A device access method, device, and computer-readable storage medium
By sensing abnormalities of the access device by the management device, using the collaborative inspection notification and mapping port update mechanism, the problem of intranet devices being unable to register due to operator network restrictions is solved, normal communication between internal and external network devices is achieved, and business success rate is improved.
Patent Information
- Application Number
- CN202010743747.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-07-29
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2040-07-29
AI Technical Summary
Due to operator network restrictions, the mapping ports of intranet devices cannot communicate with external network devices, resulting in registration failure and information sharing cannot be achieved.
The management device senses the abnormality of the access device, querys the list of devices that have been accessed normally, selects the second access device and sends a cooperative inspection notification, updates the mapping port to bypass the operator's network restrictions, and realizes normal communication between intranet devices and external network devices.
It improves the success rate of cross-internal and external network services and solves the problem of access registration failure caused by operator port restrictions.
Smart Images

Figure CN114095691B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of internal and external network communication, and particularly relates to a device access method, device, and computer-readable storage medium. Background Art
[0002] With the advent of the Internet era, the vast majority of enterprises need to establish an internal local area network and at the same time need to connect the enterprise internal local area network to the Internet. However, with the rapid development of the Internet, the shortage of IP addresses has become a very prominent problem. It is impossible for every computer in an enterprise to have a real IP address. Therefore, most enterprise users achieve communication with the external network through address conversion.
[0003] For security reasons, external network users cannot directly access internal network computers, so they cannot directly browse WEB, FTP servers, etc. built on the internal network. In order to enable the external network to access various servers built on the internal network and achieve information and resource sharing, usually, the internal network egress router needs to perform port mapping for internal network computers and set the mapping relationship between the external network access port and the internal network access port, so as to forward the data of the external network accessing the specified port of the internal network to the corresponding internal network computer.
[0004] However, in some specific applications, for example, in a video security system, when an internal network IP camera (IPC) needs to register with an external network video management server (VM), it often occurs that when the internal network egress router performs port mapping for the internal network IP camera and allocates a corresponding mapping port for the registration port of the IP camera, the allocated mapping port is restricted from communicating by the operator network. This results in the registration message sent by the IP camera to the video management server being able to be sent to the video management server, but the destination port of the 200OK message responded by the video management server is the mapping port allocated by the egress router for the IP camera. Since this mapping port is restricted from communicating by the operator network, the 200OK message responded by the video management server will be discarded in the operator network and cannot reach the IP camera, resulting in the failure of the IP camera to register. Summary of the Invention
[0005] The purpose of this application is to provide a device access method, device, and computer-readable storage medium, which are used for a device on the internal network to smoothly communicate with other devices on the external network when the mapping port allocated for it by the egress router is restricted, overcoming the situation in the background art where communication cannot be carried out after the mapping port is restricted from communicating by the operator network.
[0006] To achieve the above purpose, the technical solution of this application is as follows:
[0007] A device access method for accessing an access device located in an internal network to a management device in an external network, the device access method comprising:
[0008] When the management device senses that the access of the first access device is abnormal, it obtains the external network address and internal network address of the first access device, and selects a second access device that is normally accessed within the same internal network as the first access device;
[0009] The management device sends a co-investigation notice to the second access device carrying the internal network address of the first access device, so that after the second access device locates the first access device in the internal network, it sends a mapping port abnormality notice to the first access device;
[0010] After receiving the mapping port abnormality notice, the first access device interacts with the port mapping device to update the mapping port, where the mapping port is the external network communication port mapped by the port mapping device for the communication port within the internal network of the first access device.
[0011] Further, the co-investigation notice includes one or more of the device code of the first access device, the abnormality notice identifier, and the mapping port number of the first access device; the mapping port abnormality notice includes one or more of the device code of the first access device, the abnormality notice identifier, and the mapping port number of the first access device.
[0012] In an implementation manner of the present application, after receiving the mapping port abnormality notice, the first access device interacts with the port mapping device to update the mapping port, including:
[0013] When the first access device requests access again, it actively changes the communication port within the internal network, so that the port mapping device reassigns a mapping port for the first access device.
