A method and apparatus for accessing a client

By allocating tunnel port numbers and tunnel IP addresses on the target server, the problem of node devices having no public IP or having public IPs that are not updated regularly is solved, enabling efficient and secure client access and improving operation and maintenance efficiency.

CN116582517BActive Publication Date: 2026-04-10HUNAN HAPPLY SUNSHINE INTERACTIVE ENTERTAINMENT MEDIA CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUNAN HAPPLY SUNSHINE INTERACTIVE ENTERTAINMENT MEDIA CO LTD
Filing Date
2023-06-08
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

When operating and maintaining node devices, these devices may be scattered in multiple locations, resulting in the lack of public IP addresses or irregular updates to public IP addresses, which increases the difficulty of operation and maintenance and reduces management efficiency.

Method used

By receiving client data at the target server, assigning a tunnel port number and tunnel IP address, and accessing the client based on these addresses, combined with encrypting the client data, access to the client is achieved.

Benefits of technology

Even when the node device has no public IP address or the public IP address is not updated regularly, it can still effectively access the client, improving the efficiency and security of operation and maintenance management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116582517B_ABST
    Figure CN116582517B_ABST
Patent Text Reader

Abstract

The application provides a method and device for accessing a client, which are applied to a server, and the method comprises the following steps: obtaining client data, and assigning a tunnel port number and a tunnel IP address to the client; the client data comprises a first protocol version number, a tunnel ID, a data length and client information; sending the tunnel port number and the tunnel IP address to the client; and accessing the client based on the tunnel port number and the tunnel IP address. According to the method, the client data is received, the tunnel port number and the tunnel IP address are assigned, and the corresponding client is accessed according to the tunnel port number and the tunnel IP address, so that the server can access the client through the tunnel even if the public network IP address of the client is changed or the public network IP address is not available.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet, in particular to a method and device for accessing a client. BACKGROUND

[0002] With the rapid development of science and technology, the performance of electronic devices is becoming more and more powerful, and the functions are becoming more and more rich, which has become an important part of people's daily life. However, electronic devices may have various problems in the process of use, which will affect people's use experience. Therefore, it is very important to reduce the problems that may occur in the use process of electronic products and to carry out operation and maintenance management of electronic products.

[0003] The current common method for operation and maintenance management of node devices is to obtain the specific public IP of the node and connect through the public IP. However, since the node devices may be scattered in multiple locations, in the process of operation and maintenance management of the node, the problem of no public IP, i.e. the node is connected to the public network through network address translation (NAT) or the public IP is updated at irregular intervals, is often encountered. When the above problem is encountered, it will increase the difficulty of operation and maintenance management of node devices, thereby reducing the efficiency of operation and maintenance management. SUMMARY

[0004] In view of the shortcomings of the prior art, the present application provides a method and device for accessing a client.

[0005] The first aspect of the present application provides a method for accessing a client, applied to a target server, the target server being a server determined according to a preset selection algorithm among a plurality of servers, the method comprising:

[0006] obtaining client data; wherein the client data includes a first protocol version number, a tunnel ID, a data length and client information;

[0007] verifying the client information according to a hash value of the client information and a preset secret key;

[0008] after the client information passes the verification, assigning a tunnel port number and a tunnel IP address to the client;

[0009] sending the tunnel port number and the tunnel IP address to the client;

[0010] accessing the client based on the tunnel port number and the tunnel IP address, and a public IP address and a public port number of the target server; wherein the public IP address and the public port number of the target server are connected with a plurality of the clients, and the data packet sent by the target server when accessing the client carries an access identifier of the client.

[0011] Optionally, before the obtaining the client data, the method further comprises:

[0012] sending a protocol version number of the target server to the client, so that the client takes the protocol version number of the target server as the first protocol version number.

[0013] Optionally, after the sending the tunnel port number and the tunnel IP address to the client, the method further comprises:

[0014] when the client is multiple, receiving a detection request sent by the client;

[0015] according to the detection request, detecting whether to send the corresponding tunnel port number and the tunnel IP address to the multiple clients in a time manner.

