A method and apparatus for establishing communication, and an electronic device

By comparing and updating communication security parameters in real time in the control center of the data communication end, the problem that the RSSP-I protocol cannot support multiple backup devices is solved, and seamless switching and secure communication of the main and backup data center is realized.

CN116016135BActive Publication Date: 2025-07-08QINGDAO JIADU WEILIAN SIGNALING SYSTEM CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211691608.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-27
Publication Date
2025-07-08
Estimated Expiration
2042-12-27

AI Technical Summary

Technical Problem

The existing RSSP-I protocol only supports a redundant structure of one central dual system, and cannot achieve secure communication between the standby data center and the main data center for shared RSSP-I link, and cannot achieve seamless switching to the standby data center when the main data center fails.

Method used

By comparing the communication security parameters of the main system equipment and other devices in real time in the control center of the data communication terminal, and updating the parameters of the backup device using the security parameters of the main system equipment to ensure that the backup device can seamlessly switch to the main device for communication when the main device fails.

Benefits of technology

The security data channel status of the main and standby data center equipment and the communication counterpart is maintained, ensuring seamless switching when the main equipment fails, and ensuring the security and continuity of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116016135B_ABST
    Figure CN116016135B_ABST
Patent Text Reader

Abstract

The present application discloses a method and apparatus for establishing communication, and an electronic device. The method includes: determining a first device for current data transmission as the primary master device, and respectively establishing secure data channels for each second device except the first device to communicate with the primary master device of the data communication peer; comparing in real time the communication security parameters respectively stored in the primary master device and the second devices; when the comparison results are inconsistent, updating the communication security parameters of the second devices with the communication security parameters of the primary master device; when the first device fails, selecting one of the second devices as the primary master device, so that the selected second device communicates with the primary master device of the data communication peer through the secure data channel where it is located based on the communication security parameters. This solves the problem that the existing RSSP-I protocol itself does not support multiple standby devices.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] The existing RSSP-I protocol only supports a redundant structure of one central dual system (one primary system and one standby system). For a system where one end of the communication simultaneously includes a primary data center and a standby data center (such as ATS), it is impossible to make the standby data center and the primary data center share RSSP-I for connection. When communicating securely with the communication peer device, in the system composed of the primary data center and the standby data center, the standby data center cannot achieve a real-time hot standby state, that is, when the primary system of the primary data center fails, the standby system of the primary data center and the primary system or the standby system of the standby data center cannot immediately switch to the primary system of the primary data center to communicate with the communication peer. Summary of the Invention

[0003] The purpose of this application is to provide a method and device for establishing communication, and an electronic device. It is used to solve the problem that in the existing situation, it is impossible to make the standby center and the primary center share the RSSP-I link, and when communicating securely with the communication peer device, the standby center cannot maintain the state of the secure data channel, and the primary and standby centers cannot achieve seamless switching.

[0004] In a first aspect, an embodiment of this application provides a method for establishing communication, which is applied to a control center at the data communication end. The control center includes two data centers, and each data center includes two devices. The method includes:

[0005] Determine that the first device for current data transmission is the primary primary system device, and respectively establish secure data channels for each second device except the first device to communicate with the primary primary system device of the data communication peer;

[0006] Compare in real time the communication security parameters stored respectively in the primary primary system device and the second device. The communication security parameters include the communication security parameters of the local end and the primary primary system device of the data communication peer;

[0007] When the comparison result is inconsistent, update the communication security parameters of the second device with the communication security parameters of the primary primary system device;

[0008] When the first device fails, select one of the second devices as the primary primary system device, so that the selected second device communicates with the primary primary system device of the data communication peer through the secure data channel where it is located based on the communication security parameters.

[0009] In some possible embodiments, respectively establishing secure data channels for each second device except the first device to communicate with the primary primary system device of the data communication peer includes:

[0010] For any second device in the standby data center, the second device receives the RSD data packet sent by the data communication peer, and the standby data center is a data center that does not include the primary main device;

[0011] Determine the primary main device of the data communication peer according to the RSD data packet, send an SSE data packet for security verification to the primary main device of the data communication peer through the second device, and receive the SSR data packet sent by the primary main device of the data communication peer to establish a secure data channel with the primary main device of the data communication peer.