[0014] In another implementation manner of the present application, after receiving the mapping port abnormality notice, the first access device interacts with the port mapping device to update the mapping port, including:
[0015] The first access device notifies the port mapping device of the abnormal mapping port, so that the port mapping device marks the abnormal mapping port;
[0016] When the first access device requests access again, the port mapping device reassigns a mapping port for the first access device after excluding the abnormal mapping port.
[0017] Further, the first access device notifying the port mapping device of the abnormal mapping port includes:
[0018] The first access device notifies the port mapping device of the abnormal mapping port through the UPnP protocol extension field.
[0019] In another implementation of this application, after receiving the mapping port exception notification, the first access device interacts with the port mapping device to update the mapping port, including:
[0020] The first access device communicates with the port mapping device, uses an unoccupied communication port within the internal network, and designates the abnormal mapping port, so that the port mapping device assigns the abnormal mapping port to the unoccupied communication port within the internal network;
[0021] The first access device requests access again, and the port mapping device reassigns a mapping port for the first access device.
[0022] Further, the first access device communicates with the port mapping device, uses an unoccupied communication port within the internal network, and designates the abnormal mapping port, including:
[0023] The first access device actively sends a UPnP message to the port mapping device. The communication port within the internal network used by the UPnP message is an unoccupied communication port within the internal network, and the mapping port that the first access device needs to use is designated as the abnormal mapping port in the UPnP message.
[0024] This application also proposes a device access device for accessing an access device located in the internal network to a management device in the external network. The device access device is applied to the management device and includes:
[0025] An abnormal perception module, configured to obtain the external network address and internal network address of the first access device when perceiving an abnormal access of the first access device, and select a second access device that is normally accessed within the same internal network as the first access device;
[0026] A cooperation investigation notification module, configured to send a cooperation investigation notification to the second access device carrying the internal network address of the first access device, so that after the second access device finds the first access device in the internal network, it sends a mapping port exception notification to the first access device, and enables the first access device to interact with the port mapping device to update the mapping port after receiving the mapping port exception notification. The mapping port is the external network communication port mapped by the port mapping device for the internal network communication port of the first access device.
[0027] This application also proposes a device access device, including a processor and a non-volatile memory storing a number of computer instructions. When the computer instructions are executed by the processor, the steps of the above device access method are implemented.
[0028] This application also proposes a computer-readable storage medium, on which computer instructions are stored. When the computer instructions are executed by a processor, the steps of the above device access method are implemented.
[0029] A device access method, device, and computer-readable storage medium provided by this application. When a management device senses abnormal access of a first access device, it queries a list of devices that have been normally accessed and selects a second access device that has been normally accessed within the same intranet as the first access device. The management device sends a co-investigation notice to the second access device carrying the intranet address of the first access device, so that after the second access device finds the first access device in the intranet, it sends a mapped port restriction notice to the first access device. After receiving the mapped port restriction notice, the first access device interacts with the port mapping device to update the mapped port. This solves the problem of cross-intranet / extranet access registration failure caused by operator port restrictions and improves the success rate of cross-intranet / extranet services. Description of the Drawings
[0030] Figure 1 It is a schematic diagram of the application scenario network of the embodiment of this application;
[0031] Figure 2 It is a flowchart of a device access method according to an embodiment of this application. Detailed Embodiments
[0032] In order to make the objectives, technical solutions, and advantages of this application clearer, the following further describes this application in detail with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not used to limit this application.
[0033] A device access method, device, and computer-readable storage medium provided by this application for connecting an access device located in an intranet to a management device in an extranet can be applied to an application environment such as Figure 1 the video security system application environment shown. Among them, access devices such as network cameras IPC1, IPC2, network video recorders NVR, etc. are located in the intranet and are connected to the extranet through an egress router. The extranet is generally an operator network. A management device such as a video management server VM can be directly connected to the extranet or located in a local area network and connected to the extranet through a router. This application takes the video security system as an example for illustration and is applicable to any device in the intranet accessing an extranet device. This application connects an access device located in the intranet (which can also be called a private network or a local area network) to a management device in the extranet. The extranet mentioned herein, relative to the intranet where the access device is located, as long as it is not in the intranet where the access device is located, is called the extranet, and will not be elaborated further below.