[0016] Optionally, the obtaining the client data comprises:

[0017] receiving encrypted data sent by the client; wherein the encrypted data is data that is encrypted by the client on the client data;

[0018] decrypting the encrypted data to obtain the client data.

[0019] Optionally, the accessing the client comprises:

[0020] converting the client data into first information; the first information is used to represent a corresponding relationship between a domain name of the client and the tunnel IP address;

[0021] accessing the client according to the first information.

[0022] A second aspect of the present application provides an apparatus for accessing a client, applied to a target server, the target server being a server determined according to a preset selection algorithm from multiple servers, and the apparatus comprising:

[0023] an obtaining unit, configured to obtain client data; wherein the client data comprises a first protocol version number, a tunnel ID, a data length and client information;

[0024] a checking unit, configured to check the client information according to a hash value of the client information and a preset secret key;

[0025] an allocating unit, configured to allocate a tunnel port number and a tunnel IP address to the client after the client information passes the check;

[0026] a sending unit, configured to send the tunnel port number and the tunnel IP address to the client.

[0027] an accessing unit, configured to access the client based on the tunnel port number and the tunnel IP address, and a public network IP address and a public network port number of the target service end; the public network IP address and the public network port number of the target service end are connected with a plurality of the clients, and a data packet sent by the target service end when accessing the client carries an access identifier of the client.

[0028] Optionally, the sending unit is configured to:

[0029] send a protocol version number of the target service end to the client, so that the client takes the protocol version number of the target service end as the first protocol version number.

[0030] Optionally, the apparatus comprises a detecting unit:

[0031] When the client is a plurality of clients, the obtaining unit is configured to receive a detection request sent by the client;

[0032] The detecting unit is configured to detect whether to send the corresponding tunnel port number and tunnel IP address to the plurality of clients according to the detection request.

[0033] Optionally, the obtaining unit is configured to:

[0034] receive encrypted data sent by the client; the encrypted data is data that is encrypted by the client on the client data;

[0035] The obtaining unit is configured to decrypt the encrypted data to obtain the client data.

[0036] Optionally, the accessing unit is configured to:

[0037] convert the client data into first information; the first information is used to represent a corresponding relationship between a domain name of the client and the tunnel IP address;

[0038] The accessing unit is configured to access the client according to the first information.

[0039] The application provides a method for accessing a client, applied to a target server, and the method comprises the following steps: obtaining client data, and assigning a tunnel port number and a tunnel IP address to the client; wherein the client data comprises a first protocol version number, a tunnel ID, a data length and client information; sending the tunnel port number and the tunnel IP address to the client; and accessing the client based on the tunnel port number and the tunnel IP address. A common method for accessing a client is to access the client according to a public network IP address of the client after the public network IP address is obtained, but some clients may not have a public network IP address or the public network IP address may be updated at irregular intervals. In view of the defects of the prior art, the method assigns a tunnel port number and a tunnel IP address according to the received client data, and accesses the corresponding client according to the tunnel port number and the tunnel IP address. In addition, in order to ensure the security of data transmission, the method can also encrypt the data sent by the client to the target server. BRIEF DESCRIPTION OF DRAWINGS

[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of the provided drawings.

[0041] Figure 1 A flow chart of a method for accessing a client is provided for the present embodiment.

[0042] Figure 2 A structural schematic diagram of an operation and maintenance system is provided for the present embodiment.

[0043] Figure 3 A structural schematic diagram of a device for accessing a client is provided for the present embodiment. DETAILED DESCRIPTION

[0044] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0045] Please refer to Figure 1 A flow chart of a method for accessing a client is provided for the present embodiment.

[0046] The method for accessing the client provided in the embodiment can be executed by a target server in the plurality of servers. The target server refers to a server selected by the client from the plurality of servers according to a selection algorithm. Each client corresponds to a target server, and the target servers corresponding to different clients can be the same or different.

[0047] The selection algorithm can be set according to an application scenario, which is not limited in the embodiment.