[0012] In some possible embodiments, the communication security parameters of the primary main device are of the same parameter type as those of the other devices; updating the communication security parameters of the second device by using the communication security parameters of the primary main device includes:

[0013] Update the second communication security parameter of the second device, which is of the same type as the first communication security parameter, by using the first communication security parameter of the primary main device.

[0014] In some possible embodiments, the parameter type includes a serial number and a timestamp.

[0015] In some possible embodiments, the RSD data packet includes a protocol interaction type and a message type;

[0016] The protocol interaction type includes primary main and non-primary main;

[0017] The message type is the device that sends the RSD.

[0018] In some possible embodiments, the primary main device of the data communication peer is determined according to the RSD data packet in the following manner:

[0019] Parse the RSD data packet and determine the primary main from the protocol interaction type;

[0020] Determine the device that is the primary main of the data communication peer from the message type.

[0021] In a second aspect, an embodiment of the present application provides a device for establishing communication. The device serves as the control center of the data communication end. The data communication end includes two data centers respectively connected to the control. Each data center includes two communication devices. The device includes:

[0022] A secure data channel establishment module, configured to determine that the first device for the current data transmission is the primary main device, and respectively establish secure data channels for each second device except the first device to communicate with the primary main device of the data communication peer;

[0023] A comparison module for comparing in real time the communication security parameters respectively stored in the primary master device and the second device, where the communication security parameters include the security parameters of the primary master device at the local end and the data communication peer end;

[0024] An update module for, when the comparison result is inconsistent, updating the communication security parameters of the second device by using the communication security parameters of the primary master device;

[0025] A determination module for, when the first device fails, selecting a second device as the primary master device, so that the selected second device communicates with the primary master device of the data communication peer end through the local security data channel based on the communication security parameters.

[0026] In a third aspect, an embodiment of the present application provides an electronic device, including at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method for establishing communication provided in the first aspect above.

[0027] In a fourth aspect, an embodiment of the present application provides a computer storage medium, where the computer storage medium stores a computer program, and the computer program is used to cause a computer to execute the method for establishing communication provided in the first aspect above.

[0028] The embodiment of the present application solves the problem that the RSSP-I protocol itself does not support multiple standby devices. After expanding the device type, it not only ensures the secure communication of the dual-system devices in the primary and standby data centers, but also maintains the state of the secure data channel between the standby data center devices of both communication parties and the primary master device of the communication peer end. On the basis of ensuring the correct synchronization of communication security parameters, seamless system switching can be achieved.

[0029] Other features and advantages of the present application will be described in the following specification, and, in part, will be obvious from the specification, or will be understood by implementing the present application. The objectives and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written specification, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] To more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required to be used in the embodiments of the present application. Obviously, the following introduced drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to these drawings.

[0031] Figure 1Schematic diagram of an application environment according to an embodiment of the present application;

[0032] Figure 2 Flow schematic diagram of a method for establishing communication according to an embodiment of the present application;

[0033] Figure 3 Partial flow schematic diagram during the establishment of communication according to an embodiment of the present application;

[0034] Figure 4 Flow schematic diagram of establishing a secure data channel according to an embodiment of the present application;

[0035] Figure 5 Detailed flow schematic diagram of establishing a secure data channel according to an embodiment of the present application;

[0036] Figure 6 Definition diagram of the RSD message format of the prior art according to an embodiment of the present application;

[0037] Figure 7 Definition diagram of the RSD message format according to an embodiment of the present application;

[0038] Figure 8 Flow schematic diagram of a method for determining the primary master device of the data communication peer according to an embodiment of the present application;

[0039] Figure 9 Another flow schematic diagram of establishing a secure data channel according to an embodiment of the present application;

[0040] Figure 10 Communication schematic diagram of establishing communication according to an embodiment of the present application;

[0041] Figure 11 Data flow schematic diagram of synchronizing data according to an embodiment of the present application;

[0042] Figure 12 Another partial flow schematic diagram during the establishment of communication according to an embodiment of the present application;

[0043] Figure 13 Overall flow schematic diagram of the method for establishing communication according to an embodiment of the present application;

[0044] Figure 14 Structural schematic diagram of a temperature decision device according to an embodiment of the present application;

[0045] Figure 15 Structural schematic diagram of an electronic device according to an embodiment of the present application. Detailed implementation mode

[0046] The technical solutions in the embodiments of the present application will be clearly and elaborately described below with reference to the accompanying drawings. In the description of the embodiments of the present application, unless otherwise specified, " / " means "or". For example, A / B may mean A or B. The "and / or" in the text is only a relationship description of associated objects, indicating that there can be three relationships. For example, A and / or B may mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of the present application, "a plurality of" means two or more than two.

