Method for device automatic network access, storage medium and electronic device

CN117714278BActive Publication Date: 2026-09-15BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311809231.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-26
Publication Date
2026-09-15
Estimated Expiration
2043-12-26

AI Technical Summary

Technical Problem

[0004]本申请实施例的目的是提供一种设备自动化入网的方法、存储介质及电子设备,用以解决现有技术中由于设备入网困难而导致人工成本高的问题

Benefits of technology

[0025] A fourth aspect of this application provides an electronic device, comprising:

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117714278B_ABST
    Figure CN117714278B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a method for automatic network access of a device, a storage medium and an electronic device. The method comprises: after the to-be-networked device is powered on, obtaining geographical location information of the to-be-networked device; determining a virtual extended local area network address of the to-be-networked device and a public network address of a target network service providing point according to the geographical location information; after the virtual extended local area network address is issued to the to-be-networked device, determining first configuration information of the to-be-networked device and second configuration information of the target network service providing point based on the virtual extended local area network address and the public network address; issuing the first configuration information and the second configuration information to the to-be-networked device and the target network service providing point, respectively, to establish a tunnel between the to-be-networked device and the target network service providing point, so that the to-be-networked device completes automatic network access through the tunnel, realizes plug and play of the to-be-networked device, and reduces the manual cost required for device network access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of device communication technology, and specifically to a method, storage medium, and electronic device for automated device network access. Background Technology

[0002] Currently, for businesses with many branches and a wide geographical coverage, such as vending machines, cinema ticket machines, and branch stores, most of them require the deployment of equipment in batches to meet the corresponding business needs.

[0003] However, when deploying devices in bulk, maintenance personnel need to go to the site to configure the network and integrate the devices into the network. If the geographical locations of the devices to be deployed are relatively scattered and remote, it is difficult for maintenance personnel to reach the site to configure the network, or the maintenance personnel who do arrive at the site do not understand network configuration, making technical support difficult to provide. This not only increases the manpower costs required for deploying the devices, but the devices may also be unable to connect to the network, making it difficult for the corresponding services to operate normally. Summary of the Invention

[0004] The purpose of this application is to provide a method, storage medium, and electronic device for automated device network access, in order to solve the problem of high labor costs caused by difficulties in device network access in the prior art.

[0005] To achieve the above objectives, the first aspect of this application provides a method for automated network access of devices, applied at the device controller end, comprising:

[0006] After the device to be connected to the network is powered on, obtain the geographical location information of the device.

[0007] Determine the virtual extended LAN address of the device to be connected to the network and the public network address of the target network service provider based on the geographical location information;

[0008] After the virtual extended LAN address is sent to the device to be connected to the network, the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider are determined based on the virtual extended LAN address and the public network address.

[0009] The first configuration information and the second configuration information are sent to the device to be connected to the network and the target network service provider, respectively, to establish a tunnel between the device to be connected to the network and the target network service provider, so that the device to be connected to the network can complete the automatic network access through the tunnel.

[0010] In this embodiment, determining the virtual extended LAN address of the device to be connected to the network and the public network address of the target network service provider based on geographical location information includes: obtaining a first address database and a second address database, wherein the first address database includes multiple preset regions and preset virtual extended LAN addresses for each preset region, and the second address database includes preset geographical location information and corresponding preset public network addresses for multiple preset network service providers; matching the preset regions corresponding to the geographical location information from the first address database; determining the virtual extended LAN address based on the preset virtual extended LAN address corresponding to the matched preset region; and determining the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database.

[0011] In this embodiment of the application, determining the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database includes: determining the connection distance between the device to be connected to the network and each preset network service provider based on the geographical location information and the preset geographical location information of each preset network service provider; selecting the minimum connection distance from all connection distances and selecting the preset network service provider corresponding to the minimum connection distance from the second address database; determining the selected preset network service provider as the target network service provider and determining the preset public network address of the selected preset network service provider as the public network address.

[0012] In this embodiment of the application, the first configuration information includes the local subnet and the peer address, and the second configuration information includes the peer subnet and the local address. Determining the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider based on the virtual extended LAN address and the public network address includes: determining that the local subnet is a virtual extended LAN address and determining that the peer address is a public network address; determining that the peer subnet is a virtual extended LAN address and determining that the local address is a public network address.

