a long connection request to the server, and the server responds to this long connection request to establish a long connection channel between the server and the intranet device, so that the server and the intranet device can communicate with each other at any time. That is to say, through this long connection channel, the server can actively send the first token information to the intranet device at any time.

[0088] In a possible implementation, after the server establishes a long connection channel with the internal network device in response to a long connection request, the server obtains an access request for the internal network device sent by the external network device. In response to this access request, when verifying that the long connection channel between the internal network device and the server exists, the server generates first token information corresponding to the internal network device and second token information corresponding to the external network device, and then performs step 202. When verifying that the long connection channel between the internal network device and the server does not exist, a prompt message is generated and sent to the external network device, and this prompt message is used to prompt the external network device that it cannot control the internal network device, or to prompt that the internal network device is in an unlogged-in state.

[0089] In a possible implementation, the internal network device includes a client (which can be referred to as an SSH client), the server includes a device controller and an SSH proxy module, and the external network device includes a client (which can also be referred to as an SSH client, and is the client corresponding to the application program that facilitates the operation and maintenance of the operation and maintenance object).

[0090] When the internal network device starts up, the client of the internal network device automatically starts up and sends a long connection request to the device controller. In response to this long connection request, the device controller establishes a long connection channel between the device controller and the internal network device.

[0091] The client of the external network device sends an access request for the internal network device to the SSH proxy module. After receiving this access request, the SSH proxy module sends verification information to the device controller, and the device controller sends a verification result to the SSH proxy module. This verification information is used to instruct the device controller to verify whether the long connection channel between the device controller and the internal network device exists.

[0092] When the verification result indicates that the long connection channel exists, it means that the internal network device is in a logged-in state. At this time, the SSH proxy module generates first token information corresponding to the internal network device and second token information corresponding to the external network device. The SSH proxy module sends the first token information corresponding to the internal network device to the device controller, and the device controller sends the first token information corresponding to the internal network device to the client of the internal network device based on the long connection channel, thereby realizing that the server sends the first token information to the internal network device based on the long connection channel. The SSH proxy module sends the second token information corresponding to the external network device to the external network controller, thereby realizing that the server sends the second token information to the external network device.

[0093] When the verification result indicates that the long connection channel does not exist (i.e., the long connection channel has been disconnected), it means that the internal network device is in an unlogged-in state. At this time, the server sends a prompt message to the external network device, and this prompt message is used to prompt the external network device that it cannot control the internal network device, or to prompt that the internal network device is in an unlogged-in state.

[0094] It should be noted that in response to an access request, in addition to verifying the existence of the long connection channel between the server and the internal network device, the server can also verify whether the external network device has the access right to the internal network device. When it is verified that the long connection channel between the internal network device and the server exists and the external network device has the access right to the internal network device, the first token information corresponding to the internal network device and the second token information corresponding to the external network device are generated. When it is verified that the long connection channel between the internal network device and the server does not exist and / or the external network device does not have the access right to the internal network device, a prompt message is generated and sent to the external network device, and the prompt message is used to prompt that the external network device cannot control the internal network device, or to prompt that the internal network device is in an unlogged state, or to prompt that the external network device does not have the access right to the internal network device.

[0095] In a possible implementation, the identification information of the first device is configured in the blacklist, and the first device is an external network device that does not have the access right to the internal network device. After the server receives the access request sent by the external network device for the internal network device, when the external network device belongs to the first device, the external network device does not have the access right to the internal network device. At this time, the server sends a prompt message to the external network device, and the prompt message is used to prompt that the external network device does not have the access right to the internal network device. When the external network device does not belong to the first device, the external network device has the access right to the internal network device. At this time, the server generates the first token information corresponding to the internal network device and the second token information corresponding to the external network device, and then executes step 202.

[0096] In another possible implementation, the identification information of the second device is configured in the white list, and the second device is an external network device that has the access right to the internal network device. After the server receives the access request sent by the external network device for the internal network device, when the external network device does not belong to the second device, the external network device does not have the access right to the internal network device. At this time, the server sends a prompt message to the external network device, and the prompt message is used to prompt that the external network device does not have the access right to the internal network device. When the external network device belongs to the second device, the external network device has the access right to the internal network device. At this time, the server generates the first token information corresponding to the internal network device and the second token information corresponding to the external network device, and then executes step 202.

[0097] Step 203, obtain the first session request carried with the first token information sent by the internal network device, and based on the first token information, establish the first session channel with the internal network device.

[0098] Exemplarily, the first session request includes, but is not limited to, a WebSocket request. The WebSocket request is a full-duplex communication protocol based on the Transmission Control Protocol (TCP), which allows the server to actively push data to the electronic device.

[0099] In the embodiment of the present application, after the server sends the first token information to the intranet device, the intranet device sends a first session request to the server, and the first session request carries the first token information. The server establishes a first session channel between the server and the intranet device based on the first token information, and the first session channel is used for data transmission.

[0100] Taking the first session request as a WebSocket request as an example, the WebSocket request carries the first token information. After establishing the first session channel between the server and the intranet device based on the first token information, a persistent connection is created between the server and the intranet device, and bidirectional data transmission can be performed.

[0101] Step 204: Obtain a second session request sent by the extranet device and carrying second token information, and establish a second session channel with the extranet device based on the second token information.

[0102] Optionally, after the server sends the second token information to the extranet device, the extranet device sends a second session request to the server, and the second session request carries the second token information. The server establishes a second session channel between the server and the extranet device based on the second token information, and the second session channel is used for data transmission. Among them, the second session request includes, but is not limited to, a WebSocket request.

[0103] Step 205: Perform data transmission between the intranet device and the extranet device based on the first session channel and the second session channel.

[0104] The server receives the data sent by the intranet device based on the first session channel and forwards the received data to the extranet device based on the second session channel, or the server receives the data sent by the extranet device based on the second session channel and forwards the received data to the intranet device based on the first session channel.

[0105] In a possible implementation manner, establishing a first session channel with the intranet device based on the first token information includes: parsing the first token information to obtain first identification information; in response to the first identification information being consistent with the identification information of the intranet device, establishing a first session channel with the intranet device.

[0106] After the server sends the first token information to the internal network device, the internal network device sends a first session request to the server, and the first token information is carried in the first session request.