[0048] As an example, the selection algorithm can be selected according to a server hash value and a client hash value. Specifically, for each server, a server hash value of the server can be calculated by using a public IP address and a port number of the server, and a client hash value interval corresponding to the server hash value can be set.

[0049] Based on this, when a client needs to establish a tunnel with a server, a client hash value of the client can be calculated according to a device serial number of the client, and then it is identified that the client hash value is located in which client hash value interval corresponding to a server. The server corresponding to the interval to which the client hash value belongs is determined as the target server.

[0050] As another example, the selection algorithm can be selected according to bandwidth information of each server. The bandwidth information of the server can include a current available bandwidth of the server. Specifically, the client can obtain the current available bandwidth of each server, and then select a server with the largest current available bandwidth as the target server.

[0051] Since there are a plurality of servers, when an operator accesses the client through a background device, the operator needs to determine in which server the client to be accessed is connected, that is, to determine the target server corresponding to the client to be accessed.

[0052] An optional determination method is that the background device is preconfigured with the same selection algorithm as the client. Thus, when accessing the client, the background device can determine the target server selected by the client to be accessed when establishing a tunnel according to the same selection algorithm as the client.

[0053] Another optional determination method is that each server records a tunnel connection relationship between itself and a client in a connection relationship database after establishing a tunnel with the client, and synchronizes the connection relationship database to each other server. When the background device needs to access the client, the background device can obtain the connection relationship database from any server, query the connection relationship corresponding to the client to be accessed from the connection relationship database, and thus determine the target server currently connected by the client to be accessed.

[0054] S101, obtain client data, and assign a tunnel port number and a tunnel IP address to the client.

[0055] In this embodiment, the client data can include a protocol version number, a tunnel ID, a data length, and client information.

[0056] The specific content of the client data is described below.

[0057] Protocol version number: 4 bytes, indicating a protocol version number, such as 0x00000011.

[0058] Tunnel ID: 10 bytes, indicating a tunnel identifier.

[0059] Data length: 4 bytes, indicating the length of the data part.

[0060] Data: variable length, indicating the actual transmitted data.

[0061] In this embodiment, the same protocol version number can be used by the client and the target server for the convenience of data transmission.

[0062] The method of using the same protocol version number is described below.

[0063] Before the client sends data to the server, the target server can send a second protocol version number to the client, wherein the second protocol version number can be understood as the protocol version number of the target server. In this embodiment, the second protocol version number can be 0x00000011, or other protocol version numbers can be used according to actual conditions, which are not limited in this embodiment.

[0064] After the client receives the second protocol version number, the same protocol version number as the second protocol version number is selected from the protocol version numbers of the plurality of clients as a first protocol version number, that is, the first protocol version number is also 0x00000011.

[0065] In this embodiment, the tunnel ID can be represented by a specific parameter, and a plurality of clients can share one tunnel ID.

[0066] Alternatively, the tunnel ID can also be the device serial number of the client.

[0067] The specific content of the actual transmitted data in the above example is described below.

[0068] Request form POST: / date?token=XXXXX.

[0069] Request data example (actually XXTEA encrypted data).

[0070] { "wan_ip" :

"public IP address, support multiple public IP"

"internal IP address, support multiple internal IP"

"client port number, 22, 60, 21, support multiple ports"

[0071] Token calculation method: MD5 (HASH value of client information + secret key).

[0072] In this embodiment, the client information can include the public IP address, internal IP address, NAT type, device manufacturer and model, serial number and port number of the client.

[0073] When the client sends data to the target server, the sent data can be encrypted. In this embodiment, the client information can be encrypted using a hash algorithm.

[0074] After the target server receives the encrypted client data, it needs to decrypt the encrypted client data to obtain the client data. The specific decryption method can be: according to the preset secret key, the encrypted client data is decrypted. In this embodiment, the upload data can be understood as the client information.

[0075] In this embodiment, the secret key can be a preset specific parameter, which can be stored in the database of the target server. For the case where there are multiple clients, multiple clients can share a secret key, or different secret keys can be preset for different clients, which is not limited in this embodiment.

