A remote communication method and apparatus
A virtual tunnel dedicated network using container images and VPS servers allows secure, cost-effective access across LANs, overcoming the limitations of private IP addresses and security risks in existing port mapping methods.
Patent Information
- Application Number
- CN202211598068.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-13
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-12-13
AI Technical Summary
In the prior art, LAN terminals cannot conveniently access other LAN terminals across networks, and the Internet IP address is limited and the application process is complicated, resulting in temporary or short-term access difficulties, and port mapping has security risks.
Build a container image of the virtual tunnel dedicated network function on the LAN terminal, use the docker component to bind the port, and establish a communication link through the VPS server to achieve full IP access.
It realizes full IP access across local area networks, which is simple to operate and low cost, and uses encryption technology to ensure communication security.
Smart Images

Figure CN116248436B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technologies, and in particular, to a remote communication method and apparatus. Background Art
[0002] With the rapid development of Internet technologies, the network space has been divided into various complex network structures such as wide area networks, metropolitan area networks, and local area networks. For example Figure 1 There are a large number of network units of types such as local area network regions A, B, C, etc. The local area network has well solved the problem of limited IP addresses, but it also brings the limitation that access can only be made by terminals within the "network". In the current context of the epidemic, online work has become the norm, and how to enable any terminal in local area network region A to access all terminals in local area network region B has become a practical problem that urgently needs to be solved.
[0003] Conventional solutions require the person in charge of the first local area network to purchase Internet addresses from a communication supervision unit or an operator, then bind the addresses to the router, and finally perform port mapping on the router or deploy other devices at the entrance.
[0004] However, the number of Internet IP addresses is limited, the distribution and authorization of private Internet IPs are restricted, and the cost of applying for private Internet IP addresses is relatively high, and the application process is rather troublesome, which is not suitable for application scenarios that are used temporarily or for a short time.
[0005] In addition, if a private Internet IP is applied for, without the aid of other special devices, port mapping can only be performed on the router. This method can first only map the ports of certain specified terminal devices in the local area network to the Internet. Users in the second local area network can only access the specified ports and cannot access any device in the first local area network in the form of a full IP. Moreover, using port mapping will expose the entire business system of the first local area network to the Internet, bringing great security risks. Summary of the Invention
[0006] The present invention aims to at least solve one of the technical problems existing in the prior art.
[0007] To this end, a first aspect of the present invention proposes a remote communication method, which is applied to a first terminal in a first local area network, and the first terminal is any terminal in the first local area network. The method includes:
[0008] Construct a container image with virtual private network (VPN) function on the first terminal;
[0009] Run the container image using the pre-installed docker component on the first terminal, and bind the first port of the first terminal to the second port of the container image to build a first communication link between the first port of the first terminal and the second port of the container image;
[0010] Initiate a connection to the VPS server using the container image or the first terminal to establish a communication connection with the VPS server; the VPS server is a cloud server with the SSH service enabled;
[0011] Forward the second port of the container image to the third port of the VPS server to build a second communication link between the second port of the container image and the third port of the VPS server;
[0012] Receive the request data packet forwarded by the VPS server using the second communication link, where the request data packet is sent by the second terminal to the VPS server; the second terminal is any terminal located in the second local area network; the destination address of the request data packet is the third terminal in the first local area network;
[0013] Obtain the destination address of the request data packet, and forward the request data packet to the third terminal through the container image using the first communication link.
[0014] Optionally, building a container image with virtual tunnel private network function on the first terminal includes:
[0015] Use the OpenVPN software to build a container image vpnserver.tar with virtual tunnel private network function.
[0016] Optionally, the number of the first port, the second port, and the third port is at least one. The first port is an unoccupied communication port of the first terminal, the second port is an unoccupied communication port of the container image, and the third port is an unoccupied communication port of the VPS server.
[0017] Optionally, the unoccupied communication ports of the first terminal and the unoccupied communication ports of the container image both include port 6943 and port 6443. The binding of the first port of the first terminal to the second port of the container image includes:
[0018] Bind the 6943 port of the first terminal and the 6943 port of the container image respectively, and bind the 6443 port of the first terminal and the 6443 port of the container image.
[0019] Optionally, the number of the third ports is at least one. The forwarding of the second port of the container image to the third port of the VPS server includes:
[0020] Forwarding the 6943 port of the container image to the 6943 port of the VPS server and forwarding the 6443 port of the container image to the 6443 port of the VPS server respectively.
