Cross-network multi-application access method, computer device, and storage medium

The method and system facilitate efficient and secure access to multiple internal network applications using a single tunnel, addressing inefficiencies in existing multi-port access methods by leveraging tunnel configuration and proxy modifications.

CN115632905BActive Publication Date: 2025-07-15HANGZHOU DBAPPSECURITY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211163540.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-23
Publication Date
2025-07-15
Estimated Expiration
2042-09-23

AI Technical Summary

Technical Problem

In the prior art, the need to open multiple ports to achieve access to multiple intranet services leads to low efficiency.

Method used

By establishing a communication tunnel between the cloud server and the cloud client, using tunnel configuration information and format conversion technology, one tunnel can access multiple intranet applications across the network.

Benefits of technology

Improve access efficiency, reduce port exposure, enhance security, and reduce the risk of malicious attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115632905B_ABST
    Figure CN115632905B_ABST
Patent Text Reader

Abstract

The present application relates to a cross-network multi-application access method, a computer device, and a storage medium, which are applied to a cloud server. The cloud server is connected to a cloud client. The method includes: obtaining a user request and tunnel configuration information generated according to the user request; sending the user request and the tunnel configuration information to a server proxy, and obtaining first request information sent by the server proxy; wherein the first request information is obtained by the server proxy modifying the user request according to the tunnel configuration information; obtaining client tunnel configuration information passed in by the cloud client, generating a communication tunnel according to the client tunnel configuration information and the tunnel configuration information, sending the first request information to the cloud client through the communication tunnel, and realizing network access to an intranet application in the cloud client based on the first request information. By using this method, cross-network multi-application access can be efficiently and securely completed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of cross-network communication, and in particular, to a cross-network multi-application access method, a computer device, and a storage medium. Background Art

[0002] With the development of cross-network communication technology, the security of network information is particularly important. It is difficult for the enterprise or unit's own operation and maintenance to meet the need for ensuring information security, and more professional security teams are required to handle the security threats of network information.

[0003] In the existing technology, access to the intranet service is usually achieved by opening different ports through the proxy method. Usually, one port corresponds to one application service in the intranet. When there are multiple services in the intranet, multiple ports need to be opened to access the services, resulting in low efficiency.

[0004] Currently, in response to the problem in the related technology that relying on opening multiple ports to access multiple intranet services leads to low efficiency, no effective solution has been proposed. Summary of the Invention

[0005] Based on this, in view of the above technical problems, it is necessary to provide a cross-network multi-application access method, a computer device, and a storage medium to solve the problem of low efficiency caused by relying on multiple ports to access multiple intranet services in the related problems.

[0006] In a first aspect, the present application provides a cross-network multi-application access method, which is applied to a cloud server. The cloud server is connected to a cloud client. The method includes:

[0007] Obtain a user request and tunnel configuration information generated according to the user request;

[0008] Send the user request and the tunnel configuration information to a server proxy, and obtain first request information sent by the server proxy; wherein, the first request information is obtained by the server proxy modifying the user request according to the tunnel configuration information;

[0009] Obtain client tunnel configuration information passed in by the cloud client, generate a communication tunnel according to the client tunnel configuration information and the tunnel configuration information, send the first request information to the cloud client through the communication tunnel, and implement network access to the intranet application in the cloud client based on the first request information.

[0010] In one of the embodiments, the cross-network multi-application access method further includes:

[0011] Obtain the address configuration information sent by the server proxy; wherein, the address configuration information is obtained by the server proxy from the preset address information and modified and configured through the user request.

[0012] Send the address configuration information to the cloud client through the communication tunnel, so that the cloud client can instruct the intranet application to display the corresponding jump page based on the address configuration information.

[0013] In one embodiment, after sending the user request and the tunnel configuration information to the server proxy, the above method further includes:

[0014] Determine the server format corresponding to the server proxy, convert the format of the tunnel configuration information based on the server format to generate server format information, and send the server format information to the server proxy.

[0015] Obtain the second request information sent by the server proxy, wherein the second request information is obtained by the server proxy by modifying the user request according to the server format information.

[0016] Send the second request information to the cloud client through the communication tunnel, and realize network access to the intranet application in the cloud client based on the second request information.