[0047] In the description of the embodiments of the present application, unless otherwise specified, the term "a plurality of" means two or more than two. Similar understanding should be given to other quantifiers. The preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application. And without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other.

[0048] To further illustrate the technical solutions provided by the embodiments of the present application, the following will be described in detail with reference to the accompanying drawings and specific implementation manners. Although the embodiments of the present application provide method operation steps as shown in the following embodiments or drawings, more or fewer operation steps may be included in the method based on routine or non-creative labor. In steps where there is no necessary causal relationship logically, the execution order of these steps is not limited to the execution order provided by the embodiments of the present application. When the method is actually processed or executed by the control device, it can be executed in the method order shown in the embodiments or drawings or executed in parallel.

[0049] In view of the problem that in the related art, when the main system of the primary data center fails, the standby system of the primary data center and the main system of the standby data center or the standby system of the standby data center cannot immediately be converted into the main system of the primary data center to communicate with the communication peer. The present application proposes a method and device for establishing communication, an electronic device, which solves the problem that the RSSP-I protocol itself does not support multiple standby devices. After expanding the device type, it not only ensures the secure communication of the dual-system devices in the primary and standby data centers, but also can maintain the secure data channel state between the standby data center devices of both communication parties and the main system device of the communication peer. On the basis of ensuring the correct synchronization of communication security parameters, seamless system switching can be achieved.

[0050] Other features and advantages of the present application will be described in the subsequent specification, and, in part, will be obvious from the specification, or will be understood by implementing the present application. The objectives and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written specification, claims, and drawings.

[0051] The following will describe in detail the method for establishing communication in the embodiments of the present application with reference to the accompanying drawings.

[0052] See Figure 1 , which is a schematic diagram of an application environment according to an embodiment of the present application.

[0053] As Figure 1 shown, in this application environment, it includes: Machine A and Machine B are the dual systems (main system and standby system) of Data Center 1, and Machine C and Machine D are the dual systems (main system and standby system) of Data Center 2. For the two data centers, one is the primary data center and the other is the standby data center. For the dual systems of each data center, one is the main system and the other is the standby system. When the system (i.e., the control center at the data communication end) is working properly, only the data of the main system device in the primary data center needs to pass through the security layer verification. The standby system device in the primary data center, the main system device in the standby data center, and the standby system device in the standby data center are all in the hot standby state and do not require security layer verification, but need to keep synchronized with the main system device in the primary data center. For the RSSP-I protocol layer, it is a state of one main and three backups.

[0054] Figure 2 shows a schematic flow diagram of a method for establishing communication provided by an embodiment of the present application, including:

[0055] Step 201: Determine that the first device for the current data transmission is the main system device of the primary data center, and respectively establish secure data channels for each second device except the first device to communicate with the main system device of the data communication peer.

[0056] Specifically, see Figure 3 , Step 301: Determine that the first device for the current data transmission is the main system device of the primary data center; Step 302: Respectively establish secure data channels for each second device except the first device to communicate with the main system device of the data communication peer.

[0057] First, define the data center where the devices of both communication parties are located as the primary data center, and define the devices of the sender and receiver of both communication parties as the main system devices of the primary data center, that is, the main system device of the primary data center. Then, since each control center has a standby system device in the primary data center, a main system device in the standby data center, and a standby system device in the standby data center in addition to the main system device of the primary data center. Therefore, respectively establish secure data channels for the standby system device in the primary data center to communicate with the main system device of the data communication peer, the main system device in the standby data center to communicate with the main system device of the data communication peer, and the standby system device in the standby data center to communicate with the main system device of the data communication peer. To ensure that when the first device fails, other devices in this control center except the first device can promptly replace the first device as the main system device to communicate with the main system device of the communication peer. It should be noted that any one of the four devices in each control center in the present application may become the main system device of the primary data center. Therefore, in the present application, the device currently serving as the main system device of the primary data center is defined as the first device;

[0058] It should be noted that there is a physical channel between any device on this side and any device on the communication peer side. That is, there is a physical channel not only between any device on this side and the primary master device on the communication peer side, but also the physical channel connection between any device on this side and the non-primary master device on the communication peer side always exists. The secure data channel in this application can be used for communication after the secure verification is completed with the primary master device on the communication peer side.

