Network configuration method, apparatus, device, and storage medium
By leveraging the collaborative work of cloud servers and network control devices and utilizing data encapsulation templates, unified management of multiple wireless access point devices has been achieved. This solves the problem of managing devices from different manufacturers or versions, improves management efficiency, and reduces operation and maintenance costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- TENCENT TECHNOLOGY (SHENZHEN) CO LTD
- Filing Date
- 2022-03-21
- Publication Date
- 2026-07-24
AI Technical Summary
The difficulty in effectively managing wireless access point devices from different manufacturers or with different versions leads to low management efficiency and high maintenance costs.
By working together with cloud servers and network control devices, network configuration parameters are uniformly encapsulated and distributed to various network access devices using data encapsulation templates, thus masking device differences and achieving unified management.
It improves the management efficiency of network access devices, reduces operation and maintenance costs, and enables unified access and management of multiple network access devices with different characteristics.
Smart Images

Figure CN116827772B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to a network configuration method, apparatus, device and storage medium. Background Technology
[0002] Wireless access point (AP) devices, also known as network access devices, are access points used to connect terminal devices (such as mobile phones and computers) to a network. They are mainly used in enterprises, homes with broadband access, large shopping malls, campuses, industrial parks, warehouses, factories, and other places requiring communication. However, the network coverage of a single AP is limited. Therefore, multiple APs are usually deployed in a single location to ensure communication quality. Since these APs belong to different manufacturers or are different versions from the same manufacturer, there are differences between them, making effective management difficult. Currently, the AP manufacturer is responsible for managing each individual network access device, resulting in low management efficiency and high maintenance costs. Summary of the Invention
[0003] This application provides a network configuration method, apparatus, device, and storage medium, which can improve the management efficiency of network access devices and reduce the maintenance costs of network access devices.
[0004] One embodiment of this application provides a network configuration method, including:
[0005] The network control device receives a first network configuration data packet sent by the cloud server; the first network configuration data packet is obtained by the cloud server encapsulating the target network configuration parameters of N network access devices according to a first data encapsulation template matching the cloud server, where the N network access devices belong to target locations associated with the network control device; N is a positive integer greater than 1;
[0006] The first network configuration data packet is parsed to obtain the target network configuration parameters of N network access devices;
[0007] The target network configuration parameters are encapsulated according to the second data encapsulation templates corresponding to the N network access devices to obtain the second network configuration data packets corresponding to the N network access devices; at least two of the N network access devices have different second data encapsulation templates.
[0008] N second network configuration data packets are sent to the corresponding network access devices respectively. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets.
[0009] One embodiment of this application provides a network configuration method, including:
[0010] The cloud server obtains the target network configuration parameters of N network access devices; the N network access devices belong to target locations associated with the network control device; N is a positive integer greater than 1; the network control device is connected to the cloud server;
[0011] The target network configuration parameters are encapsulated according to the first data encapsulation template that matches the cloud server to obtain the first network configuration data packet;
[0012] The first network configuration data packet is sent to the network control device. The first network configuration data packet is used to instruct the network control device to send N second network configuration data packets to the corresponding network access devices. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets. The N second network configuration data packets are obtained by encapsulating the target network configuration parameters according to the second data encapsulation templates corresponding to the N network access devices. The target network configuration parameters are obtained by parsing the first network configuration data packet. At least two of the N network access devices have different second data encapsulation templates.
[0013] One embodiment of this application provides a network configuration device, including:
[0014] The receiving module is used to receive a first network configuration data packet sent by the cloud server; the first network configuration data packet is obtained by the cloud server encapsulating the target network configuration parameters of N network access devices according to a first data encapsulation template matching the cloud server, where the N network access devices belong to target locations associated with the network control device; N is a positive integer greater than 1.
[0015] The parsing module is used to parse the first network configuration data packet to obtain N target network configuration parameters of the network access devices;
[0016] An encapsulation module is used to encapsulate the target network configuration parameters according to the second data encapsulation templates corresponding to the N network access devices respectively, to obtain the second network configuration data packets corresponding to the N network access devices respectively; at least two of the N network access devices have different second data encapsulation templates.
[0017] The sending module is used to send N second network configuration data packets to the corresponding network access devices respectively. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets.
[0018] One embodiment of this application provides a network configuration device, including:
[0019] The acquisition module is used to acquire target network configuration parameters for N network access devices; the N network access devices belong to target locations associated with the network control device; N is a positive integer greater than 1; the network control device is connected to the cloud server;
[0020] The encapsulation module is used to encapsulate the target network configuration parameters according to a first data encapsulation template that matches the cloud server, so as to obtain a first network configuration data packet;
[0021] The sending module is used to send the first network configuration data packet to the network control device. The first network configuration data packet is used to instruct the network control device to send N second network configuration data packets to the corresponding network access devices. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets. The N second network configuration data packets are obtained by encapsulating the target network configuration parameters according to the second data encapsulation templates corresponding to the N network access devices. The target network configuration parameters are obtained by parsing the first network configuration data packet. At least two of the N network access devices have different second data encapsulation templates.
[0022] One embodiment of this application provides a computer-readable storage medium storing a computer program, the computer program including program instructions, which, when executed by a processor, perform the aforementioned method.
[0023] One embodiment of this application provides a computer program product, including a computer program / instructions, which, when executed by a processor, implements the above-described method.
[0024] In this application, when network configuration of network access devices within a target location is required, the cloud server can obtain the target network configuration parameters of N network access devices within the target location, encapsulate the target network configuration data of the N network access devices according to a first data encapsulation template, obtain a first network configuration data packet, and send the first network configuration data packet to the network control device associated with the target location. After receiving the first network configuration data packet, the network control device can parse the first network configuration data packet to obtain the target network configuration parameters of the N network access devices. These target network configuration parameters include the network configuration parameters of all network access devices within the target location. In other words, users do not need to operate on individual network access devices; all configurations are performed at the location level (e.g., enterprise level), enabling batch configuration of network access devices and improving configuration efficiency. Furthermore, the network control device can encapsulate the target network configuration parameters according to the second data encapsulation template corresponding to each of the N network access devices, obtaining N second network configuration data packets corresponding to each network access device, and send the N second network configuration data packets to the corresponding network access devices. The network access devices can then perform network configuration based on the second network configuration data packets. The second data encapsulation template here is the template used by the network access device for data encapsulation processing. That is, the second network configuration data packet is a data packet that the network access device can recognize. In other words, the network control device converts the first network configuration data packet sent by the cloud server into a second network configuration data packet that each network access device can recognize. This masks the differences between the various network access devices, enabling unified access to the cloud server for all network access devices. In other words, the network control device achieves interconnection and interoperability between the cloud server and multiple diverse network access devices. The cloud server is responsible for managing all network access devices in the target location, enabling unified management of network access point devices within the target location, improving management efficiency, and reducing network access device operation and maintenance costs. Attached Figure Description
[0025] Figure 1 This is a schematic diagram of the architecture of a network configuration system provided in this application;
[0026] Figure 2 This is a schematic diagram of the interaction scenario between various devices in a network configuration system provided in this application;
[0027] Figure 3 This is a flowchart illustrating a network configuration method provided in this application;
[0028] Figure 4 This is a schematic diagram illustrating a scenario for synchronizing the network configuration of a network access device, as provided in this application.
[0029] Figure 5 This is a flowchart illustrating a network configuration method provided in this application;
[0030] Figure 6 This is a schematic diagram of a system architecture for generating keys related to a target organization, as provided in this application;
[0031] Figure 7 This is a schematic diagram illustrating a scenario for generating employee keys corresponding to employee terminals of a target organization, as provided in this application.
[0032] Figure 8 This is a schematic diagram illustrating a scenario for synchronizing employee keys corresponding to employee terminals, as provided in this application.
[0033] Figure 9 This is a schematic diagram illustrating a scenario for generating a visitor key for a visitor terminal corresponding to a target organization, as provided in this application.
[0034] Figure 10 This is a schematic diagram of the online information of visitors promoted by employee A, as provided in this application;
[0035] Figure 11 This is a schematic diagram of the structure of a network configuration device provided in an embodiment of this application;
[0036] Figure 12 This is a schematic diagram of the structure of a network configuration device provided in an embodiment of this application;
[0037] Figure 13 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Detailed Implementation
[0038] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings.
[0039] To facilitate a clearer understanding of this application, we will first introduce a network configuration system that implements the network configuration method of this application, such as... Figure 1 As shown, the network configuration system includes the device side, the cloud side, and the application side.
[0040] The device side includes one or more Wireless Access Point Controllers (ACs), also known as network control devices. These network control devices may contain data processing components, also known as software development kits (SDKs). These SDKs are used to manage network access devices within the associated location by connecting them to the cloud. Specifically, they provide functions such as reporting network configuration data related to the network access devices and receiving and distributing such data. For example, the SDK can maintain a persistent connection with a cloud server via the WebSocket protocol (a full-duplex communication protocol based on TCP) and periodically report heartbeats, allowing the cloud server to monitor the operational status of the network access devices in real time.
[0041] For example, the SDK here can be used to convert data packets that the cloud server needs to send to network access devices into data packets that the network access devices can recognize, and then send the converted data packets to the network access devices. For instance, when the cloud server needs to send a first network configuration data packet carrying target network configuration parameters for N network access devices in the target location to N network access devices, the SDK in the network control device is used to convert the first network configuration data packet into a second network configuration data packet that each of the N network access devices can recognize, and then send the second network configuration data packet to the corresponding network access device. Alternatively, the SDK can be used to convert data packets that the network access devices need to report to the cloud server into data packets that the cloud server can recognize, and then report the converted data packets to the cloud server. For instance, when network access device Pi in the target location needs to send a fourth network configuration data packet carrying the current network configuration parameters, the network control device can convert the fourth network configuration data packet into a third network configuration data packet that the cloud server can recognize, and then send the third network configuration data packet to the cloud server.
[0042] Optionally, a network control device in this application can be used to manage all or some network access devices within a location, or a network control device can be used to manage network node devices within multiple locations. The network access devices managed by the network control device can be determined based on one or more factors such as the number of network access devices within the location or the communication needs within the location. The aforementioned locations include enterprises, broadband homes, large shopping malls, campuses, industrial parks, and areas requiring communication, such as warehouses and factories. This application primarily uses the example of a network control device managing network access devices within a single location for illustration. For example, such as... Figure 1As shown, the device side includes network control device 1 and network control device 2. Network control device 1 manages the network access devices within location 1. Location 1 includes n network access devices, labeled as network access device 1, network access device 2, ..., network access device n. The network access devices in location 1 are deployed in different areas within location 1 to provide network connectivity for terminal devices within location 1. Similarly, network control device 2 manages the network access devices within location 2. Location 2 includes m network access devices, labeled as network access device 1, network access device 2, ..., network access device m. The network access devices in location 2 are deployed in different areas within location 2 to provide network connectivity for terminal devices within location 2.
