A remote operation and maintenance method

By adopting a zero-trust model and single-packet authorization and authentication messages in industrial automation systems, network security and compatibility issues in remote operation and maintenance are resolved, achieving security protection and cost reduction for equipment and networks, and improving the flexibility of remote operation and maintenance.

CN115361209BActive Publication Date: 2026-03-06SUPCON TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-19
Publication Date
2026-03-06

AI Technical Summary

Technical Problem

In existing technologies, remote operation and maintenance of unattended automated base stations in industrial enterprises faces challenges such as difficulty in ensuring network security, VPN compatibility issues, performance bottlenecks, and high operation and maintenance costs.

Method used

Employing a Zero Trust security model and Single Packet Authorization and Authentication (SPA) messages, and through the collaborative work of the operation and maintenance gateway and server, all connections are pre-screened and controlled to establish a legitimate two-way communication channel, hiding device and network resources and avoiding direct exposure to the public network.

Benefits of technology

It effectively protects equipment and network resources, reduces the attack surface, lowers operation and maintenance costs, and improves the flexibility and security of remote operation and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115361209B_ABST
    Figure CN115361209B_ABST
Patent Text Reader

Abstract

This application provides a remote operation and maintenance method, relating to the field of industrial automation technology. It involves receiving a remote operation and maintenance request sent by a field client, wherein the request includes information about the industrial field equipment; sending the remote operation and maintenance request to a server, enabling the server to assign remote operation and maintenance tasks to the industrial field equipment based on the request; receiving a first connection request sent by the operation and maintenance client; verifying the first connection request; and if the verification is successful, establishing a bidirectional connection with both the operation and maintenance client and the field client, allowing bidirectional communication between the operation and maintenance client and the field client during the execution of remote operation and maintenance tasks. This method pre-screens and controls all connections, effectively hiding and protecting all devices, networks, and resources, minimizing the attack surface, avoiding direct exposure of operation and maintenance-related systems to the public network, saving remote operation and maintenance costs, and improving the flexibility of remote operation and maintenance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial automation technology, and more specifically, to a remote operation and maintenance method. Background Technology

[0002] As industrial enterprises continue to expand, more and more are adopting a headquarters-branch architecture, with factories also setting up unattended automated base stations in remote areas. During production and maintenance, these factories need to aggregate all data to the enterprise's central data center. However, due to various unforeseen risks, maintenance personnel and technical experts may not be able to reach the site in a timely manner to troubleshoot and resolve issues. Therefore, achieving effective and secure data transmission from branch factories, remote maintenance of unattended equipment, and timely, safe, and cost-effective troubleshooting of industrial control system faults have become urgent challenges for enterprises.

[0003] Existing remote access solutions based on Virtual Private Networks (VPNs) and firewalls rely on a perimeter security model, requiring firewalls to be configured with different VPN access policies. Furthermore, with the development of the Industrial Internet of Things (IIoT), security boundaries are becoming increasingly blurred, making traditional access control policies easily bypassable and compromising security. VPN servers are constantly exposed to the external network, becoming a significant entry point for hackers. VPNs also involve compatibility issues; switching between different VPNs is necessary for multi-platform operations, causing inconvenience. Additionally, VPNs have limited processing power and are prone to performance bottlenecks. Summary of the Invention

[0004] The purpose of this invention is to address the shortcomings of the prior art by providing a remote operation and maintenance method to solve network security issues in the remote operation and maintenance process.

[0005] To achieve the above objectives, the technical solutions adopted in the embodiments of this application are as follows:

[0006] In a first aspect, embodiments of this application provide a remote operation and maintenance method applied to an operation and maintenance gateway, the method comprising:

[0007] Receive remote operation and maintenance requests sent by field clients, wherein the remote operation and maintenance requests include: information of industrial field equipment;

[0008] Send the remote maintenance request to the server so that the server can assign remote maintenance tasks to the industrial field equipment according to the remote maintenance request;

[0009] Receive the first connection request sent by the operations and maintenance client;

[0010] Verify the first connection request;

[0011] If the verification is successful, a bidirectional connection is established between the operation and maintenance client and the field client, so that the operation and maintenance client and the field client can communicate bidirectionally during the execution of the remote operation and maintenance task.

[0012] Optionally, after sending the remote maintenance request to the server, the method further includes:

[0013] Receive the operation and maintenance allocation notification message returned by the server;

[0014] Send the maintenance assignment notification message to the field client to indicate that the remote maintenance task has been assigned to the industrial field equipment.

[0015] Optionally, before receiving the first connection request sent by the operation and maintenance client, the method further includes:

[0016] The system receives an authorization notification message sent by the server. The authorization notification message is sent by the server after the login verification of the operation and maintenance client is successful. The authorization notification message includes information about the operation and maintenance client.

[0017] The verification of the first connection request includes:

[0018] The first connection request is verified based on the information from the maintenance client.

[0019] Optionally, the method further includes:

[0020] Receive a first authorization termination message sent by the server, wherein the first authorization termination message is a termination message sent by the server when it detects an abnormal state between the operation and maintenance client and the server;

[0021] Disconnect the bidirectional connection with the maintenance client and the bidirectional connection with the field client.

[0022] Optionally, the method further includes:

[0023] Receive a second authorization termination message sent by the server, wherein the second authorization termination message is a termination message sent by the server after receiving a task execution completion message sent by the operation and maintenance client;

[0024] Disconnect the bidirectional connection with the maintenance client and the bidirectional connection with the field client.

[0025] Secondly, embodiments of this application provide a remote operation and maintenance method applied to a server, the method comprising:

[0026] Receive a remote maintenance request sent from a field client by the maintenance gateway, wherein the remote maintenance request includes: information about the industrial field equipment;

[0027] Based on the remote maintenance request, remote maintenance tasks are assigned to the industrial field equipment;

[0028] Receive login verification requests sent by the operations and maintenance client;

[0029] After the login verification of the operation and maintenance client is successful, an authorization notification message is sent to the operation and maintenance gateway. The authorization notification message includes the information of the operation and maintenance client, so that the operation and maintenance gateway verifies the first connection request sent by the operation and maintenance client based on the information of the operation and maintenance client, and establishes bidirectional connections with the operation and maintenance client and the field client respectively, so that the operation and maintenance client and the field client can communicate bidirectionally during the execution of the remote operation and maintenance task.