[0107] In a possible implementation, since the first token information is generated by the server, the server can store the first token information. When the server receives the first session request, when the server detects that it has stored the first token information carried in the first session request, the server establishes a first session channel with the internal network device. When the server detects that it has not stored the first token information carried in the first session request, the server sends a prompt message to the internal network device, and the prompt message is used to prompt that the server cannot respond to the first session request.

[0108] In another possible implementation, the server parses (i.e., decrypts) the first token information to obtain first identification information. When the first identification information is consistent with the identification information of the internal network device, the server establishes a first session channel with the internal network device. When the first identification information is inconsistent with the identification information of the internal network device in the corresponding relationship, the server sends a prompt message to the internal network device, and the prompt message is used to prompt that the server cannot respond to the first session request.

[0109] In the embodiment of the present application, based on the second token information, establishing a second session channel with an external network device includes: parsing the second token information to obtain second identification information; and in response to the second identification information being consistent with the identification information of the external network device, establishing a second session channel with the external network device.

[0110] After the server sends the second token information to the external network device, the external network device sends a second session request to the server, and the second token information is carried in the second session request.

[0111] In a possible implementation, since the second token information is generated by the server, the server can store the second token information. When the server receives the second session request, when the server detects that it has stored the second token information carried in the second session request, the server establishes a second session channel with the external network device. When the server detects that it has not stored the second token information carried in the second session request, the server sends a prompt message to the external network device, and the prompt message is used to prompt that the server cannot respond to the second session request.

[0112] In another possible implementation, the server parses (i.e., decrypts) the second token information to obtain the second identification information. When the second identification information is consistent with the identification information of the external network device in the corresponding relationship, the server establishes a second session channel with the external network device. When the second identification information is inconsistent with the identification information of the external network device in the corresponding relationship, the server sends a prompt message to the external network device, and the prompt message is used to prompt that the server cannot respond to the second session request.

[0113] In the embodiments of the present application, the acquisition time interval between the first session request and the second session request is less than or equal to the target duration. The value of the target duration is not limited. Exemplarily, the target duration is 2 minutes.

[0114] The embodiments of the present application do not limit the acquisition sequence of the first session request and the second session request. That is to say, the first session request can be acquired first, and then the second session request can be acquired. Or the second session request can be acquired first, and then the first session request can be acquired. Or the first session request and the second session request can be acquired simultaneously.

[0115] After acquiring the first session request sent by the internal network device, based on the first token information carried in the first session request, a first session channel is established with the internal network device. When the second session request sent by the external network device is acquired within the target duration, based on the second token information carried in the second session request, a second session channel is established with the external network device. Or, after acquiring the second session request sent by the external network device, based on the second token information carried in the second session request, a second session channel is established with the external network device. When the first session request sent by the internal network device is acquired within the target duration, based on the first token information carried in the first session request, a first session channel is established with the internal network device.

[0116] After the first session channel and the second session channel are established, before data transmission between the internal network device and the external network device is performed based on the first session channel and the second session channel, it further includes: sending a notification message to the internal network device and the external network device, and the notification message is used to notify that the first session channel and the second session channel have been successfully established.

[0117] By sending a notification message to the internal network device, notifying the internal network device that the first session channel and the second session channel have been successfully established, it is convenient for the internal network device to send data to the external network device, that is, the internal network device sends data to the server, and the server forwards the data to the external network device.

[0118] By sending a notification message to the external network device, notifying the external network device that the first session channel and the second session channel have been successfully established, it is convenient for the external network device to send data to the internal network device, that is, the external network device sends data to the server, and the server forwards the data to the internal network device.

[0119] In the embodiment of the present application, the method further includes: in response to establishing a first session channel with an intranet device and not obtaining a second session request within a target duration, disconnecting the first session channel; or, in response to establishing a second session channel with an extranet device and not obtaining a first session request within a target duration, disconnecting the second session channel.

[0120] When the first session channel has been established and a second session request is not obtained within the target duration, the first session channel is disconnected, and a prompt message is sent to the intranet device, where the prompt message is used to prompt that the first session channel has been disconnected.

[0121] When the second session channel has been established and a first session request is not obtained within the target duration, the second session channel is disconnected, and a prompt message is sent to the extranet device, where the prompt message is used to prompt that the second session channel has been disconnected.

[0122] The embodiment of the present application provides a specific scenario, which includes an intranet device, an extranet device, and a cloud (i.e., Figure 1 the server 103 in), the intranet device is communicatively connected to the cloud, and the extranet device is communicatively connected to the cloud. The schematic diagram of the framework applicable to this scenario is as shown in Figure 3 shown, Figure 3 It is a schematic diagram of a framework for communication between an intranet device and an extranet device provided by an embodiment of the present application. The extranet device, intranet device, and cloud included in this framework schematic diagram will be described in detail below.

[0123] An application program facilitating operation and maintenance operations for operation and maintenance objects is installed on the extranet device. The application program is a browser. The operation and maintenance object opens a web version of the SSH page based on the browser, facilitating selecting the intranet device to be controlled on this SSH page and sending an access request to the SSH proxy module in the cloud.

[0124] A client is installed on the intranet device. After the intranet device is started, the client is automatically started and connected to the device controller in the cloud. The client is connected to the device controller based on the remote procedure call framework. The remote procedure call framework supports batch operations between the client and the cloud. The client can send multiple requests to the cloud together, and the cloud can also return the results of these multiple requests together to implement streaming remote procedure call (RPC). Among them, when the client receives the reverse SSH opening event sent by the device controller, on the one hand, it starts the local SSH channel, and on the other hand, it establishes a first session channel with the SSH proxy module. The client receives the data sent by the SSH proxy module based on the first session channel and inputs the data into the SSH channel. The client also sends the instructions returned by the local SSH channel to the SSH proxy module.

[0125] The cloud is composed of at least one server, and the functions of the server can be as shown in the functions of the device controller and the SSH proxy module. The device controller communicates with the SSH proxy module based on RPC. The device controller is a background service that sends instructions to the intranet devices, and the instructions include but are not limited to the restart instruction of the intranet device, the network configuration instruction of the intranet device, and the reverse SSH opening instruction of the intranet device. After the intranet device starts, the client actively accesses the device controller, and the device controller provides an interface to send the reverse SSH opening event to the client of the intranet device. The SSH proxy module performs data transmission with the client in the intranet device based on the first session channel, and the SSH proxy module performs data transmission with the browser in the extranet device based on the second session channel, so as to realize data transmission between the intranet device and the extranet device.