[0043] Optionally, the network control devices in the equipment terminal can also have disaster recovery capabilities. This means that each network control device, while not only having the ability to manage network access devices within its own corresponding location, also has the ability to manage network access devices within the locations corresponding to other network control devices. For example, ... Figure 1 In this configuration, network control device 2 has the capability to manage network access devices within locations 1 and 2. When network control device 1 fails, network control device 2 can take over the management of network access devices within location 1. Similarly, network control device 1 has the capability to manage network access devices within locations 1 and 2. When network control device 2 fails, network control device 1 can take over the management of network access devices within location 2. This improves the security of the network configuration system and increases the utilization rate of the network control devices.
[0044] Optionally, the network control device in the equipment can also have disaster recovery capabilities, and the equipment can include a backup network control device for disaster recovery, such as... Figure 1 In this system, if network control device 1 fails, the backup network control device can manage the network access devices within location 1, ensuring the normal operation of network access points within location 1. Similarly, if network control device 2 fails, the backup network control device can manage the network access devices within location 2, ensuring the normal operation of network access points within location 2; this improves the security of the network configuration system.
[0045] Optionally, the cloud includes a cloud server, which can establish a network connection with one or more network control devices to manage network access devices in one or more locations. Specifically, the cloud server may include modules such as location management, key management, operation platform, and object model. These functional modules can be deployed simultaneously on the same cloud server, or they can be deployed separately on different cloud servers.
[0046] The venue management function is responsible for venue-level network configuration management. For example, a venue could refer to an enterprise or organization. Venue management can be used to assign network configuration parameters to the network access devices of the enterprise or organization corresponding to the network control device, and synchronize these network configuration parameters with the corresponding network access devices to achieve enterprise-level configuration management. These network configuration parameters may include an AC device list, wireless network switch, Service Set Identifier (SSID), the range of users allowed to access the internet, and network connection speed and duration limits.
[0047] The operation platform can be used to verify network configuration parameters, such as verifying whether the data format, data length, and data size of the network configuration parameters are correct, while the object model is used to update the network configuration parameters of network access devices.
[0048] The application side can include network application devices that can establish a network connection with the cloud server. This network connection enables the management of network access devices in one or more locations. Specifically, the cloud server can include a network configuration page, which can be used to configure the network configuration parameters of the network access devices. This network configuration page can be a web page, a page from a public WeChat account, a page from a mini-program, or a page from a network configuration application, etc.
[0049] It should be noted that the aforementioned cloud server can refer to a single physical server, a server cluster or distributed system consisting of at least two physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms. The aforementioned network application devices, visitor terminals, and employee terminals can refer to in-vehicle terminals, smartphones, tablets, laptops, desktop computers, smart speakers, speakers with screens, smartwatches, etc., but are not limited to these.
[0050] Based on the above Figure 1The network configuration system in the system enables unified management of network access devices within the venue. Specifically, Figure 2 Taking a business or organization as an example, the unified management of network access devices can include the network configuration distribution process.
[0051] During the network configuration distribution process, the network application device in the application terminal can display a network configuration page. Users can configure candidate network configuration parameters for N network access devices corresponding to the enterprise organization managed by the network application device through this page. These candidate network configuration parameters include wireless network switch, SSID, network connection speed limit, and network connection duration limit, etc. After the network application device obtains the candidate network configuration parameters configured by the user, it can send these parameters to the cloud server's operation platform through a first external interface. This first external interface can be a business interface, such as HTTP RESTful. Upon receiving the candidate network configuration parameters, the operation platform can verify them and obtain the verification result. If the verification result indicates that the candidate network configuration parameter is invalid, it can send a request to the network application device to reallocate the network configuration parameters, so that the network application device can reassign the network configuration parameters to the access point devices. If the verification result indicates that the candidate network configuration parameter is valid (i.e., the verification passed), the candidate network configuration parameter can be sent to the venue management through the cloud server's internal interface. This internal interface can refer to a local call interface or a remote procedure call (RPC) interface. That is, when the operation platform and venue management are deployed on the same cloud server, the internal interface here can refer to a local call interface; when the operation platform and venue management are deployed on different cloud servers, the internal interface here can refer to a remote procedure call interface.
[0052] The aforementioned verification of candidate network configuration parameters may include checking whether the data format, data length, and data size of the candidate network configuration parameters conform to preset parameter standards. These preset parameter standards may refer to those configured by the user in the network application device. In other words, the validity of candidate network configuration parameters means that their data format, data length, and data size all meet the preset parameter standards, while the invalidity of candidate network configuration parameters means that at least one of these parameters does not meet the preset parameter standards.
[0053] When this configuration of network access devices is the initial configuration for those devices, after receiving candidate network configuration parameters, the site management system identifies these parameters as the target network configuration parameters for N network access devices. These target network configuration parameters are stored in the local database of the cloud server and then sent to the cloud server's HUB module (i.e., multi-port forwarder). The HUB module, through a WebSocket connection with the network control device, sends a first network configuration data packet carrying the target network configuration parameters to the network control device's SDK. This first network configuration data packet is encapsulated according to a first data encapsulation template matching the cloud server. Upon receiving the first network configuration data packet, the SDK in the network control device converts it into a second network configuration data packet that each network access device can recognize. The SDK then sends the network configuration parameters to the corresponding network access device, completing the network configuration distribution.
[0054] like Figure 2 In this configuration, when the current configuration of a network access device is not the first time, after receiving candidate network configuration parameters, the site management can store these parameters in the local database of the cloud server and retrieve the local network configuration parameters of the network access point device from the local database. These local network configuration parameters can refer to the most recently stored network configuration parameters in the local database. Further, the candidate network configuration parameters and the local network configuration parameters are sent to the object model of the cloud server. The object model obtains the changed network configuration parameters between the candidate and local network configuration parameters; that is, the changed network configuration parameters can refer to the difference between the current network configuration parameters and the local network configuration parameters. These changed network configuration parameters are then sent to the cloud server's HUB module through an internal interface. The HUB module, through a WebSocket connection with the network control device, uses these changed network configuration parameters to determine the target network configuration parameters for N network access devices and sends a first network configuration data packet carrying these target network configuration parameters to the SDK of the network control device. When the SDK in the network control device receives the first network configuration data packet, it can convert the first network configuration data packet into a second network configuration data packet that can be recognized by each network access device. The SDK then sends the network configuration parameters to the corresponding network access device, thus completing the network configuration distribution.
[0055] It should be noted that during the process of distributing network configuration to network access devices, differences in transmission time may occur due to the different network environments of the network control device and the network access device, leading to failure in distributing network configuration parameters. The object model in the cloud server can use any one or more of the following three methods to ensure that network configuration parameters are distributed to the network access device: 1) If the distribution of network configuration to the network access device fails or times out, a maximum of three retransmissions will be performed; 2) If all three retransmissions fail, an alarm message will be reported to the operation platform, prompting the user to check the network status of the network access device; 3) The SDK will periodically collect the current network configuration parameters of the network access device and report them to the cloud. The object model module will then re-distribute incorrect configurations for the network access device.
[0056] In summary, the SDK on the network control device enables the unified connection of diverse network access point devices within an enterprise to the cloud server. The cloud server then manages these diverse network access point devices in a unified manner, eliminating the need for individual network access device vendors to manage each device separately. This improves the management efficiency of network access devices and reduces their maintenance costs.
[0057] Further, please see Figure 3 This is a flowchart illustrating a network configuration method provided in an embodiment of this application. Figure 3 As shown, this method can be derived from... Figure 1 The network configuration method is executed by the network control device in the system, and may include steps S101 to S104:
[0058] S101. The network control device receives a first network configuration data packet sent by the cloud server; the first network configuration data packet is obtained by the cloud server encapsulating the target network configuration parameters of N network access devices according to a first data encapsulation template matching the cloud server, and the N network access devices belong to the target locations associated with the network control device; N is a positive integer greater than 1.
[0059] In this application, the network control device can receive a first network configuration data packet sent by a cloud server. This first network configuration data packet is obtained by the cloud server encapsulating the target network configuration parameters of the network access devices in the target location according to a first data encapsulation template matching the cloud server. The first data encapsulation template can refer to a data encapsulation method matching the cloud server; that is, the first data encapsulation template can refer to the cloud server's original data encapsulation method, meaning no changes are needed to the cloud server, and this solution is unaffected by the cloud server. The aforementioned target locations include enterprises, broadband homes, large shopping malls, campuses, industrial parks, warehouses, factories, and other areas requiring communication.
[0060] Optionally, all network access devices within the target location share the same target network configuration parameters. These parameters can be configured by the user within the network application device. This means that from the user's perspective, no operation is required on individual network access devices; all configurations are performed at the location level (e.g., enterprise level). The cloud server manages all network access devices within the target location. This enables unified management of network access point devices within the target location by the cloud server, improving management efficiency and reducing operational costs.
[0061] Optionally, the network configuration parameters of each network access device in the target location are different. That is, the target network configuration parameters include the network configuration data corresponding to each network access device in the target location, which can realize personalized configuration of each network access device. At the same time, the network configuration parameters of each network access device are uniformly distributed to the network control device by the cloud server, which can realize the unified management of network access point devices in the target location by the cloud server, improve the management efficiency of network access devices, and reduce the operation and maintenance costs of network access devices.
[0062] It should be noted that the network control device here may refer to the network control device used to manage the network access devices in the target location, or it may refer to the backup network control device in the network configuration system, or it may refer to the network control device used to manage the network access devices in other locations. That is, when the network control device used to manage the network access devices in the target location fails, the network control device temporarily manages the network access devices in the target location.
[0063] S102, The network control device parses the first network configuration data packet to obtain the target network configuration parameters of the N network access devices.
[0064] In this application, the network control device can decapsulate the first network configuration data packet according to the first data encapsulation template to obtain the target network configuration parameters of the N network access devices. The target network configuration parameters include wireless network switch, SSID, network connection speed limit and duration limit, network connection blacklist and whitelist, etc.