[0030] Optionally, after assigning remote maintenance tasks to the industrial field equipment according to the remote maintenance request, the method further includes:

[0031] The maintenance gateway sends a maintenance allocation notification message to the field client to indicate that the remote maintenance task has been allocated to the industrial field equipment.

[0032] Optionally, before receiving the login verification request sent by the operation and maintenance client, the method further includes:

[0033] Receive the second connection request sent by the maintenance client;

[0034] After the second connection request is verified, a bidirectional connection is established with the operation and maintenance client.

[0035] Optionally, the method further includes:

[0036] Perform status monitoring on the aforementioned operation and maintenance client;

[0037] If an abnormal status is detected between the operation and maintenance client and the client, the bidirectional connection between the client and the operation and maintenance client is disconnected, and a first authorization termination message is sent to the operation and maintenance gateway. This causes the operation and maintenance gateway to disconnect the bidirectional connection between the client and the operation and maintenance client and disconnect the bidirectional connection between the client and the field client according to the first authorization termination message.

[0038] Optionally, the method further includes:

[0039] Receive the task execution completion message sent by the operation and maintenance client;

[0040] Based on the task completion message, the bidirectional connection with the maintenance client is disconnected, and a second authorization termination message is sent to the maintenance gateway; so that the maintenance gateway disconnects the bidirectional connection with the maintenance client and the bidirectional connection with the field client based on the second authorization termination message.

[0041] Compared with the prior art, this application has the following beneficial effects:

[0042] This application provides a remote operation and maintenance method. The method involves receiving a remote operation and maintenance request from a field client, whereby the request includes information about the industrial field equipment. The method then sends the request to a server, enabling the server to assign remote operation and maintenance tasks to the industrial field equipment based on the request. Next, it receives a first connection request from the operation and maintenance client. The first connection request is verified. If the verification is successful, a bidirectional connection is established between the operation and maintenance client and the field client, allowing bidirectional communication between the operation and maintenance client and the field client during the execution of remote operation and maintenance tasks. This method pre-screens and controls all connections, effectively hiding and protecting all devices, networks, and resources, minimizing the attack surface, and preventing operation and maintenance-related systems from being directly exposed to the public network and thus vulnerable to attacks. This saves on remote operation and maintenance costs and improves the flexibility of remote operation and maintenance. Attached Figure Description

[0043] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0044] Figure 1 This is a schematic diagram of the structure of a remote operation and maintenance system provided in an embodiment of this application;

[0045] Figure 2 A flowchart illustrating a remote operation and maintenance method provided in an embodiment of this application;

[0046] Figure 3 A flowchart illustrating a method for prompting maintenance and operation notification messages, provided in an embodiment of this application;

[0047] Figure 4 A flowchart illustrating a verification method based on an authorization notification provided in this application embodiment;

[0048] Figure 5 A flowchart illustrating a remote operation and maintenance termination method provided in an embodiment of this application;

[0049] Figure 6 A flowchart illustrating a remote operation and maintenance termination method provided in an embodiment of this application;

[0050] Figure 7 A flowchart illustrating another remote operation and maintenance method provided in this application embodiment;

[0051] Figure 8 A flowchart illustrating another method for prompting maintenance and operation notification messages provided in an embodiment of this application;

[0052] Figure 9 A flowchart illustrating a remote operation and maintenance verification method provided in an embodiment of this application;

[0053] Figure 10 A flowchart illustrating another remote operation and maintenance termination method provided in this application embodiment;

[0054] Figure 11 A flowchart illustrating another remote operation and maintenance termination method provided in this application embodiment;

[0055] Figure 12 A flowchart illustrating yet another remote operation and maintenance method provided in this application embodiment;

[0056] Figure 13 A schematic diagram of a remote operation and maintenance device provided in an embodiment of this application;

[0057] Figure 14 A schematic diagram of another remote operation and maintenance device provided in the embodiments of this application;

[0058] Figure 15 A schematic diagram of an operation and maintenance gateway provided in an embodiment of this application;

[0059] Figure 16 This is a schematic diagram of a server provided in an embodiment of this application.

[0060] Icons: 100 - Operation and Maintenance Gateway, 200 - Server, 300 - Field Client, 400 - Operation and Maintenance Client, 1302 - First Sending Module, 1301 - First Receiving Module, 1303 - Second Receiving Module, 1304 - Verification Module, 1305 - Establishment Module, 1401 - Third Receiving Module, 1402 - Allocation Module, 1403 - Fourth Receiving Module, 1404 - Second Sending Module, 1501 - First Processor, 1502 - First Storage Medium, 1601 - Second Processor, 1602 - Second Storage Medium. Detailed Implementation

[0061] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. The components of the embodiments of the present application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0062] Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0063] It should be noted that similar labels and letters in the following figures indicate similar items. Therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0064] Furthermore, the terms "first" and "second" are used only to distinguish descriptions and should not be interpreted as indicating or implying relative importance.

[0065] It should be noted that, where there is no conflict, the features in the embodiments of the present invention can be combined with each other.

[0066] During production and operation, factories need to aggregate all data to the factory's central data center. However, due to various unforeseen risks, maintenance personnel and technical experts may be unable to reach the site in a timely manner to troubleshoot and resolve problems. To make industrial automation control safer and more reliable, this application provides a remote operation and maintenance method.

[0067] In the field of industrial automation technology, Zero Trust (ZT) is a series of security concepts and ideas that, assuming the network environment has been compromised, continuously verify and never trust each access request to reduce uncertainty during execution. Single Packet Authorization (SPA) messages are knocking messages with specific formats and data, used to implement "authentication before connection." The controller and connection-accepting host will not respond to any connection attempts until they receive a valid SPA message.

[0068] The following is an explanation of a remote operation and maintenance system provided in this application through specific examples.