[0059] As an alternative implementation, refer to Figure 4 Establish secure data channels for each second device except the first device to communicate with the primary master device of the data communication peer, including:

[0060] Step 401: For any second device in the standby data center, the second device receives the RSD data packet sent by the data communication peer. The standby data center is a data center that does not include the primary master device;

[0061] Step 402: Determine the primary master device of the data communication peer according to the RSD data packet, send the SSE data packet for secure verification to the primary master device of the data communication peer through the second device, and receive the SSR data packet sent by the primary master device of the data communication peer to establish a secure data channel with the primary master device of the data communication peer.

[0062] Specifically, in this application, any device in the standby data center is defined as the second device. In order to maintain the hot standby state of the second device, when the first device corresponding to the primary master in the primary center fails, if any second device in the standby data center replaces the previous first device as the primary master device, the secure data channel with the primary master device on the peer side can be unobstructed, thus avoiding the situation where the temporarily replaced second device cannot communicate seamlessly with the primary master device on the communication peer side.

[0063] Refer to Figure 5 : Step 501, determine the primary master device of the data communication peer according to the RSD data packet.

[0064] Step 502, send the SSE data packet for secure verification to the primary master device of the data communication peer through the second device.

[0065] Step 503, receive the SSR data packet sent by the primary master device of the data communication peer to establish a secure data channel with the primary master device of the data communication peer.

[0066] As an alternative implementation, the RSD data packet includes a protocol interaction type and a message type; the protocol interaction type includes a primary master and a non-primary master; the message type is the device that sends the RSD.

[0067] The process of the second device establishing a secure data channel with the primary master device of the communication peer is explained in detail below:

[0068] Before the introduction, it should be noted that in step 501, each device on both sides of the communication will send RSD data packets to each device on the opposite side all the time. The second device will receive communication RSD data packets of 4 message types of RSSP_I. By parsing the data packets, the second device can accurately identify which device the RSD data packet comes from the communication peer from the message type in the header of the data packet. See Figure 6 The current definition method of the RSD message format specified in the "RSSP_I Railway Signal Secure Communication Protocol (V1.0)". Based on the existing RSSP_I protocol, this application expands the message type. See Figure 7 , in addition to 0x80 and 0x81, 0x82 and 0x83 are also added. Among them, for the four message types, 0x80 indicates that Figure 1 the A machine in is the primary master device; 0x81 indicates that Figure 1 the B machine in is the primary master device; 0x82 indicates that Figure 1 the C machine in is the primary master device, and 0x83 indicates that Figure 1 the D machine in is the primary master device. And 4 secure communication states are defined, namely master-master (primary master device of the primary center), master-backup (backup device of the primary center), backup-master (primary master device of the backup center), and backup-backup (backup device of the backup center). In RSSP_I, it is stipulated that the protocol interaction type 0X01 indicates the primary master of the primary data center.

[0069] As an alternative implementation, see Figure 8 , determine the primary master device of the data communication peer according to the RSD data packet in the following manner:

[0070] Step 801: Parse the RSD data packet and determine the primary master from the protocol interaction type.

[0071] Step 802: Determine the device that is the primary master of the data communication peer from the message type.

[0072] When receiving a data packet, security verification is required only when the parsed protocol interaction type and message type are 0X01 0x80, 0X01 0x81, 0X01 0x82, 0X01 0x83, that is, the primary master device. The process of security verification is as follows: in steps 502 and 503, the second device sends an SSE data packet for security verification to the primary master device of the data communication peer; and receives an SSR data packet sent by the primary master device of the data communication peer. When the SSR data packet sent by the primary master device of the peer is received, it proves that the secure data channel with the primary master device of the data communication peer is established. When receiving a data packet and the parsed protocol interaction type and message type indicate that it is not sent by the primary master device of the peer, no security verification is required, and the second device will not trigger sending an SSE data packet for security verification to the primary master device of the data communication peer.

[0073] The second device feeds back different secure communication messages to different devices of the communication peer according to the received message type and secure communication data packet. For example, when any device in the second device is the primary master device and only receives the SSE message of the C machine of the communication peer, it only needs to reply with an SSR message to the peer C machine and does not need to send an SSR message to other devices of the peer. Each secure data channel is maintained independently.