[0017] In one embodiment, the cloud server is further connected to a configuration module, the configuration module is connected to an API service module, and the API service module is connected to the user side through the development interface provided by the API service module. Obtaining the tunnel configuration information generated according to the user request includes:

[0018] Obtain the tunnel configuration information obtained and stored by the configuration module from the API service module; wherein, the tunnel configuration information is obtained by the API service module from the user side through the development interface according to the user request.

[0019] In one embodiment, the first request information at least includes the intranet application name. Realizing network access to the intranet application in the cloud client based on the first request information includes:

[0020] Judge the target intranet application accessed by the user side through the intranet application name, and realize access to the target intranet application through the first request information.

[0021] In one embodiment, the cross-network multi-application access method is applied to the cloud client. The cloud client is respectively connected to the cloud server and the client proxy, and the cloud server is connected to the server proxy. The cross-network multi-application access method further includes:

[0022] Obtain the tunnel configuration information generated according to the user request, generate the client tunnel configuration information based on the tunnel configuration information, and send the client tunnel configuration information to the cloud server so that the cloud server can generate a communication tunnel;

[0023] Obtain the first request information obtained by the cloud server from the server proxy through the communication tunnel, where the first request information is obtained by the server proxy modifying the user request according to the tunnel configuration information;

[0024] Send the first request information to the client proxy, where the client proxy processes and converts the first request information to obtain the application request information, sends the application request information to the intranet application, and realizes network access to the intranet application based on the application request information.

[0025] In one embodiment, after sending the request information to the client proxy, where the client proxy processes and converts the first request information to obtain the application request information, the method further includes:

[0026] Determine the client format required by the client proxy, convert the format of the tunnel configuration information based on the client format to generate the client format information, and send the client format information to the client proxy;

[0027] Send the application request information to the intranet application, where the application request information is obtained by the client proxy modifying the request information according to the client format information;

[0028] Send the application request information to the intranet application and realize access to the intranet application based on the application request information.

[0029] In a second aspect, the present application also provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0030] Obtain the user request and the tunnel configuration information generated according to the user request;

[0031] Send the user request and the tunnel configuration information to the server proxy and obtain the first request information sent by the server proxy; where the first request information is obtained by the server proxy modifying the user request according to the tunnel configuration information;

[0032] Obtain the client tunnel configuration information passed in by the cloud client, generate a communication tunnel according to the client tunnel configuration information and the tunnel configuration information, send the first request information to the cloud client through the communication tunnel, and realize network access to the intranet application in the cloud client based on the first request information.

[0033] In a third aspect, the present application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, and when the computer program is executed by a processor, the following steps are implemented:

[0034] Obtain a user request and tunnel configuration information generated according to the user request;

[0035] Send the user request and the tunnel configuration information to a server proxy, and obtain first request information sent by the server proxy; wherein, the first request information is obtained by the server proxy modifying the user request according to the tunnel configuration information;

[0036] Obtain client tunnel configuration information passed in by a cloud client, generate a communication tunnel according to the client tunnel configuration information and the tunnel configuration information, send the first request information to the cloud client through the communication tunnel, and implement network access to an intranet application in the cloud client based on the first request information.

[0037] Compared with the related art, the cross-network multi-application access method provided by the embodiments of the present application realizes cross-network access to multiple applications through one tunnel by establishing a communication tunnel, solves the problem of low efficiency caused by the need to open multiple ports to access services in the traditional technology in the face of multiple intranet service scenarios, and realizes efficient and secure access to multiple intranet applications through one tunnel.

[0038] Details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more concise and understandable. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 It is a schematic flowchart of a cross-network multi-application access method in an embodiment;

[0040] Figure 2 It is an architecture diagram of a cross-network multi-application access method in a preferred embodiment;

[0041] Figure 3 It is a structural block diagram of a cross-network multi-application access device in an embodiment;

[0042] Figure 4 It is an internal structure diagram of a cross-network multi-application access device in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0043] In order to make the objectives, technical solutions, and advantages of the present application clearer and more understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0044] In one embodiment, a method for cross-network multi-application access is provided, which is applied to a cloud server, and the cloud server is connected to a cloud client; Figure 1 It is a flowchart of the cross-network multi-application access method according to an embodiment of the present application, as Figure 1 shown, this process includes the following steps:

[0045] Step S110, obtain a user request and tunnel configuration information generated according to the user request.