[0069] Figure 1This is a schematic diagram of a remote operation and maintenance system provided in an embodiment of this application. The system includes: an operation and maintenance gateway 100, a server 200, a field client 300, and an operation and maintenance client 400.

[0070] The maintenance gateway 100 communicates with the server 200, the field client 300, and the maintenance client 400; the server 200 also communicates with the maintenance client 400. It establishes communication connections between remote maintenance systems based on remote maintenance requests from the field client 300, assigns remote maintenance tasks, and completes these tasks. Specifically, after successful connection between the remote maintenance systems, authentication and control are achieved through the connection between the server 200 and the maintenance gateway 100 and the maintenance client 400; authentication and control as well as data transmission are achieved through the connection between the maintenance gateway 100 and the field clients 300 and 400.

[0071] For example, the maintenance gateway 100 can be a zero-trust remote maintenance gateway, and the server 200 can be a maintenance data cloud platform. The field client 300 is installed on the terminal device of the field personnel for easy operation; the maintenance client 400 is installed on the terminal device of the maintenance personnel for easy operation.

[0072] Figure 2 This is a flowchart illustrating a remote operation and maintenance method provided in an embodiment of this application. The method is applied to an operation and maintenance gateway. Figure 2 As shown, the method includes:

[0073] S101: Receive remote operation and maintenance requests sent by the on-site client.

[0074] When industrial equipment requires maintenance due to malfunctions, upgrades, or other reasons, and maintenance personnel are unable to travel to the site due to objective circumstances, on-site personnel need to use a field client to contact maintenance personnel through a remote maintenance system for remote maintenance.

[0075] First, on-site personnel use a field client to send a remote maintenance request to the maintenance gateway to establish a remote connection with the remote maintenance system. The maintenance gateway receives the remote maintenance request from the field client and then performs further processing based on it.

[0076] The remote maintenance request includes information about the industrial field equipment. For example, this information includes: equipment model, problem type, problem description, and equipment identifier. At the industrial site, personnel log into the field client and, based on the specific details of the equipment, select the equipment model, problem type, and equipment identifier, fill in the problem description, and then send a remote maintenance request.

[0077] S102. Send a remote maintenance request to the server so that the server can assign remote maintenance tasks to the industrial field equipment according to the remote maintenance request.

[0078] Upon receiving a remote maintenance request, the request is further sent to the server. Once received, the server can assign the remote maintenance task to maintenance personnel (such as experienced technicians or technical experts) with the corresponding capabilities, based on the equipment model, problem type, and problem description provided in the industrial field equipment information. For example, if the maintenance personnel are online and capable of performing maintenance operations, the server can notify them via email or SMS after the task assignment is complete.

[0079] S103, Receive the first connection request sent by the operation and maintenance client.

[0080] After receiving the maintenance notification, the operations and maintenance personnel will use the maintenance client to connect to the maintenance gateway and send an initial connection request. This initial connection request includes information about the maintenance client. The maintenance gateway receives this initial connection request and can then obtain the maintenance client's information.

[0081] For example, the first connection request can be a Single Packet Authorization (SPA) message. An SPA message is a knock-on message with a specific format and data, used to implement "authentication before connection." The information of the operations and maintenance client can include: the hardware identifier of the operations and maintenance client, and the Media Access Control Address (MAC) address of the operations and maintenance client.

[0082] S104. Verify the first connection request.

[0083] The operations and maintenance gateway verifies the first connection request. It verifies whether the first connection request is a legitimate and valid connection request.

[0084] S105. If the verification is successful, a bidirectional connection is established between the operation and maintenance client and the field client, so that the operation and maintenance client and the field client can communicate bidirectionally during the execution of remote operation and maintenance tasks.

[0085] If the verification passes, it indicates that the operations and maintenance client is a legitimate and valid client. A bidirectional connection is then established between the operations and maintenance client and the field client. This enables bidirectional communication between the operations and maintenance client and the field client via the operations and maintenance gateway, allowing them to perform remote operations and maintenance tasks. This, in turn, completes the remote operations and maintenance task.

[0086] If the verification fails, a bidirectional connection will not be established with the operation and maintenance client, nor with the on-site client.

[0087] This allows for pre-screening and control of all connections, refraining from responding to any connection requests before receiving legitimate ones. This effectively hides and protects all devices, networks, and resources, minimizing the attack surface and preventing maintenance-related systems from being directly exposed to the public network and thus vulnerable to attacks. Simultaneously, it reduces the cost of remote maintenance for industrial control systems, improves the flexibility of remote maintenance, and is simple to use and highly compatible.

[0088] For example, a bidirectional connection can be a Mutual Transport Layer Security (MTLS) bidirectional encrypted connection to ensure secure remote communication.

[0089] In summary, this embodiment receives a remote maintenance request sent by a field client, where the request includes information about the industrial field equipment; sends the remote maintenance request to the server, enabling the server to assign remote maintenance tasks to the industrial field equipment based on the request; receives a first connection request sent by the maintenance client; verifies the first connection request; and if the verification is successful, establishes a bidirectional connection with both the maintenance client and the field client, allowing bidirectional communication between them during the execution of remote maintenance tasks. This pre-screening and control of all connections effectively hides and protects all devices, networks, and resources, minimizing the attack surface and preventing maintenance-related systems from being directly exposed to the public network and thus vulnerable to attacks. This saves on remote maintenance costs and improves the flexibility of remote maintenance.

[0090] In the above Figure 2 Based on the embodiments, this application also provides a method for prompting operation and maintenance allocation notification messages. Figure 3 This is a flowchart illustrating a method for prompting maintenance and operation notification messages, provided in an embodiment of this application. Figure 3 As shown, after sending a remote maintenance request to the server in S102, the method further includes:

[0091] S201. Receive the operation and maintenance allocation notification message returned by the server.

[0092] After the server successfully assigns an operation and maintenance task to the operation and maintenance personnel, it sends an operation and maintenance assignment notification message to the operation and maintenance gateway. The operation and maintenance gateway receives this notification message from the server and is thus aware that the operation and maintenance task has been successfully assigned.