[0074] See Figure 9 , step 901: Parse the RSD data packet and determine the primary master from the protocol interaction type.

[0075] Step 902: Determine the device of the data communication peer as the primary master from the message type.

[0076] Step 903: For any second device in the standby data center, the second device receives the RSD data packet sent by the data communication peer.

[0077] Step 904: Determine the primary master device of the data communication peer according to the RSD data packet, send an SSE data packet for security verification to the primary master device of the data communication peer through the second device, and receive the SSR data packet sent by the primary master device of the data communication peer to establish a secure data channel with the primary master device of the data communication peer.

[0078] See Figure 10 , Figure 10 The primary master in the primary center is the primary master device in this application. Figure 10The non-primary central main system in [the system] is the second device in this application. For the data interaction process between the two communication parties, in this application, the two communication parties are respectively defined as the M end and the N end. Among them, A is the primary main system device at the M end, and B, C, and D are non-primary main system devices at the M end (including the backup system device of the primary data center, the primary system device of the backup data center, and the backup system device of the backup data center). To simplify the interaction process, the N end only focuses on the primary main system device for the time being.

[0079] The interaction process between the primary main system device (A) at the M end and the N end is described as follows. A and N are both the sender and the receiver to each other:

[0080] Cycle T: A and N periodically send and receive RSD data packets to each other, and the receiving end monitors the timing of the RSD sent from the sending end in real time;

[0081] Cycle T + 1: If the timing is incorrect, trigger the timing correction mechanism and send SSE data packets;

[0082] Cycle T + 2: After receiving the SSE data packet, the receiving end sends an SSR data packet to the opposite end;

[0083] Cycle T + 3: After the timing correction is restored, receive the RSD data packet from the opposite end;

[0084] The interaction process between the non-primary main system devices (B, C, D) at the M end and the N end is described as follows:

[0085] Cycle T: B, C, and D and N periodically send and receive RSD data packets to each other. Only B, C, and D verify the timing of the RSD at the N end, and the N end does not need to verify the timing of B, C, and D;

[0086] Cycle T + 1: If B, C, and D verify that the timing at the N end is incorrect, trigger the timing correction mechanism and send SSE data packets respectively;

[0087] Cycle T + 2: After receiving the SSE data packet, the N end sends an SSR data packet to the corresponding B, C, and D;

[0088] Cycle T + 3: After the timing correction is restored, B, C, and D receive the RSD data packet from the N end.

[0089] Step 202: Compare in real time the communication security parameters stored in the primary main system device and the second device respectively. The communication security parameters include the communication security parameters of the primary main system device of the local end and the data communication opposite end.

[0090] Specifically, to ensure that the control center can seamlessly switch between the devices included in the center, that is, the switching does not affect the secure communication with the devices of the external communication opposite end and there is no need to re-establish a link, the communication security parameters need to be synchronized among the devices in the control center. For the data flow direction of the synchronized data, seeFigure 11 As shown, the standby system devices of the primary data center, the primary system devices of the standby data center, and the standby system devices of the standby data center all need to synchronize using the communication security parameters of the primary primary system device. Among them, the communication security parameters in the primary primary system device include two parts. The first part is its own communication security parameters, and the second part is the communication security parameters of the primary primary system device of the communication peer.

[0091] Step 203: When the comparison results are inconsistent, update the communication security parameters of the second device using the communication security parameters of the primary primary system device.

[0092] Specifically, when the comparison results of the communication security parameters respectively stored in the primary primary system device and the second device are inconsistent, the specific update process is as follows: Synchronize the first part and the second part of the communication security parameters in the primary primary system device to other devices in this control center that are not the primary primary system device at the same time.

[0093] As an optional implementation manner, the parameter types of the communication security parameters of the primary primary system device and the communication security parameters of the other devices are the same; updating the communication security parameters of the second device using the communication security parameters of the primary primary system device includes:

[0094] Update the second communication security parameter of the second device with the same type as the first communication security parameter using the first communication security parameter of the primary primary system device.

[0095] As an optional implementation manner, the parameter types include serial numbers and timestamps.

[0096] Specifically, the parameter types of the first communication security parameter include serial numbers and timestamps; the parameter types of the second communication security parameter include serial numbers and timestamps.