[0126] In the scenario of the embodiment of the present application, the intranet device and the extranet device communicate based on Figure 3 the framework diagram shown. As Figure 4 shown, Figure 4 is a schematic diagram of the communication process between the intranet device and the extranet device provided by the embodiment of the present application, and the communication process will be introduced in detail below.

[0127] First, a long connection channel is established between the intranet device and the device controller, and this long connection channel is the connection channel for control signaling.

[0128] Secondly, the extranet device sends an access request to the SSH proxy module, and the access request carries information such as the ID of the intranet device, the identification information of the extranet device, the host, and the computer port. The SSH proxy module sends verification information to the device controller, and this verification information is used to verify whether the long connection channel exists and whether the extranet device has the access right to the intranet device. The device controller returns a verification result to the SSH proxy module.

[0129] When the verification result is successful, that is, the long connection channel exists and the extranet device has the access right to the intranet device, the steps in part A are executed at this time. First, the SSH proxy module generates the first token information and the second token information. Then, the SSH proxy module sends the second token information to the extranet device, and at the same time, the SSH proxy module sends the first token information to the device controller, and the device controller sends the first token information to the intranet device.

[0130] After the internal network device receives the first token information, the internal network device initiates a session request, that is, executes the steps in part B. First, the internal network device starts a local SSH channel and sends a first session request to the SSH proxy module. After the SSH proxy module receives the first session request, it establishes a first session channel. Then, when a second session channel is established within the target duration, the steps in part b1 are executed, that is, the SSH proxy module sends notification messages to the internal network device and the external network device respectively. The notification messages are used to notify that the first session channel and the second session channel have been successfully established. The SSH proxy module is also used to receive data sent by the internal network device based on the first session channel and the second session channel and send the data to the external network device, or receive data sent by the external network device and send the data to the internal network device. When the second session channel is not established within the target duration, the steps in part b2 are executed, that is, the SSH proxy module disconnects the first session channel and sends a prompt message to the internal network device. The prompt message is used to prompt that the first session channel has been disconnected.

[0131] After the external network device receives the second token information, the external network device initiates a session request, that is, executes the steps in part C. First, the external network device sends a second session request to the SSH proxy module. After the SSH proxy module receives the second session request, it establishes a second session channel. Then, when a first session channel is established within the target duration, the steps in part c1 are executed, that is, the SSH proxy module sends notification messages to the internal network device and the external network device respectively. The notification messages are used to notify that the first session channel and the second session channel have been successfully established. The SSH proxy module is also used to receive data sent by the internal network device based on the first session channel and the second session channel and send the data to the external network device, or receive data sent by the external network device and send the data to the internal network device. When the first session channel is not established within the target duration, the steps in part c2 are executed, that is, the SSH proxy module disconnects the second session channel and sends a prompt message to the external network device. The prompt message is used to prompt that the second session channel has been disconnected.

[0132] In the embodiment of the present application, this method is executed by the target server. That is Figure 1 the server 103 in is the target server. In a possible implementation manner, the first session channel is a channel between the internal network device and the target server, and the second session channel is a channel between the external network device and the target server. The target server can receive data sent by the internal network device and directly forward the data to the external network device. The target server can also receive data sent by the external network device and directly forward the data to the internal network device. For details, see the description of steps 201-step 205 above, which will not be elaborated here.

[0133] In another possible implementation, the communication method in the embodiments of the present application is applied to a server cluster, which includes a target server, a first server, and a second server. The method includes:

[0134] The target server is configured to generate first token information corresponding to the internal network device and second token information corresponding to the external network device in response to obtaining an access request for the internal network device sent by the external network device.

[0135] The target server is further configured to send the first token information to the internal network device and send the second token information to the external network device.

[0136] The target server is further configured to obtain a first session request sent by the internal network device carrying the first token information, and establish a first session channel with the internal network device through the first server based on the first token information.

[0137] The target server is further configured to obtain a second session request sent by the external network device carrying the second token information, and establish a second session channel with the external network device through the second server based on the second token information.

[0138] Data transmission between the internal network device and the external network device based on the first session channel and the second session channel includes: data transmission between the internal network device and the external network device through the first server and the second server based on the first session channel and the second session channel.

[0139] In the embodiments of the present application, the target server is communicatively connected to the first server and the second server. The first session channel is a channel between the internal network device and the first server, and the second session channel is a channel between the external network device and the second server.

[0140] The target server obtains an access request for the internal network device sent by the external network device, generates first token information corresponding to the internal network device and second token information corresponding to the external network device, sends the first token information to the internal network device, and sends the second token information to the external network device. For details, see the description of steps 201 - 202 above, and will not be elaborated here.

[0141] After that, the target server obtains the first session request sent by the intranet device, and based on the first token information carried in the first session request, sends the first channel establishment information to the first server. The first channel establishment information is used to enable the first server to establish a first session channel with the intranet device. Based on the same principle, the target server obtains the second session request sent by the extranet device, and based on the second token information carried in the second session request, sends the second channel establishment information to the second server. The second channel establishment information is used to enable the second server to establish a second session channel with the extranet device. For details, see the description of steps 203-step 204 above, which will not be elaborated here.

[0142] Among them, taking the example of sending the first channel establishment information to the first server based on the first token information carried in the first session request. When the target server detects that it has stored the first token information carried in the first session request, or the first identification information obtained by parsing the first token information is consistent with the identification information of the intranet device, it sends the first channel establishment information to the first server. When the target server detects that it has not stored the first token information carried in the first session request, or the first identification information obtained by parsing the first token information is inconsistent with the identification information of the intranet device, the target server sends a prompt message to the intranet device. The prompt message is used to prompt that the server cannot respond to the first session request.

[0143] The process of sending the second channel establishment information to the second server based on the second token information carried in the second session request is similar to the process of sending the first channel establishment information to the first server based on the first token information carried in the first session request, which will not be elaborated here.

[0144] In the embodiment of this application, data transmission between the intranet device and the extranet device is carried out through the first server and the second server based on the first session channel and the second session channel, including: receiving, by the first server, the data sent by the intranet device based on the first session channel, and storing the data sent by the intranet device in the queue of the second server; reading, by the second server, the data sent by the intranet device from the queue of the second server, and sending the data sent by the intranet device to the extranet device based on the second session channel.

