An access method, device, server, and user terminal device for a terminal
Through TR069 channel and STUN technology, the task of indicating the NAT device across the private network is solved, and the problem that the SSH client cannot directly access the server is realized, and the remote access management of NAT devices is realized, reducing operation and maintenance costs.
Patent Information
- Application Number
- CN202111387949.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-22
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2041-11-22
AI Technical Summary
The prior art is difficult to realize automatic remote access management of devices after NAT, especially when the SSH client cannot directly access the SSH server, additional transit proxy server and manual configuration are required.
Through TR069 channel and STUN technology, OMC and STUN servers are used to indicate to the CPE across the private network that there are tasks to be consumed, establish a communication channel between the CPE and the first server, and automatically manage remote access of the NAT device.
It realizes automatic remote access management of devices after NAT, reduces manual operations of operation and maintenance personnel, saves personnel costs, and uses TR069 and STUN technologies for batch remote management.
Smart Images

Figure CN116155966B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to a method and apparatus for accessing a terminal, a server, and a user terminal device. Background Art
[0002] SSH (Secure Shell) is a security protocol based on the application layer, developed by the Network Working Group of the IETF (The Internet Engineering Task Force). SSH is a protocol designed to provide security for remote login sessions and other network services, and is relatively reliable. Using the SSH protocol can effectively prevent information leakage problems during the remote management process.
[0003] The SSH server is located in the local area network behind the NAT (Network Address Translation) gateway, and the SSH client is in the public network. Since the SSH client cannot directly access the SSH server, a proxy server in the local area network needs to be used for relay processing, or the local area network firewall needs to perform mapping processing, or TCP (Transmission Control Protocol) forwarding is used to implement SSH.
[0004] Among them, the method of implementing SSH using TCP forwarding requires setting up a relay proxy server in the public network. The terminal behind the local area network NAT first establishes a channel with the public network relay proxy SSH server, and the public network SSH client accesses the SSH service of the terminal behind the local area network NAT by accessing the public network relay proxy SSH server. However, this method requires purchasing a server and a public network IP separately, and also requires pre-configuring forwarding rules on the terminal side, and cannot achieve automatic configuration.
[0005] In summary, the current implementation of remotely accessing a local area network device behind NAT using a public network IP is relatively complex, and it is difficult to achieve automatic management of remotely accessing devices behind NAT. Summary of the Invention
[0006] The present invention provides a method and apparatus for accessing a terminal, a server, and a user terminal device, which solves the problem in the prior art that it is difficult to achieve automatic management of remotely accessing devices behind NAT.
[0007] In a first aspect, an embodiment of the present invention provides a method for accessing a terminal, which is applied to a first server and includes:
[0008] Obtain first indication information, where the first indication information is used to indicate to perform a first operation on a CPE (Customer Premise Equipment) after network address translation (NAT), and the first operation includes at least one of the following: enabling a Secure Shell (SSH) connection, closing the SSH connection, and transmitting a key;
[0009] Generate a first task according to the first indication information;
[0010] Send second indication information to a second server, where the second indication information is used to indicate that the first server has generated a first task to be consumed, so that the second server sends third indication information indicating that there is a first task to be consumed on the first server to the CPE;
[0011] Establish communication with the CPE through a TR069 channel to access the CPE;
[0012] Wherein, the first server and the second server are in the public network.
[0013] In a second aspect, an embodiment of the present invention provides a method for accessing a terminal, which is applied to a second server and includes:
[0014] Receive second indication information sent by a first server, where the second indication information is used to indicate that the first server has generated a first task to be consumed;
[0015] According to the second indication information, send third indication information to the CPE, where the third indication information is used to indicate that there is a first task to be consumed on the first server;
[0016] Wherein, the first server and the second server are in the public network.
[0017] In a third aspect, an embodiment of the present invention provides a method for accessing a terminal, which is applied to the CPE and includes:
[0018] Receive third indication information sent by a second server, where the third indication information is used to indicate that there is a first task to be consumed on a first server;
[0019] Establish a TR069 channel with the first server according to the third indication information;
[0020] Establish communication with the first server through the TR069 channel to consume the first task.
[0021] In a fourth aspect, an embodiment of the present invention provides an access device for a terminal, which is applied to the first server and includes:
[0022] An information acquisition module, configured to acquire first indication information, where the first indication information is used to indicate to perform a first operation on a customer premise equipment (CPE) after network address translation (NAT), and the first operation includes at least one of the following: enabling a secure shell (SSH) connection, closing the SSH connection, and transmitting a key;
[0023] A task generation module, configured to generate a first task according to the first indication information;
[0024] A first sending module, configured to send second indication information to a second server, where the second indication information is used to indicate that the first server has generated a first task to be consumed, so that the second server sends third indication information indicating that there is a first task to be consumed on the first server to the CPE;
[0025] A first communication module, configured to establish communication with the CPE through a TR069 channel to access the CPE;
[0026] Wherein, the first server and the second server are in a public network.
[0027] In a fifth aspect, an embodiment of the present invention provides an access device for a terminal, applied to a second server, including:
[0028] A first receiving module, configured to receive second indication information sent by a first server, where the second indication information is used to indicate that the first server has generated a first task to be consumed;
[0029] A second sending module, configured to send third indication information to a CPE according to the second indication information, where the third indication information is used to indicate that there is a first task to be consumed on the first server;
[0030] Wherein, the first server and the second server are in a public network.
[0031] In a sixth aspect, an embodiment of the present invention provides an access device for a terminal, applied to a CPE, including:
[0032] A second receiving module, configured to receive third indication information sent by a second server, where the third indication information is used to indicate that there is a first task to be consumed on a first server;
[0033] A channel establishment module, configured to establish a TR069 channel with the first server according to the third indication information;
[0034] A second communication module, configured to establish communication with the first server through the TR069 channel to consume the first task.
[0035] Seventh aspect, an embodiment of the present invention provides a server, including: a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the access method of the terminal as described in the first aspect, or implements the steps of the access method of the terminal as described in the second aspect when executing the computer program.
[0036] Eighth aspect, an embodiment of the present invention provides a CPE, including: a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the access method of the terminal as described in the third aspect.
[0037] Ninth aspect, an embodiment of the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of the access method of the terminal as described in the first aspect, or implements the steps of the access method of the terminal as described in the second aspect, or implements the steps of the access method of the terminal as described in the third aspect.
[0038] The beneficial effects of the above technical solutions of the present invention are as follows:
[0039] In the embodiment of the present invention, through the second server, it is possible to indicate to the CPE across the private network that there is a first task to be consumed on the first server, so that the CPE establishes a TR069 channel with the first server, realizes the establishment of communication between the first server and the CPE, and completes task consumption. In this way, based on the TR069 and STUN technologies, automatic management of remote access of devices behind NAT can be achieved, avoiding a large number of manual operations by operation and maintenance personnel and saving personnel costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 A flowchart showing the access method of the terminal in the embodiment of the present invention;
[0041] Figure 2 A schematic diagram of the network relationship of the access method of the terminal in the embodiment of the present invention;
[0042] Figure 3 A schematic diagram of the process of the access method of the terminal in the embodiment of the present invention;
[0043] Figure 4 A flowchart showing the access method of the terminal in the embodiment of the present invention when using the password authentication method;
[0044] Figure 5 A flowchart showing the access method of the terminal in the embodiment of the present invention when using the key authentication method;
[0045] Figure 6Flowchart of the access method of the terminal according to another embodiment of the present invention;
[0046] Figure 7 Flowchart of the access method of the terminal according to still another embodiment of the present invention;
[0047] Figure 8 Flowchart of the access method of the terminal according to yet another embodiment of the present invention;
[0048] Figure 9 Structural block diagram of the access device of the terminal according to the embodiment of the present invention;
[0049] Figure 10 Structural block diagram of the access device of the terminal according to another embodiment of the present invention;
[0050] Figure 11 Structural block diagram of the access device of the terminal according to still another embodiment of the present invention;
[0051] Figure 12 Structural block diagram of the first server according to the embodiment of the present invention;
[0052] Figure 13 Structural block diagram of the CPE according to the embodiment of the present invention. Detailed implementation manners
[0053] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments. In the following description, specific details such as specific configurations and components are provided only to help a comprehensive understanding of the embodiments of the present invention. Therefore, those skilled in the art should clearly understand that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Additionally, descriptions of known functions and configurations are omitted for clarity and conciseness.