[0097] When the serial number representing the local end of the communication in the communication security parameters of the second device is different from the serial number representing the local end in the communication security parameters of the primary primary system device, update the communication security parameters in the second device with the serial number representing the local end in the communication security parameters of the primary primary system device and the timestamp representing the local end in the communication security parameters of the primary primary system device.

[0098] When the serial number representing the communication peer in the communication security parameters of the second device is different from the serial number representing the peer in the communication security parameters of the primary primary system device, update the communication security parameters in the second device with the serial number representing the peer in the communication security parameters of the primary primary system device and the timestamp representing the peer in the communication security parameters of the primary primary system device.

[0099] Step 204: When the first device fails, select a second device as the primary master device, so that the selected second device communicates with the primary master device of the data communication peer through the local secure data channel based on the communication security parameters.

[0100] Specifically, refer to Figure 12 : Step 1201: When the first device fails, select a second device as the primary master device;

[0101] Step 1202: The second device communicates with the primary master device of the data communication peer through the local secure data channel based on the communication security parameters.

[0102] This application solves the problem that the RSSP-I protocol itself does not support multiple standby devices. After expanding the device type, it not only ensures the secure communication between the dual-system devices of the primary and standby data centers, but also maintains the state of the secure data channel between the standby data center devices of both communication parties and the primary master device of the communication peer. On the basis of ensuring the correct synchronization of the communication security parameters, seamless system switching can be achieved.

[0103] Refer to Figure 13 which is the overall flowchart of a method for establishing communication in this application;

[0104] Step 1301, parse the RSD data packet, and determine the primary master from the protocol interaction type;

[0105] Step 1302, determine the device of the data communication peer as the primary master from the message type;

[0106] Step 1303, for any second device in the standby data center, the second device receives the RSD data packet sent by the data communication peer;

[0107] Step 1304, determine the primary master device of the data communication peer according to the RSD data packet, and send an SSE data packet for security verification to the primary master device of the data communication peer through the second device;

[0108] Step 1305, receive the SSR data packet sent by the primary master device of the data communication peer, and establish a secure data channel with the primary master device of the data communication peer;

[0109] Step 1306, compare the communication security parameters stored in the primary master device and the second device in real time;

[0110] Step 1307, when the comparison results are inconsistent, update the second communication security parameter of the second device of the same type as the first communication security parameter of the primary master device;

[0111] Step 1308: When the first device fails, select a second device as the primary master device;

[0112] Step 1309: The second device communicates with the primary master device of the data communication peer through the secure data channel where it is located based on the communication security parameters.

[0113] Embodiment 2

[0114] Based on the same inventive concept, the present application further provides a device for establishing communication. The device serves as the control center of the data communication end. The data communication end includes two data centers respectively connected to the control. Each data center includes two communication devices. As Figure 14 shown, the device includes:

[0115] A secure data channel establishment module 1401, configured to determine that the first device for current data transmission is the primary master device, and respectively establish secure data channels for each second device other than the first device to communicate with the primary master device of the data communication peer;

[0116] A comparison module 1402, configured to compare in real time the communication security parameters respectively stored in the primary master device and the second device. The communication security parameters include the security parameters of the primary master device at the local end and the data communication peer end;

[0117] An update module 1403, configured to update the communication security parameters of the second device with the communication security parameters of the primary master device when the comparison results are inconsistent;

[0118] A determination module 1404, configured to, when the first device fails, select a second device as the primary master device, so that the selected second device communicates with the primary master device of the data communication peer through the secure data channel where it is located based on the communication security parameters.

[0119] Optionally, the secure data channel establishment module 1401 is specifically configured to: for any second device in the standby data center, the second device receives the RSD data packet sent by the data communication peer. The standby data center is the data center that does not include the primary master device;

[0120] Determine the primary master device of the data communication peer according to the RSD data packet, send the SSE data packet for security verification to the primary master device of the data communication peer through the second device, and receive the SSR data packet sent by the primary master device of the data communication peer, and establish a secure data channel with the primary master device of the data communication peer.

[0121] Optionally, the communication security parameters of the primary master device are of the same parameter type as those of the other devices; the update module 1403 is specifically configured to:

[0122] Update the second communication security parameter of the second device, which is of the same type as the first communication security parameter, with the first communication security parameter of the primary master device.

[0123] Optionally, the parameter type includes a serial number and a timestamp.