[0076] The HASH value of the decrypted upload data can be calculated.

[0077] In this embodiment, in the process of sending client data from the client to the target server and receiving client data by the target server, it can be normal sending or there can be problems. If there is a problem in the process of transmitting data, the sending data can fail; therefore, when there is a problem in the transmission process, the protocol is processed accordingly to ensure normal data transmission.

[0078] The following describes the problems that can occur in the above data sending and receiving process, the normal sending situation and the corresponding processing method.

[0079] The return data is HTTP CODE.

[0080] 200 normal.

[0081] 403 authentication failure.

[0082] 404 The data passed by the client is invalid.

[0083] 405 The device information is repeated, and the unique ID is conflicted.

[0084] 600 The target server is abnormal.

[0085] After the target server receives the data sent by the client, the target server can return result data to the client, which is used to indicate the result of receiving the data. The result data can be understood as the HTTP CODE in the above example, and the HTTP CODE in the form of a numerical value is used to indicate the result of the target server receiving the data sent by the client.

[0086] Moreover, if the process of receiving data by the target server has a problem, the specific numerical value of the above HTTP CODE can also be used to indicate the specific problem. After the client obtains the specific problem, the client can perform corresponding processing for the specific problem until the target server can normally receive the data of the client.

[0087] The specific meanings of the numerical values of the above HTTP CODE are introduced as follows.

[0088] If the HTTP CODE returned by the target server to the client is 200, it can be understood that the process of the client sending data to the target server does not have a problem, that is, the client accurately and correctly sends data to the target server.

[0089] If the HTTP CODE returned by the target server to the client is 405, it can be understood that the sending process has a problem, and the specific problem is that the device information is repeated, and the unique ID is conflicted; that is, there are multiple client serial numbers in the data of the client. The serial number of the client is the unique ID of the client.

[0090] In view of the above problem of repeated device information, the client can requery the serial number of the client itself, obtain the correct serial number, and delete other serial numbers; and re-send the modified serial number to the target server.

[0091] In this embodiment, after the target server obtains the data of the client, the target server can store the data of the client into a database. The specific storage method can be to deploy MySQL to store the data of the client, and of course the database can also store the public network IP address of the target server and other administrator specified parameters and the like.

[0092] After the target server stores the data of the client into the database, the target server can allocate a tunnel port number and a tunnel IP address to the client. For the case of multiple clients, the target server can allocate corresponding tunnel port numbers and tunnel IP addresses to multiple clients.

[0093] The tunnel port number and the tunnel IP address corresponding to the client can be input by the user or generated by the target server according to the client data of different clients.

[0094] S101 can include the following steps: obtaining client data; checking the client information according to the hash value of the client information and the preset secret key; and assigning the tunnel port number and the tunnel IP address to the client after the client information passes the check.

[0095] As described above, the client data carries the label (i.e., the token) calculated by the client. Therefore, the specific checking process of the client information can include: the target server first calculates the hash value of the client information after completing the decryption of the client data, then calculates the target server label by using the MD5 algorithm on the hash value of the client information and the secret key, and finally compares the client label with the target server label. If they are consistent, it is determined that the client information passes the check. If they are inconsistent, it is determined that the client information fails the check.

[0096] The target server can generate the tunnel port number and the tunnel IP address in the following way: the target server randomly generates a plurality of tunnel port numbers and tunnel IP addresses according to the number of clients that need to be assigned.

[0097] The target server can also generate the tunnel port number and the tunnel IP address in the following way: for each client that needs to be assigned a tunnel port number and a tunnel IP address, the target server generates the tunnel port number and the tunnel IP address of the client according to the client data of the client, such as the public IP, the internal IP, the NAT type and the client port number of the client.

[0098] Optionally, if the client information fails the check, the target server can feed back a check failure message to the client, so as to indicate to the client that the current received client information fails the check and cannot be assigned a tunnel port number and a tunnel IP address.