[0046] Specifically, the communication tunnel in the present application is a one-to-many tunnel, and multiple services in the intranet can access through one tunnel. After obtaining the tunnel configuration information, it can be saved to the configuration module through the API service module. In addition to the tunnel configuration information, other functional logic information is also saved in the configuration module.

[0047] Step S120, send the user request and the tunnel configuration information to the server proxy, and obtain the first request information sent by the server proxy; wherein, the first request information is obtained by the server proxy modifying the user request according to the tunnel configuration information.

[0048] Specifically, the cloud server will pull the data saved in the configuration module, convert the format of the tunnel configuration information. For example, a json file can be generated according to the tunnel configuration information, and then the server proxy modifies the user request based on this json file to generate the first request information. In some cases, the server proxy modifies the request header and response header in the user request according to the host information in the tunnel configuration information to implement the modification of the user request.

[0049] Step S130, obtain the client tunnel configuration information passed in by the cloud client, generate a communication tunnel according to the client tunnel configuration information and the tunnel configuration information, send the first request information to the cloud client through the communication tunnel, and implement network access to the intranet application in the cloud client based on the first request information.

[0050] Specifically, the cloud client generates the client tunnel configuration information by obtaining the tunnel configuration information in the configuration module and sends it to the cloud server. The cloud server generates a communication tunnel through the client tunnel configuration information and the tunnel configuration information obtained from the configuration center. That is, the configuration module connects the cloud server and the cloud client. Specifically, the cloud server mainly reads and writes the data in the configuration module, while the cloud client mainly reads the data in the configuration module. Through the communication tunnel jointly generated by the cloud server and the cloud client, the first request information is transmitted to the cloud client, and the target intranet application corresponding to the user request is judged based on different intranet application names in the first request information, so as to realize network access to the target intranet application.

[0051] Through the above steps S110 to S130, first, a user request is obtained, and tunnel configuration information is generated according to the user request; then, the user request and the tunnel configuration information are sent to the server proxy. Among them, the server proxy first converts the format of the tunnel configuration information. For example, the tunnel configuration information can be converted into a json file, and then the server proxy modifies the user request according to the tunnel configuration information after format conversion to generate the first request information; finally, the client tunnel configuration information passed in by the cloud client is obtained, and the cloud server generates a communication tunnel according to the client tunnel configuration information and the tunnel configuration information obtained from the configuration module. The cloud server sends the first request information to the cloud client through the communication tunnel, realizing network access to the intranet applications in the cloud client based on the master of ceremonies request information. It can be seen that, on the one hand, different from the traditional method, the present application can realize accessing multiple applications across network segments through one communication tunnel, reducing the cost and time required to establish multiple ports and communication tunnels, efficiently completing the access to multiple applications across network segments, and since only one communication tunnel needs to be established, the exposure surface is reduced, making the cross-network segment access more secure and controllable; on the other hand, since the cloud server and the user are connected through the server proxy, and the cloud server obtains the user request through the server proxy, it can be seen that the user does not directly connect to the cloud server, realizing the protection of the cloud server from malicious attacks.

[0052] In this embodiment, the cross-network multi-application access method further includes:

[0053] Obtain the address configuration information sent by the server proxy; wherein, the address configuration information is generated by the server proxy obtaining preset address information and modifying and configuring the preset address information through the user request;

[0054] Send the address configuration information to the cloud client through the communication tunnel so that the cloud client can indicate the intranet application to display the corresponding jump page based on the address configuration information.

[0055] Specifically, the server proxy modifies the request information sent by the user according to the tunnel configuration information. In practical applications, a common operation is to first convert the tunnel configuration information into a JSON file, and then the server proxy obtains the host information by reading the JSON file to modify the request header information in the user request. It should be noted that in practical applications, the 302 redirection problem often occurs, that is, the access target path is temporarily changed, redirecting the user request and causing the request to be interrupted. At this time, the server proxy module can also modify the preset address information according to the user request, including changing the response header information, to generate address configuration information, and access the intranet application according to the address configuration information. It can be seen that modifying the preset address information according to the user request avoids the interruption of the user access request caused by the 302 redirection problem, and can solve the common 302 redirection problem without manual intervention, improving the efficiency of cross-network multi-application access.