[0054] It should be understood that the term "one embodiment" or "an embodiment" mentioned throughout the specification means that a specific feature, structure or characteristic related to the embodiment is included in at least one embodiment of the present invention. Therefore, the appearances of "in one embodiment" or "in an embodiment" throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner.
[0055] In various embodiments of the present invention, it should be understood that the magnitudes of the serial numbers of the following processes do not mean the order of execution is prior or subsequent, and the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0056] In addition, the terms "system" and "network" are often used interchangeably herein.
[0057] In the embodiments provided in this application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean determining B only according to A, and B can also be determined according to A and / or other information.
[0058] In the embodiments of the present invention, the form of the access network is not limited, and it can be an access network including a macro base station, a pico base station, a Node B (the name of a 3G mobile base station), an evolved Node B (eNB), a home evolved Node B (Femto eNB or Home eNode B or Home eNB or HeNB), a relay station, an access point, a Remote Radio Unit (RRU), a Remote Radio Head (RRH), etc. The user terminal can be a mobile phone (or cell phone), or other devices capable of sending or receiving wireless signals, including a user equipment, a personal digital assistant (PDA), a wireless modem, a wireless communication device, a handheld device, a laptop computer, a cordless phone, a wireless local loop (WLL) station, a customer premise equipment (CPE) capable of converting a mobile signal into a WiFi signal or a mobile intelligent hotspot, a smart home appliance, or other devices that can spontaneously communicate with the mobile communication network without human operation.
[0059] Specifically, the embodiments of the present invention provide a method, a device, a server, and a user terminal device for accessing a terminal, which solves the problem that it is difficult to automatically manage the remote access of devices after network address translation (NAT) in the prior art.
[0060] The first embodiment
[0061] As Figure 1 shown, the embodiments of the present invention provide a method for accessing a terminal, which is applied to a first server and specifically includes the following steps:
[0062] Step 11: Obtain first indication information, where the first indication information is used to indicate to perform a first operation on a user terminal device CPE located behind a network address translation (NAT), and the first operation includes at least one of the following: opening a Secure Shell (SSH) connection, closing the SSH connection, and transmitting a key.
[0063] As an alternative embodiment of the present invention, the first server may be an OMC (Operation and Maintenance Center), or an ACS (Auto-Configuration Server), or other servers that can remotely manage the CPE (based on the TR069 protocol). Here, the example is given with the first server being an OMC.
[0064] In this step, the first indication information may be the instruction information issued by the user when operating on the operation interface of the OMC. For example, when the user selects a certain device (i.e., CPE) on the operation interface of the OMC and performs an operation to enable (or disable) the SSH function (i.e., SSH connection) after NAT for the CPE, this operation can trigger the OMC to obtain the first indication information. Another example is that when the user selects a certain device on the operation interface of the OMC and operates the device to download the public key of the SSH proxy server, this operation can also trigger the OMC to obtain the first indication information.
[0065] Step 12: Generate a first task according to the first indication information.
[0066] After obtaining the first indication information, the OMC can generate a corresponding task (i.e., the first task) according to the first indication information, and the task enters the task queue waiting to be consumed.
[0067] Step 13: Send second indication information to the second server, where the second indication information is used to indicate that the first server has generated a first task to be consumed, so that the second server sends third indication information indicating that there is a first task to be consumed on the first server to the CPE.
[0068] After generating the first task, the OMC can notify the second server by sending second indication information to the second server, informing the second server that the OMC has generated a first task to be consumed.
[0069] As an alternative embodiment of the present invention, the second server may be a STUN server, or other servers based on the UDP or TCP protocol. Here, the example is given with the second server being a STUN server.
[0070] It should be noted that STUN (Simple Traversal of User Datagram Protocol through Network Address Translators (NATs), UDP simple traversal of NAT) is a network protocol that allows a client located behind a NAT (or multiple NATs) to find its public network address, determine which type of NAT it is located behind, and the Internet-side port bound by the NAT for a certain local port. Through STUN technology, real-time access to the NAT terminal can be achieved for reverse connection operations.
[0071] Step 14: Establish communication with the CPE through the TR069 channel to access the CPE; wherein, the first server and the second server are in the public network.
[0072] It should be noted that TR069 is a communication protocol for communication between the CPE and the OMC. Through this protocol, the CPE can complete necessary actions for initialization and operation management such as service activation, function setting, file upload and download, and system detection. Through TR069 technology, task management can be realized, including enabling functions, disabling functions, and querying whether functions are enabled, which is convenient for batch operations.
[0073] As Figure 2 shown, in the embodiment of the present invention, the OMC and the STUN server are in the public network (external network), and the CPE (i.e., Terminal 1, Terminal 2, and Terminal 3) is in the local area network (internal network). The OMC (i.e., the SSH client) cannot directly access the CPE (i.e., the SSH server). The STUN server needs to cross the private network to indicate to the CPE that there is a first task to be consumed on the first server.
[0074] In this embodiment, as Figure 3 shown, through the second server, it is possible to cross the private network to indicate to the CPE that there is a first task to be consumed on the first server, so that the CPE establishes a TR069 channel with the first server, realizes communication between the first server and the CPE, and completes task consumption. In this way, based on TR069 and STUN technologies, automatic management of remote access to devices behind the NAT can be achieved.
[0075] Optionally, the establishing communication with the CPE through the TR069 channel to access the CPE includes:
[0076] (1) Receiving a first message sent by the CPE through the TR069 channel, where the first message is used to request the first task from the first server.
[0077] For example, the CPE sends an empty message to the OMC, indicating that the CPE has no other tasks and is waiting for the OMC to issue tasks.
[0078] (2) Send the task information corresponding to the first task to the CPE according to the first information.
[0079] For example, the OMC can use a custom method to issue task information to notify the CPE to open an SSH connection; for another example, the OMC can issue task information through the Upload method to notify the CPE to upload the public key of the CPE itself to the specified path of the SSH proxy server; for still another example, the OMC can issue task information through the Download method to notify the CPE to download the public key of the SSH proxy server to the CPE.
[0080] (3) Receive the fourth indication information sent by the CPE, where the fourth indication information is used to indicate that the CPE has successfully executed the first task.
[0081] For example, after the CPE uploads the public key of the CPE to the specified path of the SSH proxy server and downloads the public key of the SSH proxy server, the CPE can send the fourth indication information (such as the 7TransferComplete event) to the OMC through the TR069 channel respectively to notify the OMC that the task has been processed and has taken effect.
[0082] For another example, as Figure 4 shown, when connecting to the SSH proxy server using the password authentication method, the CPE can determine that the task has been successfully executed and has taken effect by checking the SSH process. At this time, the CPE initiates an active connection to the OMC and reports the second information to the OMC in the way of actively reporting nodes. Here, the second information may include the following content: the fourth indication information indicating that the SSH function has been enabled (that is, the CPE has successfully executed the first task), the username and password for logging in to the SSH proxy server, v2x.obu.natSSH.status is 1, v2x.obu.natSSH.user is root, and v2x.obu.natSSH.password is 1qaz2wsx. After receiving the fourth indication information, the OMC can detect the natSSH enable status. After confirming the enablement, the OMC uses ssh root@localhost -p 8000 to log in to the SSH proxy server, and the password is 1qaz2wsx.