[0065] S103. The network control device encapsulates the target network configuration parameters according to the second data encapsulation templates corresponding to the N network access devices respectively, to obtain the second network configuration data packets corresponding to the N network access devices respectively; at least two of the N network access devices have different second data encapsulation templates.
[0066] In this application, because different network access devices belong to different manufacturers or are different versions of the same manufacturer, the data packets that different network access devices can recognize are different. Therefore, the network control device can encapsulate the target network configuration parameters according to the second data encapsulation template corresponding to each of the N network access devices, to obtain the second network configuration data packets corresponding to each of the N network access devices. The second data encapsulation template is the original data encapsulation method of the network access device, that is, no changes need to be made to the network access device, and the second network configuration data packet is a data packet that the network access device can recognize.
[0067] In this context, the second data encapsulation templates for network access devices from different manufacturers within the target location may differ, or the second data encapsulation templates for different versions of network access devices from the same manufacturer within the target location may differ. For example, the target location may include network access devices 1, 2, and 3. Network access devices 1 and 2 belong to the same manufacturer, and their second data encapsulation templates are both data encapsulation template A, while network access device 3 uses data encapsulation template B. When the network configuration parameters of all network access devices are identical (i.e., they are all target network configuration parameters), the network control device can encapsulate the target network configuration parameters according to data encapsulation template A to obtain the second network configuration data packet corresponding to network access device 1. Since network access devices 1 and 2 use the same data encapsulation template, and their network configuration parameters are identical, the second network configuration data packet corresponding to network access device 1 can be identified as the second network configuration data packet corresponding to network access device 2. Then, the target network configuration parameters can be encapsulated according to data encapsulation template B to obtain the second network configuration data packet corresponding to network access device 3.
[0068] Alternatively, when the network configuration parameters of each network access device are different, the network control device can obtain the network configuration parameters corresponding to network access device 1, network access device 2, and network access device 3 respectively from the target network configuration parameters. It can encapsulate the network configuration parameters corresponding to network access device 1 according to data encapsulation template A to obtain the second network configuration data packet corresponding to network access device 1. It can also encapsulate the network configuration parameters corresponding to network access device 2 according to data encapsulation template A to obtain the second network configuration data packet corresponding to network access device 2. Finally, it can encapsulate the network configuration parameters corresponding to network access device 3 according to data encapsulation template B to obtain the second network configuration data packet corresponding to network access device 3.
[0069] Optionally, the N network access devices include network access device Pi, where i is a positive integer less than or equal to N; the network access device Pi corresponds to the second data encapsulation template Qi, and the second data encapsulation template Qi contains a second data encapsulation format and a second data encryption method. The second data encapsulation format can be determined according to the communication protocol of the network access device Pi, and the second data encryption method can include one or more of the following: shared key encryption, message digest algorithm (MD5), and symmetric encryption algorithm (DES). When the network configuration parameters of all network access devices in the target location are the same, the network control device can encapsulate the target network configuration parameters to obtain the second network configuration data packet corresponding to the network access device Pi in the following way: encapsulate the target network configuration parameters according to the second data encapsulation format in the second data encapsulation template Qi to obtain a second data packet; encrypt the second data packet according to the second data encryption method in the second data encapsulation template Qi to obtain the second network configuration data packet corresponding to the network access device Pi. By analogy, the second network configuration data packets corresponding to N network access devices can be obtained, enabling site-level network configuration and improving the configuration efficiency of network access devices.
[0070] When the network configuration parameters of various network access devices within the target location are different, the network control device can encapsulate the target network configuration parameters to obtain a second network configuration data packet corresponding to network access device Pi in the following way: Obtain the network configuration parameters corresponding to network access device Pi from the target configuration parameters; encapsulate the network configuration parameters corresponding to network access device Pi according to the second data encapsulation format in the second data encapsulation template Qi to obtain a second data packet; encrypt the second data packet according to the second data encryption method in the second data encapsulation template Qi to obtain the second network configuration data packet corresponding to network access device Pi. By analogy, second network configuration data packets corresponding to N network access devices can be obtained, enabling personalized configuration of network access devices within the target location and improving the configuration efficiency of network access devices.
[0071] S104. The network control device sends N second network configuration data packets to the corresponding network access devices respectively. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets.
[0072] In this application, the network control device can send the second network configuration data packet corresponding to network access device 1 to network access device 1, send the second network configuration data packet corresponding to network access device 2 to network access device 2, and so on, sending the second network configuration data packets corresponding to N network access devices to their respective network access devices. Each network access device can perform network configuration according to the network configuration parameters in the second network data packet, realizing unified network configuration distribution, improving the configuration efficiency of network access point devices, and reducing costs.
[0073] Optionally, the network control device can periodically report the network configuration parameters of each network access device within the target location to prevent the network configuration parameters of the network access devices from being tampered with, which could cause the network access devices to malfunction. Specifically, the network control device can encapsulate the current network configuration parameters of the network access device Pi according to the first data encapsulation template to obtain a third network configuration data packet, and send the third network configuration data packet to the cloud server. The third network configuration data packet is used to instruct the cloud server to generate a network configuration difference data packet. The network configuration difference data packet is obtained by encapsulating the network configuration difference parameters of the network access device Pi according to the first data encapsulation template. The network configuration difference parameters are obtained based on the third network configuration data packet and the local network configuration parameters of the network access device Pi stored in the cloud server. The device can also receive the network configuration difference data packet sent by the cloud server and update the network configuration parameters of the network access device Pi according to the network configuration difference data packet.
[0074] The network control device can encapsulate the current network configuration parameters of the network access device Pi according to the first data encapsulation template to obtain a third network configuration data packet, and send the third network configuration data packet to the cloud server. After receiving the third network configuration data packet, the cloud server can parse the third network configuration data packet to obtain the current network configuration parameters of the network access device Pi. Furthermore, the cloud server can obtain the local network configuration parameters of the network access device Pi from its local database. These local network configuration parameters can be the most recent network configuration parameters of the network access device Pi in the local database. If the current network configuration parameters are the same as the local network configuration parameters, it indicates that the network configuration parameters of the network access device Pi have not been tampered with, or that the previous network configuration of the network access device Pi was successfully issued. Therefore, the cloud server can send a message to the network control device not to update the network configuration parameters of the network access device Pi. If the current network configuration parameters are different from the local network configuration parameters, it indicates that the network configuration parameters of the network access device Pi have been tampered with, or that the previous network configuration of the network access device Pi failed to be issued. Therefore, the cloud server can obtain the network configuration difference parameters between the current network configuration parameters and the local network configuration parameters. Furthermore, the cloud server can encapsulate the network configuration difference parameters of the network access device Pi according to the first data encapsulation template to obtain a network configuration difference data packet. This network configuration difference data packet is then sent to the network control device. Upon receiving the network configuration difference data packet, the network control device can parse it to obtain the network configuration difference parameters. Furthermore, the network control device can update the network configuration parameters of the network access device Pi based on these network configuration difference parameters. This enables the cloud server to monitor network access devices within the target location in real time, improving the operational security of the network access devices.
[0075] For example, enterprise-level network configurations typically require all network access devices within the enterprise to have the same network configuration. However, during use, due to network or human factors, the network configuration of the network access devices may differ from the network configuration parameters stored on the cloud server. In this case, the network control device's SDK needs to periodically report the current network configuration parameters of the network access devices to the cloud server. The cloud server then reissues the network configuration difference parameters to the network access devices, and the network access devices update their network configurations based on these differences. Figure 4As shown, the SDK of the network control device can periodically collect the current network configuration parameters of the network access device Pi in the target location, encapsulate the current network configuration parameters according to the first data encapsulation format, and obtain a third network configuration parameter data packet carrying the current network configuration parameters. This third network configuration data packet carrying the current network configuration parameters is sent to the HUB module of the cloud server via a WebSocket connection. The HUB module parses the third network configuration data packet to obtain the current network configuration parameters, and sends the current network configuration parameters to the object model and operation platform of the cloud server through an internal interface. The operation platform stores the current network configuration parameters, generates and displays statistical analysis reports on the current network configuration parameters, and the object model obtains the local network configuration parameters of the network access device Pi in the local database from the location management, compares the local network configuration parameters with the current network configuration parameters, and if there is a difference, obtains the network configuration difference parameter between the two and sends the network configuration difference parameter to the HUB module. At the same time, the operation platform sends a network configuration update message to the network application control device to record the local network configuration synchronization event for easy viewing by the user later. Furthermore, the HUB module generates a network configuration difference data packet carrying network configuration difference parameters, and sends the network configuration difference data packet to the SDK of the network control device. The SDK updates the network configuration of the network access device Pi according to the network configuration difference parameters.
[0076] Optionally, the network control device may obtain a third network configuration data packet carrying the current network configuration parameters of the network access device Pi through any one or a combination of the following two methods:
[0077] Method 1: The network control device sends the first data encapsulation template to the network access device Pi. The first data encapsulation template is used to instruct the network access device Pi to encapsulate the current network configuration parameters according to the first data encapsulation template to obtain a third network configuration data packet; and receives the third network configuration data packet sent by the network access device Pi.
[0078] In Method 1, the network control device can send the first data encapsulation template to the network access device Pi. The network access device Pi can encapsulate its current network configuration parameters according to the second data encapsulation template to obtain a third network configuration data packet, and then send the third network configuration data packet to the network control device. In other words, the network control device does not need to convert and process the data packets sent by each network access device in the target location, which can reduce the data processing pressure on the network control device.
[0079] Method 2: The network control device receives a fourth network configuration data packet sent by the network access device Pi; the fourth network configuration data packet is obtained by encapsulating the current network configuration parameters of the network access device Pi according to the second data encapsulation template Qi; the fourth network configuration data packet is parsed to obtain the current network configuration parameters of the network access device Pi; the current network configuration parameters are encapsulated according to the first data encapsulation format in the first data encapsulation template to obtain a first data packet; the first data packet is encrypted according to the first data encryption method in the first data encapsulation template to obtain the third network configuration data packet.
[0080] In Method Two, the network control device can receive a fourth network configuration data packet sent by the network access device Pi. This fourth network configuration data packet is obtained by encapsulating the current network configuration parameters of the network access device Pi according to the second data encapsulation template Qi. When the network control device receives the fourth network configuration data packet, it can parse the fourth network configuration data packet to obtain the current network configuration parameters of the network access device Pi. The network control device can encapsulate the current network configuration parameters according to the first data encapsulation format in the first data encapsulation template to obtain a first data packet; and encrypt the first data packet according to the first data encryption method in the first data encapsulation template to obtain the third network configuration data packet. In other words, the network control device can convert the fourth network configuration data packet sent by the network access device Pi into a third network configuration data packet that the cloud server can recognize. This allows the cloud server to uniformly manage network access devices with different characteristics, improving the management efficiency of network access devices.