[0013] The second aspect of this application provides another method for automated network access of devices, including:

[0014] After powering on, the device to be connected to the network sends its geographical location information to the device controller.

[0015] The device controller determines the virtual extended LAN address of the device to be connected to the network and the public network address of the target network service provider based on the geographical location information.

[0016] The device controller sends the virtual extended LAN address to the device to be connected to the network;

[0017] The device controller determines the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider based on the virtual extended LAN address and the public network address.

[0018] The device controller sends the first configuration information and the second configuration information to the device to be connected to the network and the target network service provider, respectively, in order to establish a tunnel between the device to be connected to the network and the target network service provider.

[0019] Devices waiting to be connected to the network complete the automated network access process through the tunnel.

[0020] In this embodiment, the process by which the device controller determines the virtual extended LAN address of the device to be connected to the network and the public network address of the target network service provider based on geographical location information includes: the device controller acquiring a first address database and a second address database, wherein the first address database includes multiple preset regions and preset virtual extended LAN addresses for each preset region, and the second address database includes preset geographical location information and corresponding preset public network addresses for multiple preset network service providers; the device controller matching the preset region corresponding to the geographical location information from the first address database; the device controller determining the virtual extended LAN address based on the preset virtual extended LAN address corresponding to the matched preset region; and the device controller determining the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database.

[0021] In this embodiment, the process of determining the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database includes: the device controller determining the connection distance between the device to be connected to the network and each preset network service provider based on the geographical location information and the preset geographical location information of each preset network service provider; the device controller selecting the minimum connection distance from all connection distances and selecting the preset network service provider corresponding to the minimum connection distance from the second address database; and the device controller determining the selected preset network service provider as the target network service provider and determining the preset public network address of the selected preset network service provider as the public network address.

[0022] In this embodiment, the automated network access process for a device seeking to join the network via a tunnel includes: the device seeking to join the network receiving a Dynamic Host Configuration Protocol (DHCP) request message sent by any host connected to it, wherein the DHCP request message includes the host's preset address and virtual extended LAN address; upon receiving the DHCP request message from the device seeking to join the network, the target device assigns a service address to the device seeking to join the network; the target device sends a response message to the device seeking to join the network, wherein the response message carries the service address; upon receiving the response message, the device seeking to join the network determines that the device seeking to join the network is interconnected with the target device and determines that the device seeking to join the network has completed automated network access.

[0023] In this embodiment, when the target device receives a Dynamic Host Configuration Protocol (DHCP) request message from a device seeking to join the network, the process of allocating a service address to the device includes: If the device seeking to join the network determines that the DHCP request message matches the tunnel route of any tunnel, it encrypts the DHCP request message into an Encapsulated Security Payload Protocol (EPP) message; the device seeking to join the network sends the EEP message to the target network service provider (NSB); the target NSB decrypts the EEP message; if the target NSB determines that the decrypted message is a DHCP request message, it re-encrypts the DHCP request message; the target NSB sends the re-encrypted DHCP request message to the target device; the target device decrypts the re-encrypted DHCP request message again; and if the target device determines that the decrypted message is a DHCP request message, it allocates a service address to the device seeking to join the network.

[0024] A third aspect of this application provides a machine-readable storage medium storing instructions that, when executed by a processor, configure the processor to perform the aforementioned method for automated network access of a device.

[0025] A fourth aspect of this application provides an electronic device, comprising:

[0026] The memory is configured to store instructions; and

[0027] The processor is configured to retrieve instructions from memory and, when executing the instructions, to implement the aforementioned method for automated device network access.

[0028] The above technical solution distributes configuration information to the device and the target network service provider based on the geographical location of the device to be connected to the network, thereby establishing a tunnel between the device and the target network service provider. This allows the device to automatically connect to the network through the tunnel, enabling plug-and-play functionality and reducing the manual costs required for network access.