[0056] In some embodiments, after sending the user request and the tunnel configuration information to the server proxy, the method of the present application further includes: determining the server format corresponding to the server proxy, converting the format of the tunnel configuration information based on the server format to generate server format information, and sending the server format information to the server proxy; obtaining the second request information sent by the server proxy, where the second request information is obtained by the server proxy modifying the user request according to the server format information; sending the second request information to the cloud client through the communication tunnel, and implementing network access to the intranet application in the cloud client based on the second request information.

[0057] Specifically, before the server proxy reads the tunnel configuration information, the tunnel configuration information can be first converted in format. In practical applications, it is common to convert the tunnel configuration information into a JSON file to generate server format information, and then send the server format information to the server proxy. The server proxy modifies the user request according to the server format information to obtain the second request information, and sends the second request information to the cloud client through the communication tunnel, realizing the access to the intranet application in the cloud client based on the second request information. Among them, the second request information is obtained by converting the tunnel configuration information into server format information and then modifying the user request through the server format information; the first request information in the above text is obtained by the server proxy modifying the user request according to the tunnel configuration information. Converting the format of the tunnel configuration information and then performing subsequent operations is beneficial for the present application to adapt to various different environmental conditions in practical applications, improving the efficiency of cross-network multi-application access and reducing the risk of errors.

[0058] In some embodiments, the cloud server is further connected to a configuration module, the configuration module is connected to an API service module, and the API service module is connected to the user side through a development interface provided by the API service module to obtain tunnel configuration information generated according to a user request, including: obtaining the tunnel configuration information obtained and stored by the configuration module from the API service module; wherein, the tunnel configuration information is obtained by the API service module from the user side through the development interface according to the user request and generated according to the user request.

[0059] Specifically, the data stored in the configuration module includes tunnel configuration information and other functional logic information. Storing the data generated according to the user request in the configuration module facilitates the invocation of the data in subsequent operations. In practical applications, the configuration module can use the etcd (distributed etc directory, i.e., distributed configuration file directory) configuration center, which is connected to the user side and the configuration module through the development interface provided by the API service module, facilitating the generation of relevant configuration information according to the user request and improving the efficiency of the cross-network multi-application access method of the present application in practical applications.

[0060] In some embodiments, at least the intranet application name is included in the above first request information. Implementing network access to the intranet application in the cloud client based on the first request information includes: determining the target intranet application accessed by the user side through the intranet application name, and implementing access to the target intranet application through the first request information.

[0061] Specifically, the cross-network multi-application access method of the present application can complete the access to multiple applications in the intranet through a one-to-many communication tunnel. When determining the target intranet application that the user side needs to access, it is usually determined by the intranet user name carried in the first request information. Since only one communication tunnel needs to be established to achieve the access to multiple intranet applications, the time and cost required to establish multiple communication tunnels are reduced. Moreover, since only one communication tunnel is used, the exposure surface is reduced, and the risk of being maliciously attacked is reduced, making the entire cross-network access process more secure and controllable.

[0062] In some embodiments, the cross-network multi-application access method is also applied to a cloud client. The cloud client is respectively connected to a cloud server and a client proxy, and the cloud server is connected to a server proxy. The method further includes: obtaining tunnel configuration information generated according to a user request, generating client tunnel configuration information according to the tunnel configuration information, and sending the client tunnel configuration information to the cloud server so that the cloud server generates a communication tunnel; obtaining, through the communication tunnel, first request information obtained by the cloud server from the server proxy, where the first request information is obtained by the server proxy modifying the user request according to the tunnel configuration information; sending the first request information to the client proxy, where the client proxy performs conversion processing on the first request information to obtain application request information, sends the application request information to an intranet application, and realizes network access to the intranet application based on the application request information.

[0063] Specifically, the cloud client can be used to monitor the data change situation in the configuration module in real time, obtain the tunnel configuration information from the configuration module, generate client tunnel configuration information according to the tunnel configuration information, and send the client tunnel configuration information to the cloud server so that the cloud server generates a communication tunnel. In practical applications, both the cloud server and the cloud client can be connected to the configuration module. The cloud server is mainly used for reading and writing data, while the cloud client is mainly for reading data and writing less. Therefore, the communication tunnel is established through the joint action of the cloud server and the cloud client. Then, the first request information of the cloud server is obtained through the communication tunnel, and then the cloud client sends the first request information to the client proxy. The client proxy performs conversion processing on the first request information to obtain application request information, and sends the application request information to the intranet application, realizing access to the intranet application based on the application request information.