[0083] For still another example, as Figure 5As shown in the figure, when connecting to the SSH proxy server using the key authentication method, the CPE can determine that the task has been successfully executed and has taken effect by checking the SSH process. The CPE initiates an active connection to the OMC server and reports the second information to the OMC in the way of actively reporting nodes. Here, the second information may include the following content: the fourth indication information indicating that the SSH function has been enabled (i.e., the CPE has successfully executed the first task) and the username, where v2x.obu.natSSH.status is 1 and v2x.obu.natSSH.user is root. After receiving the fourth indication information, the OMC can detect the natSSH enable status. After confirming the enablement, it directly logs in using ssh root@localhost -p 8000.
[0084] (4) According to the fourth indication information, execute the second operation corresponding to the first operation;
[0085] Among them, the second operation is one of the following:
[0086] (1) When the first operation is to enable the SSH connection, the second operation is: connect to the SSH proxy server.
[0087] In this case, the OMC can initiate an SSH connection and connect to the SSH proxy server.
[0088] (2) When the first operation is to close the SSH connection, the second operation is: prompt that the connection between the CPE and the SSH proxy server has been disconnected.
[0089] In this case, the OMC can prompt on its operation interface that the SSH function of the CPE is in the closed state, indicating that the connection between the CPE and the SSH proxy server has been disconnected.
[0090] (3) When the first operation is to transfer the key, the second operation is: prompt that the key transfer is completed.
[0091] In this case, the OMC can prompt on its operation interface that the key transfer is successful. At this time, the user can perform other operations on the OMC. For example, the user can perform an operation to enable the SSH function (i.e., SSH connection) on the CPE on the operation interface of the OMC, so that the OMC generates a task corresponding to this operation.
[0092] It should be noted that the OMC and the SSH server proxy can use the same server, which saves server costs. As an integrated function of the OMC, it can also save operation and maintenance costs.
[0093] Optionally, before receiving the first information sent by the CPE through the TR069 channel, the method further includes:
[0094] (1) Receive the task request information sent by the CPE through the TR069 channel, where the task request information is used to request a connection to consume the first task.
[0095] For example, after establishing the TR069 channel between the CPE and the OMC, the CPE sends an inform request (i.e., task request information) to the OMC, and the event code is: 6 connection request.
[0096] (2) Send authentication information to the CPE according to the task request information.
[0097] For example, the OMC replies with an informresponse (information response) according to the task request information, and the authentication information is carried in the information response. The authentication information can indicate the permission level for the OMC to operate on the CPE. The CPE can judge whether the OMC has the permission to operate on the CPE according to the authentication information.
[0098] Optionally, the task information includes one of the following: task information for opening an SSH connection; task information for closing an SSH connection; task information for transmitting a key;
[0099] Among them, the task information for opening an SSH connection includes at least one of the following: a custom method name, a task identifier, the Internet Protocol (IP) address of the SSH proxy server, the port assigned by the SSH proxy server to the CPE, the SSH authentication method, a username, and a password; the SSH authentication method is password authentication or key authentication;
[0100] The task information for transmitting a key includes at least one of the following: a transmission method name, a task identifier, a file type, the first File Transfer Protocol (FTP) address for storing the public key of the CPE, the second FTP address for storing the public key of the SSH proxy server, an FTP authentication username, and an FTP authentication password.
[0101] Here, the explanations of the contents in the task information for opening an SSH connection are as follows:
[0102] cwmp: represents the transmission method name; NATSSH is a custom method name;
[0103] CommandKey: represents the task identifier, which is the unique identifier of the task. For tasks that need to be processed asynchronously, such as upgrades and opening an SSH connection, when the CPE reports the task processing process or result, it needs to carry the task identifier to indicate which task the reply is for;
[0104] SSHServer: represents the IP address of the SSH proxy server;
[0105] SSHPort: It represents the port assigned by the SSH proxy server to the CPE.
[0106] AuthMethod: It represents the SSH authentication method, including two methods: password authentication (password) and key authentication (cert). Among them, compared with the password authentication method, the key authentication method requires using the TR069 channel to complete the mutual transmission of the public keys between the SSH proxy server and the CPE.
[0107] Username: It represents the user name, that is, the user name used when the SSH authentication method is password authentication.
[0108] Password: It represents the password, that is, the password used when the SSH authentication method is password authentication.
[0109] In addition, the explanations of the contents in the transmission key task information are as follows:
[0110] cwmp: It represents the name of the transmission method. For example: Upload means using the Upload download method; another example: Download means using the Download download method.
[0111] CommandKey: It represents the task identifier, which is the unique identifier of the task. For tasks that need to be processed asynchronously, such as upgrades and enabling SSH, when the CPE reports the task processing process or result, it needs to carry the task identifier to indicate which task the reply is for.
[0112] FileType: It represents the file type. For example, the file type is 10SSH PUB File, and this file type is a file format customized specifically for SSH keys.
[0113] URL: It represents the first File Transfer Protocol (FTP) address for storing the public key of the CPE, or the second FTP address for storing the public key of the SSH proxy server.
[0114] Username: It represents the FTP authentication user name.
[0115] Password: It represents the FTP authentication password.
[0116] It should be noted that when the OMC sends the task information corresponding to the first task to the CPE, it is sent in the form of a message.
[0117] The following are the message examples of different task information in some optional embodiments of the present invention:
[0118] Example 1. The task information sent by the OMC to the CPE is the task information for enabling an SSH connection. The authentication method is password authentication. Optional message examples are as follows:
[0119]
[0120]
[0121] Example 2. The task information sent by the OMC to the CPE is the task information for enabling an SSH connection. The authentication method is key authentication. Optional message examples are as follows:
[0122]
[0123] Example 3. The task information sent by the OMC to the CPE is the task information for transmitting a key. Among them, when the transmission method name (cwmp) is Upload, it means an upload task, that is, the OMC notifies the CPE that it is necessary to upload the public key of the CPE to the specified path of the SSH proxy server; when the transmission method name (cwmp) is Download, it means a download task, that is, download the public key of the SSH proxy server to the CPE. Specifically as follows:
[0124] (1) In the upload task, optional message examples are as follows:
[0125]
[0126]
[0127] (2) In the download task, optional message examples are as follows:
[0128]
[0129] It should be noted that when using key authentication (cert), before the OMC issues the task information for enabling an SSH connection, it is necessary to first issue the task information for transmitting a key, so that the CPE first completes the mutual transmission of the public keys between the SSH proxy server and the CPE.
[0130] As an alternative embodiment of the present invention, the OMC may issue task information for the upload task (i.e., transmission key task information) through the Upload method, notifying the CPE to upload its public key to the specified path of the SSH proxy server; wherein, the task information for the upload task may include the following parameters: transmission method name, task identifier, file type, the first File Transfer Protocol (FTP) address for storing the public key of the CPE, FTP authentication username, and FTP authentication password. The OMC may also issue task information for the download task (i.e., transmission key task information) through the Download method, notifying the CPE to download the public key of the SSH proxy server to the CPE; wherein, the task information for the download task may include the following parameters: transmission method name, task identifier, file type, the second FTP address for storing the public key of the SSH proxy server, FTP authentication username, and FTP authentication password.
[0131] Optionally, the method further includes:
[0132] Receiving fifth indication information fed back by the CPE according to the task information, the fifth indication information being used to indicate that the CPE has received the task information.
[0133] For example, after receiving the task information, the CPE feeds back fifth indication information with a status of 1 to the OMC, indicating that the task has been received and will be processed later, that is, indicating that the CPE will process the task asynchronously.
[0134] In the embodiment of the present invention, by combining the SSH proxy, TR069 remote management technology, and STUN private network traversal technology, the automatic configuration and operation of remote access of the terminal after NAT are realized, avoiding a large number of manual operations by operation and maintenance personnel and saving personnel costs; making full use of the advantages of TR069 and STUN remote management, the batch remote management of NAT terminals is realized, which is beneficial to the remote access management of terminals supporting the TR069 protocol.
[0135] Second Embodiment
[0136] As Figure 7 shown, an embodiment of the present invention provides a method for accessing a terminal, which is applied to a second server and specifically includes the following steps:
[0137] Step 71: Receiving second indication information sent by the first server, the second indication information being used to indicate that the first server has generated a first task to be consumed.