[0124] Optionally, the RSD data packet includes a protocol interaction type and a message type;

[0125] The protocol interaction type includes primary master and non-primary master;

[0126] The message type is the device that sends the RSD.

[0127] The secure data channel establishment module 1401 is specifically configured to: determine the primary master device of the data communication peer through the following manner according to the RSD data packet:

[0128] Parse the RSD data packet and determine the primary master from the protocol interaction type;

[0129] Determine the device that is the primary master of the data communication peer from the message type.

[0130] After introducing the communication establishment method and apparatus of the exemplary embodiments of the present application, next, an electronic device according to another exemplary embodiment of the present application will be introduced.

[0131] Those skilled in the art to which the present application pertains can understand that various aspects of the present application can be implemented as a system, a method, or a program product. Therefore, various aspects of the present application can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuit", "module", or "system" here.

[0132] In some possible implementation manners, the electronic device according to the present application may at least include at least one processor and at least one memory. Among them, the memory stores program code, and when the program code is executed by the processor, the processor is caused to execute the steps in the communication establishment method according to various exemplary embodiments of the present application described above in this specification.

[0133] Next, with reference to Figure 15 an electronic device 130 according to this implementation manner of the present application, that is, the above-mentioned temperature prediction and decision-making device, will be described. Figure 15The illustrated electronic device 130 is merely an example and is not intended to impose any limitation on the functionality and scope of use of the embodiments of the present application.

[0134] As Figure 15 shown, the electronic device 130 is presented in the form of a general-purpose electronic device. The components of the electronic device 130 may include, but are not limited to: at least one of the above-mentioned processors 131, at least one of the above-mentioned memories 132, and a bus 133 connecting different system components (including the memory 132 and the processor 131).

[0135] The bus 133 represents one or more of several types of bus architectures, including a memory bus or memory controller, a peripheral bus, a processor, or a local area bus using any of the multiple bus architectures.

[0136] The memory 132 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 1321 and / or cache memory 1322, and may further include read-only memory (ROM) 1323.

[0137] The memory 132 may also include a program / utility 1325 having a set (at least one) of program modules 1324. Such program modules 1324 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.

[0138] The electronic device 130 may also communicate with one or more external devices 134 (such as a keyboard, a pointing device, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 130, and / or may communicate with any device that enables the electronic device 130 to communicate with one or more other electronic devices (such as a router, a modem, etc.). Such communication may be carried out through an input / output (I / O) interface 135. Moreover, the electronic device 130 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 136. As shown in the figure, the network adapter 136 communicates with other modules for the electronic device 130 through the bus 133. It should be understood that although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 130, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0139] In some possible embodiments, aspects of a method for establishing communication provided by the present application can also be implemented in the form of a program product, which includes program code. When the program product runs on a computer device, the program code is used to cause the computer device to execute the steps of a method for establishing communication according to various exemplary embodiments of the present application described above in this specification.

[0140] The program product can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0141] The program product for monitoring in the embodiments of the present application can adopt a portable compact disk read-only memory (CD-ROM) and include program code, and can run on an electronic device. However, the program product of the present application is not limited to this. In this document, the readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device.

[0142] The readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The readable signal medium can also be any readable medium other than the readable storage medium, and this readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device.

[0143] The program code contained on the readable medium can be transmitted by any suitable medium, including but not limited to wireless, wired, optical cable, RF, etc., or any suitable combination of the above.

[0144] The program code for performing the operations of this application can be written in any combination of one or more programming languages. The programming languages include object-oriented programming languages such as Java, C++, etc., and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's electronic device, partially on the user's device, executed as an independent software package, partially on the user's electronic device and partially on a remote electronic device, or entirely on a remote electronic device or server. In cases involving a remote electronic device, the remote electronic device can be connected to the user's electronic device through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external electronic device (e.g., by connecting through the Internet using an Internet service provider).

[0145] It should be noted that although several units or subunits of the device are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of this application, the features and functions of two or more of the above-described units can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.

[0146] In addition, although the operations of the method of this application are described in a specific order in the drawings, this does not require or imply that these operations must be performed in that specific order, or that all the shown operations must be performed to achieve the desired result. Additionally or alternatively, certain steps can be omitted, multiple steps can be combined into one step for execution, and / or one step can be decomposed into multiple steps for execution.

[0147] Those skilled in the art should understand that the embodiments of this application can be provided as a method, a system, or a computer program product. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.