[0021] Optionally, the first terminal and the third terminal are respectively any terminal among a computer, a server, a smart phone, and a laptop located in the first local area network, and the second terminal is any terminal among a computer, a server, a smart phone, and a laptop located in the second local area network.
[0022] A second aspect of the present invention provides a remote communication device, which is applied to a first terminal in a first local area network. The first terminal is any terminal in the first local area network. The device includes:
[0023] A construction module, configured to construct a container image with a virtual tunnel private network function on the first terminal;
[0024] A binding module, configured to run the container image by using a docker component pre-installed on the first terminal, and bind a first port of the first terminal to a second port of the container image, so as to construct a first communication link between the first port of the first terminal and the second port of the container image;
[0025] A connection module, configured to initiate a connection to a VPS server by using the container image or the first terminal, so as to establish a communication connection with the VPS server; the VPS server is a cloud server with an SSH service enabled;
[0026] A first forwarding module, configured to forward the second port of the container image to the third port of the VPS server, so as to construct a second communication link between the second port of the container image and the third port of the VPS server;
[0027] A receiving module, configured to receive a request data packet forwarded by the VPS server by using the second communication link. The request data packet is sent by a second terminal to the VPS server; the second terminal is any terminal in a second local area network; the destination address of the request data packet is a third terminal in the first local area network;
[0028] A second forwarding module, configured to obtain the destination address of the request data packet, and forward the request data packet to the third terminal through the container image by using the first communication link.
[0029] Optionally, the building module is specifically configured to:
[0030] Use the OpenVPN software to build a container image vpnserver.tar with the function of a virtual tunnel private network.
[0031] Optionally, the binding module is specifically configured to:
[0032] Bind the 6943 port of the first terminal and the 6943 port of the container image respectively, and bind the 6443 port of the first terminal and the 6443 port of the container image.
[0033] Optionally, the first forwarding module is specifically configured to:
[0034] Forward the 6943 port of the container image to the 6943 port of the VPS server respectively, and forward the 6443 port of the container image to the 6443 port of the VPS server.
[0035] A fifth aspect of the present invention provides an electronic device, which includes a processor and a memory. At least one instruction, at least one program, a code set or an instruction set is stored in the memory, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by the processor to implement the remote communication method as described in the first aspect.
[0036] A sixth aspect of the present invention provides a computer-readable storage medium, in which at least one instruction, at least one program, a code set or an instruction set is stored, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by a processor to implement the remote communication method as described in the first aspect.
[0037] The embodiments of the present invention have the following beneficial effects:
[0038] Build a container image with the function of virtual tunnel private network on the first terminal; use the pre-installed docker component on the first terminal to run the container image, and bind the first port of the first terminal to the second port of the container image to build a first communication link between the first port of the first terminal and the second port of the container image; use the container image or the first terminal to initiate a connection to the VPS server to establish a communication connection with the VPS server; the VPS server is a cloud server with the SSH service enabled; forward the second port of the container image to the third port of the VPS server to build a second communication link between the second port of the container image and the third port of the VPS server; receive the request data packet forwarded by the VPS server through the second communication link, and the request data packet is sent by the second terminal to the VPS server; the second terminal is any terminal located in the second local area network; the destination address of the request data packet is the third terminal in the first local area network; obtain the destination address of the request data packet, and forward the request data packet to the third terminal through the container image using the first communication link. This solution constructs a link to access any terminal in the first local area network through the first terminal by using a container image with the function of virtual tunnel private network, and constructs a link that can access the first terminal from the external network by using the VPS server. In this way, the second terminal located in the external network can access any terminal in the first local area network in the form of full IP through the VPS server and the container image. The above construction is simple and low-cost, and uses the encryption technology of the virtual tunnel private network to ensure the security of the communication link.
[0039] Additional aspects and advantages of the present invention will be given in part in the following description, become apparent in part from the following description, or be understood through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions of the present invention, the drawings required for use in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings without creative efforts.