[0064] It can be seen from this that the communication tunnel jointly established by the cloud client and the cloud server is more secure and reliable. Both the cloud server and the cloud client can monitor the data change situation in the configuration module in real time. The cloud server generates relevant tunnel configuration information according to the information in the configuration center for the server proxy to use. Similarly, the cloud client generates relevant tunnel configuration information according to the information in the configuration center for the client proxy to use. Connecting the user side and the cloud server through the server proxy, and connecting the intranet application and the cloud client through the client proxy both avoid directly connecting the site to the user or the source site, and achieve the purpose of protecting the source site by setting up the user-side proxy and the client proxy.

[0065] In some embodiments, the first request information is sent to the client proxy. After the client proxy processes and converts the first request information to obtain application request information, the cross-network multi-application access method of the present application further includes: determining the client format required by the client proxy, converting the format of the tunnel configuration information based on the client format to generate client format information, and sending the client format information to the client proxy; sending the application request information to the intranet application, where the application request information is obtained by the client proxy modifying the first request information according to the client format information; sending the application request information to the intranet application and implementing access to the intranet application based on the application request information.

[0066] Specifically, the client proxy mainly processes requests from cloud clients. In actual applications, the cloud client usually converts the format of the tunnel configuration information based on the client format by generating a json file according to the tunnel configuration information for use by the client proxy. The client proxy modifies the first request information according to the client format information to obtain application request information, and then sends the application request information to the intranet application to implement access to the intranet application based on the application request information. Specifically, in actual operations, the client format information generated by the cloud client can be used to convert the intranet application name information in the first request information into information about the corresponding actual intranet application, including ip and port information, to achieve access to different intranet applications.

[0067] This embodiment also provides a specific embodiment of the cross-network multi-application access method, as Figure 2 shown, Figure 2 is an architecture diagram of the cross-network multi-application access method in a preferred embodiment.

[0068] From Figure 2As can be seen, the user side, the server proxy, the cloud user side, and the configuration module belong to Network 1, and the cloud client, the client proxy, and the intranet application belong to Network 2. When the user side in Network 1 wants to access the intranet application in Network 2, it first sends the user request to the server proxy, and obtains the tunnel configuration information according to the user request through the development interface provided by the API service module, and saves the tunnel configuration information to the configuration module. The configuration module can use the etcd configuration center. The data information saved in the configuration module includes tunnel configuration information, functional logic information, and some key.value values. Then the cloud server converts the format of the tunnel configuration information to generate server-side format information, and sends the server-side format information to the server proxy. The server proxy modifies the user request according to the server-side format information to generate a second request message. Usually, the tunnel configuration information is converted into a json file, and the json file is sent to the server proxy. The service single proxy obtains the host information according to the json file and modifies the user request, including modifying the request header information in the user request, to generate a second request message. In some embodiments, modifying the user request further includes modifying the response header information, modifying the preset address information according to the user request to obtain address configuration information, and solving the 302 redirection problem that often occurs in practical applications. Then the cloud server obtains the tunnel configuration information from the configuration module and the client tunnel configuration information passed in from the cloud client to generate a communication tunnel, and sends the second request message to the cloud client through the communication tunnel. The cloud client can monitor the information in the configuration module in real time, generate client tunnel configuration information through the tunnel configuration information in the configuration module, and send it to the cloud server for the cloud server to generate a communication tunnel. At the same time, the cloud client also generates relevant client-side format information according to the tunnel configuration information obtained from the configuration module for the client proxy to use. The client-side format information is usually a json file generated according to the tunnel configuration information. The cloud client obtains the second request message through the communication tunnel and sends the second request message to the client proxy. Then the client proxy converts and processes the second request message according to the client-side format information to obtain an application request message. In practical applications, usually according to the json file generated by the client proxy, the information such as the intranet application name in the second request message is converted into the corresponding ip and port of the intranet application, etc., to realize cross-network access from the user side in Network 1 to the intranet application in Network 2.