[0145] The server cluster includes multiple servers, and these multiple servers include the target server, the first server, and the second server. These multiple servers correspond to a database, and the database includes, but is not limited to, a Remote Dictionary Server (Redis) database.

[0146] Since there is a first session channel between the intranet device and the first server, and a second session channel between the extranet device and the second server, it is necessary to implement the first server receiving the data sent by the intranet device and the second server forwarding the data to the extranet device based on the database corresponding to the server cluster.

[0147] The first server corresponds to a queue in the database. The queue of the first server is used to store the data sent to the first server. When forwarding the data sent by the intranet device to the extranet device based on the first session channel and the second session channel, the intranet device sends data to the first server based on the first session channel. After receiving the data, the first server stores the data in the queue of the second server. The second server monitors the queue of the second server in real time. When the second server monitors that the data is stored in the queue of the second server, it reads the data from the queue of the second server and sends the data to the extranet device based on the second session channel, thus realizing forwarding the data sent by the intranet device to the extranet device.

[0148] Among them, storing the data sent by the intranet device in the queue of the second server includes: based on the identification information of the extranet device, searching in the first form information for the third identification information corresponding to the identification information of the extranet device, where the first form information stores the corresponding relationship between the identification information of the extranet device and the third identification information; storing the data sent by the intranet device in the queue of the second server corresponding to the third identification information.

[0149] In the embodiment of the present application, there is first form information in the database, and the first form information stores the corresponding relationship between the identification information of the extranet device and the identification information of the server.

[0150] When the first server stores the data sent by the intranet device in the queue of the second server, based on the identification information of the extranet device, it searches in the first form information for the third identification information corresponding to the identification information of the extranet device, and the third identification information is the identification information of the second server. Based on the third identification information, the data sent by the intranet device is stored in the queue of the second server.

[0151] Based on the same principle, the data transmission between the intranet device and the extranet device by the first server and the second server based on the first session channel and the second session channel includes: the second server receiving the data sent by the extranet device based on the second session channel and storing the data sent by the extranet device in the queue of the first server; the first server reading the data sent by the extranet device from the queue of the first server and sending the data sent by the extranet device to the intranet device based on the first session channel.

[0152] The second server corresponds to another queue in the database. The queue of the second server is used to store the data sent to the second server. When forwarding the data sent by the external network device to the internal network device based on the first session channel and the second session channel, the external network device sends data to the second server based on the second session channel. After receiving the data, the second server stores the data in the queue of the first server. The first server monitors the queue of the first server in real time. When the first server monitors that the data is stored in the queue of the first server, it reads the data from the queue of the first server and sends the data to the internal network device based on the first session channel, so as to realize forwarding the data sent by the external network device to the internal network device.

[0153] Among them, storing the data sent by the external network device in the queue of the first server includes: based on the identification information of the internal network device, searching for the fourth identification information corresponding to the identification information of the internal network device from the second form information, and the corresponding relationship between the identification information of the internal network device and the fourth identification information is stored in the second form information; storing the data sent by the external network device in the queue of the first server corresponding to the fourth identification information.

[0154] There is also second form information in the database, and the corresponding relationship between the identification information of the internal network device and the identification information of the server is stored in the second form information. When the second server stores the data sent by the external network device in the queue of the first server, based on the identification information of the internal network device, it searches for the fourth identification information corresponding to the identification information of the internal network device from the second form information, and the fourth identification information is the identification information of the first server. The data sent by the external network device is stored in the queue of the first server based on the first identification information.

[0155] The embodiment of the present application provides a specific scenario, and this scenario is a scenario of a server cluster. As Figure 5 shown, Figure 5 is a schematic diagram of communication between an internal network device and an external network device through a server cluster provided by the embodiment of the present application.

[0156] In the scenario of the embodiment of the present application, when the first server and the second server are the same server, this server is server 02, the internal network device is internal network device 02, and the external network device is external network device 02. At this time, there is a first session channel between the internal network device 02 and the server 02, and there is a second session channel between the external network device 02 and the server 02. The server 02 can receive the data sent by the internal network device 02 and directly forward the data to the external network device 02. The server 02 can also receive the data sent by the external network device 02 and directly forward the data to the internal network device 02.

[0157] When the first server and the second server are different servers, the first server is server 03, the second server is server 01, the internal network device is internal network device 01, and the external network device is external network device 01. There is a first session channel between internal network device 01 and server 03, and a second session channel between external network device 01 and server 01.

[0158] There are 4 queues in the database, namely the queue of internal network device x - server 01, the queue of external network device 01 - server 01, the queue of internal network device 01 - server 03, and the queue of external network device y - server 03. Among them, both x and y represent the numbers of the servers. Among them, the queue of external network device 01 - server 01 is the queue of the second server mentioned above, and the queue of internal network device 01 - server 03 is the queue of the first server mentioned above.

[0159] There are also two forms in the database, namely the form of the internal network device (i.e., the second form information mentioned above) and the form of the external network device (i.e., the first form information mentioned above). The form of the internal network device stores the corresponding relationships between internal network device x and server 01 and between internal network device 01 and server 03. The form of the external network device stores the corresponding relationships between external network device 01 and server 01 and between external network device y and server 03.

[0160] In a possible implementation, internal network device 01 sends data to server 03. After receiving the data, server 03 first determines server 01 based on the corresponding relationship between external network device 01 and server 01 stored in the form of the external network device, and sends the data to the queue of external network device 01 - server 01. Server 01 monitors the queue of external network device 01 - server 01 in real time. When it monitors that the queue of external network device 01 - server 01 receives data, it reads the data from the queue of external network device 01 - server 01 and sends the data to external network device 01.

[0161] In another possible implementation, external network device 01 sends data to server 01. After receiving the data, server 01 first determines server 03 based on the corresponding relationship between internal network device 01 and server 03 stored in the form of the internal network device, and sends the data to the queue of internal network device 01 - server 03. Server 03 monitors the queue of internal network device 01 - server 03 in real time. When it monitors that the queue of internal network device 01 - server 03 receives data, it reads the data from the queue of internal network device 01 - server 03 and sends the data to internal network device 01.