[0041] Figure 1 It is a schematic diagram of the local area network network structure in the prior art;
[0042] Figure 2 It is a schematic diagram of the local area network network structure provided by an embodiment of the present invention;
[0043] Figure 3 It is a flowchart of the steps of a remote communication method provided by an embodiment of the present invention;
[0044] Figure 4 This is a structural block diagram of a remote communication device provided by an embodiment of the present invention. Detailed implementation manners
[0045] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0046] This specification provides method operation steps as described in the embodiments or flowcharts, but may include more or fewer operation steps based on routine or non-creative efforts. When actually executed in a system or server product, it may be executed in the order shown in the embodiments or the drawings or in parallel (for example, in an environment of parallel processors or multi-threaded processing).
[0047] Figure 1 This is a schematic diagram of the local area network structure in the prior art.
[0048] As Figure 1 shown, the first local area network and the second local area network are common home networks or enterprise networks, and each network includes a router, a firewall, and terminal devices such as computers, smartphones, and laptops.
[0049] The inventor found during the research on related technologies that since the router at the entrance of the local area network uses address translation technology, any target in the Internet area can be accessed in the local area network area, while devices such as laptops, computers, and smartphones in the local area network area cannot be accessed from the Internet area.
[0050] This network structure well protects the security of devices and terminals in the local area network area. This is because the Internet area uses Internet addresses, commonly known as public network addresses, while the local area network area uses private addresses, commonly known as local area network addresses. In the entire network space, the addresses in the local area network are allowed to repeat, and in real life, most are local area network networks.
[0051] For example Figure 1There will be a large number of network units of similar types such as the first local area network, the second local area network, etc. For example, the home networks of each of our families, most enterprise networks, etc. Since the number of Internet addresses is limited, the allocation rights of such addresses are generally held by cloud providers, operators, communication management units, etc., and most users cannot directly allocate and directly use them. With online office becoming the norm currently, how to enable any terminal in the second local area network to access all terminals in the first local area network has become a difficult point.
[0052] The conventional solution requires the person in charge of the first local area network to purchase Internet addresses from the communication regulatory unit or the operator, then bind the addresses to the router, and finally perform port mapping on the router or deploy other devices at the entrance to enable access. However, due to the limited number of Internet IP addresses, the issuance and authorization of Internet IPs are restricted; secondly, generally, the application process for using Internet IPs by communication regulatory units is rather cumbersome and not suitable for temporary or short-term usage scenarios.
[0053] Assuming there is a private Internet IP and without relying on other special devices, only port mapping can be done on the router. Only the ports of some specified terminal devices in the local area network can be mapped to the Internet. Users in the second local area network can only access the specified ports and cannot access any device in the first local area network in the form of full IP. Secondly, if port mapping is used, the business system will be exposed to the entire Internet, indirectly bringing great security risks.
[0054] Figure 2 Schematic diagram of the local area network structure provided by the embodiment of the present invention.
[0055] As Figure 2 shown, this local area network structure includes the first local area network, the second local area network, and other local area networks. In this solution, a cloud host is added to the Internet, and through relevant settings for any terminal in the first local area network, this solution can solve the problem that no matter how many users like user A in the second local area network and no matter where they are geographically located, as long as they can access the Internet, they can easily access any terminal device or servers A, B, C... etc. in local area B in the form of full IP and full port, and the access method is exactly the same as the access form in the second local area network.
[0056] The specific implementation method of this solution will be described in detail below based on Figure 3 the step methods in
[0057] Figure 3The flowchart of steps of a remote communication method provided by an embodiment of the present invention. This method is applied to a first terminal in a first local area network, and the first terminal is any terminal in the first local area network. The method includes the following steps:
[0058] Step 101, build a container image with virtual tunnel private network function on the first terminal.
[0059] The first terminal can be a terminal device located in any local area network. Refer to Figure 2 , for example, the first terminal can be server A in the first local area network.
[0060] A Virtual Private Network (VPN) relies on Internet Service Providers (ISPs) and other Network Service Providers (NSPs) to establish a dedicated data communication network technology in the public network, which can provide secure data transmission tunnel services between enterprises or between individuals and enterprises. There is no end-to-end physical link required for a traditional private network between any two points in a VPN. Instead, it is dynamically composed of public network resources and is implemented by borrowing the public Internet network.
[0061] A container image contains a packaged application, its dependencies, and the process information it runs when starting up. A container image can be created by providing a set of instructions in a special format.
[0062] Here, any software with virtual tunnel private network function can be selected to build a container image with virtual tunnel private network function on the first terminal.