[0138] It should be noted that, as an alternative embodiment of the present invention, the first server may be an OMC, or an ACS, or other servers that can remotely manage the CPE (based on the TR069 protocol). The second server may be a STUN server, or other servers based on the UDP or TCP protocol. Here, an example is given where the first server is an OMC and the second server is a STUN server.
[0139] Step 72: According to the second indication information, send third indication information to the CPE, where the third indication information is used to indicate that there is a first task to be consumed on the first server; wherein, the first server and the second server are in the public network.
[0140] As an alternative embodiment of the present invention, through the STUN technology, the NAT terminal (i.e., the CPE located behind the NAT) can be accessed in real time for reverse connection operations, so that the CPE establishes a communication connection with the OMC through the TR069 channel. Specifically, after receiving the second indication information, the STUN server can notify the CPE across the private network that there is a task on the server side (i.e., the OMC side), waiting for the CPE to consume it through the TR069 channel; after receiving the second indication information, the CPE can establish a TR069 channel with the OMC, and further establish communication with the OMC through the TR069 channel to consume the first task.
[0141] In the embodiment of the present invention, the second server can indicate to the CPE across the private network that there is a first task to be consumed on the first server, so that the CPE establishes a TR069 channel with the first server, realizes the establishment of communication between the first server and the CPE, and completes task consumption. In this way, based on the TR069 and STUN technologies, automatic management of remote access to devices behind the NAT can be achieved.
[0142] The third embodiment
[0143] As Figure 8 shown, an embodiment of the present invention provides a method for accessing a terminal, which is applied to the CPE and specifically includes the following steps:
[0144] Step 81: Receive the third indication information sent by the second server, where the third indication information is used to indicate that there is a first task to be consumed on the first server.
[0145] It should be noted that, as an alternative embodiment of the present invention, the first server may be an OMC, or an ACS, or other servers that can remotely manage the CPE (based on the TR069 protocol). The second server may be a STUN server, or other servers based on the UDP or TCP protocol. Here, an example is given where the first server is an OMC and the second server is a STUN server.
[0146] In this embodiment, the CPE located behind the NAT can be accessed in real time through the STUN server for reverse connection operation, so that the CPE establishes a communication connection with the OMC through the TR069 channel.
[0147] Step 82: Establish a TR069 channel with the first server according to the third indication information;
[0148] Step 83: Establish communication with the first server through the TR069 channel and consume the first task.
[0149] In this embodiment, by receiving the third indication information sent by the second server across the private network, it can be known that there is a first task to be consumed on the first server, so as to establish a TR069 channel between the CPE and the first server, realize the establishment of communication between the first server and the CPE, and complete task consumption. In this way, based on the TR069 and STUN technologies, automatic management of remote access to devices behind the NAT can be realized.
[0150] Optionally, the establishing communication with the first server through the TR069 channel and consuming the first task includes:
[0151] (1) When it is determined that the first server has the operation authority for the CPE, send a first message to the first server through the TR069 channel, where the first message is used to request the first task from the first server.
[0152] For example, the CPE sends an empty message to the OMC, indicating that the CPE has no other tasks and is waiting for the OMC to issue tasks.
[0153] (2) Receive the task information corresponding to the first task sent by the first server.
[0154] Optionally, the task information includes any one of the following: task information for opening an SSH connection; task information for closing an SSH connection; task information for transmitting a key;
[0155] Among them, the task information for opening an SSH connection includes at least one of the following: a custom method name, a task identifier, the Internet Protocol (IP) address of the SSH proxy server, the port assigned by the SSH proxy server to the CPE, the SSH authentication method, the username, and the password; the SSH authentication method is password authentication or key authentication;
[0156] The transmission key task information includes at least one of the following: transmission method name, task identifier, file type, the first File Transfer Protocol (FTP) address for storing the public key of the CPE, the second FTP address for storing the public key of the SSH proxy server, FTP authentication username, and FTP authentication password.
[0157] (3) According to the task information, perform a third operation; the third operation includes at least one of the following: connecting to the SSH proxy server, closing the SSH process, and transmitting the key.
[0158] In this step, according to different task information, it is divided into the following three cases:
[0159] Case 1, when the task information is the task information for enabling the SSH connection, performing the third operation according to the task information includes: generating an execution script according to the task information; executing the execution script to connect to the SSH proxy server.
[0160] As an optional embodiment of the present invention, when using the password authentication method, the CPE can generate a corresponding execution script according to the task parameters (i.e., task information) issued by the OMC. After the script is executed and takes effect, the SSH proxy server can be successfully connected. Optionally, an example of the script for connecting to the SSH proxy server is as follows:
[0161] ssh -f -N -R 8000:localhost:22 root@14.215.177.39
[0162] set port 8000
[0163] set user root
[0164] set host 14.215.177.39
[0165] set password 12345678
[0166] set timeout -1
[0167] spawn ssh -f -N -R $port:localhost:22 $user@$host
[0168] expect "*assword:*"
[0169] send "$password\r"
[0170] expect eof
[0171] As another alternative embodiment of the present invention, when using the password authentication method, the CPE terminal generates a corresponding execution script according to the task parameters sent by the OMC. After the script is executed and takes effect, it connects to the SSH proxy server. The script example is as follows: ssh -f -N -R 8000:localhost:22 root@14.215.177.39.
[0172] Case 2: When the task information is the task information for closing the SSH connection, performing a third operation according to the task information includes: closing the SSH process.
[0173] As Figure 6 shown, in this embodiment, the task information for closing the SSH connection can be v2x.obu.natSSH.enable = 0. For example, the OMC can send the task information (such as the parameter v2x.obu.natSSH.enable = 0) to the CPE through the setParameterValues method; the CPE sends a fifth indication message to the OMC, for example, sending a status of 1 to indicate that the task has been received and will be processed later.
[0174] Here, after closing the SSH process, the CPE can send a sixth indication message to the OMC. The sixth indication message is used to indicate that the connection between the CPE and the SSH proxy server has been disconnected, that is, to notify the OMC that the SSH function has been successfully closed. For example, the sixth indication message can be: v2x.obu.natSSH.status = 1.
[0175] Case 3: When the task information is the task information for transferring keys, performing a third operation according to the task information includes: uploading the public key of the CPE according to the first FTP address; downloading the public key of the SSH proxy server according to the second FTP address.
[0176] (4) When it is determined that the third operation is successfully executed, send a fourth indication message to the first server. The fourth indication message is used to indicate that the CPE has successfully executed the first task.
[0177] For example, when the third operation is key transfer, after the CPE finishes the two key transfer tasks, that is, after the CPE uploads the public key of the CPE to the specified path of the SSH proxy server and downloads the public key of the SSH proxy server, it can send a fourth indication message (such as the 7TransferComplete event) to the OMC through the TR069 channel respectively to notify the OMC that the task has been processed and has taken effect.
[0178] Again, for example, as Figure 4As shown in the figure, the third operation is to connect to the SSH proxy server, and the password authentication method is adopted to connect to the SSH proxy server. After the CPE executes the third operation, it can determine that the task has been successfully executed and has taken effect by checking the SSH process. At this time, the CPE initiates an active connection to the OMC and reports the second information to the OMC in the way of actively reporting nodes. Here, the second information may include the following content: the fourth indication information indicating that the SSH function has been enabled (that is, the CPE has successfully executed the first task), the username and password for logging in to the SSH proxy server, v2x.obu.natSSH.status is 1, v2x.obu.natSSH.user is root, and v2x.obu.natSSH.password is 1qaz2wsx. After receiving the fourth indication information, the OMC can detect the natSSH enabled state. After confirming the enabling, it uses ssh root@localhost -p 8000 to log in to the SSH proxy server, and the password is 1qaz2wsx.