[0162] The above method establishes a first session channel with an intranet device based on the first token information carried in the first session request, and establishes a second session channel with an extranet device based on the second token information carried in the second session request. Through the first session channel with the intranet device and the second session channel with the extranet device, it is realized to forward the data sent by the intranet device to the extranet device, or forward the data sent by the extranet device to the intranet device. The extranet device no longer accesses the intranet device through the public network jump server, reducing the deployment difficulty, not limiting the number of intranet devices that the extranet device can access, and reducing the difficulty of device maintenance.

[0163] Figure 6 The following is a schematic structural diagram of a communication device provided by an embodiment of the present application, as Figure 6 shown, the device includes:

[0164] A generation module 601, configured to generate first token information corresponding to the intranet device and second token information corresponding to the extranet device in response to obtaining an access request sent by the extranet device for the intranet device;

[0165] A sending module 602, configured to send the first token information to the intranet device and send the second token information to the extranet device;

[0166] A establishing module 603, configured to obtain a first session request sent by the intranet device carrying the first token information, and establish a first session channel with the intranet device based on the first token information;

[0167] The establishing module 603 is further configured to obtain a second session request sent by the extranet device carrying the second token information, and establish a second session channel with the extranet device based on the second token information;

[0168] A transmission module 604, configured to perform data transmission between the intranet device and the extranet device based on the first session channel and the second session channel.

[0169] In a possible implementation manner, the generation module 601 is configured to generate identification information of the intranet device and identification information of the extranet device in response to obtaining an access request sent by the extranet device for the intranet device; perform encryption processing on the identification information of the intranet device to obtain the first token information corresponding to the intranet device; perform encryption processing on the identification information of the extranet device to obtain the second token information corresponding to the extranet device.

[0170] In a possible implementation manner, the establishing module 603 is configured to parse the first token information to obtain first identification information; and establish a first session channel with the intranet device in response to the first identification information being consistent with the identification information of the intranet device.

[0171] In a possible implementation, a establishing module 603 is configured to parse the second token information to obtain second identification information; in response to the second identification information being consistent with the identification information of the external network device, a second session channel is established with the external network device.

[0172] In a possible implementation, the apparatus further includes:

[0173] A receiving module, configured to receive a long connection request sent by an internal network device;

[0174] The establishing module 603 is further configured to, in response to the long connection request, establish a long connection channel with the internal network device;

[0175] A sending module 602, configured to send the first token information to the internal network device based on the long connection channel.

[0176] In a possible implementation, the apparatus further includes:

[0177] A disconnecting module, configured to, in response to establishing a first session channel with the internal network device and not obtaining a second session request within a target duration, disconnect the first session channel; or, in response to establishing a second session channel with the external network device and not obtaining a first session request within a target duration, disconnect the second session channel.

[0178] In a possible implementation, the sending module 602 is further configured to send a notification message to the internal network device and the external network device, where the notification message is used to notify that the first session channel and the second session channel have been successfully established.

[0179] Based on the first token information carried in the first session request, the above apparatus establishes a first session channel with the internal network device, and based on the second token information carried in the second session request, establishes a second session channel with the external network device. Through the first session channel with the internal network device and the second session channel with the external network device, data sent by the internal network device is forwarded to the external network device, or data sent by the external network device is forwarded to the internal network device. The external network device no longer accesses the internal network device through the public network jump server, reducing the deployment difficulty, not limiting the number of internal network devices that the external network device can access, and reducing the difficulty of device maintenance.

[0180] It should be understood that when the above Figure 6 provided apparatus implements its functions, only the above division of each functional module is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. In addition, the apparatus provided in the above embodiments and the method embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be elaborated here.

[0181] An embodiment of the present application further provides a communication system, which is applied to a server cluster. The server cluster includes a target server, a first server, and a second server;

[0182] The target server is configured to, in response to obtaining an access request sent by an external network device for an internal network device, generate first token information corresponding to the internal network device and second token information corresponding to the external network device; send the first token information to the internal network device and send the second token information to the external network device;

[0183] The target server is further configured to obtain a first session request sent by the internal network device carrying the first token information, and establish a first session channel with the internal network device through the first server based on the first token information;

[0184] The target server is further configured to obtain a second session request sent by the external network device carrying the second token information, and establish a second session channel with the external network device through the second server based on the second token information;

[0185] The first server and the second server are configured to perform data transmission between the internal network device and the external network device based on the first session channel and the second session channel.

[0186] In a possible implementation manner, the target server is configured to, in response to obtaining an access request sent by an external network device for an internal network device, generate identification information of the internal network device and identification information of the external network device; perform encryption processing on the identification information of the internal network device to obtain first token information corresponding to the internal network device; perform encryption processing on the identification information of the external network device to obtain second token information corresponding to the external network device.

[0187] In a possible implementation manner, the target server is configured to parse the first token information to obtain first identification information; in response to the first identification information being consistent with the identification information of the internal network device, establish a first session channel with the internal network device.

[0188] In a possible implementation manner, the target server is configured to parse the second token information to obtain second identification information; in response to the second identification information being consistent with the identification information of the external network device, establish a second session channel with the external network device.

[0189] In a possible implementation manner, the target server is further configured to receive a long connection request sent by the internal network device; in response to the long connection request, establish a long connection channel with the internal network device; and based on the long connection channel, send the first token information to the internal network device.

[0190] In a possible implementation, the target server is further configured to disconnect the first session channel in response to establishing the first session channel with the internal network device and not receiving a second session request within the target duration; or, disconnect the second session channel in response to establishing the second session channel with the external network device and not receiving a first session request within the target duration.

[0191] In a possible implementation, the target server is further configured to send notification information to the internal network device and the external network device, where the notification information is used to notify that the first session channel and the second session channel have been successfully established.

[0192] In a possible implementation, the first server is configured to receive data sent by the internal network device based on the first session channel and store the data sent by the internal network device in the queue of the second server;

[0193] The second server is configured to read the data sent by the internal network device from the queue of the second server and send the data sent by the internal network device to the external network device based on the second session channel.

[0194] In a possible implementation, the first server is configured to, based on the identification information of the external network device, find the corresponding third identification information of the identification information of the external network device from the first form information, where the corresponding relationship between the identification information of the external network device and the third identification information is stored in the first form information; store the data sent by the internal network device in the queue of the second server corresponding to the third identification information.

[0195] In a possible implementation, the second server is configured to receive data sent by the external network device based on the second session channel and store the data sent by the external network device in the queue of the first server;

[0196] The first server is configured to read the data sent by the external network device from the queue of the first server and send the data sent by the external network device to the internal network device based on the first session channel.