[0034] It is easy to understand that when IPC1 and IPC2 in the intranet register with the video management server VM in the extranet, information interaction is required. At this time, port mapping must be done through the egress router to establish a mapping relationship between the external network address / port number and the internal network address / port number. Port mapping has been widely used and will not be elaborated here.
[0035] For example, the public network / private network IPs and port numbers corresponding to IPC1 and IPC2 are shown in Table 1 as follows:
[0036] Access device IPC1 IPC2 … Internal network address 202.100.10.2 202.100.10.7 External network address 10.10.10.2 10.10.10.7 Internal network registration port 80 60 External network registration port 5060 1028 Internal network media stream port 5042 5047 External network media stream port 21815 21817
[0037] Table 1
[0038] In the above example, the mapped port corresponding to the registration port 80 of IPC1 is 5060, and it can be normally registered to the video management server VM. Suppose the mapped port corresponding to the registration port 60 of IPC2 is 1028. However, since port 1028 is restricted in communication in the operator's network, the registration of IPC2 is abnormal, manifested as the register message can be sent to the VM, but the 200OK returned by the VM cannot reach IPC2.
[0039] An equipment access method proposed in this application aims to switch the external network mapped port when the mapped port is unavailable (or abnormal) during port mapping by the egress router, so as to improve the success rate of the internal network / external network service. The registration port and the media stream port are common communication ports. This application is not limited to a specific type of communication port. The following takes the registration port as an example for illustration.
[0040] In one embodiment, as Figure 2 shown, an equipment access method is provided for accessing an access device located in the internal network to a management device in the external network. The equipment access method includes:
[0041] Step S1: When the management device senses that the first access device has abnormal access, obtain the external network address and internal network address of the first access device.
[0042] In this embodiment, the first access device and the second access device are devices located in the internal network. For example, Figure 1 IPC2 in Figure 1 is the first access device, and IPC1 is the second access device. The internal network where the first access device and the second access device are located is connected to the external network through an egress router. The egress router performs address conversion and port mapping, and assigns corresponding mapped ports to the communication ports of the first access device and the second access device. In this embodiment, the device performing port mapping is also referred to as the port mapping device, which is the egress router in Figure 1 . The mapped port is the external network communication port mapped by the port mapping device for the internal network communication port of the access device. The management device is the management device accessing the first access device and the second access device, which is the video management server in
[0043] Taking Figure 1For example, the mapped port of IPC1 is 5060, and it successfully accesses the video management server. The video management server records the list of devices that have been normally accessed. In the device list, it records the IP address, registration port number, media stream port number, etc. of IPC1 in the internal network, as well as the corresponding IP address, registration port number, media stream port number, etc. mapped to the external network. For the convenience of explanation, this embodiment takes the registration port as an example. After the registration port in the internal network is mapped to the external network, the mapped port is the registration port of the external network assigned by the egress router. The registration port number of IPC1 in the internal network is 80, and after being mapped to the external network, the mapped port number is 5060.
[0044] However, the registration port number of IPC2 in the internal network is 60. Suppose the mapped port number assigned by the egress router for it is 1028. Due to the communication restriction of port 1028 by the operator network, when the video management server receives the registration message of IPC2, the response 200OK message cannot reach IPC2. Since IPC2 does not receive the response 200OK message, the registration fails and the registration message is sent continuously.
[0045] At this time, the video management server can sense the abnormal access of IPC2 and obtain the external network address and internal network address of IPC2 from the registration message.
[0046] For example, after the video management server receives the registration message of IPC2, it responds with a 200OK message. Thereafter, if the registration is normal, it should receive the keep-alive message sent by IPC2. But since the 200OK message cannot reach IPC2, IPC2 will continue to send the registration message. At this time, if the video management server receives the abnormal registration messages of IPC2 multiple times, it will sense the abnormal access of IPC2. For example, after the video management server receives the registration message of IPC2 and responds with a 200OK message, if it continues to receive the registration message of the first access device after responding with 200OK for multiple consecutive times (such as twice or three times), it is considered abnormal.
[0047] After the video management server of the present application senses the abnormal access of the first access device, it can immediately enter step S2, or continue to send the response 200OK message, and then enter step S2 after multiple consecutive times.