[0081] Optionally, the network control device can obtain the sending time of sending the second network configuration data packet to the network access device Pi. If no feedback message is received from the network access device Pi within a limited time period after the sending time, the current network configuration parameters of the network access device Pi are encapsulated according to the first data encapsulation template to obtain a third network configuration data packet. The feedback message is used to reflect that the network access device Pi has received the second network configuration data packet.
[0082] The network control device can obtain the sending time of the second network configuration data packet sent to the network access device Pi. If no feedback message is received from the network access device Pi within the limited time period after the sending time, it indicates that the second network configuration data packet failed to be sent to the network access device Pi. Therefore, the network control device can encapsulate the current network configuration parameters of the network access device Pi according to the first data encapsulation template to obtain the third network configuration data packet. This is beneficial for the network control device to resend the network configuration to the network access device Pi and ensure that the network access device can operate normally.
[0083] Optionally, the target location is a target organization. When an employee's terminal within the target organization needs to connect to a network access device Pi, the network control device can generate an employee key for establishing a network connection between the network access device Pi and the employee terminal as follows: Obtain the terminal identifier of the employee terminal to be connected to the network access device Pi; the employee terminal belongs to the target organization; generate a first key acquisition request carrying the terminal identifier of the employee terminal according to the first data encapsulation template; and send the first key acquisition request to the cloud server. The first key acquisition request instructs the cloud server to generate an employee key corresponding to the employee terminal, encapsulate the employee key according to the first data encapsulation template to obtain a first key data packet; receive the first key data packet sent by the cloud server; the first key data packet instructs the network control device to establish a network connection between the employee terminal and the network access device Pi.
[0084] The network control device can obtain the terminal identifier of the employee terminal to be connected to the network access device Pi, generate a first key acquisition request carrying the terminal identifier of the employee terminal according to the first data encapsulation template, and send the first key acquisition request to the cloud server. After receiving the first key acquisition request, the cloud server can generate the employee key corresponding to the employee terminal according to the terminal identifier of the employee terminal and the organization identifier of the target organization. The cloud server can encapsulate the employee key according to the first data encapsulation template to obtain a first key data packet, and send the first key data packet to the network control device. After receiving the first key data packet sent by the cloud server, the network control device parses the first key data packet to obtain the employee key, and establishes a network connection between the network access device Pi and the employee terminal according to the employee key. Since the employee key corresponding to the employee terminal is generated according to the terminal identifier of the employee terminal and the organization identifier of the target organization, that is, the terminal identifier and the organization identifier are unique, therefore, the employee key corresponding to all employee terminals within the target organization is unique, which can improve the network connection security of the employee terminal.
[0085] Optionally, the network control device includes a data processing component, which is used to perform the steps in S101 to S104 above. That is, the data processing component can refer to an SDK. Users do not need to configure the network control device. It is plug-and-play after powering on and connecting to the network, which can reduce the operation and maintenance costs of network access point devices.
[0086] In this application, when network configuration of network access devices within a target location is required, the cloud server can obtain the target network configuration parameters of N network access devices within the target location, encapsulate the target network configuration data of the N network access devices according to a first data encapsulation template, obtain a first network configuration data packet, and send the first network configuration data packet to the network control device associated with the target location. After receiving the first network configuration data packet, the network control device can parse the first network configuration data packet to obtain the target network configuration parameters of the N network access devices. These target network configuration parameters include the network configuration parameters of all network access devices within the target location. In other words, users do not need to operate on individual network access devices; all configurations are performed at the location level (e.g., enterprise level), enabling batch configuration of network access devices and improving configuration efficiency. Furthermore, the network control device can encapsulate the target network configuration parameters according to the second data encapsulation template corresponding to each of the N network access devices, obtaining N second network configuration data packets corresponding to each network access device, and send the N second network configuration data packets to the corresponding network access devices. The network access devices can then perform network configuration based on the second network configuration data packets. The second data encapsulation template here is the template used by the network access device for data encapsulation processing. That is, the second network configuration data packet is a data packet that the network access device can recognize. In other words, the network control device converts the first network configuration data packet sent by the cloud server into a second network configuration data packet that each network access device can recognize. This masks the differences between the various network access devices, enabling unified access to the cloud server for all network access devices. In other words, the network control device achieves interconnection and interoperability between the cloud server and multiple diverse network access devices. The cloud server is responsible for managing all network access devices in the target location, enabling unified management of network access point devices within the target location, improving management efficiency, and reducing network access device operation and maintenance costs.
[0087] Further, please see Figure 5 This is a flowchart illustrating a network configuration method provided in an embodiment of this application. Figure 5 As shown, this method can be derived from... Figure 1 The network configuration method is executed by IoT devices in the network and may include S201 to S204:
[0088] S201. The cloud server obtains the target network configuration parameters of N network access devices; the N network access devices belong to target locations associated with the network control device; N is a positive integer greater than 1; the network control device is connected to the cloud server.
[0089] In this application, the cloud server can obtain candidate network configuration parameters configured for N network access devices from the network application device. These candidate network configuration parameters can be configured by the user in the network configuration page of the network application device. If the cloud server is obtaining the network configuration parameters of the N network access devices for the first time, it can store the candidate network configuration parameters in the local database of the cloud server and determine the candidate network configuration parameters as the target network configuration parameters for the N network access devices.
[0090] Alternatively, if the cloud server is not obtaining the network configuration parameters of N network access devices for the first time, it can obtain the target network configuration parameters of the N network access devices as follows: It retrieves the local network configuration parameters of the N network access devices from the local database. These local network configuration parameters are the most recently stored network configuration parameters in the local database. If the local network configuration parameters are the same as the candidate network configuration parameters, it indicates that the network access device already has the latest network configuration, and a message not to update the network configuration parameters of the N network access devices can be sent to the network control device. If the local network configuration parameters are different from the candidate network configuration parameters, it indicates that the network access device does not have the latest network configuration, and the changed network configuration parameters between the candidate network configuration parameters and the local network configuration parameters are determined. That is, the changed network configuration parameters here can refer to the network configuration difference parameters (i.e., incremental data) between the local network configuration parameters and the candidate network configuration parameters. Furthermore, the changed network configuration parameter is determined as the target network configuration parameter for N network access devices. The local network configuration parameter in the local database is updated using the changed network configuration parameter. By sending the changed network configuration parameter in the candidate network configuration parameter to the network control device, it is not necessary to send all the data in the candidate network configuration parameter to the network control device. This can reduce the data transmission pressure and improve the configuration efficiency of the network access device.
[0091] S202. The cloud server encapsulates the target network configuration parameters according to the first data encapsulation template that matches the cloud server to obtain the first network configuration data packet.
[0092] The cloud server can encapsulate the target network configuration parameters according to a first data encapsulation template that matches the cloud server, resulting in a first network configuration data packet. Here, the first data encapsulation template can refer to the cloud server's original data encapsulation template, meaning that no modifications are required from the cloud server. This allows multiple different network access devices within the target location to be connected to the cloud server, enabling unified management of these devices, improving management efficiency, and reducing maintenance costs.
[0093] Optionally, the cloud server can obtain the first network configuration data packet by: encapsulating the target network configuration parameters according to the first data encapsulation format in the first data encapsulation template to obtain a third data packet; encrypting the third data packet according to the first data encryption method in the first data encapsulation template to obtain the first network configuration data packet.
[0094] The cloud server can encapsulate the target network configuration parameters according to the first data encapsulation format in the first data encapsulation template to obtain a third data packet. The first data encapsulation format can be determined according to the communication protocol of the cloud server. Further, the third data packet is encrypted according to the first data encryption method in the first data encapsulation template to obtain the first network configuration data packet. The first data encryption method here can include one or more of the following: shared key encryption method, message digest algorithm (MD5), and symmetric encryption algorithm (DES).
[0095] S203. The cloud server sends the first network configuration data packet to the network control device. The first network configuration data packet is used to instruct the network control device to send N second network configuration data packets to the corresponding network access devices. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets. The N second network configuration data packets are obtained by encapsulating the target network configuration parameters according to the second data encapsulation templates corresponding to the N network access devices. The target network configuration parameters are obtained by parsing the first network configuration data packet. At least two of the N network access devices have different second data encapsulation templates.
[0096] In this application, after the cloud server obtains the first network configuration data packet, it sends the first network configuration data packet to the network control device. The network control device can parse the first network configuration parameters to obtain the target network configuration parameters for N network access devices. The network control device can encapsulate the target network configuration parameters according to the second data encapsulation template corresponding to each of the N network access devices, obtaining the second network configuration data packets corresponding to each of the N network access devices. The second data encapsulation template is the original data encapsulation method of the network access devices, that is, no changes need to be made to the network access devices, and the second network configuration data packets are data packets that the network access devices can recognize. In other words, the network control device can convert the first network configuration data sent by the cloud server into second network configuration data packets that can be recognized by each network access device, which can realize the interconnection and interoperability between the cloud server and multiple network access devices with differences in the target location, can shield the differences between the network access devices, realize unified management of multiple network access devices with differences, improve the management efficiency of network access devices, and reduce the operation and maintenance costs of network access devices.
[0097] Optionally, the cloud server can receive a third network configuration data packet sent by the network control device; the third network configuration data packet is obtained by encapsulating the current network configuration parameters of network access point Pi according to the first data encapsulation template; the network access device Pi belongs to N network access devices, and i is a positive integer less than or equal to N. The third network configuration data packet is parsed to obtain the current network configuration parameters of network access point Pi; the local network configuration parameters of network access point Pi are obtained from the local database; the network configuration difference parameters between the current network configuration parameters and the local network configuration parameters are determined. The network configuration difference parameters are encapsulated according to the first data encapsulation template to obtain a network configuration difference data packet; the network configuration difference data packet is sent to the network control device, and the network configuration difference data packet is used to instruct the network control device to update the network configuration parameters of network access device Pi.