[0093] S202. Send an operation and maintenance allocation notification message to the field client to indicate that a remote operation and maintenance task has been assigned to the industrial field equipment.

[0094] After receiving the maintenance assignment notification message from the server, the maintenance gateway sends a maintenance assignment notification message to the field client to indicate that a remote maintenance task has been assigned to the industrial field equipment. Once the field client receives the maintenance assignment notification message, field personnel can wait for the remote maintenance system to connect successfully for maintenance communication.

[0095] Furthermore, prior to receiving the operation and maintenance allocation notification message returned by the receiving server in S201, the method also includes:

[0096] Return a waiting prompt message to the field client so that the industrial field equipment enters the waiting maintenance state.

[0097] After the maintenance gateway sends a remote maintenance request to the server, but before receiving the maintenance assignment notification message from the server, a waiting prompt message is returned to the field client to put the industrial field equipment into a waiting maintenance state.

[0098] In summary, this embodiment receives the maintenance allocation notification message returned by the server and sends the maintenance allocation notification message to the field client to indicate that a remote maintenance task has been assigned to the industrial field equipment. This makes remote maintenance more real-time and accurate.

[0099] In the above Figure 2 Based on the embodiments, this application also provides a verification method based on the authorization notice. Figure 4 This is a flowchart illustrating a verification method based on an authorization notification, provided as an embodiment of this application. Figure 4 As shown, before receiving the first connection request sent by the maintenance client in S103, the method further includes:

[0100] S301, Receive the authorization notification message sent by the server.

[0101] Before the operations and maintenance gateway verifies the connection request from the operations and maintenance client, the server will verify the operations and maintenance client. If the verification is successful, the server will send an authorization notification message to the operations and maintenance gateway.

[0102] Specifically, the authorization notification message is a message sent by the server after successfully authenticating the login of the operation and maintenance client; the authorization notification message includes information about the operation and maintenance client.

[0103] Furthermore, the authorization notification message is a message sent by the server after it has successfully verified the second connection request from the operations and maintenance client and successfully verified the login of the operations and maintenance client.

[0104] The verification of the first connection request in S104 includes:

[0105] S302. Verify the first connection request based on the information from the maintenance client.

[0106] The operations and maintenance gateway has received the information from the operations and maintenance client, and the first connection request also includes the information sent by the operations and maintenance client. Therefore, the first connection request can be verified.

[0107] In summary, in this embodiment, the server receives an authorization notification message, which is sent after the server has successfully verified the login of the maintenance client. The authorization notification message includes information about the maintenance client. Based on this information, the first connection request is verified. This makes the verification of the maintenance client more accurate.

[0108] In the above Figure 2 Based on the embodiments, this application also provides a method for remote operation and maintenance termination. Figure 5 This is a flowchart illustrating a remote operation and maintenance termination method provided in an embodiment of this application. Figure 5 As shown, the method also includes:

[0109] S401, Receive the first authorization termination message sent by the server.

[0110] During remote operation and maintenance communication, the operation and maintenance client continuously sends keep-alive request messages to the server, enabling the server to monitor the client's status. Once the server detects data anomalies or an anomaly in the status between the operation and maintenance client and the client, it must terminate the connection to the remote operation and maintenance system and send a first authorized termination message to the operation and maintenance gateway. The operation and maintenance gateway receives this first authorized termination message from the server; this message is a termination message sent by the server when it detects an anomaly in the status between the operation and maintenance client and the server itself.

[0111] S402. Disconnect the bidirectional connection with the maintenance client and the on-site client.

[0112] Based on the first authorization termination message, the operations and maintenance gateway disconnects the bidirectional connection with the operations and maintenance client, and also disconnects the bidirectional connection with the on-site client. This disconnects the entire remote operations and maintenance system, preventing the leakage of remote operations and maintenance communication information.

[0113] In summary, in this embodiment, the server receives a first authorization termination message, which is sent when the server detects an abnormal state between the maintenance client and the server; the bidirectional connection with the maintenance client is disconnected, and the bidirectional connection with the on-site client is also disconnected. This prevents the leakage of remote maintenance communication information.

[0114] In the above Figure 2 Based on the embodiments, this application also provides a method for ending remote operation and maintenance. Figure 6 This is a flowchart illustrating a remote operation and maintenance termination method provided in an embodiment of this application. Figure 6 As shown, the method also includes:

[0115] S501, Receive the second authorization termination message sent by the server.

[0116] During remote operation and maintenance communication, if the remote operation and maintenance ends, the operation and maintenance client will send a task completion message to the server. This causes the server to terminate the connection to the remote operation and maintenance system, and the server sends a second authorized termination message to the operation and maintenance gateway. The operation and maintenance gateway receives the second authorized termination message from the server, which is a termination message sent by the server after receiving the task completion message from the operation and maintenance client.

[0117] S502. Disconnect the bidirectional connection between the maintenance client and the field client.

[0118] According to the second authorization termination message, the operations and maintenance gateway disconnects the bidirectional connection with the operations and maintenance client, and also disconnects the bidirectional connection with the on-site client. This disconnects the entire remote operations and maintenance system, ensuring the timely completion of the entire remote operations and maintenance task and avoiding resource waste.

[0119] In summary, in this embodiment, the server receives a second authorization termination message, which is a termination message sent by the server after receiving a task completion message from the maintenance client; the bidirectional connection between the server and the maintenance client is disconnected, as well as the bidirectional connection between the server and the on-site client. This ensures the timely completion of the entire remote maintenance task and avoids resource waste.

[0120] In the above Figure 2 Based on the embodiments, this application also provides another remote operation and maintenance method. Figure 7 This is a flowchart illustrating another remote operation and maintenance method provided in an embodiment of this application, which is applied to a server. Figure 7 As shown, the method includes:

[0121] S601: Receives remote maintenance requests sent from field clients by the maintenance gateway.

[0122] After receiving a remote maintenance request from a field client, the maintenance gateway further forwards the request to the server. The remote maintenance request includes information about the industrial field equipment.