[0179] For another example, as Figure 5 shown in the figure, the third operation is to connect to the SSH proxy server, and the key authentication method is adopted to connect to the SSH proxy server. After the CPE executes the third operation, it can determine that the task has been successfully executed and has taken effect by checking the SSH process. The CPE initiates an active connection to the OMC server and reports the second information to the OMC in the way of actively reporting nodes. Here, the second information may include the following content: the fourth indication information indicating that the SSH function has been enabled (that is, the CPE has successfully executed the first task) and the username, v2x.obu.natSSH.status is 1, v2x.obu.natSSH.user is root. After receiving the fourth indication information, the OMC can detect the natSSH enabled state. After confirming the enabling, it directly logs in using ssh root@localhost -p 8000.
[0180] Optionally, before sending the first information to the first server, the method further includes:
[0181] (1) Send a task request message to the first server through the TR069 channel. The task request message is used to request a connection to consume the first task.
[0182] For example, after establishing a TR069 channel between the CPE and the OMC, the CPE sends an inform request (i.e., a task request message) to the OMC, and the event code is: 6 connection request.
[0183] (2) Receive the authentication information fed back by the first server according to the task request message.
[0184] For example, the OMC replies with an informresponse (information response) according to the task request information, and the information response carries authentication information, which can indicate the permission level for the OMC to operate on the CPE.
[0185] (3) Determine whether the first server has the permission to operate on the CPE according to the authentication information.
[0186] In this embodiment, the CPE can determine whether the OMC has the permission to operate on the CPE according to the authentication information sent by the OMC.
[0187] Optionally, before performing the third operation according to the task information, the method further includes:
[0188] Feedback the fifth indication information to the first server according to the task information, where the fifth indication information is used to indicate that the CPE has received the task information.
[0189] For example, after receiving the task information, the CPE feeds back the fifth indication information with a status of 1 to the OMC, indicating that the task has been received and will be processed later, that is, it indicates that the CPE will process the task asynchronously.
[0190] In the embodiment of the present invention, by combining the SSH proxy, TR069 remote management technology, and STUN private network traversal technology, the automatic configuration and operation of remote access to the terminal after NAT are realized, avoiding a large number of manual operations by operation and maintenance personnel, saving personnel costs; making full use of the advantages of TR069 and STUN remote management, realizing batch remote management of NAT terminals, which is beneficial to realizing remote access management of terminals supporting the TR069 protocol.
[0191] Fourth Embodiment
[0192] As Figure 9 shown, an access device 900 for a terminal provided by an embodiment of the present invention is applied to a first server and includes:
[0193] An information acquisition module 901, configured to acquire first indication information, where the first indication information is used to indicate to perform a first operation on a user terminal device CPE located after network address translation (NAT), and the first operation includes at least one of the following: opening a Secure Shell (SSH) connection, closing the SSH connection, and transmitting a key;
[0194] A task generation module 902, configured to generate a first task according to the first indication information.
[0195] The first sending module 903 is configured to send second indication information to the second server, where the second indication information is used to indicate that the first server has generated a first task to be consumed, so that the second server sends third indication information to the CPE to indicate that there is a first task to be consumed on the first server;
[0196] The first communication module 904 is configured to establish communication with the CPE through the TR069 channel to access the CPE;
[0197] Wherein, the first server and the second server are in the public network.
[0198] In this embodiment, through the second server, it is possible to indicate to the CPE across the private network that there is a first task to be consumed on the first server, so that the CPE establishes a TR069 channel with the first server, realizes the establishment of communication between the first server and the CPE, and completes task consumption. In this way, based on the TR069 and STUN technologies, automatic management of remote access of devices behind NAT can be realized.
[0199] Optionally, the first communication module 904 includes:
[0200] The first receiving unit is configured to receive first information sent by the CPE through the TR069 channel, where the first information is used to request the first task from the first server;
[0201] The first sending unit is configured to send task information corresponding to the first task to the CPE according to the first information;
[0202] The second receiving unit is configured to receive fourth indication information sent by the CPE, where the fourth indication information is used to indicate that the CPE has successfully executed the first task;
[0203] The first execution unit is configured to execute a second operation corresponding to the first operation according to the fourth indication information;
[0204] Wherein, the second operation is one of the following:
[0205] When the first operation is to open an SSH connection, the second operation is: connect to the SSH proxy server;
[0206] When the first operation is to close the SSH connection, the second operation is: prompt that the connection between the CPE and the SSH proxy server has been disconnected;
[0207] When the first operation is to transfer a key, the second operation is: prompt that the key transfer is complete.
[0208] Optionally, the first communication module further includes:
[0209] A third receiving unit, configured to receive task request information sent by the CPE through the TR069 channel, where the task request information is used to request a connection to consume the first task;
[0210] A second sending unit, configured to send authentication information to the CPE according to the task request information.
[0211] Optionally, the task information includes one of the following:
[0212] SSH connection opening task information;
[0213] SSH connection closing task information;
[0214] Key transmission task information;
[0215] Wherein, the SSH connection opening task information includes at least one of the following: a custom method name, a task identifier, the Internet Protocol (IP) address of the SSH proxy server, the port assigned by the SSH proxy server to the CPE, the SSH authentication method, a username, and a password;
[0216] The SSH authentication method is password authentication or key authentication;
[0217] The key transmission task information includes at least one of the following: a transmission method name, a task identifier, a file type, the first File Transfer Protocol (FTP) address for storing the public key of the CPE, the second FTP address for storing the public key of the SSH proxy server, an FTP authentication username, and an FTP authentication password.
[0218] Optionally, the access device 900 further includes:
[0219] A third receiving module, configured to receive fifth indication information fed back by the CPE according to the task information, where the fifth indication information is used to indicate that the CPE has received the task information.
[0220] The fourth embodiment of the present invention corresponds to the method of the above first embodiment. All the implementation means in the above first embodiment are applicable to the embodiment of the access device of this terminal and can achieve the same technical effects.
[0221] Fifth Embodiment
[0222] As Figure 10 shown, an embodiment of the present invention provides an access device 1000 for a terminal, which is applied to a second server and includes:
[0223] The first receiving module 1001 is configured to receive second indication information sent by the first server, where the second indication information is used to indicate that the first server has generated a first task to be consumed;
[0224] The second sending module 1002 is configured to send third indication information to the CPE according to the second indication information, where the third indication information is used to indicate that there is a first task to be consumed on the first server;
[0225] Wherein, the first server and the second server are in the public network.
[0226] The fifth embodiment of the present invention corresponds to the method of the second embodiment above. All the implementation means in the second embodiment above are applicable to the embodiment of the access device of the terminal, and the same technical effect can be achieved.
[0227] Sixth embodiment
[0228] As Figure 11 shown, an access device 1100 of a terminal provided by an embodiment of the present invention is applied to a CPE and includes:
[0229] The second receiving module 1101 is configured to receive third indication information sent by the second server, where the third indication information is used to indicate that there is a first task to be consumed on the first server;
[0230] The channel establishing module 1102 is configured to establish a TR069 channel with the first server according to the third indication information;
[0231] The second communication module 1103 is configured to establish communication with the first server through the TR069 channel to consume the first task.
[0232] In this embodiment, by receiving the third indication information sent by the second server across the private network, it can be known that there is a first task to be consumed on the first server, so as to establish a TR069 channel between the CPE and the first server, realize the establishment of communication between the first server and the CPE, and complete task consumption. In this way, based on the TR069 and STUN technologies, automatic management of remote access of devices after NAT can be realized.
[0233] Optionally, the second communication module 1103 includes:
[0234] The third sending unit is configured to send first information to the first server through the TR069 channel when it is determined that the first server has the operation authority for the CPE, where the first information is used to request the first task from the first server;
[0235] A fourth receiving unit, configured to receive the task information corresponding to the first task sent by the first server;
[0236] A second execution unit, configured to perform a third operation according to the task information; the third operation includes at least one of the following: connecting to an SSH proxy server, closing an SSH process, and transmitting a key;
[0237] A fourth sending unit, configured to send fourth indication information to the first server when it is determined that the third operation is successfully executed, where the fourth indication information is used to indicate that the CPE has successfully executed the first task.