[0098] The network control device can encapsulate the current network configuration parameters of the network access device Pi according to the first data encapsulation template to obtain a third network configuration data packet, and send the third network configuration data packet to the cloud server. After receiving the third network configuration data packet, the cloud server can parse it to obtain the current network configuration parameters of the network access device Pi. Furthermore, the cloud server can retrieve the local network configuration parameters of the network access device Pi from its local database. These local network configuration parameters can be the most recent network configuration parameters of the network access device Pi in the local database. If the current network configuration parameters are the same as the local network configuration parameters, it indicates that the network configuration parameters of the network access device Pi have not been tampered with, or that the previous network configuration of the network access device Pi was successfully issued. Therefore, the cloud server can send a message to the network control device not to update the network configuration parameters of the network access device Pi. If the current network configuration parameters are different from the local network configuration parameters, it indicates that the network configuration parameters of the network access device Pi have been tampered with, or that the previous network configuration of the network access device Pi failed to be issued. Therefore, the cloud server can obtain the network configuration difference parameters between the current network configuration parameters and the local network configuration parameters. Furthermore, the cloud server can encapsulate the network configuration difference parameters of the network access device Pi according to the first data encapsulation template to obtain a network configuration difference data packet. This network configuration difference data packet is then sent to the network control device. Upon receiving the network configuration difference data packet, the network control device can parse it to obtain the network configuration difference parameters. Furthermore, the network control device can update the network configuration parameters of the network access device Pi based on these network configuration difference parameters. This enables the cloud server to monitor network access devices within the target location in real time, improving the operational security of the network access devices.
[0099] Optionally, the target location is a target organization. The cloud server receives a first key acquisition request sent by the network control device. The first key acquisition request is generated based on the terminal identifier of the employee terminal to be connected to the network access point Pi according to the first data encapsulation template. The employee terminal belongs to the target organization. The first key acquisition request is parsed to obtain the terminal identifier of the employee terminal. Based on the terminal identifier of the employee terminal and the organization identifier of the target organization, an employee key corresponding to the employee terminal is generated. The employee key is encapsulated according to the first data encapsulation template to obtain a first key data packet. The first key data packet is sent to the network control device. The first key data packet is used to instruct the network control device to establish a network connection between the employee terminal and the network access device Pi.
[0100] When an employee terminal of a target organization needs to access the network corresponding to network access device Pi, the network control device can generate a first key acquisition request carrying the terminal identifier of the employee terminal and send the first key acquisition request to the cloud server. Upon receiving the first key acquisition request, the cloud server can parse it to obtain the terminal identifier corresponding to the employee terminal. Based on the terminal identifier and the organization identifier of the target organization, the cloud server can generate an employee key corresponding to the employee terminal. The cloud server can encapsulate the employee key according to a first data encapsulation template to obtain a first key data packet, which is then sent to the network control device. After receiving the first key data packet from the cloud server, the network control device parses it to obtain the employee key. Based on this employee key, a network connection is established between network access device Pi and the employee terminal. Since the employee key corresponding to the employee terminal is generated based on the terminal identifier of the employee terminal and the organization identifier of the target organization (i.e., the terminal identifier and organization identifier are unique), all employee terminals within the target organization have unique employee keys, thus improving the network connection security of the employee terminals.
[0101] Optionally, generating the employee key corresponding to the employee terminal based on the terminal identifier of the employee terminal and the organization identifier of the target organization includes: calling a function computing engine to obtain the key generation function corresponding to the target organization, and performing calculations on the terminal identifier of the employee terminal and the organization identifier based on the key generation function to obtain the employee key corresponding to the employee terminal.
[0102] The cloud server includes a Function Compute engine, which generates unique employee keys for network connections for employee terminals within the target organization. Each employee terminal has a distinct key. Therefore, the Function Compute engine is invoked to obtain the key generation function corresponding to the target organization. Based on this function, the terminal identifier and the organization identifier of the employee terminal are used to perform calculations to obtain the corresponding employee key. Since different employee terminals have different key outputs, network connection security is improved. For example, if the employee key of one employee terminal is tampered with, only the network connection security of that terminal is affected. Subsequent modifications only require changing the employee key of that terminal, thus improving network connection security and reducing maintenance costs.
[0103] It should be noted that the network control device includes key management, which can be a functional module based on the Function Compute engine. The Function Compute engine is based on the Serverless (i.e., microservice computing) theoretical framework. Serverless is an internet-based technical architecture concept where application logic is not entirely implemented on the server side, but rather uses a FAAS (Function as a Service) architecture, implementing application logic through functional combination. Furthermore, the Serverless architecture allows developers to focus on the acquisition and maintenance of computing resources during application construction, as the platform allocates computing resources on demand, effectively saving application costs. For example, ... Figure 6 As shown, the database includes one or more key generation functions. This data packet can be located in a network application device or a device associated with the network application device. The network application device can obtain the key generation function corresponding to the target organization from the database, such as... Figure 6 In this process, network application devices can retrieve key generation functions from a database based on the Content Delivery Network (CDN). A CDN is an intelligent virtual network built on top of the existing network infrastructure. Relying on edge servers deployed in various locations, and through the central platform's load balancing, content distribution, and scheduling modules, it enables users to access the content they need (such as key generation functions) from the nearest location, reducing network congestion and improving user access response speed and hit rate. Furthermore, based on this key generation function, a function computing engine is triggered to generate keys related to the target organization.
[0104] For example, such as Figure 7 In this process, network control device 1 is associated with the target organization. When an employee terminal within the target organization needs to connect to the network corresponding to network access device Pi within the target organization, network control device 1 can generate a first key acquisition request carrying the terminal identifier of the employee terminal. This first key acquisition request is used to request a key and is sent to the HUB module of the cloud server. The HUB module sends the first key acquisition request to key management. Key management obtains the key generation function corresponding to the target organization from the operation platform. This key generation function can be selected by the user from the database in the network application platform. Key management calls the function computing engine to generate an employee key corresponding to the employee terminal based on the key generation function, the employee terminal's key, and the target organization's identifier. This employee key is then sent to the HUB. The HUB generates a first key data packet carrying the employee key and sends this first key data packet to the SDK of the network control device. Based on this first key data packet, a network connection is established between the employee terminal and network access device Pi.
[0105] Optionally, to prevent malicious tampering of employee terminal keys, which could lead to network connection failures, the network control device's SDK can periodically report the current employee key of the employee terminal to the cloud server. Alternatively, when an employee terminal's network connection fails, the network control device's SDK can report the current employee key to the cloud server, which will then update the employee key and reissue it to the employee terminal. The employee terminal can then reconnect to the network based on the updated employee key. Figure 8 As shown, the SDK of the network control device can collect the current employee key of the employee terminal connected to the network access device Pi in the target location, encapsulate the current employee key according to the first data encapsulation format, and obtain a third key data packet carrying the current employee key. This third key data packet carrying the current employee key is sent to the HUB module of the cloud server via a WebSocket connection. The HUB module parses the third key data packet to obtain the current employee key and sends it to the object model and operation platform of the cloud server through an internal interface. The operation platform stores the current employee key, generates and displays statistical analysis reports about the current employee key. The object model obtains the local employee key from the local database of the employee terminal from the location management, compares the local employee key with the current employee key, and if there is a difference, obtains the key difference data between the two, uses this key difference data as the updated employee key, and sends the updated employee key to the HUB module. Simultaneously, the operation platform sends an employee key configuration update message to the network application control device to record the local network configuration synchronization event for later user review. Furthermore, the HUB module generates an update key data packet carrying the updated employee key, and sends the update key data packet to the SDK of the network control device. The SDK re-establishes the network connection between the employee terminal and the network access device Pi based on the update key data packet.
[0106] Optionally, a second key acquisition request is received from a visitor terminal; the second key acquisition request carries the terminal identifier of the visitor terminal, which is associated with the employee terminal; according to the key generation function, the terminal identifier of the visitor terminal and the terminal identifier of the employee terminal are calculated to obtain the visitor key corresponding to the visitor terminal; the visitor key is encapsulated according to the first data encapsulation template to obtain a second key data packet; the second key data packet is sent to the network control device, which instructs the network control device to establish a network connection between the visitor terminal and the network access device Pi.
[0107] When a visitor enters a target organization and their corresponding terminal needs to connect to the organization's network access device Pi for network connectivity, this terminal can be referred to as a visitor terminal. This visitor terminal can be associated with any employee terminal within the target area and sends a second key retrieval request carrying the visitor terminal's identifier to the cloud server. Upon receiving this request, the cloud server can perform calculations on the visitor terminal's identifier and the employee terminal's identifier using the key generation function to obtain the visitor key corresponding to the visitor terminal. The visitor key is then encapsulated according to the first data encapsulation template to obtain a second key data packet. This second key data packet is sent to the network control device, instructing the network control device to establish a network connection between the visitor terminal and the network access device Pi. In other words, dynamically generating a visitor key for establishing a network connection between a visitor terminal and the network access device Pi when a visitor terminal needs to connect to the target organization's network improves the security of the visitor terminal's network connection.
[0108] For example, such as Figure 9As shown, the process of a visitor terminal connecting to the network corresponding to the target organization includes the following steps S51 to S57: S51: The visitor terminal adds employee A within the target organization as a friend. For example, when a visitor needs to connect to the target organization's wireless network (Wi-Fi), the visitor terminal can scan employee A's QR code to add employee A as a friend. Employee A's QR code is generated based on employee A's employee information in the network connection application, which can be a social application, web application, etc. S52: The employee terminal sends a link for network connection to the visitor terminal. The employee terminal can send a link for network connection to the visitor terminal through the network connection application. S53: The visitor clicks the link, and the visitor terminal sends a second key retrieval request to the cloud server. After receiving the link, the visitor terminal can display the link on the interface of the network connection application. If a click operation on the link is detected, the visitor terminal sends a second key retrieval request to the enterprise management of the cloud server. S54: The key management in the cloud server generates a visitor key and sends the visitor key to the enterprise management (i.e., venue management) of the cloud server. After receiving the second key acquisition request, the enterprise management system of the cloud server applies for a visitor key for employee A from the key management system. The key management system generates the visitor key corresponding to the visitor and sends the employee key to the enterprise management system, which then returns the visitor key to the visitor terminal. S55. The visitor terminal uses the visitor key to connect to the network. S56. The network control device reports visitor network connection information to the enterprise management system in the cloud server. When a visitor terminal connects to the network corresponding to the target organization, the network control device generates visitor network connection information for that visitor terminal and reports it to the enterprise management system in the cloud server. This way, the next time the visitor needs to connect to the target organization's network, it can automatically connect based on the visitor network connection information. This visitor network connection information includes the visitor key, the link used for network connection, the connection time, the connection duration, the visitor terminal's terminal identifier, and the terminal identifier of the employee terminal corresponding to employee A, etc. S57. The enterprise management system in the cloud server records the network connection information of visitors promoted by employee A. For example, the network connection information of visitors promoted by employee A is as follows: Figure 10As shown, based on the network access information of visitors promoted by employee A, the visitors promoted by employee A include customer 1 and customer 2. The visitor key corresponding to customer 1 is PPSK1. According to customer 1's visitor records, customer 1's network access times are: 10:00:00 on January 1, 2022 and 14:11:21 on January 3, 2022. The visitor key corresponding to customer 2 is PPSK2. According to customer 2's visitor records, customer 2's network access times are: 10:00:00 on January 1, 2022, 14:11:21 on January 3, 2022, and 19:37:55 on January 10, 2022. Optionally, the cloud server can analyze visitor behavior based on this network access information. Both obtaining visitor network access information and analyzing the network access information by the cloud server are only performed after the visitor authorizes the transaction.