[0069] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this document, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0070] Based on the same inventive concept, an embodiment of the present application further provides a cross-network multi-application access device for implementing the above-mentioned cross-network multi-application access method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the cross-network multi-application access device provided below can refer to the limitations on the cross-network multi-application access method in the above text, and will not be repeated here.

[0071] In one embodiment, as Figure 3 shown, it is a structural block diagram of a cross-network multi-application access device. A cross-network multi-application access device is provided, including: a server proxy module 31, a cloud server module 32, a cloud client module 33, and a client proxy module 34, where:

[0072] The server proxy module 31 is used to process user requests, generate first request information, and send the first request information to the cloud server module 32.

[0073] The cloud server module 32 is used to receive the connection request of the cloud client module 33, obtain the client tunnel configuration information and the tunnel configuration information to generate a communication tunnel, and send the user request to the cloud client module 33.

[0074] The cloud client module 33 is used to determine the client format required by the client proxy module 34, convert the tunnel configuration information based on this client format to generate client format information, and send the client format information to the client proxy module 34.

[0075] The client proxy module 34 is used to perform conversion processing on the first request information to obtain application request information, and send the application request information to the intranet application to implement access to the intranet application based on the application request information.

[0076] Specifically, the user request and tunnel configuration information are saved to the configuration module through the API service module. The cloud server module 32 obtains the tunnel configuration information, determines the server format required by the server proxy module 31, converts the tunnel configuration information based on this server format to generate server format information, and sends the server format information to the server proxy module 31. The server proxy module 31 obtains the server format information and the user request, modifies the user request according to the server format information to generate the first request information, and sends the first request information to the cloud server module 32; the cloud server module 32 receives the first request information and the client tunnel configuration information, and the cloud server module 32 generates a communication tunnel based on the client tunnel configuration information and the tunnel configuration information, and sends the first request information to the cloud client module 33 through this communication tunnel; the cloud client module 33 monitors the information in the configuration module in real time, generates the above-mentioned client tunnel configuration information based on the tunnel configuration information in the configuration module to facilitate the cloud server module 32 to generate a communication tunnel. Moreover, the cloud client module 33 determines the client format required by the client proxy module 34, converts the tunnel configuration information based on this client format to generate client format information, and sends the client format information and the first request information to the client proxy module 34. The client proxy module 34 obtains the above-mentioned client format information and the first request information, modifies the first request information based on the client format information to generate an application request information, and sends the application request information to the intranet application, realizing the access to the intranet application based on this application request information.

[0077] Through the above cross-network multi-application access device, on the one hand, not only can efficient cross-network application access be carried out, but also the access to multiple intranet applications can be completed based on one communication tunnel, saving a large amount of time and cost required for establishing multiple communication tunnels; on the other hand, since only one communication tunnel needs to be established to complete the access to multiple intranet applications, the exposure surface of the tunnel port is reduced, the risk is lowered, and the entire cross-network access process is made more secure and controllable.

[0078] Each module in the above cross-network multi-application access device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the computer device in hardware form or be independent of it, or can be stored in the memory in the computer device in software form so that the processor can call and execute the operations corresponding to the above modules.

[0079] In one embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as Figure 4As shown in the figure. The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it realizes an interface information synchronization method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0080] Those skilled in the art can understand that Figure 4 the structure shown in the figure is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0081] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following steps are implemented:

[0082] The cloud server obtains a user request and tunnel configuration information generated according to the user request;

[0083] Send the user request and the tunnel configuration information to the server proxy, and obtain the first request information sent by the server proxy; among them, the first request information is obtained by the server proxy modifying the user request according to the tunnel configuration information;

[0084] The cloud server obtains the client tunnel configuration information passed in by the cloud client, generates a communication tunnel according to the client tunnel configuration information and the tunnel configuration information, sends the first request information to the cloud client through the communication tunnel, and realizes network access to the intranet application in the cloud client based on the first request information.

[0085] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the following steps are implemented:

[0086] The cloud server obtains a user request and tunnel configuration information generated according to the user request;

[0087] Send the user request and tunnel configuration information to the server proxy, and obtain the first request information sent by the server proxy; wherein, the first request information is obtained by the server proxy modifying the user request according to the tunnel configuration information.