[0099] S102, sends the tunnel port number and the tunnel IP address to the client.

[0100] The target server can associate the tunnel port number with the above-mentioned client port number and the tunnel IP address with the serial number of the client, i.e., establish a corresponding relationship between the tunnel port number and the above-mentioned client port number and the tunnel IP address and the serial number of the client.

[0101] The target server sends the tunnel port number and the tunnel IP address to the client.

[0102] The target service end can distinguish the plurality of clients according to the correspondence, that is, the target service end can distinguish the corresponding clients according to the tunnel port number and the tunnel IP address.

[0103] After the target service end sends the tunnel port number and the tunnel IP address to the client, the client can send a detection request to the target service end at a regular time. The detection request is used to request the target service end to detect whether the corresponding tunnel port number and tunnel IP address are sent to all clients.

[0104] The target service end can check whether the corresponding tunnel port number and tunnel IP address are sent to all clients at a regular time according to the detection request. If it is found that the corresponding tunnel port number and tunnel IP address are not sent to one or more clients, the target service end sends the corresponding tunnel port number and tunnel IP address to the corresponding one or more clients.

[0105] S103, access the client based on the tunnel port number and the tunnel IP address, and the public network IP address and the public network port number of the target service end.

[0106] In this embodiment, the connection relationship between the target service end and the client can be that the target service end establishes a tunnel connection with a plurality of clients through a specific public network IP address and public network port number. The connection mode has the following advantages: on the one hand, the public network IP address and the public network port number of the target service end can be reused, so that the target service end can connect as many devices on the network as possible; on the other hand, when an operator needs to access the client through a background device, it is not necessary to determine which public network IP address and public network port number the client is connected to, so that the access efficiency is improved.

[0107] In the above connection mode, in order to realize the communication between the target service end and a specific client to be accessed, the target service end can send a data packet to the client to be accessed in the following manner:

[0108] When the target service end generates the data packet to be sent to the client to be accessed, the access identifier of the client to be accessed is added to the data packet. The access identifier can be the tunnel IP address and the tunnel port number of the client to be accessed, or the device serial number of the client to be accessed.

[0109] After the data packet is generated, the target service end sends the data packet through the public network IP address and the public network port number used to connect the client. Since the public network IP address and the public network port number are connected to a plurality of clients, the data packet is received by a plurality of clients, including the client to be accessed and other clients that are not the client to be accessed.

[0110] Each client can compare the access identifier carried in the data packet issued by the target server with the locally recorded access identifier to determine whether they are consistent, for example, comparing the tunnel IP address and tunnel port number carried in the data packet with the tunnel IP address and tunnel port number recorded locally by the client, or comparing the device serial number carried in the data packet with the device serial number recorded locally by the client.

[0111] If they are consistent, it indicates that the data packet is the data packet issued by the server to itself, and then the client processes the data packet. If they are inconsistent, it indicates that the data packet is not the data packet issued by the server to itself, and then the client ignores the data packet.

[0112] In this way, the server can communicate with a specific client to be accessed.

[0113] The target server can access the related port of the corresponding client according to the tunnel port number and tunnel IP address. The specific access method is described below.

[0114] The related user can input the device serial number of the client and the client port number. The target server can obtain the tunnel port number and tunnel IP address of the corresponding client according to the input device serial number of the client and the client port number. The specific query method is to query through the correspondence between the tunnel port number and the client port number, and the correspondence between the tunnel IP address and the device serial number of the client.

[0115] After the target server obtains the tunnel port number and tunnel IP address of the corresponding client, it can access the related port of the corresponding client.

[0116] Another method for accessing the client is described below.

[0117] The target server can read the corresponding client data in the database and convert the client data into first information. The first information can be a DNS A record.

[0118] The way of converting the client data into the first information can be: generating the domain name or host name of the client according to the device serial number, public IP, NAT type and other information, and then determining the mapping relationship between the domain name (or host name) of the client and the tunnel IP address of the client as the first information of the client.