[0048] It should be noted that the reason for the above abnormality may be that the operator restricts the mapped port (i.e., restricted), or it may be that other reasons cause the mapped port to be unavailable (for example, the mapped port is fixedly set as a certain functional port). The present application uniformly refers to this as an abnormality.
[0049] In this embodiment, by confirming the abnormal access of the first access device after multiple responses of 200OK, the phenomenon of registration failure caused by occasional factors can be avoided, making the network more stable.
[0050] After the video management server senses an abnormal access of IPC2, it obtains the external network address and internal network address of IPC2 from the registration message. For example, the obtained external network address of IPC2 is 202.100.10.7, and the internal network address is 10.10.10.7. Regarding the video management server obtaining the external network address and internal network address of the access device IPC from the registration message, it is a relatively mature technology in this technical field and will not be elaborated here.
[0051] Step S2: The management device selects a second access device with normal access within the same internal network as the first access device.
[0052] In this embodiment, the video management server will record the list of devices that have been normally accessed, and record information such as the internal network address, external network address, and mapped port number of IPC1 in the device list. After sensing that a device has abnormal access, the video management server will query the list of devices that have been normally accessed and find other devices in the same internal network environment as the device with abnormal access.
[0053] Still taking Figure 1 as an example, IPC1 has been normally registered and recorded in the list of devices that have been normally accessed. If IPC2 cannot be normally registered to the video management server, at this time, the video management server queries the list of devices that have been normally accessed and will find that IPC1 has been normally registered, and its external network address is the same as the external network address corresponding to IPC2, and the internal network address of IPC1 and the internal network address of IPC2 are in the same local area network, then it is considered that IPC1 and IPC2 are in the same internal network, so the target second access device, that is, IPC1, is found. Regarding the method of finding other devices in the same internal network environment as the device with abnormal access, those skilled in the art can also adopt the method of naming the access devices in the same internal network with the same prefix, which will not be elaborated here.
[0054] It is easy to understand that there may be multiple devices within the same internal network as the first access device. For example, there is also IPC3, etc. The video management server can find multiple devices within the same internal network as IPC2 in the list of devices that have been normally accessed. The video management server needs to select one of them as the second access device. This application can randomly select from the found devices, or select according to the priority of the devices. The priority of the devices can be set according to the duration of the video management server pinging the device, or directly set according to the IP address of the device. The closer the internal network address is to the first access device, the higher the priority. This application is not limited to how the video management server selects the second access device from multiple accessed devices.
[0055] In another embodiment, the present application may also select multiple devices that have been normally connected as the second access device. In this way, in the case where one of them cannot communicate normally with the first access device, another device can be used to communicate with the first access device, fully ensuring that the second access device can notify the first access device.
[0056] Step S3: The management device sends a cooperation inquiry notice to the second access device carrying the internal network address of the first access device, so that after the second access device finds the first access device in the internal network, it sends a mapping port exception notice to the first access device.
[0057] The management device of the present application sends a cooperation inquiry notice to the second access device carrying the internal network address of the first access device, notifies the internal network address of the first access device to the second access device, so that after the second access device finds the first access device in the internal network, it notifies the first access device of the mapping port exception.
[0058] For example, the video management server notifies the internal network address 10.10.10.7 of IPC2 to the second access device, that is, to IPC1. Since IPC1 is normally registered to the video management server, the video management server can easily notify IPC1, so that IPC1 obtains the internal network address of IPC2, so that IPC1 can communicate with IPC2 within the internal network.