[0063] In a possible implementation manner, building a container image with virtual tunnel private network function on the first terminal includes:
[0064] Use OpenVPN software to build a container image vpnserver.tar with virtual tunnel private network function.
[0065] In the embodiment of the present invention, OpenVPN is an open-source VPN under Linux, which provides good performance and a friendly user GUI. It makes extensive use of the SSLv3 / TLSv1 protocol function library in the OpenSSL encryption library. OpenVPN can run on Solaris, Linux, Mac OS X, Microsoft Windows, Android, and iOS, and includes many security functions.
[0066] By operating the OpenVPN software, a container image vpnserver.tar with the function of a virtual tunnel private network is constructed.
[0067] Step 102: Use the pre-installed docker component on the first terminal to run the container image, and bind the first port of the first terminal to the second port of the container image to construct a first communication link between the first port of the first terminal and the second port of the container image.
[0068] Docker is an open-source application container engine that allows developers to package their applications and dependencies into a portable image, and then publish it to any machine with a popular Linux or Windows operating system, and virtualization can also be achieved. Containers use a sandbox mechanism completely and there will be no interfaces between them.
[0069] Pre-install the docker component on the first terminal and execute the response docker command to import the container image in step 101.
[0070] For example, execute the command:
[0071] docker import vpnserver.tar vpnserver:latest
[0072] Thus, the container image vpnserver.tar can be imported.
[0073] Then, execute the docker command to bind the first port of the first terminal to the second port of the container image through command parameters.
[0074] For example, execute the following docker command:
[0075] docker run–itd–p first port:second port–privileged = true vpnserver / usr / sbin / init
[0076] Among them, the first port is the port of the first terminal, and the second port is the port of the container image, so that the first port of the first terminal can be bound to the second port of the container image. In this way, a first communication link between the first port of the first terminal and the second port of the container image is constructed.
[0077] Among them, in order to ensure the timeliness of data transmission on the first communication link, the first port and the second port are respectively communication ports that are not occupied or used by the first terminal and the container image currently.
[0078] In this solution, since there is a VPN service in Docker, the communication ports of the first terminal and the container image are bound, which is equivalent to building a reverse virtual private network that can access the entire local area network where the first terminal is located. That is, as long as the first terminal receives a data request from the Internet, it can forward the data request to any terminal in the first local area network through the VPN service.
[0079] In a possible implementation manner, the currently unoccupied communication ports of the first terminal and the currently unoccupied communication ports of the container image both include port 6943 and port 6443. The binding of the first port of the first terminal to the second port of the container image includes:
[0080] Bind the 6943 port of the first terminal and the 6943 port of the container image respectively, and bind the 6443 port of the first terminal and the 6443 port of the container image.
[0081] Specifically, the following Docker command can be executed:
[0082] docker run–itd–p6943:6943–p6443:6443–privileged=true vpnserver / usr / sbin / init
[0083] Among them, the first 6943 is the port of the first terminal, the second 6943 is the port of the container image, the first 6443 is the port of the first terminal, and the second 6443 is the port of the container image. Thus, the 6943 port of the first terminal and the 6943 port of the container image can be bound, and the 6443 port of the first terminal and the 6443 port of the container image can be bound.
[0084] Step 103: Use the container image or the first terminal to initiate a connection to the VPS server to establish a communication connection with the VPS server; the VPS server is a cloud server with the SSH service enabled.
[0085] A VPS server (Virtual Private Server) is to create multiple isolated small servers on a physical server using virtual server software. Each VPS server can be restarted independently and has its own root access rights, users, IP addresses, memory, processes, files, application programs, system function libraries, and configuration files. VPS servers have unique advantages in cost savings.
[0086] It is possible to apply for temporary use of a VPS server at an Internet cloud service provider. Such VPS servers are inexpensive and very easy to apply for. After the SSH service of the VPS server's open link is enabled, it can be accessed by any local area network address.
[0087] SSH (Secure Shell, a security protocol) is a security protocol built on top of the application layer. SSH is a relatively reliable protocol that provides security for remote login sessions and other network services. Using the SSH protocol can effectively prevent information leakage problems during remote management.
[0088] After the SSH service of the VPS server is set up, the container image or the first terminal in the reverse virtual machine private network in the local area network initiates a connection to the VPS server to establish a communication connection with the VPS server.