[0109] In this application, when network configuration of network access devices within a target location is required, the cloud server can obtain the target network configuration parameters of N network access devices within the target location, encapsulate the target network configuration data of the N network access devices according to a first data encapsulation template, obtain a first network configuration data packet, and send the first network configuration data packet to the network control device associated with the target location. After receiving the first network configuration data packet, the network control device can parse the first network configuration data packet to obtain the target network configuration parameters of the N network access devices. These target network configuration parameters include the network configuration parameters of all network access devices within the target location. In other words, users do not need to operate on individual network access devices; all configurations are performed at the location level (e.g., enterprise level), enabling batch configuration of network access devices and improving configuration efficiency. Furthermore, the network control device can encapsulate the target network configuration parameters according to the second data encapsulation template corresponding to each of the N network access devices, obtaining N second network configuration data packets corresponding to each network access device, and send the N second network configuration data packets to the corresponding network access devices. The network access devices can then perform network configuration based on the second network configuration data packets. The second data encapsulation template here is the template used by the network access device for data encapsulation processing. That is, the second network configuration data packet is a data packet that the network access device can recognize. In other words, the network control device converts the first network configuration data packet sent by the cloud server into a second network configuration data packet that each network access device can recognize. This masks the differences between the various network access devices, enabling unified access to the cloud server for all network access devices. In other words, the network control device achieves interconnection and interoperability between the cloud server and multiple diverse network access devices. The cloud server is responsible for managing all network access devices in the target location, enabling unified management of network access point devices within the target location, improving management efficiency, and reducing network access device operation and maintenance costs.
[0110] Please see Figure 11 This is a schematic diagram of a network configuration device provided in an embodiment of this application. The aforementioned network configuration device can be a computer program (including program code) running on a network device; for example, the network configuration device is an application software. This device can be used to execute corresponding steps in the methods provided in the embodiments of this application. Figure 11 As shown, the network configuration device may include: a receiving module 111, a parsing module 112, an encapsulation module 113, a sending module 114, an acquisition module 115, and a generation module 116.
[0111] The receiving module is used to receive a first network configuration data packet sent by the cloud server; the first network configuration data packet is obtained by the cloud server encapsulating the target network configuration parameters of N network access devices according to a first data encapsulation template matching the cloud server, where the N network access devices belong to target locations associated with the network control device; N is a positive integer greater than 1.
[0112] The parsing module is used to parse the first network configuration data packet to obtain N target network configuration parameters of the network access devices;
[0113] An encapsulation module is used to encapsulate the target network configuration parameters according to the second data encapsulation templates corresponding to the N network access devices respectively, to obtain the second network configuration data packets corresponding to the N network access devices respectively; at least two of the N network access devices have different second data encapsulation templates.
[0114] The sending module is used to send N second network configuration data packets to the corresponding network access devices respectively. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets.
[0115] Optionally, the N network access devices include network access device Pi, where i is a positive integer less than or equal to N; the network access device Pi corresponds to the second data encapsulation template Qi; the encapsulation module encapsulates the target network configuration parameters according to the second data encapsulation templates corresponding to the N network access devices respectively, to obtain the second network configuration data packets corresponding to the N network access devices respectively, including:
[0116] The target network configuration parameters are encapsulated according to the second data encapsulation format in the second data encapsulation template Qi to obtain a second data packet;
[0117] The second data packet is encrypted according to the second data encryption method in the second data encapsulation template Qi to obtain the second network configuration data packet corresponding to the network access device Pi.
[0118] The encapsulation module is also used to encapsulate the current network configuration parameters of the network access device Pi according to the first data encapsulation template to obtain a third network configuration data packet;
[0119] The sending module is further configured to send the third network configuration data packet to the cloud server. The third network configuration data packet is used to instruct the cloud server to generate a network configuration difference data packet. The network configuration difference data packet is obtained by encapsulating the network configuration difference parameters of the network access device Pi according to the first data encapsulation template. The network configuration difference parameters are obtained based on the third network configuration data packet and the local network configuration parameters of the network access device Pi stored in the cloud server.
[0120] The receiving module is also used to receive the network configuration difference data packet sent by the cloud server, and update the network configuration parameters of the network access device Pi according to the network configuration difference data packet.
[0121] Optionally, the encapsulation module encapsulates the current network configuration parameters of the network access device Pi according to the first data encapsulation template to obtain a third network configuration data packet, including:
[0122] The first data encapsulation template is sent to the network access device Pi. The first data encapsulation template is used to instruct the network access device Pi to encapsulate the current network configuration parameters according to the first data encapsulation template to obtain a third network configuration data packet.
[0123] Receive the third network configuration data packet sent by the network access device Pi.
[0124] Optionally, the encapsulation module encapsulates the current network configuration parameters of the network access device Pi according to the first data encapsulation template to obtain a third network configuration data packet, including:
[0125] The system receives a fourth network configuration data packet sent by the network access device Pi; the fourth network configuration data packet is obtained by encapsulating the current network configuration parameters of the network access device Pi according to the second data encapsulation template Qi.
[0126] The fourth network configuration data packet is parsed to obtain the current network configuration parameters of the network access device Pi;
[0127] The current network configuration parameters are encapsulated according to the first data encapsulation format in the first data encapsulation template to obtain a first data packet;
[0128] The first data packet is encrypted according to the first data encryption method in the first data encapsulation template to obtain the third network configuration data packet.
[0129] Optionally, the encapsulation module encapsulates the current network configuration parameters of the network access device Pi according to the first data encapsulation template to obtain a third network configuration data packet, including:
[0130] Obtain the time when the second network configuration data packet is sent to the network access device Pi;
[0131] If no feedback message is received from the network access device Pi within the limited time period after the sending time, the current network configuration parameters of the network access device Pi are encapsulated according to the first data encapsulation template to obtain a third network configuration data packet; the feedback message is used to reflect that the network access device Pi has received the second network configuration data packet.
[0132] Optionally, the target location is a target organization, and the acquisition module is used to acquire the terminal identifier of the employee terminal to be connected to the network access device Pi; the employee terminal belongs to the target organization;
[0133] The generation module is used to generate a first key acquisition request carrying the terminal identifier of the employee terminal based on the first data encapsulation template;
[0134] The sending module is further configured to send the first key acquisition request to the cloud server. The first key acquisition request is used to instruct the cloud server to generate an employee key corresponding to the employee terminal and to encapsulate the employee key according to the first data encapsulation template to obtain a first key data packet.
[0135] The receiving module is also used to receive a first key data packet sent by the cloud server; the first key data packet is used to instruct the network control device to establish a network connection between the employee terminal and the network access device Pi.
[0136] According to one embodiment of this application, Figure 3 The steps involved in the network configuration method shown can be derived from... Figure 11 The network configuration device shown is executed by each module. For example, Figure 3 Step S101 shown can be performed by Figure 11 The receiving module 111 in the middle is used to perform this. Figure 3 Step S102 shown can be performed by Figure 11 The parsing module 112 in the middle is used for execution; Figure 3 Step S103 shown can be performed by Figure 11 The encapsulation module 113 in the middle is used to execute; Figure 3 Step S104 shown can be performed by Figure 11 The sending module 114 in the middle is used to execute this.
[0137] According to one embodiment of this application, Figure 11 The modules in the network configuration device shown can be individually or entirely combined into one or more units, or some of these units can be further divided into at least two functionally smaller sub-units to achieve the same operation without affecting the technical effects of the embodiments of this application. The above modules are based on logical functional division. In practical applications, the function of one module can be implemented by at least two units, or the function of at least two modules can be implemented by one unit. In other embodiments of this application, the network configuration device may also include other units. In practical applications, these functions can also be implemented with the assistance of other units, and can be implemented collaboratively by at least two units.
[0138] According to one embodiment of this application, a general-purpose computer device, such as a computer, which includes processing elements and storage elements such as a central processing unit (CPU), random access memory (RAM), and read-only memory (ROM), can perform operations such as... Figure 3 The computer program (including program code) for each step involved in the corresponding method shown, to construct such... Figure 11 The network configuration apparatus shown herein, and the network configuration method for implementing the embodiments of this application, are described. The computer program described above may be recorded on, for example, a computer-readable recording medium, loaded onto the aforementioned computing device via the computer-readable recording medium, and run therein.
[0139] In this application, when network configuration of network access devices within a target location is required, the cloud server can obtain the target network configuration parameters of N network access devices within the target location, encapsulate the target network configuration data of the N network access devices according to a first data encapsulation template, obtain a first network configuration data packet, and send the first network configuration data packet to the network control device associated with the target location. After receiving the first network configuration data packet, the network control device can parse the first network configuration data packet to obtain the target network configuration parameters of the N network access devices. These target network configuration parameters include the network configuration parameters of all network access devices within the target location. In other words, users do not need to operate on individual network access devices; all configurations are performed at the location level (e.g., enterprise level), enabling batch configuration of network access devices and improving configuration efficiency. Furthermore, the network control device can encapsulate the target network configuration parameters according to the second data encapsulation template corresponding to each of the N network access devices, obtaining N second network configuration data packets corresponding to each network access device, and send the N second network configuration data packets to the corresponding network access devices. The network access devices can then perform network configuration based on the second network configuration data packets. The second data encapsulation template here is the template used by the network access device for data encapsulation processing. That is, the second network configuration data packet is a data packet that the network access device can recognize. In other words, the network control device converts the first network configuration data packet sent by the cloud server into a second network configuration data packet that each network access device can recognize. This masks the differences between the various network access devices, enabling unified access to the cloud server for all network access devices. In other words, the network control device achieves interconnection and interoperability between the cloud server and multiple diverse network access devices. The cloud server is responsible for managing all network access devices in the target location, enabling unified management of network access point devices within the target location, improving management efficiency, and reducing network access device operation and maintenance costs.