[0059] The cooperation inquiry notice sent by the video management server in this embodiment can be implemented through the keep-alive message with IPC1, and the internal network address of IPC2 is notified to IPC1. In order to facilitate IPC1 to know that it is a message notifying the mapping port exception after receiving the keep-alive message, the present application expands the fields in the keep-alive message. When notifying IPC1 of the internal network address of the abnormal IPC2, it also carries an exception notification identifier and mapping port information. An example of this keep-alive message is as follows:
[0060] MESSAGE sip:33180800002000000088@202.5.33.31:5061SIP / 2.0
[0061] Via:SIP / 2.0 / UDP 192.168.104.196:5061;branch=z9hG4bKfee227f42de227f424e227f42
[0062] Call-ID:6439d16eb739d16ebe39d16ebe39d16e@192.168.104.196
[0063] From:
[0064] <sip:33180800002000000047@192.168.104.196:5061>;tag=0c607ea4df607ea4d6607e a4d6607ea4
[0065] To:<sip:33180800002000000088@202.5.33.31>
[0066] CSeq:10716 MESSAGE
[0067] Contact:<sip:33180800002000000047@192.168.104.196:5061>
[0068] OutUserInfo:
[0069] DomainId=33180800002000000147; UserName=33180800002000000188; UserPri=10
[0070] Max-Forwards:70
[0071] Expires:90
[0072] User-Agent:IMOS / V3
[0073] Content-Length:173
[0074] Content-Type:application / MANSCDP+xml
[0075] <?xml version="1.0" encoding="GB2312"?
[0076] <notify>
[0077] <cmdtype>Keepalive< / cmdtype>
[0078] <sn> 7032< / sn>
[0079] <deviceid> 33180800002000000047< / deviceid>
[0080] <status>OK< / status>
[0081] <errorcode> 0001 <errorcode>< / errorcode> < / errorcode>
[0082] <errordeviceip>ip2 <errordeviceip>< / errordeviceip> < / errordeviceip>
[0083] <errordeviceport> 1028 <errordeviceport>< / errordeviceport> < / errordeviceport>
[0084] < / notify>
[0085] In the above example, the DeviceID is the national standard code of IPC2, the ErrorCode is the exception notification identifier, such as 0001; the ErrorDeviceIp is the internal network address of IPC2, such as 10.10.10.7, and the ErrorDevicePort is the mapped port number of IPC2, such as 1028.
[0086] It should be noted that in the above example, DeviceID, ErrorCode, ErrorDeviceIp, and ErrorDevicePort are included. Including the above information can facilitate IPC1 to quickly determine that the currently received message is a co-investigation notice based on ErrorCode after receiving the co-investigation notice. Moreover, through DeviceID, it can be determined that the co-investigation notice is for IPC2, and through ErrorDevicePort, the mapped port number where the exception occurred can be learned, that is, the restricted mapped port is 1028.
[0087] It is easy to understand that the video management server notifies the internal network address of IPC2 to the second access device, and only the internal network address of the first access device may also be included in the notification message. After receiving the notification message, the second access device defaults it to be a co-investigation notice and locks that the device with the exception is the device corresponding to the internal network address, that is, IPC2. As for the mapped port number ErrorDevicePort where the exception occurred, it may not be notified to IPC1 either, and IPC2 can interact with the egress router (port mapping device) to learn it.
[0088] After receiving the above keep-alive message, IPC1 learns that the message notifies that the mapped port of IPC2 is abnormal and needs to find IPC2 and notify IPC2. At this time, IPC1 finds IPC2 within the internal network according to the address information provided by ErrorDeviceIp. Specifically, IPC2 can be found through technologies such as ping or device discovery, which will not be elaborated here.
[0089] Then, IPC1 notifies IPC2 of the exception obtained from the video management server. The sent mapped port exception notice includes DeviceID, ErrorCode, and ErrorDevicePort. The example of the notice message is as follows:
[0090] POST / HTTP / 1.1
[0091] <?xml version="1.0" encoding="UTF-8"?>
[0092] <root>
[0093] <t>Assist< / t>
[0094] <di> 33180800002000000047< / di> ----Platform national standard code
[0095] <ec> 0001< / ec> ---errorcode value
[0096] <np> 1028< / np> ---External port
[0097] < / root>
[0098] Thus, after receiving the mapped port exception notice message, IPC2 quickly determines that the currently received message is an exception notice message based on ErrorCode. Moreover, through DeviceID, it can be determined that the exception notice message is for itself, and through ErrorDevicePort, the mapped port number where the exception occurred can be learned.
[0099] Similarly, in the notification message sent by IPC1 to IPC2, a special message can be agreed upon with IPC2, and it is not necessary to carry the DeviceID, ErrorCode, and ErrorDevicePort. After receiving this notification message, the first access device defaults it to an exception notification and locks the device with the exception as itself, i.e., IPC2. As for the mapped port number ErrorDevicePort where the exception occurred, IPC2 can interact with the egress router (port mapping device) to obtain it.