[0089] Step 104: Forward the second port of the container image to the third port of the VPS server to construct a second communication link between the second port of the container image and the third port of the VPS server.
[0090] Through the autossh command, forward the second port of the container image to the third port of the VPS server. In this way, the VPS server monitors the ssh reverse proxy port (i.e., the second port of the container image) with a specific port (i.e., the third port), thereby achieving a stable communication connection.
[0091] In a possible implementation, the number of the third ports is at least one, and the forwarding of the second port of the container image to the third port of the VPS server includes:
[0092] Forward the 6943 port of the container image to the 6943 port of the VPS server and forward the 6443 port of the container image to the 6443 port of the VPS server respectively.
[0093] Specifically, the container image or the first terminal executes the following commands:
[0094] autossh–fcnr 0.0.0.0:6443: the IP of the first terminal:6443root@the IP of the VPS serverautossh–fcnr 0.0.0.0:6943: the IP of the first terminal:6943root@the IP of the VPS server
[0095] In this way, the port 6443 of the first terminal is forwarded to the port 6443 of the VPS server, and the port 6943 of the first terminal is forwarded to the port 6943 of the VPS server, thereby establishing a second communication link. The second communication link includes the link between the port 6443 of the first terminal and the port 6443 of the VPS server, and the link between the port 6943 of the first terminal and the port 6943 of the VPS server.
[0096] At this time, when the user accesses the port 6934 of the VPS server, they can access the port 6943 of the first terminal, which is equivalent to accessing the port 6943 of the container image in the first local area network.
[0097] In a possible implementation manner, the first port is a communication port that is not currently occupied by the first terminal, the second port is a communication port that is not currently occupied by the container image, and the third port is a communication port that is not currently occupied by the VPS server.
[0098] The ports on a computer are unique. Once a process is using a port, it generally cannot be used again unless some special technical means are used for reuse. Therefore, select unoccupied communication ports for opening to ensure the availability of the communication link and the efficient transmission of data.
[0099] It can be understood that the first terminal, the VPS server, and the container image can open the same ports or different ports as long as the ports are not occupied.
[0100] Step 105: Receive the request data packet forwarded by the VPS server through the second communication link. The request data packet is sent by a second terminal to the VPS server; the second terminal is any terminal located in a second local area network; the destination address of the request data packet is a third terminal in the first local area network.
[0101] The second terminal is located in the second local area network and is in a different local area network from the first terminal.
[0102] The second terminal sends a request data packet to the VPS server in the Internet. The VPS server parses the request data packet and finds that the destination address is the third terminal in the first local area network. At this time, the VPS server uses the second communication link to send the request data packet to the first terminal. The first terminal receives the request data packet.
[0103] Step 106: Obtain the destination address of the request data packet, and forward the request data packet to the third terminal through the container image using the first communication link.
[0104] The first terminal parses the request data packet, obtains the destination address of the request data packet, and finds that the destination address is a third terminal in the first local area network. The first terminal then sends the request data to the container image through the first communication link, and the container image sends the request data to the third terminal.
[0105] In this way, users in the second LAN can directly use the OpenVPN client to connect to the specified port of the VPS server (for example, port 6943) to access the VPN container in the first LAN. At this time, the user can access the first LAN where the entire container is located as a container, and can access any device and network in the first LAN. The entire VPN is built on the first LAN without a private Internet address.
[0106] It then actively initiates a connection to the Internet to establish a forwarding relationship, thereby building a communication link through a reverse connection.
[0107] This solution allows users in a LAN to easily access any service in another LAN, and the access is in the form of full IP and full port range access, making the visitor feel like they are in the LAN. In addition, this method is simple to build and use reverse VPN technology.
[0108] The encryption technology of VPN ensures the security of communication links, which can not only allow users to access across LANs, break through the limitations of network structure, but also reduce the cost of use.
[0109] In a possible implementation, the first terminal is one of a computer, a server, a smart phone, and a laptop computer located in the first local area network, and the second terminal is one of a computer, a server, a smart phone, and a laptop computer located in the second local area network.
[0110] Reference Figure 2 The first terminal and the third terminal are any terminal in the first local area network, and the second terminal is any terminal in the second local area network. This solution can make any terminal in the second local area network
[0111] Access any terminal in the first local area network.