[0140] Please see Figure 12 This is a schematic diagram of a network configuration device provided in an embodiment of this application. The aforementioned network configuration device can be a computer program (including program code) running on an Internet of Things (IoT) device; for example, the network configuration device is an application software. This device can be used to execute corresponding steps in the methods provided in the embodiments of this application. Figure 12 As shown, the network configuration device may include: an acquisition module 121, an encapsulation module 122, a sending module 123, a receiving module 124, a parsing module 125, a determination module 126, and a generation module 127.
[0141] The acquisition module is used to acquire target network configuration parameters for N network access devices; the N network access devices belong to target locations associated with the network control device; N is a positive integer greater than 1; the network control device is connected to the cloud server;
[0142] The encapsulation module is used to encapsulate the target network configuration parameters according to a first data encapsulation template that matches the cloud server, so as to obtain a first network configuration data packet;
[0143] The sending module is used to send the first network configuration data packet to the network control device. The first network configuration data packet is used to instruct the network control device to send N second network configuration data packets to the corresponding network access devices. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets. The N second network configuration data packets are obtained by encapsulating the target network configuration parameters according to the second data encapsulation templates corresponding to the N network access devices. The target network configuration parameters are obtained by parsing the first network configuration data packet. At least two of the N network access devices have different second data encapsulation templates.
[0144] Optionally, the encapsulation module encapsulates the target network configuration parameters according to a first data encapsulation template matching the cloud server to obtain a first network configuration data packet, including:
[0145] The target network configuration parameters are encapsulated according to the first data encapsulation format in the first data encapsulation template to obtain a third data packet;
[0146] The third data packet is encrypted according to the first data encryption method in the first data encapsulation template to obtain the first network configuration data packet.
[0147] Optionally, the acquisition module acquires the target network configuration parameters of N network access devices, including:
[0148] The cloud server obtains N candidate network configuration parameters for the network access devices from the network application device;
[0149] Retrieve local network configuration parameters for N network access devices from the local database;
[0150] Determine the network configuration parameters that change between the candidate network configuration parameters and the local network configuration parameters;
[0151] The changed network configuration parameters are determined as the target network configuration parameters for N network access devices.
[0152] Optionally, a receiving module is configured to receive a third network configuration data packet sent by the network control device; the third network configuration data packet is obtained by encapsulating the current network configuration parameters of the network access point Pi according to the first data encapsulation template; the network access device Pi belongs to N network access devices, and i is a positive integer less than or equal to N;
[0153] The parsing module is used to parse the third network configuration data packet to obtain the current network configuration parameters of the network access point Pi;
[0154] The acquisition module is also used to acquire local network configuration parameters of the network access point Pi from the local database;
[0155] The determination module is used to determine the network configuration difference parameters between the current network configuration parameters and the local network configuration parameters;
[0156] The encapsulation module is also used to encapsulate the network configuration difference parameters according to the first data encapsulation template to obtain a network configuration difference data packet;
[0157] The sending module is further configured to send the network configuration difference data packet to the network control device, wherein the network configuration difference data packet is used to instruct the network control device to update the network configuration parameters of the network access device Pi.
[0158] Optionally, the target location is a target organization, and the receiving module is further configured to receive a first key acquisition request sent by the network control device; the first key acquisition request is generated based on the terminal identifier of the employee terminal to be connected to the network access point Pi according to the first data encapsulation template, and the employee terminal belongs to the target organization;
[0159] The parsing module is also used to parse the first key acquisition request to obtain the terminal identifier of the employee terminal;
[0160] The generation module is also used to generate an employee key corresponding to the employee terminal based on the terminal identifier of the employee terminal and the organization identifier of the target organization;
[0161] The encapsulation module is further configured to encapsulate the employee key according to the first data encapsulation template to obtain a first key data packet, and send the first key data packet to the network control device. The first key data packet is used to instruct the network control device to establish a network connection between the employee terminal and the network access device Pi.
[0162] Optionally, the generation module generates an employee key corresponding to the employee terminal based on the terminal identifier of the employee terminal and the organization identifier of the target organization, including:
[0163] Call the function computation engine to obtain the key generation function corresponding to the target organization;
[0164] The employee key corresponding to the employee terminal is obtained by performing calculations on the terminal identifier and the organization identifier of the employee terminal according to the key generation function.
[0165] Optionally, the receiving module is further configured to receive a second key acquisition request sent by the visitor terminal; the second key acquisition request carries the terminal identifier of the visitor terminal, and the visitor terminal is associated with the employee terminal;
[0166] The receiving module is further configured to perform calculations on the terminal identifier of the visitor terminal and the terminal identifier of the employee terminal according to the key generation function to obtain the visitor key corresponding to the visitor terminal;
[0167] The encapsulation module is also used to encapsulate the visitor key according to the first data encapsulation template to obtain a second key data packet;
[0168] The sending module is further configured to send the second key data packet to the network control device, wherein the second key data packet is used to instruct the network control device to establish a network connection between the guest terminal and the network access device Pi.
[0169] In this application, when network configuration of network access devices within a target location is required, the cloud server can obtain the target network configuration parameters of N network access devices within the target location, encapsulate the target network configuration data of the N network access devices according to a first data encapsulation template, obtain a first network configuration data packet, and send the first network configuration data packet to the network control device associated with the target location. After receiving the first network configuration data packet, the network control device can parse the first network configuration data packet to obtain the target network configuration parameters of the N network access devices. These target network configuration parameters include the network configuration parameters of all network access devices within the target location. In other words, users do not need to operate on individual network access devices; all configurations are performed at the location level (e.g., enterprise level), enabling batch configuration of network access devices and improving configuration efficiency. Furthermore, the network control device can encapsulate the target network configuration parameters according to the second data encapsulation template corresponding to each of the N network access devices, obtaining N second network configuration data packets corresponding to each network access device, and send the N second network configuration data packets to the corresponding network access devices. The network access devices can then perform network configuration based on the second network configuration data packets. The second data encapsulation template here is the template used by the network access device for data encapsulation processing. That is, the second network configuration data packet is a data packet that the network access device can recognize. In other words, the network control device converts the first network configuration data packet sent by the cloud server into a second network configuration data packet that each network access device can recognize. This masks the differences between the various network access devices, enabling unified access to the cloud server for all network access devices. In other words, the network control device achieves interconnection and interoperability between the cloud server and multiple diverse network access devices. The cloud server is responsible for managing all network access devices in the target location, enabling unified management of network access point devices within the target location, improving management efficiency, and reducing network access device operation and maintenance costs.
[0170] Please see Figure 13 This is a schematic diagram of the structure of a computer device provided in an embodiment of this application. Figure 13As shown, the computer device 1000 may include a processor 1001, a network interface 1004, and a memory 1005. Furthermore, the computer device 1000 may also include a user interface 1003 and at least one communication bus 1002. The communication bus 1002 is used to enable communication between these components. The user interface 1003 may include a display screen and a keyboard; optionally, the user interface 1003 may also include a standard wired interface or a wireless interface. The network interface 1004 may optionally include a standard wired interface or a wireless interface (such as a Wi-Fi interface). The memory 1005 may be high-speed RAM or non-volatile memory, such as at least one disk storage device. Optionally, the memory 1005 may also be at least one storage device located remotely from the processor 1001. Figure 13 As shown, the memory 1005, which is a computer-readable storage medium, may include an operating system, a network communication module, a user interface module, and a device control application.
[0171] exist Figure 13 In the computer device 1000 shown, the network interface 1004 provides network communication functionality; the user interface 1003 is mainly used to provide an input interface; and the processor 1001 can be used to call the device control application stored in the memory 1005 to achieve:
[0172] Receive a first network configuration data packet sent by a cloud server; the first network configuration data packet is obtained by the cloud server encapsulating the target network configuration parameters of N network access devices according to a first data encapsulation template matching the cloud server, where the N network access devices belong to target locations associated with the network control device; N is a positive integer greater than 1;
[0173] The first network configuration data packet is parsed to obtain the target network configuration parameters of N network access devices;
[0174] The target network configuration parameters are encapsulated according to the second data encapsulation templates corresponding to the N network access devices to obtain the second network configuration data packets corresponding to the N network access devices; at least two of the N network access devices have different second data encapsulation templates.
[0175] N second network configuration data packets are sent to the corresponding network access devices respectively. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets.
[0176] It should be understood that the computer device 1000 described in the embodiments of this application can execute the foregoing text. Figure 3 or Figure 5 The description of the network configuration method in the corresponding embodiments can also be executed as described above. Figure 11 and Figure 12 The description of the network configuration device in the corresponding embodiments will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated.
[0177] Furthermore, it should be noted that this application embodiment also provides a computer-readable storage medium, which stores a computer program executed by the aforementioned network configuration device. The computer program includes program instructions, and when the processor executes the program instructions, it can execute the aforementioned... Figure 5 and the preceding text Figure 3 The network configuration method described in the corresponding embodiments will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated. For technical details not disclosed in the computer-readable storage medium embodiments related to this application, please refer to the description of the method embodiments of this application.
[0178] As an example, the above program instructions can be deployed and executed on a computer device, or deployed and executed on at least two computer devices in one location, or executed on at least two computer devices distributed in at least two locations and interconnected by a communication network. At least two computer devices distributed in at least two locations and interconnected by a communication network can form a blockchain network.
[0179] The aforementioned computer-readable storage medium may be a network configuration device provided in any of the foregoing embodiments or a central storage unit of the aforementioned computer device, such as a hard disk or central storage of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., provided on the computer device. Furthermore, the computer-readable storage medium may include both the central storage unit and external storage devices of the computer device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.
[0180] The terms "first," "second," etc., in the specification, claims, and drawings of this application are used to distinguish content in different media, rather than to describe a specific order. Furthermore, the term "comprising," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, apparatus, product, or device that includes a series of steps or units is not limited to the listed steps or modules, but may optionally include steps or modules not listed, or may optionally include other step units inherent to these processes, methods, apparatuses, products, or devices.
[0181] This application also provides a computer program product, including a computer program / instructions, which, when executed by a processor, implement the foregoing description. Figure 3 and Figure 5 The network configuration method described in the corresponding embodiments will not be repeated here. Furthermore, the beneficial effects of using the same method will also not be repeated. For technical details not disclosed in the embodiments of the computer program product involved in this application, please refer to the description of the method embodiments of this application.