[0100] The message for sending a co-investigation notice between the video management server of this application and IPC1 is not limited to a keep-alive message, and the mapped port exception notification message between IPC1 and IPC2 is not limited to the message in the above example either. It can be any private message or an extension of the existing communication message, which will not be elaborated here.
[0101] Step S4: After receiving the notification of the mapped port exception, the first access device interacts with the port mapping device to update the mapped port.
[0102] After learning this exception message, IPC2 of this application knows that an exception has occurred and needs to interact with the port mapping device to update the mapped port so that it can be normally registered.
[0103] The following uses specific embodiments to elaborate on how IPC2 interacts with the port mapping device to update the mapped port.
[0104] Embodiment 1: When the first access device requests access again, it actively changes the communication port within the intranet so that the port mapping device reassigns a mapped port for the first access device.
[0105] For example, the process of IPC2 interacting with the port mapping device (egress router) to update the mapped port is as follows:
[0106] 1) When IPC2 resends the registration message, it actively changes the registration port (such as 5061);
[0107] 2) The egress router generates a dynamic mapping entry according to the message. Since the registration port in the message has changed at this time, a new dynamic mapping entry will be generated at this time:
[0108] “10.10.10.7:5061 202.100.10.7:1029”;
[0109] 3) The new mapped port 1029 is not restricted in the carrier network, and the 200OK of the video management server VM can be normally returned. If 1029 is still a restricted port, the registration port continues to be updated. The update method is not limited. For example, add a preset value to the port number and repeat the above steps until the registration is successful.
[0110] In this embodiment, the registered port of the access device is actively changed to realize the change of the mapped port, so as to communicate with the external network device smoothly. However, after the egress router is restarted, the technical solution of this embodiment may allocate port 1028 to the access device again, that is, the normal registration cannot occur again, and the method of this application needs to be used to interact with the port mapping device (egress router) again to update the mapped port.
[0111] Embodiment 2: The first access device notifies the port mapping device of the abnormal mapped port so that the port mapping device marks the abnormal mapped port; when the first access device requests access again, the port mapping device reallocates a mapped port for the first access device after excluding the abnormal mapped port.
[0112] For example, the process of IPC2 interacting with the port mapping device (egress router) to update the mapped port is as follows:
[0113] 1). The first access device notifies the port mapping device of the abnormal mapped port through the UPnP protocol extension field. For example, IPC2 notifies the egress router of the restricted external network mapped port 1028, which can be implemented through the UPnP protocol extension, and carry it in the extension field of the UPnP message <errorport> 1208< / errorport> That's it;
[0114] 2). After receiving the information of the restricted mapped port, the egress router adds an abnormal mark to port 1028 in the local table entry, and at the same time immediately ages the dynamic mapped table entry corresponding to 1028;
[0115] 3). When IPC2 registers again, since the external network abnormal port has been marked locally by the egress router, when generating a dynamic mapped table again, the mapped port allocated to IPC2 bypasses port 1028 and allocates other ports, such as port 1030;
[0116] 4). Port 1030 is not restricted in the operator network, and IPC2 can register normally.
[0117] In this embodiment, the port mapping device is used to exclude the restricted mapped port, so as to gradually prohibit all restricted ports. In this way, when the egress router performs port mapping for the access devices in the internal network, the restricted mapped ports are excluded, so as to ensure the smooth registration of the access devices in the internal network.
[0118] Universal Plug and Play (UPnP) is mainly used for the intelligent interconnection and interoperability of devices. UPnP defines the protocols for communication between devices, between devices and control points, and between control points. Once any device with UPnP enabled is connected to the network, all devices on the network can immediately know that a new device has joined. These devices can communicate with each other, and can directly use or control it. Everything does not require manual settings and is completely plug-and-play. In this embodiment, the restricted external network mapping port 1028 is informed to the egress router through the extension of the UPnP protocol, or it can also be achieved through other private protocols or notification messages, which will not be elaborated here. Since most devices in the existing network support the UPnP protocol, therefore, the technical solution of this application has stronger applicability, and does not require more modifications to the devices in the existing network, and the configuration cost is low. In Embodiment 3 below, UPnP is also used for illustration. This application is not limited to using UPnP to notify the port mapping device.