[0112] In summary, in the embodiment of the present invention, a container image with a virtual tunnel private network function is constructed on the first terminal; the container image is run by using the docker component pre-installed on the first terminal;
[0113] The first terminal and the second port of the container image are bound to establish a first communication port between the first terminal and the second port of the container image.
[0114] Link; initiate a connection to the VPS server using the container image or the first terminal to establish a communication connection with the VPS server; the VPS server is a cloud server with the SSH service enabled; forward the second port of the container image to the third port of the VPS server to construct the second communication link between the second port of the container image and the third port of the VPS server; receive the request data packet forwarded by the VPS server using the second communication link, and the request data packet is sent by the second terminal to the VPS server; the second terminal is any terminal located in the second local area network; the destination address of the request data packet is the third terminal in the first local area network; obtain the destination address of the request data packet, and forward the request data packet to the third terminal through the container image using the first communication link. This solution constructs a link for accessing any terminal in the first local area network through the first terminal using the container image with the virtual tunnel private network function, and constructs a link for accessing the first terminal from the external network using the VPS server. In this way, the second terminal located in the external network can access any terminal in the first local area network in the form of all IPs through the VPS server and the container image. The above solution has simple construction operation and low cost, and uses the encryption technology of the virtual tunnel private network to ensure the security of the communication link.
[0115] The second communication link between the second port of the container image and the third port of the VPS server; receive the request data packet forwarded by the VPS server using the second communication link, and the request data packet is sent by the second terminal to the VPS server; the second terminal is any terminal located in the second local area network; the destination address of the request data packet is the third terminal in the first local area network; obtain the destination address of the request data packet, and forward the request data packet to the third terminal through the container image using the first communication link.
[0116] The second terminal sends to the VPS server; the second terminal is any terminal located in the second local area network; the destination address of the request data packet is the third terminal in the first local area network; obtain the destination address of the request data packet, and forward the request data packet to the third terminal through the container image using the first communication link.
[0117] This solution constructs a link for accessing any terminal in the first local area network through the first terminal using the container image with the virtual tunnel private network function, and constructs a link for accessing the first terminal from the external network using the VPS server. In this way, the second terminal located in the external network can access any terminal in the first local area network in the form of all IPs through the VPS server and the container image. The above solution has simple construction operation and low cost, and uses the encryption technology of the virtual tunnel private network to ensure the security of the communication link.
[0118] Figure 4 It is a structural block diagram of a remote communication device provided by an embodiment of the present invention.
[0119] The device is applied to the first terminal in the first local area network, and the first terminal is any terminal in the first local area network. The device 200 includes:
[0120] A construction module 201, configured to construct a container image with a virtual tunnel private network function on the first terminal;
[0121] A binding module 202, configured to run the container image using the docker component pre-installed on the first terminal, and bind the first port of the first terminal to the second port of the container image to construct the first communication link between the first port of the first terminal and the second port of the container image;
[0122] A connection module 203, configured to initiate a connection to the VPS server using the container image or the first terminal to establish a communication connection with the VPS server; the VPS server is a cloud server with the SSH service enabled;
[0123] The first forwarding module 204 is configured to forward the second port of the container image to the third port of the VPS server, so as to establish a second communication link between the second port of the container image and the third port of the VPS server;
[0124] The receiving module 205 is configured to receive, via the second communication link, a request data packet forwarded by the VPS server, where the request data packet is sent by a second terminal to the VPS server; the second terminal is any terminal located in a second local area network; and the destination address of the request data packet is a third terminal in the first local area network;
[0125] The second forwarding module 206 is configured to obtain the destination address of the request data packet, and forward the request data packet to the third terminal through the container image via the first communication link.
[0126] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described system, apparatus, and unit can refer to the corresponding processes in the foregoing method embodiments, and will not be described herein again.
[0127] In another embodiment provided by the present invention, there is also provided a device, where the device includes a processor and a memory, and the memory stores at least one instruction, at least one segment of program, a code set, or an instruction set, and the at least one instruction, the at least one segment of program, the code set, or the instruction set is loaded and executed by the processor to implement the remote communication method described in the embodiments of the present invention.
[0128] In another embodiment provided by the present invention, there is also provided a computer-readable storage medium, where the storage medium stores at least one instruction, at least one segment of program, a code set, or an instruction set, and the at least one instruction, the at least one segment of program, the code set, or the instruction set is loaded and executed by a processor to implement the remote communication method described in the embodiments of the present invention.