[0197] In a possible implementation, the second server is configured to, based on the identification information of the internal network device, find the corresponding fourth identification information of the identification information of the internal network device from the second form information, where the corresponding relationship between the identification information of the internal network device and the fourth identification information is stored in the second form information; store the data sent by the external network device in the queue of the first server corresponding to the fourth identification information.

[0198] Based on the first token information carried in the first session request, the above system establishes a first session channel with the internal network device, and based on the second token information carried in the second session request, establishes a second session channel with the external network device. Through the first session channel with the internal network device and the second session channel with the external network device, it is realized to forward the data sent by the internal network device to the external network device, or forward the data sent by the external network device to the internal network device. The external network device no longer accesses the internal network device through the public network jump server, reducing the deployment difficulty, not limiting the number of internal network devices that the external network device can access, and reducing the difficulty of device maintenance.

[0199] Figure 7 The block diagram of the terminal device 700 provided by an exemplary embodiment of the present application is shown. The terminal device 700 may be a portable mobile terminal, such as: a smart phone, a tablet computer, an MP3 (Moving Picture Experts Group Audio Layer III) player, an MP4 (Moving Picture Experts Group Audio Layer IV) player, a notebook computer or a desktop computer. The terminal device 700 may also be referred to by other names such as user equipment, portable terminal, laptop terminal, desktop terminal, etc.

[0200] Generally, the terminal device 700 includes: a processor 701 and a memory 702.

[0201] The processor 701 may include one or more processing cores, such as a quad-core processor, an octa-core processor, etc. The processor 701 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor 701 may also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor 701 may be integrated with a GPU (Graphics Processing Unit), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 701 may further include an AI (Artificial Intelligence) processor, and the AI processor is used to process computational operations related to machine learning.

[0202] The memory 702 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 702 may also include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In some embodiments, the non-transitory computer-readable storage media in the memory 702 is used to store at least one instruction, and the at least one instruction is used to be executed by the processor 701 to implement the communication method provided in the method embodiments of the present application.

[0203] In some embodiments, the terminal device 700 may also optionally include: a peripheral device interface 703 and at least one peripheral device. The processor 701, the memory 702, and the peripheral device interface 703 may be connected by a bus or signal lines. Each peripheral device may be connected to the peripheral device interface 703 through a bus, signal lines, or a circuit board. Specifically, the peripheral devices include at least one of a radio frequency circuit 704, a display screen 705, a camera assembly 706, an audio circuit 707, and a power supply 709.

[0204] The peripheral device interface 703 can be used to connect at least one I / O (Input / Output) related peripheral device to the processor 701 and the memory 702. In some embodiments, the processor 701, the memory 702, and the peripheral device interface 703 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 701, the memory 702, and the peripheral device interface 703 can be implemented on separate chips or circuit boards, and this embodiment does not limit this.

[0205] The radio frequency circuit 704 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The radio frequency circuit 704 communicates with the communication network and other communication devices through electromagnetic signals. The radio frequency circuit 704 converts an electrical signal into an electromagnetic signal for transmission, or converts the received electromagnetic signal into an electrical signal. Optionally, the radio frequency circuit 704 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a subscriber identity module card, and so on. The radio frequency circuit 704 can communicate with other terminals through at least one wireless communication protocol. The wireless communication protocol includes but is not limited to: the World Wide Web, a metropolitan area network, an intranet, generations of mobile communication networks (2G, 3G, 4G, and 5G), a wireless local area network, and / or a WiFi (Wireless Fidelity) network. In some embodiments, the radio frequency circuit 704 may further include a circuit related to NFC (Near Field Communication), and this application does not limit this.

[0206] The display screen 705 is used to display the UI (User Interface). The UI may include graphics, text, icons, videos, and any combination thereof. When the display screen 705 is a touch display screen, the display screen 705 also has the ability to collect touch signals on or above the surface of the display screen 705. The touch signals can be input as control signals to the processor 701 for processing. At this time, the display screen 705 can also be used to provide virtual buttons and / or virtual keyboards, also known as soft buttons and / or soft keyboards. In some embodiments, there can be one display screen 705, which is set on the front panel of the terminal device 700; in other embodiments, there can be at least two display screens 705, which are respectively set on different surfaces of the terminal device 700 or are in a foldable design; in other embodiments, the display screen 705 can be a flexible display screen, which is set on the curved surface or the folding surface of the terminal device 700. Even, the display screen 705 can also be set as an irregular non-rectangular shape, that is, a special-shaped screen. The display screen 705 can be prepared using materials such as LCD (Liquid Crystal Display) and OLED (Organic Light-Emitting Diode).

[0207] The camera module 706 is used to collect images or videos. Optionally, the camera module 706 includes a front camera and a rear camera. Generally, the front camera is set on the front panel of the terminal, and the rear camera is set on the back of the terminal. In some embodiments, there are at least two rear cameras, which are any one of a main camera, a depth-of-field camera, a wide-angle camera, and a telephoto camera respectively, to achieve functions such as the combination of the main camera and the depth-of-field camera to achieve the background blurring function, the combination of the main camera and the wide-angle camera to achieve panoramic shooting and VR (Virtual Reality) shooting functions or other combined shooting functions. In some embodiments, the camera module 706 can also include a flash. The flash can be a single-color temperature flash or a two-color temperature flash. A two-color temperature flash refers to the combination of a warm light flash and a cold light flash, which can be used for light compensation under different color temperatures.

[0208] The audio circuit 707 may include a microphone and a speaker. The microphone is used to collect sound waves of the user and the environment, and convert the sound waves into electrical signals for input to the processor 701 for processing, or input to the radio frequency circuit 704 to enable voice communication. For the purpose of stereo collection or noise reduction, there may be multiple microphones, which are respectively arranged at different parts of the terminal device 700. The microphone may also be an array microphone or an omnidirectional collection microphone. The speaker is used to convert the electrical signal from the processor 701 or the radio frequency circuit 704 into sound waves. The speaker may be a traditional thin film speaker or a piezoelectric ceramic speaker. When the speaker is a piezoelectric ceramic speaker, it can not only convert the electrical signal into sound waves audible to humans, but also convert the electrical signal into sound waves inaudible to humans for uses such as ranging. In some embodiments, the audio circuit 707 may further include a headphone jack.