[0119] Embodiment 3: The first access device communicates with the port mapping device, uses an unoccupied communication port within the internal network, and specifies an abnormal mapping port, so that the port mapping device allocates the abnormal mapping port for the unoccupied communication port within the internal network; the first access device requests access again, and the port mapping device reallocates a mapping port for the first access device.
[0120] For example, the process of IPC2 interacting with the port mapping device (egress router) to update the mapping port is as follows:
[0121] 1). The first access device actively sends a UPnP message to the port mapping device. The communication port within the internal network used by the UPnP message uses an unoccupied communication port within the internal network, and specifies the mapping port it needs to use as the abnormal mapping port in the UPnP message. For example, IPC2 actively initiates a UPnP with the egress router. An unoccupied port on the device locally within the internal network is randomly selected as the communication port within the internal network (assuming 5044), and it is specified in the UPnP message that it needs to use the external mapping port 1028; 10.10.10.7:5044 202.100.10.7:1028;
[0122] 2) The egress router locally generates a static mapping table entry: "10.10.10.7:5044 202.100.10.7:1028", and at the same time sends a success message to IPC2;
[0123] 3). After IPC2 receives the success response from the egress router, it sends a registration again using the internal port 60;
[0124] 4) At this time, since the static mapping table entry on the egress router has occupied the external port 1028, other external ports such as 1029 will be enabled when generating the dynamic mapping table entry.
[0125] 5) If 1029 can end normally, this process ends; if the port 1029 is still abnormal, repeat the above process until the registration is successful.
[0126] In this embodiment, since the IPC locally records the abnormal ports and will actively occupy the abnormal external ports of the router through UPnP, even in special cases such as abnormal power-off of the router, there is no need to repeat the above steps. And it is very easy to implement without protocol extension.
[0127] The technical solution of this application can solve the problem of cross-internal / external network access registration failure caused by operator port restrictions and improve the success rate of cross-internal / external network services.
[0128] In one embodiment, the present application also proposes a device access device for accessing an access device located in the internal network to a management device in the external network. The device access device is applied to the management device and includes:
[0129] An abnormal perception module, configured to obtain the external network address and the internal network address of the first access device and select a second access device that is normally accessed within the same internal network as the first access device when perceiving that the access of the first access device is abnormal;
[0130] A co-investigation notification module, configured to send a co-investigation notification to the second access device with the internal network address of the first access device, so that after the second access device finds the first access device in the internal network, it sends a mapping port abnormality notification to the first access device, and enables the first access device to interact with the port mapping device to update the mapping port after receiving the mapping port abnormality notification, where the mapping port is the external network communication port mapped by the port mapping device for the internal network communication port of the first access device.
[0131] The device of this embodiment is applied to the management device and is a specific embodiment of the above device access scheme on the management device, which will not be elaborated here. For the specific limitations of the device access device in this embodiment, reference can be made to the limitations on the device access method in the above text, which will not be elaborated here. Each module in the above device access device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0132] In one embodiment, the present application further provides a device access apparatus, including a processor and a non-volatile memory storing a number of computer instructions. When the computer instructions are executed by the processor, the steps of the above-mentioned device access method are implemented, for accessing an access device located in the internal network to a management device in the external network.
[0133] The above apparatus may be a mobile phone, a computer, a server or other intelligent hardware devices, for executing the above-mentioned device access method.
[0134] The memory and the processor are electrically connected directly or indirectly to achieve data transmission or interaction. For example, these components may be electrically connected to each other through one or more communication buses or signal lines. A computer program operable on the processor is stored in the memory, and the processor realizes the network topology layout method in the embodiments of the present invention by running the computer program stored in the memory.
[0135] Among them, the memory may be, but is not limited to, random access memory (RAM), read only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc. The memory is used to store programs, and the processor executes the programs after receiving execution instructions.
[0136] The processor may be an integrated circuit chip with data processing capabilities. The above-mentioned processor may be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0137] It can be understood that the network topology layout apparatus in this embodiment may further include other components in addition to the memory and the processor, and each component may be implemented by hardware, software or a combination thereof.