[0123] S602. Assign remote maintenance tasks to industrial field equipment based on remote maintenance requests.

[0124] Remote maintenance requests include information about industrial field equipment.

[0125] For example, the information for industrial field equipment includes: equipment model, problem type, problem description, and equipment identifier. After receiving a remote maintenance request, the server can assign the remote maintenance task to the corresponding maintenance personnel based on the equipment model, problem type, and problem description in the industrial field equipment information. For example, if the maintenance personnel are online and can perform maintenance operations, after the task is assigned, the server can notify the maintenance personnel via email or SMS that the maintenance task has been assigned, based on their communication information.

[0126] S603: Receive login verification request sent by the operation and maintenance client.

[0127] After receiving the maintenance prompt, the operations and maintenance personnel use the maintenance client to send a login verification request to the server. The server receives the login verification request sent by the maintenance client. For example, the login verification can be dynamic multi-factor authentication. The specific verification information can be generated by the server.

[0128] S604. After the login verification of the operation and maintenance client is successful, an authorization notification message is sent to the operation and maintenance gateway.

[0129] After successful login verification for the operations and maintenance client, an authorization notification message is sent to the operations and maintenance gateway.

[0130] Specifically, the authorization notification message includes: information about the operation and maintenance client, so that the operation and maintenance gateway verifies the first connection request sent by the received operation and maintenance client based on the information of the operation and maintenance client, and establishes bidirectional connections with the operation and maintenance client and the field client respectively, so that the operation and maintenance client and the field client can communicate bidirectionally during the execution of remote operation and maintenance tasks.

[0131] After successful login verification on the operations and maintenance client, users can log in and view detailed information about maintenance tasks, gaining the minimum permissions required for that task. If login verification fails, access to the operations and maintenance client will be denied.

[0132] In summary, this embodiment receives remote maintenance requests from field clients sent by the maintenance gateway; assigns remote maintenance tasks to industrial field equipment based on the remote maintenance requests; receives login verification requests from maintenance clients; and after successful login verification of the maintenance clients, sends an authorization notification message to the maintenance gateway. This pre-screening and control of all connections effectively hides and protects all devices, networks, and resources, minimizing the attack surface and preventing maintenance-related systems from being directly exposed to the public network and thus vulnerable to attacks.

[0133] In the above Figure 7 Based on the embodiments, this application also provides another method for prompting operation and maintenance allocation notification messages. Figure 8 This is a flowchart illustrating another method for prompting maintenance and operation notification messages, provided in an embodiment of this application. Figure 8 As shown, after assigning remote maintenance tasks to industrial field equipment based on remote maintenance requests in S602, the method further includes:

[0134] S701 sends an operation and maintenance assignment notification message to the field client through the operation and maintenance gateway to indicate that a remote operation and maintenance task has been assigned to the industrial field equipment.

[0135] After the server successfully assigns the maintenance task to the maintenance personnel, it sends a maintenance assignment notification message to the maintenance gateway. Upon receiving the maintenance assignment notification message from the server, the maintenance gateway recognizes that the maintenance task has been successfully assigned, indicating that a remote maintenance task has been assigned to the industrial field equipment.

[0136] In the above Figure 7 Based on the embodiments, this application also provides a verification method for remote operation and maintenance. Figure 9 This is a flowchart illustrating a remote operation and maintenance verification method provided in an embodiment of this application. Figure 9 As shown, before receiving the login verification request sent by the operation and maintenance client in S603, the method also includes:

[0137] S801: Receive the second connection request sent by the maintenance client.

[0138] After receiving the maintenance notification, the operations and maintenance personnel will use the maintenance client to verify the connection with the server and send a second connection request to the maintenance gateway. This second connection request includes information about the maintenance client. Upon receiving this second connection request, the server can obtain this information about the maintenance client.

[0139] For example, the second connection request can be an SPA message, which is a knock message with a specific format and data used to implement "authentication before connection". The information of the operations and maintenance client can include: the hardware identifier of the operations and maintenance client and the MAC address of the operations and maintenance client.

[0140] S802. After the second connection request is verified, a bidirectional connection is established with the operation and maintenance client.

[0141] The server verifies the second connection request. It verifies whether the first connection request is valid. If the second connection request passes verification, a bidirectional connection is established with the operations and maintenance client. If the second connection request fails verification, the server does not respond.

[0142] In summary, in this embodiment, a second connection request sent by the operations and maintenance client is received; after the second connection request is verified, a bidirectional connection is established with the operations and maintenance client. This makes the connection more secure.

[0143] In the above Figure 7 Based on the embodiments, this application also provides another method for remote operation and maintenance termination. Figure 10 This is a flowchart illustrating another remote operation and maintenance termination method provided in an embodiment of this application. Figure 10 As shown, the method also includes:

[0144] S901. Monitor the status of the operation and maintenance client.

[0145] During remote operation and maintenance communication, the operation and maintenance client will continuously send keep-alive request messages to the server so that the server can monitor the status of the operation and maintenance client.

[0146] S902. If an abnormal status is detected between the operator and the maintenance client, disconnect the bidirectional connection between the operator and the maintenance client and send the first authorization termination message to the maintenance gateway.

[0147] Once the server detects data anomalies and an abnormal state between the server and the maintenance client, it must terminate the connection to the remote maintenance system. This involves disconnecting the bidirectional connection with the maintenance client and sending a first authorized termination message to the maintenance gateway. The maintenance gateway then disconnects both its bidirectional connection with the maintenance client and its bidirectional connection with the on-site client based on the first authorized termination message.

[0148] In summary, this embodiment monitors the status of the operations and maintenance (O&M) client. If an abnormal status is detected between the O&M client and the client, the bidirectional connection is disconnected, and a first authorization termination message is sent to the O&M gateway. This prevents the leakage of O&M communication information.

[0149] In the above Figure 7 Based on the embodiments, this application also provides another method for ending remote operation and maintenance. Figure 11 This is a flowchart illustrating another remote operation and maintenance termination method provided in an embodiment of this application. Figure 11 As shown, the method also includes:

[0150] S1001, Receive the task execution completion message sent by the operation and maintenance client.