[0088] The cloud server obtains the client tunnel configuration information passed in by the cloud client, generates a communication tunnel according to the client tunnel configuration information and the tunnel configuration information, sends the first request information to the cloud client through the communication tunnel, and realizes network access to the intranet application in the cloud client based on the first request information.

[0089] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0090] Those skilled in the art should understand that the technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0091] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0092] The above-described embodiments merely represent several implementation manners of this application, and the description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of this application. It should be pointed out that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application should be subject to the appended claims.

Claims

1. A cross-network multi-application access method, characterized in that Applied to a cloud server, the cloud server is connected to a cloud client, and the method includes: Obtain a user request and tunnel configuration information generated according to the user request; Send the user request and the tunnel configuration information to a server proxy, and obtain first request information sent by the server proxy; wherein, the first request information is obtained by the server proxy modifying the user request according to the tunnel configuration information; Obtain client tunnel configuration information incoming from the cloud client, generate a communication tunnel according to the client tunnel configuration information and the tunnel configuration information, send the first request information to the cloud client through the communication tunnel, and implement network access to an intranet application in the cloud client based on the first request information. Among them, the client proxy converts the intranet application name information in the first request information into corresponding real intranet application information to achieve access to different intranet applications, and the client proxy is connected to the cloud client.

2. The method according to claim 1, characterized in that, The method further includes: Obtain address configuration information sent by the server proxy; wherein, the address configuration information is generated by the server proxy obtaining preset address information and modifying and configuring the preset address information through the user request; Send the address configuration information to the cloud client through the communication tunnel, so that the cloud client instructs the intranet application to display a corresponding jump page based on the address configuration information.

3. The cross-network multi-application access method according to claim 1, wherein After sending the user request and the tunnel configuration information to the server proxy, the method further includes: Determine the server format corresponding to the server proxy, convert the format of the tunnel configuration information based on the server format to generate server format information, and send the server format information to the server proxy; Obtain second request information sent by the server proxy, wherein the second request information is obtained by the server proxy modifying the user request according to the server format information; Send the second request information to the cloud client through the communication tunnel, and implement network access to an intranet application in the cloud client based on the second request information.

4. The cross-network multi-application access method according to claim 1, characterized in that The cloud server is further connected to a configuration module, the configuration module is connected to an API service module, and the API service module is connected to a user side through a development interface provided by the API service module; Obtaining the tunnel configuration information generated according to the user request includes: Obtain the tunnel configuration information obtained and stored by the configuration module from the API service module; wherein, the tunnel configuration information is generated by the API service module obtaining the user request from the user side through the development interface and generating it according to the user request.

5. The cross-network multi-application access method according to claim 1, wherein At least the intranet application name is included in the first request information, and implementing network access to an intranet application in the cloud client based on the first request information includes: Judge the target intranet application accessed by the user side through the intranet application name, and achieve access to the target intranet application through the first request information.

6. A cross-network multi-application access method, characterized in that Applied to a cloud client, the cloud client is respectively connected to a cloud server and a client proxy, and the cloud server is connected to a server proxy. The method includes: Obtain tunnel configuration information generated according to a user request, generate client tunnel configuration information based on the tunnel configuration information, and send the client tunnel configuration information to the cloud server so that the cloud server generates a communication tunnel; Obtain, through the communication tunnel, first request information obtained by the cloud server from the server proxy, where the first request information is obtained by the server proxy modifying the user request according to the tunnel configuration information; Send the first request information to the client proxy, where the client proxy performs conversion processing on the first request information to obtain application request information, sends the application request information to an intranet application, and realizes network access to the intranet application based on the application request information. Specifically, the client proxy converts the intranet application name information in the first request information into corresponding real intranet application information to realize access to different intranet applications.

7. The cross-network multi-application access method according to claim 6, characterized in that, After sending the first request information to the client proxy, where the client proxy performs conversion processing on the first request information to obtain application request information, the method further includes: Determine the client format required by the client proxy, perform format conversion on the tunnel configuration information based on the client format to generate client format information, and send the client format information to the client proxy; Send the application request information to the intranet application, where the application request information is obtained by the client proxy modifying the request information according to the client format information; Send the application request information to the intranet application and realize access to the intranet application based on the application request information.

8. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Data communication method and device and electronic equipment

    CN111464609A

  • Access method, access system, computer equipment and storage medium

    CN114598498A