[0138] In another embodiment, the present application also provides a computer-readable storage medium, on which computer instructions are stored. When the computer instructions are executed by a processor, the steps of the above-mentioned device access method are implemented when executed by the processor.
[0139] The above-mentioned computer-readable storage medium may be a disk, a USB flash drive or other storage devices that can be read by a computer, and the computer instructions are stored in the readable storage medium in the form of software. When it is necessary to connect an access device located in the intranet to a management device in the extranet, it is read by a computer or a processor to execute the above-mentioned device access method.
[0140] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
Claims
1. A device access method for accessing an access device located in an internal network to a management device in an external network, characterized in that, The device access method includes: When the management device senses that the first access device has an abnormal access, it obtains the external network address and internal network address of the first access device, and selects a second access device with normal access within the same internal network as the first access device; The management device sends a co - investigation notice to the second access device carrying the internal network address of the first access device, so that after the second access device finds the first access device in the internal network, it sends a mapping port abnormal notice to the first access device; After receiving the mapping port abnormal notice, the first access device interacts with the port mapping device to update the mapping port, where the mapping port is the external network communication port mapped by the port mapping device for the communication port within the internal network of the first access device.
2. The device access method according to claim 1, wherein The co - investigation notice includes one or more of the device code of the first access device, the abnormal notice identifier, and the mapping port number of the first access device; the mapping port abnormal notice includes one or more of the device code of the first access device, the abnormal notice identifier, and the mapping port number of the first access device.
3. The device access method according to claim 1, wherein After receiving the mapping port abnormal notice, the first access device interacts with the port mapping device to update the mapping port, including: When the first access device requests access again, it actively changes the communication port within the internal network, so that the port mapping device re - assigns a mapping port for the first access device.
4. The device access method according to claim 1, wherein After receiving the mapping port abnormal notice, the first access device interacts with the port mapping device to update the mapping port, including: The first access device notifies the port mapping device of the abnormal mapping port, so that the port mapping device marks the abnormal mapping port; When the first access device requests access again, the port mapping device re - assigns a mapping port for the first access device after excluding the abnormal mapping port.
5. The device access method according to claim 4, wherein The first access device notifies the port mapping device of the abnormal mapping port, including: The first access device informs the port mapping device of the abnormal mapping port through the UPnP protocol extension field.
6. The device access method according to claim 1, wherein After receiving the mapping port abnormal notice, the first access device interacts with the port mapping device to update the mapping port, including: The first access device communicates with the port mapping device, uses an unoccupied communication port within the internal network, and designates the abnormal mapping port to be used, so that the port mapping device assigns the abnormal mapping port to the unoccupied communication port within the internal network; The first access device requests access again, and the port mapping device re - assigns a mapping port for the first access device.
7. The device access method according to claim 6, wherein The first access device communicates with the port mapping device, uses an unoccupied communication port within the internal network, and designates the abnormal mapping port to be used, including: The first access device actively sends a UPnP message to the port mapping device. The communication port within the internal network used in the UPnP message is an unoccupied communication port within the internal network, and it designates the mapping port it needs to use as the abnormal mapping port in the UPnP message.
8. An apparatus for device access, which is used to access an access device located in an internal network to a management device in an external network, is characterized in that The access device with restricted mapping port, applied to the management device, includes: Anomaly perception module, configured to obtain the external network address and internal network address of the first access device when an anomaly in the access of the first access device is perceived, and select a second access device that is normally accessed within the same internal network as the first access device; Co-investigation notification module, configured to send a co-investigation notification to the second access device carrying the internal network address of the first access device, so that after the second access device locates the first access device in the internal network, it sends a mapped port anomaly notification to the first access device, and causes the first access device to interact with the port mapping device to update the mapped port after receiving the mapped port anomaly notification, where the mapped port is the external network communication port mapped by the port mapping device for the communication port within the internal network of the first access device.
9. An apparatus for device access, comprising a processor and a non-volatile memory storing a number of computer instructions, characterized in that, When the computer instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having computer instructions stored thereon, characterized in that, The computer instructions are executed by a processor to implement the steps of the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method and device for automatically accessing monitoring equipment in NAT (Network Address Translation)
CN109962990A