[0209] The power supply 709 is used to supply power to each component in the terminal device 700. The power supply 709 may be alternating current, direct current, a primary battery or a rechargeable battery. When the power supply 709 includes a rechargeable battery, the rechargeable battery may be a wired rechargeable battery or a wireless rechargeable battery. A wired rechargeable battery is a battery charged through a wired line, and a wireless rechargeable battery is a battery charged through a wireless coil. The rechargeable battery can also be used to support fast charging technology.

[0210] In some embodiments, the terminal device 700 further includes one or more sensors 710. The one or more sensors 710 include but are not limited to: an acceleration sensor 711, a gyroscope sensor 712, a pressure sensor 713, an optical sensor 715, and a proximity sensor 716.

[0211] The acceleration sensor 711 can detect the magnitude of acceleration on the three coordinate axes of the coordinate system established with the terminal device 700. For example, the acceleration sensor 711 can be used to detect the components of the gravitational acceleration on the three coordinate axes. The processor 701 can control the display screen 705 to display the user interface in a landscape view or a portrait view according to the gravitational acceleration signal collected by the acceleration sensor 711. The acceleration sensor 711 can also be used for collecting game or user movement data.

[0212] The gyroscope sensor 712 can detect the body direction and rotation angle of the terminal device 700. The gyroscope sensor 712 can cooperate with the acceleration sensor 711 to collect the 3D actions of the user on the terminal device 700. Based on the data collected by the gyroscope sensor 712, the processor 701 can achieve the following functions: motion sensing (such as changing the UI according to the user's tilt operation), image stabilization during shooting, game control, and inertial navigation.

[0213] The pressure sensor 713 can be disposed on the side frame of the terminal device 700 and / or the lower layer of the display screen 705. When the pressure sensor 713 is disposed on the side frame of the terminal device 700, it can detect the holding signal of the user on the terminal device 700, and the processor 701 can perform left / right hand recognition or quick operation according to the holding signal collected by the pressure sensor 713. When the pressure sensor 713 is disposed on the lower layer of the display screen 705, the processor 701 can control the operable controls on the UI interface according to the pressure operation of the user on the display screen 705. The operable controls include at least one of a button control, a scroll bar control, an icon control, and a menu control.

[0214] The optical sensor 715 is used to collect the ambient light intensity. In one embodiment, the processor 701 can control the display brightness of the display screen 705 according to the ambient light intensity collected by the optical sensor 715. Specifically, when the ambient light intensity is high, the display brightness of the display screen 705 is increased; when the ambient light intensity is low, the display brightness of the display screen 705 is decreased. In another embodiment, the processor 701 can also dynamically adjust the shooting parameters of the camera assembly 706 according to the ambient light intensity collected by the optical sensor 715.

[0215] The proximity sensor 716, also known as the distance sensor, is usually disposed on the front panel of the terminal device 700. The proximity sensor 716 is used to collect the distance between the user and the front of the terminal device 700. In one embodiment, when the proximity sensor 716 detects that the distance between the user and the front of the terminal device 700 is gradually decreasing, the processor 701 controls the display screen 705 to switch from the lit state to the off state; when the proximity sensor 716 detects that the distance between the user and the front of the terminal device 700 is gradually increasing, the processor 701 controls the display screen 705 to switch from the off state to the lit state.

[0216] Those skilled in the art can understand that Figure 7 the structure shown in does not constitute a limitation on the terminal device 700, and may include more or fewer components than shown in the figure, or combine certain components, or adopt a different component layout.

[0217] Figure 8It is a schematic structural diagram of the server provided by the embodiment of the present application. The server 800 may vary greatly due to different configurations or performances, and may include one or more processors 801 and one or more memories 802. Among them, at least one program code is stored in the one or more memories 802, and the at least one program code is loaded and executed by the one or more processors 801 to implement the communication methods provided by the above various method embodiments. Exemplarily, the processor 801 is a CPU. Of course, the server 800 may also have components such as wired or wireless network interfaces, keyboards, and input / output interfaces for input / output. The server 800 may also include other components for implementing device functions, which will not be elaborated here.

[0218] In an exemplary embodiment, a computer-readable storage medium is also provided. At least one program code is stored in the storage medium, and the at least one program code is loaded and executed by a processor to enable an electronic device to implement any of the above communication methods.

[0219] Optionally, the above computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CD-ROM), a magnetic tape, a floppy disk, an optical data storage device, etc.

[0220] In an exemplary embodiment, a computer program or a computer program product is also provided. At least one computer instruction is stored in the computer program or the computer program product, and the at least one computer instruction is loaded and executed by a processor to enable a computer to implement any of the above communication methods.

[0221] It should be understood that the "plurality" mentioned herein refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0222] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.

[0223] The above are only exemplary embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A communication method, characterized in that, The method is applied to a server cluster, which includes a target server, a first server, and a second server. The target server includes a Secure Shell (SSH) proxy module and a device controller. The method includes: In response to obtaining an access request sent by an external network device to the SSH proxy module for an internal network device, and verifying the existence of a long connection channel between the device controller and the internal network device, generate, through the SSH proxy module, first token information corresponding to the internal network device and second token information corresponding to the external network device, where the external network device is used to maintain the internal network device; Through the SSH proxy module, send the first token information to the internal network device through the long connection channel, and send the second token information to the external network device; Obtain a first session request sent by the internal network device carrying the first token information, and based on the first token information, establish a first session channel between the first server and the internal network device; Obtain a second session request sent by the external network device carrying the second token information, and based on the second token information, establish a second session channel between the second server and the external network device; Through the first server, receive data sent by the internal network device based on the first session channel, and based on the correspondence between the identification information of the external network device stored in the first form information and the third identification information, store the data sent by the internal network device in the queue of the second server corresponding to the third identification information; Through the second server, detect the queue of the second server in real time, read the data sent by the internal network device from the queue of the second server, and send the data sent by the internal network device to the external network device based on the second session channel.

2. The method according to claim 1, characterized in that, The step of "In response to obtaining an access request sent by an external network device to the SSH proxy module for an internal network device, and verifying the existence of a long connection channel between the device controller and the internal network device, generate, through the SSH proxy module, first token information corresponding to the internal network device and second token information corresponding to the external network device" includes: In response to obtaining an access request sent by an external network device to the SSH proxy module for an internal network device, and verifying the existence of a long connection channel between the device controller and the internal network device, generate, through the SSH proxy module, the identification information of the internal network device and the identification information of the external network device; Perform an encryption process on the identification information of the internal network device to obtain the first token information corresponding to the internal network device; Perform an encryption process on the identification information of the external network device to obtain the second token information corresponding to the external network device.