[0148] This application is described with reference to the flowcharts and block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and block diagrams, and combinations of flows and blocks in the flowcharts and block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce a means for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and blocks Figure 1 or one or more of the blocks.

[0149] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction means that implements the functions specified in one or more of the flows Figure 1 one or more of the flows and blocks Figure 1 or one or more of the blocks.

[0150] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more of the flows Figure 1 one or more of the flows and blocks Figure 1 or one or more of the blocks.

[0151] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications falling within the scope of the present application.

[0152] Obviously, those skilled in the art can make various changes and variations to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these changes and variations.

Claims

1. A method for establishing communication, characterized in that, A control center applied to a data communication terminal, the control center includes two data centers, and each data center includes two devices. The method includes: Determine the first device for current data transmission as the primary master device, and respectively establish secure data channels for each second device except the first device to communicate with the primary master device of the data communication peer; Compare in real time the communication security parameters stored in the primary master device and the second devices respectively, where the communication security parameters include the communication security parameters of the primary master device at the local end and the data communication peer end; When the comparison results are inconsistent, update the communication security parameters of the second devices with the communication security parameters of the primary master device; When the first device fails, select one of the second devices as the primary master device, so that the selected second device communicates with the primary master device of the data communication peer through the secure data channel where it is located based on the communication security parameters; Among them, the step of respectively establishing secure data channels for each second device except the first device to communicate with the primary master device of the data communication peer includes: For any second device in the standby data center, the second device receives the RSD data packet sent by the data communication peer, and the standby data center is the data center that does not include the primary master device; Determine the primary master device of the data communication peer according to the RSD data packet, send an SSE data packet for security verification to the primary master device of the data communication peer through the second device, and receive the SSR data packet sent by the primary master device of the data communication peer to establish a secure data channel with the primary master device of the data communication peer.

2. The method according to claim 1, characterized in that, The parameter types of the communication security parameters of the primary master device and the communication security parameters of other devices are the same; Updating the communication security parameters of the second devices with the communication security parameters of the primary master device includes: Updating the second communication security parameters of the second devices of the same type as the first communication security parameter with the first communication security parameter of the primary master device.

3. The method according to claim 2, wherein The parameter types include serial numbers and timestamps.

4. The method according to claim 1, characterized in that, The RSD data packet includes a protocol interaction type and a message type; The protocol interaction type includes primary master and non-primary master; The message type is the device that sends the RSD; 5. The method according to claim 4, wherein Determine the primary master device of the data communication peer according to the RSD data packet in the following manner: Parse the RSD data packet and determine the primary master from the protocol interaction type; Determine the device of the data communication peer as the primary master from the message type.

6. A device for establishing communication, characterized in that, The device serves as a control center for a data communication terminal. The data communication terminal includes two data centers respectively connected to the control. Each data center includes two communication devices. The device includes: A secure data channel establishment module, configured to determine the first device for current data transmission as the primary master device, and respectively establish secure data channels for each second device except the first device to communicate with the primary master device of the data communication peer; A comparison module, configured to compare in real time the communication security parameters respectively stored in the primary master device and the second device, where the communication security parameters include the security parameters of the primary master device at the local end and the data communication peer end; An update module, configured to update the communication security parameters of the second device with the communication security parameters of the primary master device when the comparison results are inconsistent; A determination module, configured to select a second device as the primary master device when the first device fails, so that the selected second device communicates with the primary master device at the data communication peer end through the security data channel where it is located based on the communication security parameters; Wherein, the security data channel establishment module is specifically configured to: For any second device in the standby data center, the second device receives the RSD data packet sent by the data communication peer end, and the standby data center is a data center that does not include the primary master device; Determine the primary master device of the data communication peer end according to the RSD data packet, send an SSE data packet for security verification to the primary master device of the data communication peer end through the second device, and receive the SSR data packet sent by the primary master device of the data communication peer end, so as to establish a security data channel with the primary master device of the data communication peer end.

7. An electronic device, characterized in that, Comprising at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so that the at least one processor can execute the method according to any one of claims 1-5.

8. A computer storage medium, characterized in that, The computer storage medium stores a computer program, and the computer program is used to cause a computer to execute the method according to any one of claims 1-5.

Citation Information

Patent Citations

  • Optical access network, and method, system and apparatus for backuping optical line terminal

    CN101562480A