[0119] The related user can input the domain name (or host name) of the client. The target server can request the DNS server to resolve the corresponding tunnel IP address according to the input domain name (or host name), that is, the DNS server can resolve the corresponding tunnel IP address through A record.

[0120] The target server can access the related port of the client after obtaining the tunnel IP address of the client.

[0121] Through the above two methods of accessing the client, it can be understood that the administrator can access the client in the form of IP+domain name (or host name). Even in the case of no public IP address, public IP address changes, etc., the administrator can access the related port of the client. Therefore, when the administrator performs operation and maintenance management on the client, the difficulty of operation and maintenance management can be reduced to improve the efficiency of operation and maintenance management.

[0122] The above method of accessing the client is equivalent to:

[0123] The client data is converted into first information; the first information is used to represent the correspondence between the domain name of the client and the tunnel IP address;

[0124] According to the first information, the client is accessed.

[0125] After introducing the method of accessing the client provided by the embodiment, the process of obtaining client data by the client and sending the client data to the target server is introduced.

[0126] The specific content of the client data can be referred to the introduction of the client data in step S102.

[0127] The client can read the public IP address through the configuration file; if the client has no configuration file, the client can call the related port in the database to query the public IP address.

[0128] Since the node device can be scattered in multiple locations, some node devices in some areas may have public IP addresses or may not have public IP addresses. Among them, the above node device can be understood as the client in the embodiment.

[0129] For the case that the client has a public IP address, the client can call the related port in the database to query the public IP address.

[0130] After the client obtains the public IP address, the client verifies whether the public IP address is a true public IP address. It can be understood that some addresses allocated by operators are NATed public IP addresses. Although they look like public IP addresses, such public IP addresses cannot be directly accessed through the Internet, so in the embodiment, the above NATed public IP addresses can be understood as false public IP addresses.

[0131] For the above false public IP address, it can be understood that the client has no public IP address, and the corresponding processing method can be referred to the processing method of the client without a public IP address to be introduced below.

[0132] For the case that the client does not have a public IP address, the client will perform corresponding processing. The following describes the specific processing method.

[0133] If the client does not have a public IP address, the client can obtain the corresponding NAT type. The specific obtaining method is that the client can request the STUN and TURN services of the target server to obtain the NAT type of the client. The specific method for obtaining the NAT type is to obtain the NAT type through the STUN, TURN and UPnP related protocols.

[0134] The client sends the obtained client data to the target server.

[0135] The application provides a method for accessing a client, applied to a target server, and the method comprises the following steps: obtaining client data and assigning a tunnel port number and a tunnel IP address to the client; wherein the client data comprises a first protocol version number, a tunnel ID, a data length and client information; sending the tunnel port number and the tunnel IP address to the client; and accessing the client based on the tunnel port number and the tunnel IP address. The common method for accessing a client is to access the client according to the public IP address of the client after obtaining the public IP address of the client, but some clients may not have a public IP or the public IP may be updated at irregular intervals. In view of the shortcomings of the prior art, the present scheme receives client data and assigns a tunnel port number and a tunnel IP address, and accesses the corresponding client according to the tunnel port number and the tunnel IP address. Moreover, in order to ensure the security of data transmission, the present scheme can also perform encryption processing on the data sent by the client to the target server.

[0136] The method provided in the embodiment can be applied to a client operation and maintenance system as shown in Figure 2 The system can comprise one or more clients, and the structures of the plurality of clients are similar. As an example, Figure 2 only the structure of one client is shown.

[0137] It can be seen that the client comprises a node information reporting module and a NAT type detection module.

[0138] The node information reporting module is configured to send the aforementioned client data to the target server, and the NAT type detection module is configured to interact with the NAT type detection service of the target server to determine the NAT type of the client.

[0139] The target server comprises a data collection service, a tunnel generation service, a NAT type detection service, a database and a DNS service.

[0140] The data collection service is configured to receive the client data and check the client information.

[0141] The tunnel generation service is configured to assign a tunnel port number and a tunnel IP address to the client and send the tunnel port number and the tunnel IP address to the client.