[0029] Other features and advantages of the embodiments of this application will be described in detail in the following detailed description section. Attached Figure Description

[0030] The accompanying drawings are provided to further illustrate the embodiments of this application and form part of the specification. They are used together with the following detailed description to explain the embodiments of this application, but do not constitute a limitation on the embodiments of this application. In the drawings:

[0031] Figure 1 This schematically illustrates a first flowchart of a method for automated network access of a device according to an embodiment of this application;

[0032] Figure 2 This illustration schematically shows a second process diagram of a method for automated network access of devices according to an embodiment of this application;

[0033] Figure 3 This illustration schematically shows a third process diagram of a method for automated network access of devices according to an embodiment of this application;

[0034] Figure 4 This illustration schematically shows an application environment diagram of the method for automated network access of devices according to an embodiment of this application;

[0035] Figure 5 A timing diagram illustrating a method for automated network access of a device according to an embodiment of this application is shown schematically.

[0036] Figure 6 The diagram illustrates the internal structure of a computer device according to an embodiment of this application. Detailed Implementation

[0037] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for illustration and explanation of the embodiments of this application and are not intended to limit the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0038] It should be noted that if the embodiments of this application involve directional indicators (such as up, down, left, right, front, back, etc.), the directional indicators are only used to explain the relative positional relationship and movement of the components in a certain specific posture (as shown in the figure). If the specific posture changes, the directional indicators will also change accordingly.

[0039] Furthermore, if the embodiments of this application involve descriptions such as "first" or "second," these descriptions are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, features defined with "first" or "second" may explicitly or implicitly include at least one of those features. Additionally, the technical solutions of various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. If the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed in this application.

[0040] Figure 1A schematic flowchart illustrating a method for automated network access of devices according to an embodiment of this application is shown. Figure 1 As shown in one embodiment of this application, a method for automated network access of a device is provided. This embodiment mainly illustrates the application of this method to the device controller, including the following steps:

[0041] Step 101: After the device to be connected to the network is powered on, obtain the geographical location information of the device.

[0042] After the device to be connected to the network is powered on, the processor can obtain the geographical location information of the device. For example, the device to be connected to the network can be an automatic vending machine or a cinema ticketing machine. Specifically, after the device to be connected to the network is powered on, its geographical location information can be obtained through GSS (Geostationary Geodesic Satellite), and it can also obtain the zero configuration file sent by the user. Based on the zero configuration file, zero-configuration online can be performed, and the geographical location information is sent to the processor.

[0043] Step 102: Determine the virtual extended LAN address of the device to be connected to the network and the public network address of the target network service provider based on the geographical location information.

[0044] The processor can determine the Virtual Extended LAN (VxLAN) address of the device to be connected to the network and the public network address of the target network service provider (POP) based on geographical location information. Here, the VxLAN address refers to the address of the virtual extended LAN, the target POP is the network service provider closest to the device, and the public network address is a public IP address.

[0045] In this embodiment, determining the virtual extended LAN address of the device to be connected to the network and the public network address of the target network service provider based on geographical location information includes: obtaining a first address database and a second address database, wherein the first address database includes multiple preset regions and preset virtual extended LAN addresses for each preset region, and the second address database includes preset geographical location information and corresponding preset public network addresses for multiple preset network service providers; matching the preset regions corresponding to the geographical location information from the first address database; determining the virtual extended LAN address based on the preset virtual extended LAN address corresponding to the matched preset region; and determining the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database.

[0046] The processor can access a first address database and a second address database. The first address database is used to maintain the VxLAN address planning for a given region. It includes multiple preset regions and preset virtual extended LAN addresses for each region. The second address database is used to maintain the address database for pop-up points (POPs). It includes preset geographical location information and corresponding preset public network addresses for multiple preset network service providers. Both the first and second address databases can be maintained as needed.

[0047] The processor can match a preset region corresponding to the geographic location information from the first address database. The processor can then determine the virtual extended LAN address of the device to be connected to the network by matching the preset virtual extended LAN address corresponding to the matched preset region. The processor can also determine the public network address of the target network service provider based on the geographic location information and all preset geographic location information in the second address database.

[0048] In this embodiment of the application, determining the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database includes: determining the connection distance between the device to be connected to the network and each preset network service provider based on the geographical location information and the preset geographical location information of each preset network service provider; selecting the minimum connection distance from all connection distances and selecting the preset network service provider corresponding to the minimum connection distance from the second address database; determining the selected preset network service provider as the target network service provider and determining the preset public network address of the selected preset network service provider as the public network address.