[0151] During remote operation and maintenance communication, if the remote operation and maintenance is completed, the operation and maintenance client will send a task completion message to the server. Upon receiving the task completion message from the operation and maintenance client, the server confirms that the operation and maintenance task has been completed.

[0152] S1002. Based on the task completion message, disconnect the bidirectional connection with the operation and maintenance client and send a second authorization termination message to the operation and maintenance gateway.

[0153] Based on the task completion message, it is determined that the operation and maintenance task has been completed. Then, the bidirectional connection with the operation and maintenance client is disconnected, and a second authorization termination message is sent to the operation and maintenance gateway. This causes the operation and maintenance gateway to disconnect its bidirectional connection with the operation and maintenance client, and also disconnect its bidirectional connection with the field client, based on the second authorization termination message.

[0154] In summary, this embodiment receives a task completion message from the operations and maintenance client; based on the task completion message, it disconnects the bidirectional connection with the operations and maintenance client and sends a second authorization termination message to the operations and maintenance gateway. This ensures the timely completion of the entire remote operations and maintenance task, avoiding resource waste.

[0155] In the above Figures 2-11 Based on the embodiments shown, this embodiment provides a systematic description of a remote operation and maintenance method provided in this application. Figure 12 This is a flowchart illustrating another remote operation and maintenance method provided in an embodiment of this application. Figure 12 As shown, the method includes:

[0156] S1101, The on-site client sends a remote maintenance request to the maintenance gateway.

[0157] When industrial equipment requires maintenance due to malfunctions, upgrades, or other reasons, and maintenance personnel are unable to travel to the site due to objective circumstances, on-site personnel need to use a field client to contact maintenance personnel through a remote maintenance system for remote maintenance.

[0158] First, on-site personnel use the on-site client to send a remote maintenance request to the maintenance gateway to establish a remote connection with the remote maintenance system. This request includes information about the industrial field equipment. For example, this information might include: equipment model, problem type, problem description, and equipment identifier. On-site personnel then log into the on-site client and, based on the specific details of the industrial field equipment, select the equipment model, problem type, and equipment identifier, and fill in the problem description. After completion, the remote maintenance request can be sent.

[0159] S1102, The operation and maintenance gateway sends a remote operation and maintenance request to the server.

[0160] The operations and maintenance gateway receives a remote operations and maintenance request from a field client, processes it further according to the request, and then sends the request to the server.

[0161] S1103. The server assigns remote maintenance tasks to the industrial field equipment according to the remote maintenance request.

[0162] After receiving a remote maintenance request from a field client sent by the maintenance gateway, the system assigns remote maintenance tasks to the industrial field equipment based on the request. These tasks are then assigned to maintenance personnel with the necessary capabilities, such as maintenance staff or technical experts. For example, if the assigned personnel are online and capable of performing maintenance operations, the system can notify them via email or SMS after task assignment.

[0163] S1104. Send an operation and maintenance allocation notification message to the field client through the operation and maintenance gateway to indicate that a remote operation and maintenance task has been assigned to the industrial field equipment.

[0164] After the server successfully assigns the maintenance task to the maintenance personnel, it sends a maintenance assignment notification message to the maintenance gateway. Upon receiving the maintenance assignment notification message from the server, the maintenance gateway recognizes that the maintenance task has been successfully assigned, indicating that a remote maintenance task has been assigned to the industrial field equipment.

[0165] S1105, The maintenance client sends a second connection request to the server.

[0166] After receiving the maintenance notification, the operations and maintenance personnel will use the maintenance client to verify the connection with the server and send a second connection request to the maintenance gateway. This second connection request includes information about the maintenance client. Upon receiving this second connection request, the server can obtain this information about the maintenance client.

[0167] S1106. After the server verifies the second connection request, it establishes a bidirectional connection with the operation and maintenance client.

[0168] The server verifies the second connection request. It verifies whether the first connection request is valid. If the second connection request passes verification, a bidirectional connection is established with the operations and maintenance client. If the second connection request fails verification, the server does not respond.

[0169] S1107. The maintenance client sends a login verification request to the server.

[0170] After receiving the maintenance prompt message and establishing a two-way connection between the maintenance client and the server, the maintenance personnel send a login verification request to the server using the maintenance client. The server receives the login verification request sent by the maintenance client. For example, the login verification can be dynamic multi-factor authentication. The specific verification information can be generated by the server.

[0171] S1108. After the login verification of the operation and maintenance client is successful, an authorization notification message is sent to the operation and maintenance gateway.

[0172] After successful login verification for the operations and maintenance client, an authorization notification message is sent to the operations and maintenance gateway.

[0173] Specifically, the authorization notification message includes: information about the operation and maintenance client, so that the operation and maintenance gateway verifies the first connection request sent by the received operation and maintenance client based on the information of the operation and maintenance client, and establishes bidirectional connections with the operation and maintenance client and the field client respectively, so that the operation and maintenance client and the field client can communicate bidirectionally during the execution of remote operation and maintenance tasks.

[0174] After successful login verification on the operations and maintenance client, users can log in and view detailed information about maintenance tasks, gaining the minimum permissions required for that task. If login verification fails, access to the operations and maintenance client will be denied.

[0175] S1109, The first connection request sent by the operation and maintenance client to the operation and maintenance gateway.

[0176] After successfully logging in, the operations and maintenance personnel will use the operations and maintenance client to connect to the operations and maintenance gateway and send an initial connection request to the gateway. This initial connection request includes information about the operations and maintenance client. The operations and maintenance gateway receives this initial connection request and can then obtain the client's information.

[0177] S1110, the operation and maintenance gateway verifies the first connection request.

[0178] The operations and maintenance gateway verifies the first connection request. It verifies whether the first connection request is a legitimate and valid connection request.

[0179] S1111 If the verification is successful, a bidirectional connection is established between the operation and maintenance client and the field client, so that the operation and maintenance client and the field client can communicate bidirectionally during the execution of remote operation and maintenance tasks.