[0129] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center via wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access, or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)).
[0130] It should be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0131] Each embodiment in this specification is described in a related manner. The same or similar parts between the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method embodiment.
[0132] The above are only the preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are all included in the protection scope of the present invention.
Claims
1. A remote communication method, characterized in that, A first terminal applied to a first local area network, where the first terminal is any terminal in the first local area network, and the method includes: Construct a container image with virtual tunnel private network function on the first terminal; Run the container image by using the docker component pre-installed on the first terminal, and bind the first port of the first terminal to the second port of the container image to construct a first communication link between the first port of the first terminal and the second port of the container image; Initiate a connection to a VPS server by using the container image or the first terminal to establish a communication connection with the VPS server; the VPS server is a cloud server with the SSH service enabled; Forward the second port of the container image to the third port of the VPS server to construct a second communication link between the second port of the container image and the third port of the VPS server; Receive, by using the second communication link, a request data packet forwarded by the VPS server, where the request data packet is sent by a second terminal to the VPS server; the second terminal is any terminal in a second local area network; the destination address of the request data packet is a third terminal in the first local area network; Obtain the destination address of the request data packet, and forward the request data packet to the third terminal through the container image by using the first communication link.
2. The method according to claim 1, wherein The constructing a container image with virtual tunnel private network function on the first terminal includes: Use the OpenVPN software to construct a container image vpnserver.tar with virtual tunnel private network function.
3. The method according to claim 1, characterized in that The number of the first port, the second port, and the third port is at least one. The first port is a communication port that is not occupied by the first terminal currently. The second port is a communication port that is not occupied by the container image currently. The third port is a communication port that is not occupied by the VPS server currently.
4. The method according to claim 3, wherein The communication ports that are not occupied by the first terminal currently and the communication ports that are not occupied by the container image currently both include port 6943 and port 6443. The binding the first port of the first terminal to the second port of the container image includes: Bind the 6943 port of the first terminal to the 6943 port of the container image respectively, and bind the 6443 port of the first terminal to the 6443 port of the container image respectively.
5. The method according to claim 4, wherein The number of the third port is at least one. The forwarding the second port of the container image to the third port of the VPS server includes: Forward the 6943 port of the container image to the 6943 port of the VPS server respectively, and forward the 6443 port of the container image to the 6443 port of the VPS server respectively.
6. The method according to claim 1, wherein The first terminal and the third terminal are respectively any terminal among a server, a smart phone, and a laptop computer in the first local area network, and the second terminal is any terminal among a server, a smart phone, and a laptop computer in the second local area network.
7. A remote communication device, characterized in that, A first terminal applied to a first local area network, where the first terminal is any terminal in the first local area network, and the device includes: A construction module, configured to construct a container image with a virtual tunnel private network function on the first terminal; A binding module, configured to run the container image by using a pre-installed docker component on the first terminal, and bind a first port of the first terminal to a second port of the container image, so as to construct a first communication link between the first port of the first terminal and the second port of the container image; A connection module, configured to initiate a connection to a VPS server by using the container image or the first terminal, so as to establish a communication connection with the VPS server; the VPS server is a cloud server with an SSH service enabled; A first forwarding module, configured to forward the second port of the container image to a third port of the VPS server, so as to construct a second communication link between the second port of the container image and the third port of the VPS server; A receiving module, configured to receive a request data packet forwarded by the VPS server by using the second communication link, where the request data packet is sent by a second terminal to the VPS server; the second terminal is any terminal located in a second local area network; the destination address of the request data packet is a third terminal in the first local area network; A second forwarding module, configured to obtain the destination address of the request data packet, and forward the request data packet to the third terminal through the container image by using the first communication link.
8. The device according to claim 7, characterized in that, The construction module is specifically configured to: Use OpenVPN software to construct a container image vpnserver.tar with a virtual tunnel private network function.
9. An electronic device, characterized in that, The electronic device includes a processor and a memory, and at least one instruction, at least one program, a code set or an instruction set is stored in the memory, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by the processor to implement the remote communication method according to any one of claims 1-6.
10. A computer-readable storage medium, characterized in that, At least one instruction, at least one program, a code set or an instruction set is stored in the storage medium, and the at least one instruction, the at least one program, the code set or the instruction set is loaded and executed by a processor to implement the remote communication method according to any one of claims 1-6.