[0142] The DNS service is configured to generate the first information and resolve a tunnel end IP address of the client according to a domain name (or a host name) input by a user and the first information, thereby supporting an operation and maintenance personnel to access the client.

[0143] The database is configured to record the client data, the tunnel port number and the tunnel IP address assigned to the client, and the first information generated by the DNS service.

[0144] According to the method for accessing the client provided in the application, the embodiment of the application further provides an apparatus for accessing the client, which is applied to a target service end, the target service end being a service end determined by the client from a plurality of service ends according to a preset selection algorithm, please refer to Figure 3 , which is a structural schematic diagram of the apparatus, the apparatus comprising the following units.

[0145] The obtaining unit 301 is configured to obtain client data; wherein the client data comprises a first protocol version number, a tunnel ID, a data length and client information.

[0146] The checking unit 302 is configured to check the client information according to a hash value of the client information and a preset secret key.

[0147] The assigning unit 303 is configured to assign a tunnel port number and a tunnel IP address to the client after the client information is checked.

[0148] The sending unit 304 is configured to send the tunnel port number and the tunnel IP address to the client.

[0149] The accessing unit 305 is configured to access the client based on the tunnel port number and the tunnel IP address, and a public network IP address and a public network port number of the target service end; wherein the public network IP address and the public network port number of the target service end are connected with a plurality of clients, and a data packet sent by the target service end when accessing the client carries an access identifier of the client.

[0150] Optionally, the sending unit is configured to:

[0151] send a protocol version number of the target service end to the client, so that the client takes the protocol version number of the target service end as the first protocol version number.

[0152] Optionally, the apparatus comprises a detecting unit 306:

[0153] When the client is a plurality of clients, the obtaining unit is configured to receive a detection request sent by the client.

[0154] The detection unit is configured to detect whether to send the corresponding tunnel port number and tunnel IP address to the plurality of clients according to a detection request.

[0155] Optionally, the obtaining unit is configured to:

[0156] receive encrypted data sent by the client; the encrypted data is data encrypted by the client on the client data;

[0157] The obtaining unit is configured to decrypt the encrypted data to obtain the client data.

[0158] Optionally, the access unit is configured to:

[0159] convert the client data into first information; the first information is used to represent the correspondence between the domain name of the client and the tunnel IP address;

[0160] The access unit is configured to access the client according to the first information.

[0161] The device for accessing the client provided in the embodiment has the specific working principle that can be referred to the related steps in the method for accessing the client provided in any embodiment of the present application, which will not be described here.

[0162] The device for accessing the client provided in the present application is applied to a target server, and the device comprises: an obtaining unit 301 configured to obtain client data; wherein the client data comprises a first protocol version number, a tunnel ID, a data length and client information; a checking unit 302 configured to check the client information according to a hash value of the client information and a preset secret key; an allocating unit 303 configured to allocate a tunnel port number and a tunnel IP address to the client after the client information passes the check; a sending unit 304 configured to send the tunnel port number and the tunnel IP address to the client; and an access unit 305 configured to access the client based on the tunnel port number and the tunnel IP address. The common method for accessing the client is to access the client according to a public network IP address of the client after the public network IP address is obtained, but some clients can not have the public network IP or the public network IP can be updated at irregular intervals. In view of the defects of the prior art, the present scheme receives client data, allocates a tunnel port number and a tunnel IP address, and accesses the corresponding client according to the tunnel port number and the tunnel IP address. Moreover, in order to ensure the security of data transmission, the present scheme can also encrypt the data sent by the client to the target server.

[0163] Finally, it needs to be pointed out that, in this document, the terms such as first and second, etc. are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or sequence between these entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of other identical elements in the process, method, article or device including the element.