[0049] The processor can determine the connection distance between the device to be connected to the network and each preset network service provider based on the geographical location information and the preset geographical location information of each preset network service provider. The processor can select the minimum connection distance from all connection distances and select the preset network service provider corresponding to the minimum connection distance from the second address library. The processor can determine the selected preset network service provider as the target network service provider and determine the preset public network address of the selected preset network service provider as the public network address.

[0050] Step 103: After the virtual extended LAN address is sent to the device to be connected to the network, the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider are determined based on the virtual extended LAN address and the public network address.

[0051] After the processor sends the virtual extended LAN address to the device to be connected to the network, the processor can determine the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider based on the virtual extended LAN address and the public network address.

[0052] In this embodiment of the application, the first configuration information includes the local subnet and the peer address, and the second configuration information includes the peer subnet and the local address. Determining the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider based on the virtual extended LAN address and the public network address includes: determining that the local subnet is a virtual extended LAN address and determining that the peer address is a public network address; determining that the peer subnet is a virtual extended LAN address and determining that the local address is a public network address.

[0053] The first configuration information includes the local subnet and peer address of the device to be connected to the network, and the second configuration information includes the peer subnet and local address of the target network service provider. The processor can determine that the local subnet of the device to be connected to the network is a Virtual Extended Local Area Network (VLAN) address, and that the peer address of the device to be connected to the network is a public network address. The processor can also determine that the peer subnet of the target network service provider is a VLAN address, and that the local address of the target network service provider is a public network address.

[0054] In one embodiment, the first configuration information may further include the peer subnet and local address of the device to be connected to the network, and the second configuration information may further include the local subnet and peer address of the target service provider. Specifically, both the peer subnet of the device to be connected to the network and the local subnet of the target service provider can be a first preset address, for example, 0.0.0.0 / 0, to facilitate subsequent communication with other devices or headquarters. The local address of the device to be connected to the network can be an IPsec virtual interface; for example, the bound physical port can be ADSL, LTE, or a physical port, depending on the actual situation. The peer address of the target service provider can be a second preset address, for example, 0.0.0.0, which may be obtained through ADSL dial-up or through LTE access, etc.

[0055] Step 104: Send the first configuration information and the second configuration information to the device to be connected to the network and the target network service provider respectively, so as to establish a tunnel between the device to be connected to the network and the target network service provider, so that the device to be connected to the network can complete the automatic network access through the tunnel.

[0056] The processor can send the first configuration information and the second configuration information to the device seeking network access and the target network service provider, respectively. After receiving the first configuration information, and after receiving the second configuration information, the target network service provider can establish a tunnel and negotiate the tunnel connection. If the first and second configuration information match and are correct, the tunnel negotiation is considered successful. At this point, both the device seeking network access and the target network service provider can generate corresponding tunnel routes, and the target network service provider can advertise these routes. Network interconnection is then established between the device seeking network access and the target network service provider. Afterward, the device seeking access can request a service address from the target device to complete automated network access.

[0057] The above technical solution distributes configuration information to the device and the target network service provider based on the geographical location of the device to be connected to the network, thereby establishing a tunnel between the device and the target network service provider. This allows the device to automatically connect to the network through the tunnel, enabling plug-and-play functionality and reducing the manual costs required for network access.

[0058] Figure 2 This illustration schematically shows another flow diagram of a method for automated network access of devices according to an embodiment of this application. For example... Figure 2 As shown in one embodiment of this application, a method for automated network access of a device is provided, comprising the following steps:

[0059] Step 201: After powering on, the device to be connected to the network sends its geographical location information to the device controller.

[0060] After a device is powered on, it can obtain its geographical location information and send it to the device controller. The device controller can then obtain the geographical location information of the device. For example, a device could be a vending machine or a cinema ticketing machine. Specifically, after the device is powered on, it can obtain its geographical location information via GSS (Geostationary Geodesic Satellite), and it can also obtain a zero-configuration profile sent by the user. Based on the zero-configuration profile, it can perform zero-configuration deployment and send the geographical location information to the device controller.

[0061] Step 202: The device controller determines the virtual extended LAN address of the device to be connected to the network and the public network address of the target network service provider based on the geographical location information.