[0238] Optionally, the task information includes one of the following:
[0239] SSH connection opening task information;
[0240] SSH connection closing task information;
[0241] Key transmission task information;
[0242] Wherein, the SSH connection opening task information includes at least one of the following: a custom method name, a task identifier, the Internet Protocol (IP) address of the SSH proxy server, the port assigned by the SSH proxy server to the CPE, an SSH authentication method, a username, and a password;
[0243] The SSH authentication method is password authentication or key authentication;
[0244] The key transmission task information includes at least one of the following: a transmission method name, a task identifier, a file type, the File Transfer Protocol (FTP) address of the first file for storing the public key of the CPE, the second FTP address of the file for storing the public key of the SSH proxy server, an FTP authentication username, and an FTP authentication password.
[0245] Optionally, the second execution unit includes:
[0246] A first execution subunit, configured to generate an execution script according to the task information;
[0247] A second execution subunit, configured to execute the execution script and connect to the SSH proxy server.
[0248] Optionally, the second execution unit includes:
[0249] A third execution subunit, configured to close the SSH process.
[0250] Optionally, the second execution unit includes:
[0251] An upload subunit, configured to upload the public key of the CPE according to a first FTP address;
[0252] A download subunit, configured to download the public key of the SSH proxy server according to the second FTP address.
[0253] Optionally, the second communication module 1103 further includes:
[0254] A fifth sending unit, configured to send task request information to the first server through the TR069 channel, where the task request information is used to request a connection to consume the first task;
[0255] A fifth receiving unit, configured to receive authentication information fed back by the first server according to the task request information;
[0256] A first processing unit, configured to determine whether the first server has the operation authority over the CPE according to the authentication information.
[0257] Optionally, the second communication module 1103 further includes:
[0258] A sixth sending unit, configured to feed back fifth indication information to the first server according to the task information, where the fifth indication information is used to indicate that the CPE has received the task information.
[0259] The sixth embodiment of the present invention corresponds to the method of the third embodiment above. All the implementation means in the third embodiment above are applicable to the embodiment of the access device of the terminal and can achieve the same technical effects.
[0260] The seventh embodiment
[0261] To better achieve the above object, as Figure 12 shown, the seventh embodiment of the present invention further provides a server, where the server is a first server and includes:
[0262] A processor 1200; and a memory 1220 connected to the processor 1200 through a bus interface, where the memory 1220 is used to store programs and data used by the processor 1200 when performing operations, and the processor 1200 calls and executes the programs and data stored in the memory 1220.
[0263] Wherein, a transceiver 1210 is connected to the bus interface and is configured to receive and send data under the control of the processor 1200; the processor 1200 is configured to read the programs in the memory 1220 and execute the following steps:
[0264] Obtain first indication information, where the first indication information is used to indicate to perform a first operation on a customer premise equipment (CPE) after network address translation (NAT). The first operation includes at least one of the following: enabling a Secure Shell (SSH) connection, closing the SSH connection, and transmitting a key;
[0265] Generate a first task according to the first indication information;
[0266] Send second indication information to a second server, where the second indication information is used to indicate that the first server has generated a first task to be consumed, so that the second server sends third indication information indicating that there is a first task to be consumed on the first server to the CPE;
[0267] Establish communication with the CPE through a TR069 channel to access the CPE;
[0268] Wherein, the first server and the second server are in the public network.
[0269] In this embodiment, through the second server, it is possible to indicate to the CPE across the private network that there is a first task to be consumed on the first server, so that the CPE establishes a TR069 channel with the first server, realizes the establishment of communication between the first server and the CPE, and completes task consumption. In this way, based on the TR069 and STUN technologies, automatic management of remote access to devices after NAT can be achieved.
[0270] Wherein, in Figure 12 The bus architecture may include any number of interconnected buses and bridges, specifically various circuits of one or more processors represented by the processor 1200 and the memory represented by the memory 1220 are linked together. The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, so they will not be further described herein. The bus interface provides an interface. The transceiver 1210 may be multiple elements, that is, including a transmitter and a transceiver, and provides a unit for communicating with various other devices on the transmission medium. For different terminals, the user interface 1230 may also be an interface capable of externally connecting and internally connecting required devices, and the connected devices include but are not limited to a keypad, a display, a speaker, a microphone, a joystick, etc. The processor 1200 is responsible for managing the bus architecture and general processing, and the memory 1220 may store data used by the processor 1200 when performing operations.
[0271] Optionally, when the processor 1200 establishes communication with the CPE through the TR069 channel to access the CPE, it is specifically used for:
[0272] Receive the first information sent by the CPE through the TR069 channel, where the first information is used to request the first task from the first server;
[0273] According to the first information, send the task information corresponding to the first task to the CPE;
[0274] Receive the fourth indication information sent by the CPE, where the fourth indication information is used to indicate that the CPE has successfully executed the first task;
[0275] According to the fourth indication information, perform the second operation corresponding to the first operation;
[0276] Wherein, the second operation is one of the following:
[0277] When the first operation is to open an SSH connection, the second operation is: connect to the SSH proxy server;
[0278] When the first operation is to close the SSH connection, the second operation is: prompt the CPE that the connection to the SSH proxy server has been disconnected;
[0279] When the first operation is to transfer a key, the second operation is: prompt that the key transfer is complete.
[0280] Optionally, the processor 1200 is further configured to:
[0281] Receive the task request information sent by the CPE through the TR069 channel, where the task request information is used to request a connection to consume the first task;
[0282] According to the task request information, send the authentication information to the CPE.
[0283] Optionally, the task information includes one of the following:
[0284] Task information for opening an SSH connection;
[0285] Task information for closing an SSH connection;
[0286] Task information for transferring a key;
[0287] Wherein, the task information for opening an SSH connection includes at least one of the following: a custom method name, a task identifier, the Internet Protocol (IP) address of the SSH proxy server, the port assigned by the SSH proxy server to the CPE, the SSH authentication method, a username, and a password;
[0288] The SSH authentication method is password authentication or key authentication;
[0289] The transmission key task information includes at least one of the following: transmission method name, task identifier, file type, the first File Transfer Protocol (FTP) address storing the public key of the CPE, the second FTP address storing the public key of the SSH proxy server, FTP authentication username, and FTP authentication password.
[0290] Optionally, the processor 1200 is further configured to:
[0291] Receive fifth indication information fed back by the CPE according to the task information, where the fifth indication information is used to indicate that the CPE has received the task information.
[0292] The first server provided by the present invention can, through a second server, indicate to the CPE across a private network that there is a first task to be consumed on the first server, so that the CPE establishes a TR069 channel with the first server, realizes communication between the first server and the CPE, and completes task consumption. Thus, based on the TR069 and STUN technologies, automatic management of remote access to devices behind NAT can be achieved.
[0293] Eighth Embodiment
[0294] To better achieve the above object, the eighth embodiment of the present invention further provides a server. The server is a second server and may adopt the same structure as the first server in the seventh embodiment. As Figure 12 shown, it includes:
[0295] A processor 1200; and a memory 1220 connected to the processor 1200 through a bus interface. The memory 1220 is used to store programs and data used by the processor 1200 when performing operations. The processor 1200 calls and executes the programs and data stored in the memory 1220.
[0296] Wherein, a transceiver 1210 is connected to the bus interface and is used to receive and send data under the control of the processor 1200. The processor 1200 is used to read the programs in the memory 1220 and execute the following steps:
[0297] Receive second indication information sent by the first server, where the second indication information is used to indicate that the first server has generated a first task to be consumed;
[0298] According to the second indication information, send third indication information to the CPE, where the third indication information is used to indicate that there is a first task to be consumed on the first server;
[0299] Wherein, the first server and the second server are in a public network.
[0300] Wherein, inFigure 12 Among them, the bus architecture may include any number of interconnected buses and bridges, specifically, various circuits represented by one or more processors represented by the processor 1200 and the memory represented by the memory 1220 are linked together. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, etc., which are well known in the art, so they will not be further described herein. The bus interface provides an interface. The transceiver 1210 may be multiple components, that is, including a transmitter and a transceiver, and provides a unit for communicating with various other devices on the transmission medium. For different terminals, the user interface 1230 may also be an interface capable of externally connecting and internally connecting required devices, and the connected devices include but are not limited to a keypad, a display, a speaker, a microphone, a joystick, etc. The processor 1200 is responsible for managing the bus architecture and general processing, and the memory 1220 may store data used by the processor 1200 when executing operations.