[0180] If the verification passes, it indicates that the operations and maintenance client is a legitimate and valid client. A bidirectional connection is then established between the operations and maintenance client and the field client. This enables bidirectional communication between the operations and maintenance client and the field client via the operations and maintenance gateway, allowing them to perform remote operations and maintenance tasks. This, in turn, completes the remote operations and maintenance task.

[0181] If the verification fails, a bidirectional connection will not be established with the operation and maintenance client, nor with the on-site client.

[0182] This allows for pre-screening and control of all connections, refraining from responding to any connection requests before receiving legitimate ones. This effectively hides and protects all devices, networks, and resources, minimizing the attack surface and preventing maintenance-related systems from being directly exposed to the public network and thus vulnerable to attacks. Simultaneously, it reduces the cost of remote maintenance for industrial control systems, improves the flexibility of remote maintenance, and is simple to use and highly compatible.

[0183] The following describes the remote operation and maintenance device, equipment, and storage medium provided in this application for execution. The specific implementation process and technical effects are described above and will not be repeated below.

[0184] Figure 13 This is a schematic diagram of a remote operation and maintenance device provided in an embodiment of this application. The device is applied to an operation and maintenance gateway. Figure 13 As shown, the device includes:

[0185] The first receiving module 1301 is used to receive remote operation and maintenance requests sent by the field client, wherein the remote operation and maintenance requests include information about the industrial field equipment.

[0186] The first sending module 1302 is used to send a remote operation and maintenance request to the server, so that the server can assign remote operation and maintenance tasks to industrial field equipment according to the remote operation and maintenance request.

[0187] The second receiving module 1303 is used to receive the first connection request sent by the operation and maintenance client.

[0188] The verification module 1304 is used to verify the first connection request.

[0189] Module 1305 is established to establish a bidirectional connection with the operation and maintenance client and a bidirectional connection with the field client if the verification is successful, so that the operation and maintenance client and the field client can communicate bidirectionally during the execution of remote operation and maintenance tasks.

[0190] Furthermore, the first receiving module 1301 is also used to receive the operation and maintenance allocation notification message returned by the server.

[0191] Furthermore, the first sending module 1302 is also used to send an operation and maintenance allocation notification message to the field client to indicate that a remote operation and maintenance task has been allocated to the industrial field equipment.

[0192] Furthermore, the second receiving module 1303 is also used to receive an authorization notification message sent by the server. The authorization notification message is a message sent by the server after the operation and maintenance client has successfully logged in. The authorization notification message includes information about the operation and maintenance client.

[0193] Furthermore, the verification module 1304 is specifically used to verify the first connection request based on the information from the operation and maintenance client.

[0194] Furthermore, the first receiving module 1301 is also used to receive a first authorization termination message sent by the server, the first authorization termination message being a termination message sent by the server when it detects an abnormal state between the maintenance client and the server; disconnect the bidirectional connection with the maintenance client, and disconnect the bidirectional connection with the field client.

[0195] Furthermore, the first receiving module 1301 is also used to receive a second authorization termination message sent by the server, the second authorization termination message being a termination message sent by the server after receiving a task execution completion message sent by the operation and maintenance client; disconnect the bidirectional connection with the operation and maintenance client, and disconnect the bidirectional connection with the field client.

[0196] Figure 14 This is a schematic diagram of another remote operation and maintenance device provided in an embodiment of this application, which is applied to a server. Figure 14 As shown, the device includes:

[0197] The third receiving module 1401 is used to receive a remote operation and maintenance request sent from a field client by the operation and maintenance gateway, wherein the remote operation and maintenance request includes information about industrial field equipment.

[0198] The allocation module 1402 is used to allocate remote maintenance tasks to industrial field equipment according to remote maintenance requests.

[0199] The fourth receiving module 1403 is used to receive login verification requests sent by the operation and maintenance client.

[0200] The second sending module 1404 is used to send an authorization notification message to the operation and maintenance gateway after the operation and maintenance client has successfully logged in. The authorization notification message includes information about the operation and maintenance client, so that the operation and maintenance gateway can verify the first connection request sent by the operation and maintenance client based on the information of the operation and maintenance client, and then establish bidirectional connections with the operation and maintenance client and the field client respectively, so that the operation and maintenance client and the field client can communicate bidirectionally during the execution of remote operation and maintenance tasks.

[0201] Furthermore, the second sending module 1404 is also used to send an operation and maintenance allocation notification message to the field client through the operation and maintenance gateway to indicate that a remote operation and maintenance task has been allocated to the industrial field equipment.

[0202] Furthermore, the fourth receiving module 1403 is also used to receive a second connection request sent by the operation and maintenance client; after the second connection request is verified, a bidirectional connection is established with the operation and maintenance client.

[0203] Furthermore, the fourth receiving module 1403 is also used to monitor the status of the operation and maintenance client; if an abnormal status is detected between the operation and maintenance client and the client, the bidirectional connection between the operation and maintenance client and the client is disconnected, and a first authorization termination message is sent to the operation and maintenance gateway; so that the operation and maintenance gateway disconnects the bidirectional connection between the operation and maintenance client and the client and the field client according to the first authorization termination message.

[0204] Furthermore, the fourth receiving module 1403 is also used to receive a task execution completion message sent by the operation and maintenance client; according to the task execution completion message, disconnect the bidirectional connection with the operation and maintenance client, and send a second authorization termination message to the operation and maintenance gateway; so that the operation and maintenance gateway disconnects the bidirectional connection with the operation and maintenance client according to the second authorization termination message, and disconnects the bidirectional connection with the field client.

[0205] Figure 15 This is a schematic diagram of an operation and maintenance gateway provided in an embodiment of this application. The operation and maintenance gateway may be a gateway with computing processing capabilities.

[0206] The maintenance gateway includes a first processor 1501 and a first storage medium 1502. The first processor 1501 and the first storage medium 1502 are connected via a bus.

[0207] The first storage medium 1502 is used to store a program, and the first processor 1501 calls the program stored in the first storage medium 1502 to execute the above method embodiment. The specific implementation method and technical effect are similar, and will not be described again here.