[0062] The device controller can determine the Virtual Extended LAN (VxLAN) address of the device to be connected to the network and the public network address of the target network service provider (POP) based on geographical location information. Here, the VxLAN address refers to the VPN address, the target POP is the network service provider closest to the device, and the public network address is a public IP address.

[0063] In this embodiment, the process by which the device controller determines the virtual extended LAN address of the device to be connected to the network and the public network address of the target network service provider based on geographical location information includes: the device controller acquiring a first address database and a second address database, wherein the first address database includes multiple preset regions and preset virtual extended LAN addresses for each preset region, and the second address database includes preset geographical location information and corresponding preset public network addresses for multiple preset network service providers; the device controller matching the preset region corresponding to the geographical location information from the first address database; the device controller determining the virtual extended LAN address based on the preset virtual extended LAN address corresponding to the matched preset region; and the device controller determining the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database.

[0064] The device controller can access a first address database and a second address database. The first address database is used to maintain the VxLAN address planning for a given region. It includes multiple preset regions and preset virtual extended LAN addresses for each region. The second address database is used to maintain the address database for pop-up points (POPs). It includes preset geographical location information and corresponding preset public network addresses for multiple preset network service providers. Both the first and second address databases can be maintained as needed.

[0065] The device controller can match a preset region corresponding to the geographical location information from the first address database. The device controller can then determine the virtual extended LAN address of the device to be connected to the network based on the preset virtual extended LAN address corresponding to the matched preset region. The device controller can also determine the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database.

[0066] In this embodiment, the process of determining the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database includes: the device controller determining the connection distance between the device to be connected to the network and each preset network service provider based on the geographical location information and the preset geographical location information of each preset network service provider; the device controller selecting the minimum connection distance from all connection distances and selecting the preset network service provider corresponding to the minimum connection distance from the second address database; and the device controller determining the selected preset network service provider as the target network service provider and determining the preset public network address of the selected preset network service provider as the public network address.

[0067] The device controller can determine the connection distance between the device to be connected to the network and each preset network service provider based on the geographical location information and the preset geographical location information of each preset network service provider. The device controller can select the minimum connection distance from all possible connection distances and choose the preset network service provider corresponding to the minimum connection distance from a second address database. The device controller can then designate the selected preset network service provider as the target network service provider and determine the preset public network address of the selected preset network service provider as its public network address.

[0068] Step 203: The device controller sends the virtual extended LAN address to the device to be connected to the network.

[0069] Step 204: The device controller determines the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider based on the virtual extended LAN address and the public network address.

[0070] After the device controller sends the virtual extended LAN address to the device to be connected to the network, the device controller can determine the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider based on the virtual extended LAN address and the public network address.

[0071] In this embodiment, the first configuration information includes the local subnet and the peer address, and the second configuration information includes the peer subnet and the local address. The device controller determines the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider based on the virtual extended LAN address and the public network address. The determination of the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider based on the virtual extended LAN address and the public network address includes: the device controller determines that the local subnet is a virtual extended LAN address and determines that the peer address is a public network address; the device controller determines that the peer subnet is a virtual extended LAN address and determines that the local address is a public network address.

[0072] The first configuration information includes the local subnet and peer address of the device to be connected to the network. The second configuration information includes the peer subnet and local address of the target network service provider. The device controller can determine that the local subnet of the device to be connected to the network is a Virtual Extended LAN address and that the peer address of the device to be connected to the network is a public network address. The device controller can also determine that the peer subnet of the target network service provider is a Virtual Extended LAN address and that the local address of the target network service provider is a public network address.

[0073] In one embodiment, the first configuration information may further include the peer subnet and local address of the device to be connected to the network, and the second configuration information may further include the local subnet and peer address of the target service provider. Specifically, both the peer subnet of the device to be connected to the network and the local subnet of the target service provider can be a first preset address, for example, 0.0.0.0 / 0, to facilitate subsequent communication with other devices or headquarters. The local address of the device to be connected to the network can be an IPsec virtual interface; for example, the bound physical port can be ADSL, LTE, or a physical port, depending on the actual situation. The peer address of the target service provider can be a second preset address, for example, 0.0.0.0, which may be obtained through ADSL dial-up or through LTE access, etc.