[0301] The second server provided by the present invention can indicate to the CPE across the private network that there is a first task to be consumed on the first server, so that the CPE establishes a TR069 channel with the first server, realizes the establishment of communication between the first server and the CPE, and completes task consumption. In this way, based on the TR069 and STUN technologies, automatic management of remote access of devices behind the NAT can be achieved.
[0302] The Ninth Embodiment
[0303] To better achieve the above object, as Figure 13 shown, the ninth embodiment of the present invention further provides a CPE, including:
[0304] A processor 1300; and a memory 1320 connected to the processor 1300 through a bus interface, where the memory 1320 is used to store programs and data used by the processor 1300 when executing operations, and the processor 1300 calls and executes the programs and data stored in the memory 1320.
[0305] Among them, the transceiver 1310 is connected to the bus interface and is used to receive and send data under the control of the processor 1300; the processor 1300 is used to read the program in the memory 1320 and execute the following steps:
[0306] Receive the third indication information sent by the second server, where the third indication information is used to indicate that there is a first task to be consumed on the first server;
[0307] According to the third indication information, establish a TR069 channel with the first server;
[0308] Establish communication with the first server through the TR069 channel and consume the first task.
[0309] In this embodiment, by receiving the third indication information sent by the second server across the private network, it can be known that there is a first task to be consumed on the first server, so as to establish a TR069 channel between the CPE and the first server, realize the establishment of communication between the first server and the CPE, and complete task consumption. In this way, based on the TR069 and STUN technologies, automatic management of remote access of devices behind NAT can be realized.
[0310] Among them, in Figure 13 the bus architecture may include any number of interconnected buses and bridges, specifically various circuits represented by one or more processors represented by processor 1300 and a memory represented by memory 1320 are linked together. The bus architecture can also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art, so they will not be further described herein. The bus interface provides an interface. The transceiver 1310 may be multiple elements, that is, including a transmitter and a transceiver, and provides a unit for communicating with various other devices on the transmission medium. For different terminals, the user interface 1330 may also be an interface capable of externally connecting or internally connecting required devices, and the connected devices include but are not limited to a keypad, a display, a speaker, a microphone, a joystick, etc. The processor 1300 is responsible for managing the bus architecture and general processing, and the memory 1320 can store the data used by the processor 1300 when executing operations.
[0311] Optionally, when the processor 1300 establishes communication with the first server through the TR069 channel and consumes the first task, it is specifically used for:
[0312] When it is determined that the first server has the operation permission for the CPE, send a first message to the first server through the TR069 channel, where the first message is used to request the first task from the first server;
[0313] Receive the task information corresponding to the first task sent by the first server;
[0314] According to the task information, perform a third operation; the third operation includes at least one of the following: connecting to an SSH proxy server, closing the SSH process, and transmitting a key;
[0315] When it is determined that the third operation is successfully executed, send a fourth indication message to the first server, where the fourth indication message is used to indicate that the CPE has successfully executed the first task.
[0316] Optionally, the task information includes one of the following:
[0317] Task information for enabling an SSH connection;
[0318] Task information for closing an SSH connection;
[0319] Task information for transferring keys;
[0320] Among them, the task information for enabling an SSH connection includes at least one of the following: a custom method name, a task identifier, the Internet Protocol (IP) address of the SSH proxy server, the port assigned by the SSH proxy server to the CPE, the SSH authentication method, a username, and a password;
[0321] The SSH authentication method is password authentication or key authentication;
[0322] The task information for transferring keys includes at least one of the following: a transfer method name, a task identifier, a file type, the first File Transfer Protocol (FTP) address for storing the public key of the CPE, the second FTP address for storing the public key of the SSH proxy server, an FTP authentication username, and an FTP authentication password.
[0323] Optionally, when the processor 1300 performs the third operation according to the task information, it is specifically configured to:
[0324] Generate an execution script according to the task information;
[0325] Execute the execution script to connect to the SSH proxy server.
[0326] Optionally, when the processor 1300 performs the third operation according to the task information, it is specifically configured to:
[0327] Close the SSH process.
[0328] Optionally, when the processor 1300 performs the third operation according to the task information, it is specifically configured to:
[0329] Upload the public key of the CPE according to the first FTP address;
[0330] Download the public key of the SSH proxy server according to the second FTP address.
[0331] Optionally, the processor 1300 is further configured to:
[0332] Send task request information to the first server through the TR069 channel, where the task request information is used to request a connection to consume the first task;
[0333] Receive the authentication information fed back by the first server according to the task request information;
[0334] Determine whether the first server has the operation authority for the CPE according to the authentication information.
[0335] Optionally, the processor 1300 is further configured to:
[0336] Feed back fifth indication information to the first server according to the task information, where the fifth indication information is used to indicate that the CPE has received the task information.
[0337] The CPE provided by the present invention can learn that there is a first task to be consumed on the first server by receiving the third indication information sent by the second server across the private network, thereby establishing a TR069 channel between the CPE and the first server, realizing the establishment of communication between the first server and the CPE, and completing task consumption. In this way, based on the TR069 and STUN technologies, automatic management of remote access of devices behind NAT can be achieved.
[0338] Those skilled in the art can understand that all or part of the steps of implementing the above embodiments can be completed by hardware, or can be completed by instructing relevant hardware through a computer program. The computer program includes instructions for executing part or all of the steps of the above methods; and the computer program can be stored in a readable storage medium, and the storage medium can be any form of storage medium.
[0339] In addition, a specific embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the steps of the method in the first embodiment as described above, or implements the steps of the method in the second embodiment as described above, or implements the steps of the method in the third embodiment as described above. And it can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0340] In addition, it should be noted that in the device and method of the present invention, obviously, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present invention. And the steps of performing the above series of processes can naturally be executed in chronological order according to the described order, but it is not necessary to execute in chronological order. Some steps can be executed in parallel or independently of each other. For those of ordinary skill in the art, it can be understood that all or any steps or components of the method and device of the present invention can be implemented in any computing device (including a processor, a storage medium, etc.) or a network of computing devices in the form of hardware, firmware, software, or a combination thereof, which can be achieved by those of ordinary skill in the art using their basic programming skills after reading the description of the present invention.
[0341] Therefore, the object of the present invention can also be achieved by running a program or a set of programs on any computing device. The computing device can be a well-known general-purpose device. Therefore, the object of the present invention can also be achieved only by providing a program product containing program code for implementing the method or device. That is to say, such a program product also constitutes the present invention, and a storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any well-known storage medium or any storage medium developed in the future. It should also be pointed out that in the device and method of the present invention, obviously, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present invention. And, the steps of performing the above series of processes can naturally be executed in chronological order according to the described order, but it is not necessary to be executed in chronological order. Some steps can be executed in parallel or independently of each other.
[0342] The above is the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present invention.