3. The method according to claim 2, characterized in that, The step of "Based on the first token information, establish a first session channel between the first server and the internal network device" includes: Parse the first token information to obtain first identification information; In response to the first identification information being consistent with the identification information of the internal network device, establish a first session channel between the first server and the internal network device.

4. The method according to claim 2, wherein Establishing a second session channel between the second server and the external network device based on the second token information includes: Parsing the second token information to obtain second identification information; In response to the second identification information being consistent with the identification information of the external network device, establishing a second session channel between the second server and the external network device.

5. The method according to claim 1, characterized in that, Before sending the first token information to the internal network device through the SSH proxy module via the long connection channel, it further includes: Receiving a long connection request sent by the internal network device; In response to the long connection request, establishing a long connection channel between the device controller and the internal network device.

6. The method according to claim 1, characterized in that, The method further includes: In response to establishing a first session channel with the internal network device and not obtaining the second session request within the target duration, disconnecting the first session channel; Alternatively, in response to establishing a second session channel with the external network device and not obtaining the first session request within the target duration, disconnecting the second session channel.

7. The method according to claim 1, wherein The method further includes: Sending a notification message to the internal network device and the external network device, where the notification message is used to notify that the first session channel and the second session channel have been successfully established.

8. The method according to any one of claims 1 to 7, characterized in that, The method further includes: Receiving data sent by the external network device by the second server based on the second session channel, and storing the data sent by the external network device in the queue of the first server; Reading the data sent by the external network device from the queue of the first server by the first server, and sending the data sent by the external network device to the internal network device based on the first session channel.

9. The method according to claim 8, characterized in that Storing the data sent by the external network device in the queue of the first server includes: Based on the identification information of the internal network device, searching for the fourth identification information corresponding to the identification information of the internal network device from the second form information, where the correspondence between the identification information of the internal network device and the fourth identification information is stored in the second form information; Storing the data sent by the external network device in the queue of the first server corresponding to the fourth identification information.

10. A communication system, characterized in that, The system is applied to a server cluster, and the server cluster includes a target server, a first server, and a second server. The target server includes a Secure Shell (SSH) proxy module and a device controller; The target server is configured to, in response to obtaining an access request from an external network device to the SSH proxy module for an internal network device and verifying the existence of a long connection channel between the device controller and the internal network device, generate a first token information corresponding to the internal network device and a second token information corresponding to the external network device through the SSH proxy module, where the external network device is used to maintain the internal network device; Sending the first token information to the internal network device through the long connection channel by the SSH proxy module, and sending the second token information to the external network device; The target server is further configured to obtain a first session request sent by the intranet device carrying the first token information, and based on the first token information, establish a first session channel between the first server and the intranet device; The target server is further configured to obtain a second session request sent by the extranet device carrying the second token information, and based on the second token information, establish a second session channel between the second server and the extranet device; The first server is configured to receive data sent by the intranet device based on the first session channel, and based on the correspondence between the identification information of the extranet device stored in the first form information and the third identification information, store the data sent by the intranet device in the queue of the second server corresponding to the third identification information; The second server is configured to detect the queue of the second server in real time, read the data sent by the intranet device from the queue of the second server, and send the data sent by the intranet device to the extranet device based on the second session channel.

11. The system according to claim 10, wherein, The target server is configured to, in response to obtaining an access request from the extranet device to the intranet device sent to the SSH proxy module and verifying the existence of the long connection channel between the device controller and the intranet device, generate the identification information of the intranet device and the identification information of the extranet device through the SSH proxy module; Perform an encryption process on the identification information of the intranet device to obtain the first token information corresponding to the intranet device; Perform an encryption process on the identification information of the extranet device to obtain the second token information corresponding to the extranet device.

12. The system according to claim 11, wherein The target server is configured to parse the first token information to obtain first identification information; in response to the first identification information being consistent with the identification information of the intranet device, establish a first session channel between the first server and the intranet device.

13. The system according to claim 11, wherein The target server is configured to parse the second token information to obtain second identification information; in response to the second identification information being consistent with the identification information of the extranet device, establish a second session channel between the second server and the extranet device.

14. The system according to claim 10, wherein The target server is further configured to receive a long connection request sent by the intranet device; in response to the long connection request, establish a long connection channel between the device controller and the intranet device.

15. The system according to claim 10, wherein The target server is further configured to, in response to establishing the first session channel with the intranet device and not obtaining the second session request within the target duration, disconnect the first session channel; Alternatively, in response to establishing the second session channel with the extranet device and not obtaining the first session request within the target duration, disconnect the second session channel.

16. The system according to claim 10, wherein The target server is further configured to send a notification message to the intranet device and the extranet device, where the notification message is used to notify that the first session channel and the second session channel have been successfully established.

17. The system according to any one of claims 10 to 16, characterized in that, The second server is configured to receive data sent by the external network device based on the second session channel, and store the data sent by the external network device in the queue of the first server; The first server is configured to read the data sent by the external network device from the queue of the first server, and send the data sent by the external network device to the internal network device based on the first session channel.

18. The system according to claim 17, wherein The second server is configured to find, based on the identification information of the internal network device, the fourth identification information corresponding to the identification information of the internal network device from the second form information, where the correspondence between the identification information of the internal network device and the fourth identification information is stored in the second form information; Store the data sent by the external network device in the queue of the first server corresponding to the fourth identification information.

19. An electronic device, characterized in that, The electronic device includes a processor and a memory, and at least one program code is stored in the memory. The at least one program code is loaded and executed by the processor to enable the electronic device to implement the communication method according to any one of claims 1 to 9.

20. A computer-readable storage medium, characterized in that, At least one program code is stored in the computer-readable storage medium. The at least one program code is loaded and executed by a processor to enable a computer to implement the communication method according to any one of claims 1 to 9.

21. A computer program product, characterized in that, At least one computer instruction is stored in the computer program product. The at least one computer instruction is loaded and executed by a processor to enable a computer to implement the communication method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Communication link establishment method and device, equipment and storage medium

    CN111385666A