[0164] It should be noted that the "first", "second", and the like concepts mentioned in the present application are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0165] The skilled person can implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method of accessing a client, characterized by, The method is applied to a target server, the target server is a server determined according to a preset selection algorithm among multiple servers, and the method comprises the following steps: Obtaining client data; wherein the client data comprises a first protocol version number, a tunnel ID, a data length and client information; each client corresponds to a target server, and a client hash value of the client belongs to an interval corresponding to a client hash value interval of the corresponding target server; Verifying the client information according to a hash value of the client information and a preset secret key; After the client information passes the verification, a tunnel port number and a tunnel IP address are allocated to the client; Sending the tunnel port number and the tunnel IP address to the client; Accessing the client based on the tunnel port number and the tunnel IP address, and a public network IP address and a public network port number of the target server; wherein the public network IP address and the public network port number of the target server are connected to multiple clients, a data packet sent by the target server when accessing the client carries an access identifier of the client, the access identifier comprises the tunnel IP address and the tunnel port number of the client, so that the client compares the access identifier with a locally recorded access identifier, and if they are consistent, the client processes the data packet.

2. The method of claim 1, wherein, Before the step of obtaining the client data, the following step is further included: Sending a protocol version number of the target server to the client, so that the client takes the protocol version number of the target server as the first protocol version number.

3. The method of claim 1, wherein, After the step of sending the tunnel port number and the tunnel IP address to the client, the following step is further included: When there are multiple clients, receiving a detection request sent by the client; According to the detection request, detecting whether the corresponding tunnel port number and tunnel IP address are sent to multiple clients in a timely manner.

4. The method of claim 1, wherein, The step of obtaining the client data comprises the following steps: Receiving encrypted data sent by the client; wherein the encrypted data is data obtained by encrypting the client data by the client; Decrypting the encrypted data to obtain the client data.

5. The method of claim 1, wherein, The step of accessing the client comprises the following steps: Converting the client data into first information; the first information is used to represent a corresponding relationship between a domain name of the client and the tunnel IP address; Accessing the client according to the first information.

6. An apparatus of an access client, the apparatus comprising: The device is applied to a target server, the target server is a server determined according to a preset selection algorithm among multiple servers, and the device comprises the following steps: An obtaining unit is configured to obtain client data; wherein the client data comprises a first protocol version number, a tunnel ID, a data length and client information; each client corresponds to a target server, and a client hash value of the client belongs to an interval corresponding to a client hash value interval of the corresponding target server; A verification unit is configured to verify the client information according to a hash value of the client information and a preset secret key; An allocation unit is configured to allocate a tunnel port number and a tunnel IP address to the client after the client information passes the verification; The sending unit is configured to send the tunnel port number and the tunnel IP address to the client. The access unit is configured to access the client based on the tunnel port number and the tunnel IP address, and a public network IP address and a public network port number of the target service end, wherein the public network IP address and the public network port number of the target service end are connected to a plurality of the clients, and a data packet sent by the target service end when accessing the client carries an access identifier of the client, the access identifier comprising the tunnel IP address and the tunnel port number of the client, so that the client compares the access identifier with a locally recorded access identifier, and if the access identifiers are consistent, the client processes the data packet.

7. The apparatus of claim 6, wherein, The sending unit is configured to: send a protocol version number of the target service end to the client, so that the client takes the protocol version number of the target service end as the first protocol version number.

8. The apparatus of claim 6, wherein, The device comprises a detection unit: When the client is a plurality of clients, the acquisition unit is configured to receive a detection request sent by the client. The detection unit is configured to detect whether the corresponding tunnel port number and tunnel IP address are sent to the plurality of clients according to the detection request.

9. The apparatus of claim 6, wherein, The acquisition unit is configured to: receive encrypted data sent by the client; wherein the encrypted data is data processed by the client by encrypting the client data; The acquisition unit is configured to decrypt the encrypted data to obtain the client data.

10. The apparatus of claim 6, wherein, The access unit is configured to: convert the client data into first information; the first information is used to represent the correspondence between the domain name of the client and the tunnel IP address; The access unit is configured to access the client according to the first information.

Citation Information

Patent Citations

  • Remote control system and remote control method used for material sorting equipment

    CN104102213A

  • Message transmission method, device and system

    CN106101617A

  • Method for remotely managing gateway equipment

    CN115550128A