[0182] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this application.
[0183] The methods and related apparatus provided in this application are described with reference to the method flowcharts and / or structural diagrams provided in this application. Specifically, each block of the method flowchart and / or structural diagram, as well as combinations of blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable network-connected device to create a machine, such that the instructions, which execute via the processor of the computer or other programmable network-connected device, generate instructions for implementing the process. Figure 1 A schematic diagram of one or more processes and / or structures. Figure 1 The computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable network-connected device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 A schematic diagram of one or more processes and / or structures. Figure 1 The functions specified in one or more boxes. These computer program instructions may also be loaded onto a computer or other programmable network-connected device to cause a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 A process or multiple processes and / or structures illustrate the steps of the functions specified in one or more boxes.
[0184] The above-disclosed embodiments are merely preferred embodiments of this application and should not be construed as limiting the scope of this application. Therefore, any equivalent variations made in accordance with the claims of this application shall still fall within the scope of this application.
Claims
1. A network configuration method, characterized in that, include: The network control device receives the first network configuration data packet sent by the cloud server; The first network configuration data packet is obtained by the cloud server encapsulating the target network configuration parameters of N network access devices according to a first data encapsulation template matching the cloud server. The N network access devices belong to target locations associated with the network control device; N is a positive integer greater than 1. The first network configuration data packet is parsed to obtain the target network configuration parameters of N network access devices; The target network configuration parameters are encapsulated according to the second data encapsulation templates corresponding to the N network access devices to obtain the second network configuration data packets corresponding to the N network access devices; at least two of the N network access devices have different second data encapsulation templates. N second network configuration data packets are sent to the corresponding network access devices respectively. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets.
2. The method as described in claim 1, characterized in that, The N network access devices include network access device Pi, where i is a positive integer less than or equal to N; the network access device Pi corresponds to the second data encapsulation template Qi; The step of encapsulating the target network configuration parameters according to the second data encapsulation template corresponding to each of the N network access devices to obtain the second network configuration data packets corresponding to each of the N network access devices includes: The target network configuration parameters are encapsulated according to the second data encapsulation format in the second data encapsulation template Qi to obtain a second data packet; The second data packet is encrypted according to the second data encryption method in the second data encapsulation template Qi to obtain the second network configuration data packet corresponding to the network access device Pi.
3. The method as described in claim 2, characterized in that, The method further includes: According to the first data encapsulation template, the current network configuration parameters of the network access device Pi are encapsulated to obtain a third network configuration data packet; The third network configuration data packet is sent to the cloud server. The third network configuration data packet is used to instruct the cloud server to generate a network configuration difference data packet. The network configuration difference data packet is obtained by encapsulating the network configuration difference parameters of the network access device Pi according to the first data encapsulation template. The network configuration difference parameters are obtained based on the third network configuration data packet and the local network configuration parameters of the network access device Pi stored in the cloud server. The network configuration difference data packet sent by the cloud server is received, and the network configuration parameters of the network access device Pi are updated according to the network configuration difference data packet.
4. The method as described in claim 3, characterized in that, The step of encapsulating the current network configuration parameters of the network access device Pi according to the first data encapsulation template to obtain a third network configuration data packet includes: The first data encapsulation template is sent to the network access device Pi. The first data encapsulation template is used to instruct the network access device Pi to encapsulate the current network configuration parameters according to the first data encapsulation template to obtain a third network configuration data packet. Receive the third network configuration data packet sent by the network access device Pi.
5. The method as described in claim 3, characterized in that, The step of encapsulating the current network configuration parameters of the network access device Pi according to the first data encapsulation template to obtain a third network configuration data packet includes: The system receives a fourth network configuration data packet sent by the network access device Pi; the fourth network configuration data packet is obtained by encapsulating the current network configuration parameters of the network access device Pi according to the second data encapsulation template Qi. The fourth network configuration data packet is parsed to obtain the current network configuration parameters of the network access device Pi; The current network configuration parameters are encapsulated according to the first data encapsulation format in the first data encapsulation template to obtain a first data packet; The first data packet is encrypted according to the first data encryption method in the first data encapsulation template to obtain the third network configuration data packet.
6. The method as described in claim 2, characterized in that, The target location is the target institution, and the method further includes: Obtain the terminal identifier of the employee terminal to be connected to the network access device Pi; the employee terminal belongs to the target organization; A first key acquisition request carrying the terminal identifier of the employee terminal is generated based on the first data encapsulation template; The first key acquisition request is sent to the cloud server. The first key acquisition request is used to instruct the cloud server to generate an employee key corresponding to the employee terminal. The employee key is encapsulated according to the first data encapsulation template to obtain a first key data packet. The system receives a first key data packet sent by the cloud server; the first key data packet is used to instruct the network control device to establish a network connection between the employee terminal and the network access device Pi.
7. A network configuration method, characterized in that, include: The cloud server obtains the target network configuration parameters of N network access devices; the N network access devices belong to the target locations associated with the network control equipment; N is a positive integer greater than 1; the network control device is connected to the cloud server; The target network configuration parameters are encapsulated according to a first data encapsulation template that matches the cloud server to obtain a first network configuration data packet; The first network configuration data packet is sent to the network control device. The first network configuration data packet is used to instruct the network control device to send N second network configuration data packets to the corresponding network access devices. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets. The N second network configuration data packets are obtained by encapsulating the target network configuration parameters according to the second data encapsulation templates corresponding to the N network access devices. The target network configuration parameters are obtained by parsing the first network configuration data packet. At least two of the N network access devices have different second data encapsulation templates.
8. The method as described in claim 7, characterized in that, The cloud server obtains the target network configuration parameters of N network access devices, including: The cloud server obtains N candidate network configuration parameters for the network access devices from the network application device; Retrieve local network configuration parameters for N network access devices from the local database; Determine the network configuration parameters that change between the candidate network configuration parameters and the local network configuration parameters; The changed network configuration parameters are determined as the target network configuration parameters for N network access devices.
9. The method as described in claim 7 or 8, characterized in that, The method further includes: The system receives a third network configuration data packet sent by the network control device. The third network configuration data packet is obtained by encapsulating the current network configuration parameters of the network access point Pi according to the first data encapsulation template. The network access device Pi belongs to N network access devices, and i is a positive integer less than or equal to N. The third network configuration data packet is parsed to obtain the current network configuration parameters of the network access point Pi; Retrieve the local network configuration parameters of the network access point Pi from the local database; Determine the network configuration difference parameters between the current network configuration parameters and the local network configuration parameters; The network configuration difference parameters are encapsulated according to the first data encapsulation template to obtain a network configuration difference data packet; The network configuration difference data packet is sent to the network control device, and the network configuration difference data packet is used to instruct the network control device to update the network configuration parameters of the network access device Pi.
10. The method as described in claim 9, characterized in that, The target location is the target institution, and the method further includes: The system receives a first key acquisition request sent by the network control device. The first key acquisition request is generated based on the terminal identifier of the employee terminal to be connected to the network access point Pi according to the first data encapsulation template. The employee terminal belongs to the target organization. The first key acquisition request is parsed to obtain the terminal identifier of the employee terminal; Based on the terminal identifier of the employee terminal and the organization identifier of the target organization, generate the employee key corresponding to the employee terminal; The employee key is encapsulated according to the first data encapsulation template to obtain a first key data packet. The first key data packet is sent to the network control device. The first key data packet is used to instruct the network control device to establish a network connection between the employee terminal and the network access device Pi.
11. The method as described in claim 10, characterized in that, The step of generating an employee key corresponding to the employee terminal based on the terminal identifier of the employee terminal and the organization identifier of the target organization includes: Call the function computation engine to obtain the key generation function corresponding to the target organization; The employee key corresponding to the employee terminal is obtained by performing calculations on the terminal identifier and the organization identifier of the employee terminal according to the key generation function.
12. The method as described in claim 11, characterized in that, The method further includes: Receive a second key acquisition request sent by a visitor terminal; the second key acquisition request carries the terminal identifier of the visitor terminal, and the visitor terminal is associated with the employee terminal; According to the key generation function, the terminal identifier of the visitor terminal and the terminal identifier of the employee terminal are calculated to obtain the visitor key corresponding to the visitor terminal; The visitor key is encapsulated according to the first data encapsulation template to obtain the second key data packet; The second key data packet is sent to the network control device, and the second key data packet is used to instruct the network control device to establish a network connection between the guest terminal and the network access device Pi.
13. A network configuration device, characterized in that, include: The receiving module is used to receive the first network configuration data packet sent by the cloud server; The first network configuration data packet is obtained by the cloud server encapsulating the target network configuration parameters of N network access devices according to a first data encapsulation template matching the cloud server, where the N network access devices belong to target locations associated with the network control device; N is a positive integer greater than 1; The parsing module is used to parse the first network configuration data packet to obtain N target network configuration parameters of the network access devices; An encapsulation module is used to encapsulate the target network configuration parameters according to the second data encapsulation templates corresponding to the N network access devices respectively, to obtain the second network configuration data packets corresponding to the N network access devices respectively; at least two of the N network access devices have different second data encapsulation templates. The sending module is used to send N second network configuration data packets to the corresponding network access devices respectively. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets.
14. A network configuration device, characterized in that, include: The acquisition module is used to acquire target network configuration parameters for N network access devices; the N network access devices belong to target locations associated with the network control device; N is a positive integer greater than 1; the network control device is connected to the cloud server; The encapsulation module is used to encapsulate the target network configuration parameters according to a first data encapsulation template that matches the cloud server, so as to obtain a first network configuration data packet; The sending module is used to send the first network configuration data packet to the network control device. The first network configuration data packet is used to instruct the network control device to send N second network configuration data packets to the corresponding network access devices. The second network configuration data packets are used to instruct the network access devices to perform network configuration according to the target network configuration parameters in the second network configuration data packets. The N second network configuration data packets are obtained by encapsulating the target network configuration parameters according to the second data encapsulation templates corresponding to the N network access devices. The target network configuration parameters are obtained by parsing the first network configuration data packet. At least two of the N network access devices have different second data encapsulation templates.
15. A computer device, characterized in that, include: Processor and memory; The memory is used to store program code, and the processor calls the program code to implement the method as described in any one of claims 1-12.
16. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program including instructions that, when executed by a processor, cause the processor to perform the method as described in any one of claims 1-12.
17. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the method according to any one of claims 1-12.