Claims
1. An access method for a terminal, characterized in that, Applied to a first server, including: Obtain first indication information, where the first indication information is used to indicate to perform a first operation on a customer premise equipment (CPE) located after network address translation (NAT), and the first operation includes at least one of the following: opening a Secure Shell (SSH) connection, closing the SSH connection, and transmitting a key; Generate a first task according to the first indication information; Send second indication information to a second server, where the second indication information is used to indicate that the first server has generated a first task to be consumed, so that the second server sends third indication information indicating that there is a first task to be consumed on the first server to the CPE through the Session Traversal Utilities for NAT (STUN) network protocol; Establish communication with the CPE through a TR069 channel to access the CPE; Wherein, the first server and the second server are in a public network, the first server is an operation and maintenance center (OMC) or an auto-configuration server (ACS), and the second server is a STUN server or a server based on the User Datagram Protocol (UDP) or Transmission Control Protocol (TCP); 2. The method according to claim 1, wherein The establishing communication with the CPE through a TR069 channel to access the CPE includes: Receive first information sent by the CPE through the TR069 channel, where the first information is used to request the first task from the first server; Send task information corresponding to the first task to the CPE according to the first information; Receive fourth indication information sent by the CPE, where the fourth indication information is used to indicate that the CPE has successfully executed the first task; Execute a second operation corresponding to the first operation according to the fourth indication information; Wherein, the second operation is one of the following: When the first operation is to open an SSH connection, the second operation is: connect to an SSH proxy server; When the first operation is to close the SSH connection, the second operation is: prompt that the connection between the CPE and the SSH proxy server has been disconnected; When the first operation is to transmit a key, the second operation is: prompt that the key transmission is complete; 3. The method according to claim 2, wherein Before receiving the first information sent by the CPE through the TR069 channel, the method further includes: Receive task request information sent by the CPE through the TR069 channel, where the task request information is used to request a connection to consume the first task; Send authentication information to the CPE according to the task request information; 4. The method according to claim 2, wherein The task information includes one of the following: Task information for opening an SSH connection; Task information for closing an SSH connection; Task information for transmitting a key; Wherein, the task information for opening an SSH connection includes at least one of the following: a custom method name, a task identifier, the Internet Protocol (IP) address of the SSH proxy server, the port assigned by the SSH proxy server to the CPE, the SSH authentication method, a username, and a password; The SSH authentication method is password authentication or key authentication; The transmission key task information includes at least one of the following: transmission method name, task identifier, file type, the first File Transfer Protocol (FTP) address for storing the public key of the CPE, the second FTP address for storing the public key of the SSH proxy server, FTP authentication username, and FTP authentication password.
5. The method according to claim 2, characterized in that, It further includes: Receiving fifth indication information fed back by the CPE according to the task information, where the fifth indication information is used to indicate that the CPE has received the task information.
6. A method for accessing a terminal, characterized in that, Applied to a second server, it includes: Receiving second indication information sent by a first server, where the second indication information is used to indicate that the first server has generated a first task to be consumed; According to the second indication information, sending third indication information to the CPE via the STUN network protocol, where the third indication information is used to indicate that there is a first task to be consumed on the first server; Wherein, the first server and the second server are in the public network, the first server is an Operation and Maintenance Center (OMC) or an Auto Configuration Server (ACS), and the second server is a STUN server or a server based on the UDP or TCP protocol.
7. A method for accessing a terminal, characterized in that Applied to the CPE, it includes: Receiving third indication information sent by the second server via the STUN network protocol, where the third indication information is used to indicate that there is a first task to be consumed on the first server; According to the third indication information, establishing a TR069 channel with the first server; Establishing communication with the first server via the TR069 channel to consume the first task; Wherein, the first server and the second server are in the public network, the first server is an Operation and Maintenance Center (OMC) or an Auto Configuration Server (ACS), and the second server is a STUN server or a server based on the UDP or TCP protocol.
8. The method according to claim 7, characterized in that, The establishing communication with the first server via the TR069 channel to consume the first task includes: When it is determined that the first server has the operation permission for the CPE, sending first information to the first server via the TR069 channel, where the first information is used to request the first task from the first server; Receiving the task information corresponding to the first task sent by the first server; According to the task information, performing a third operation; the third operation includes at least one of the following: connecting to the SSH proxy server, closing the SSH process, and transmitting the key; When it is determined that the third operation is successfully executed, sending fourth indication information to the first server, where the fourth indication information is used to indicate that the CPE has successfully executed the first task.
9. The method according to claim 8, characterized in that, The task information includes one of the following: SSH connection opening task information; SSH connection closing task information; Transmission key task information; Wherein, the SSH connection opening task information includes at least one of the following: custom method name, task identifier, Internet Protocol (IP) address of the SSH proxy server, port assigned by the SSH proxy server to the CPE, SSH authentication method, username, and password; The SSH authentication method is password authentication or key authentication; The transmitted key task information includes at least one of the following: the name of the transmission method, the task identifier, the file type, the first File Transfer Protocol (FTP) address for storing the public key of the CPE, the second FTP address for storing the public key of the SSH proxy server, the FTP authentication username, and the FTP authentication password.
10. The method according to claim 9, wherein When the task information is the task information for opening an SSH connection, the performing of the third operation according to the task information includes: Generating an execution script according to the task information; Executing the execution script to connect to the SSH proxy server.
11. The method according to claim 9, wherein When the task information is the task information for closing an SSH connection, the performing of the third operation according to the task information includes: Closing the SSH process.
12. The method according to claim 9, wherein When the task information is the transmitted key task information, the performing of the third operation according to the task information includes: Uploading the public key of the CPE according to the first FTP address; Downloading the public key of the SSH proxy server according to the second FTP address.
13. The method according to claim 8, wherein Before sending the first information to the first server, the method further includes: Sending task request information for requesting a connection to consume the first task to the first server through the TR069 channel; Receiving the authentication information fed back by the first server according to the task request information; Determining whether the first server has the operation permission for the CPE according to the authentication information.
14. The method according to claim 8, characterized in that, Before performing the third operation according to the task information, the method further includes: Feeding back fifth indication information to the first server according to the task information, where the fifth indication information is used to indicate that the CPE has received the task information.
15. A server, comprising: A transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the access method of the terminal as described in any one of claims 1 to 5 are implemented, or when the processor executes the computer program, the steps of the access method of the terminal as described in claim 6 are implemented.
16. A CPE, comprising: A transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the access method of the terminal as described in any one of claims 7 to 14 are implemented.
17. An access device for a terminal, characterized in that, Applied to a first server, it includes: An information acquisition module, configured to acquire first indication information, where the first indication information is used to indicate performing a first operation on a customer premises equipment (CPE) after network address translation (NAT), and the first operation includes at least one of the following: opening a Secure Shell (SSH) connection, closing the SSH connection, and transmitting a key; A task generation module, configured to generate a first task according to the first indication information; A first sending module, configured to send second indication information to a second server, where the second indication information is used to indicate that the first server has generated a first task to be consumed, so that the second server sends third indication information indicating that there is a first task to be consumed on the first server to the CPE through the STUN network protocol; A first communication module, configured to establish communication with the CPE through the TR069 channel to access the CPE; Wherein, the first server and the second server are in the public network, the first server is an operation and maintenance center OMC or an auto-configuration server ACS, and the second server is a STUN server or a server based on the UDP or TCP protocol.
18. An access device for a terminal, characterized in that, Applied to the second server, including: A first receiving module, configured to receive the second indication information sent by the first server, where the second indication information is used to indicate that the first server has generated a first task to be consumed; A second sending module, configured to send third indication information to the CPE through the STUN network protocol according to the second indication information, where the third indication information is used to indicate that there is a first task to be consumed on the first server; Wherein, the first server and the second server are in the public network, the first server is an operation and maintenance center OMC or an auto-configuration server ACS, and the second server is a STUN server or a server based on the UDP or TCP protocol.
19. An access device for a terminal, characterized in that, Applied to the CPE, including: A second receiving module, configured to receive the third indication information sent by the second server through the STUN network protocol, where the third indication information is used to indicate that there is a first task to be consumed on the first server; A channel establishment module, configured to establish a TR069 channel with the first server according to the third indication information; A second communication module, configured to establish communication with the first server through the TR069 channel to consume the first task; Wherein, the first server and the second server are in the public network, the first server is an operation and maintenance center OMC or an auto-configuration server ACS, and the second server is a STUN server or a server based on the UDP or TCP protocol.
20. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the access method of the terminal according to any one of claims 1 to 5, or implements the steps of the access method of the terminal according to claim 6, or implements the steps of the access method of the terminal according to any one of claims 7 to 14.
Citation Information
Patent Citations
Client terminal device management method and system, and automatic configuration server
CN107465529A
Remote access method and device, electronic equipment and storage medium
CN113259344A