[0208] Optionally, the present invention also provides a first storage medium including a program, which, when executed by a processor, is used to perform the above-described method embodiments.

[0209] Figure 16 This is a schematic diagram of a server provided in an embodiment of this application. The server may be a server with computing processing capabilities.

[0210] The server includes a second processor 1601 and a second storage medium 1602. The second processor 1601 and the second storage medium 1602 are connected via a bus.

[0211] The second storage medium 1602 is used to store a program, and the second processor 1601 calls the program stored in the second storage medium 1602 to execute the above method embodiment. The specific implementation method and technical effect are similar, and will not be described again here.

[0212] Optionally, the present invention also provides a second storage medium including a program, which, when executed by a processor, is used to perform the above-described method embodiments.

[0213] In the several embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0214] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0215] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0216] The integrated units implemented as software functional units described above can be stored in a computer-readable storage medium. These software functional units, stored in a storage medium, include several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute some steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0217] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A remote operation method, characterized by, The method is applied to a zero-trust remote operation gateway, and the method comprises the following steps: receiving a remote operation request sent by a field client, wherein the remote operation request comprises information of an industrial field device, and the information of the industrial field device comprises a device model, a problem type, a problem description, and a device identifier; sending the remote operation request to a server, so that the server allocates a remote operation task for the industrial field device according to the device model, the problem type, the problem description, and the device identifier in the remote operation request, and allocates the remote operation task to an operation personnel who meets an operation capability corresponding to the problem; receiving an authorization notification message sent by the server, wherein the authorization notification message is sent after the server receives a login verification request sent by an operation client and performs login verification on the operation client, and the authorization notification message comprises information of the operation client, wherein the login verification request is sent by the operation personnel through the operation client; receiving a first connection request sent by the operation client, wherein the first connection request is a single-packet authorization authentication packet, and the first connection request comprises the information of the operation client; verifying the first connection request according to the information of the operation client; if the verification is passed, establishing a bidirectional connection between the remote operation gateway and the operation client and a bidirectional connection between the remote operation gateway and the field client, so that the operation client and the field client perform bidirectional communication during execution of the remote operation task, and the bidirectional connection is a mutual transport layer security bidirectional encryption connection.

2. The method of claim 1, wherein, After the step of sending the remote operation request to the server, the method further comprises the following steps: receiving an operation allocation notification message returned by the server; sending the operation allocation notification message to the field client to indicate that the remote operation task has been allocated to the industrial field device.

3. The method of claim 1, wherein, The method further comprises the following steps: receiving a first authorization termination message sent by the server, wherein the first authorization termination message is a termination message sent by the server when the server monitors that a state between the operation client and the server is abnormal; disconnecting the bidirectional connection between the remote operation gateway and the operation client and the bidirectional connection between the remote operation gateway and the field client.

4. The method of claim 1, wherein, The method further comprises the following steps: receiving a second authorization termination message sent by the server, wherein the second authorization termination message is a termination message sent by the server after the server receives a task execution completion message sent by the operation client; disconnecting the bidirectional connection between the remote operation gateway and the operation client and the bidirectional connection between the remote operation gateway and the field client.

5. A remote operation method characterized by, The method is applied to a server, and the method comprises the following steps: receiving a remote operation request sent by a zero-trust remote operation gateway from a field client, wherein the remote operation request comprises information of an industrial field device, and the information of the industrial field device comprises a device model, a problem type, a problem description, and a device identifier; allocating a remote operation and maintenance task for the industrial field device according to the device model, the problem type, the problem description, and the device identifier in the remote operation and maintenance request, so as to allocate the remote operation and maintenance task to an operation and maintenance personnel who meets an operation and maintenance capability corresponding to the problem; receiving a login verification request sent by an operation and maintenance client; the login verification request is a request sent by the operation and maintenance personnel through the operation and maintenance client; sending an authorization notification message to the zero-trust remote operation and maintenance gateway after the operation and maintenance client passes the login verification; the authorization notification message includes information of the operation and maintenance client, so that the zero-trust remote operation and maintenance gateway verifies a first connection request received from the operation and maintenance client according to the information of the operation and maintenance client, and establishes a bidirectional connection between the operation and maintenance client and the field client, so that the operation and maintenance client and the field client perform bidirectional communication during execution of the remote operation and maintenance task; the first connection request is a single-packet authorization authentication packet; the first connection request includes information of the operation and maintenance client, and the bidirectional connection is a mutual transport layer security bidirectional encryption connection.

6. The method of claim 5, wherein, After the remote operation and maintenance task is allocated for the industrial field device according to the remote operation and maintenance request, the method further includes: sending an operation and maintenance allocation notification message to the field client through the zero-trust remote operation and maintenance gateway to indicate that the remote operation and maintenance task has been allocated for the industrial field device.

7. The method of claim 5, wherein, Before the login verification request sent by the operation and maintenance client is received, the method further includes: receiving a second connection request sent by the operation and maintenance client; after the second connection request passes the verification, establishing a bidirectional connection between the operation and maintenance client.

8. The method of claim 5, wherein, The method further includes: performing state monitoring on the operation and maintenance client; if an abnormal state between the operation and maintenance client is monitored, disconnecting the bidirectional connection between the operation and maintenance client, and sending a first authorization termination message to the zero-trust remote operation and maintenance gateway; so that the zero-trust remote operation and maintenance gateway disconnects the bidirectional connection between the operation and maintenance client and the bidirectional connection between the field client according to the first authorization termination message.

9. The method of claim 5, wherein, The method further includes: receiving a task execution completion message sent by the operation and maintenance client; according to the task execution completion message, disconnecting the bidirectional connection between the operation and maintenance client, and sending a second authorization termination message to the zero-trust remote operation and maintenance gateway; so that the zero-trust remote operation and maintenance gateway disconnects the bidirectional connection between the operation and maintenance client and the bidirectional connection between the field client according to the second authorization termination message.

Citation Information

Patent Citations

  • Remote assistance method, device and system, electronic equipment and storage medium

    CN112463281A

  • Resource access control method based on zero-trust single packet authentication and authorization

    CN114553568A