[0074] Step 205: The device controller sends the first configuration information and the second configuration information to the device to be connected to the network and the target network service provider, respectively, to establish a tunnel between the device to be connected to the network and the target network service provider.

[0075] Step 206: The device to be connected to the network completes the automated network access process through the tunnel.

[0076] The device controller can send the first configuration information and the second configuration information to the device seeking network access and the target network service provider, respectively. After receiving the first configuration information, and after receiving the second configuration information, the target network service provider can establish a tunnel and negotiate the tunnel connection. If the first and second configuration information match and are correct, the tunnel negotiation is considered successful. At this point, both the device seeking network access and the target network service provider can generate corresponding tunnel routes, and the target network service provider can advertise these routes. Network interconnection is then established between the device seeking network access and the target network service provider. Afterward, the device seeking network access can request a service address from the target device to complete automated network access.

[0077] In this embodiment, the automated network access process for a device seeking to join the network via a tunnel includes: the device seeking to join the network receiving a Dynamic Host Configuration Protocol (DHCP) request message sent by any host connected to it, wherein the DHCP request message includes the host's preset address and virtual extended LAN address; upon receiving the DHCP request message from the device seeking to join the network, the target device assigns a service address to the device seeking to join the network; the target device sends a response message to the device seeking to join the network, wherein the response message carries the service address; upon receiving the response message, the device seeking to join the network determines that the device seeking to join the network is interconnected with the target device and determines that the device seeking to join the network has completed automated network access.

[0078] A device seeking to join the network can obtain Dynamic Host Configuration Protocol (DHCP) request messages sent by any host connected to it. These DHCP request messages include the host's default address and Virtual Extended LAN (VLAN) address. The default address is the source address in the DHCP request message, and the VLAN address is the destination address.

[0079] After receiving a Dynamic Host Configuration Protocol (DHCP) request message, the device seeking to join the network can send the message to the target device. The target device can be the DHCP server on the headquarters gateway device. Upon receiving the DHCP request message, the target device can assign a service address to the device seeking to join the network. Then, the target device can send a response message to the device seeking to join the network. This response message carries the service address. Upon receiving the response message, the device seeking to join the network completes automatic network access, at which point the device seeking to join the network and the target device are interconnected.

[0080] In this embodiment, when the target device receives a Dynamic Host Configuration Protocol (DHCP) request message from a device seeking to join the network, the process of allocating a service address to the device includes: If the device seeking to join the network determines that the DHCP request message matches the tunnel route of any tunnel, it encrypts the DHCP request message into an Encapsulated Security Payload Protocol (EPP) message; the device seeking to join the network sends the EEP message to the target network service provider (NSB); the target NSB decrypts the EEP message; if the target NSB determines that the decrypted message is a DHCP request message, it re-encrypts the DHCP request message; the target NSB sends the re-encrypted DHCP request message to the target device; the target device decrypts the re-encrypted DHCP request message again; and if the target device determines that the decrypted message is a DHCP request message, it allocates a service address to the device seeking to join the network.

[0081] When a device seeking network access receives a Dynamic Host Configuration Protocol (DMP) request message, it can determine whether the DMP request message matches the tunnel route of any tunnel. If the DMP request message matches the tunnel route of any tunnel, meaning the DMP request message hits a tunnel, it can encrypt the DMP request message into an Encapsulated Security Payload Protocol (ESP) message. The Encapsulated Security Payload Protocol (ESP) message refers to the ESP message. The device seeking network access can then send the encrypted DMP request message (i.e., the Encapsulated Security Payload Protocol message) to the target network service provider.

[0082] The target network service provider (ISP) decrypts the Encapsulated Security Payload Protocol (EPP) message. If the ISP determines that the decrypted message is a Dynamic Host Configuration Protocol (DMP) request message, it can re-encrypt the DMP message. The ISP then sends the re-encrypted DMP message, i.e., the Encapsulated Security Payload Protocol (EPP) message, to the target device. Upon receiving the re-encrypted DMP message, the target device can decrypt it again. If the target device determines that the decrypted message is indeed a DMP message, it can assign a service address to the device seeking network access.

[0083] like Figure 3 As shown, a flowchart illustrating another method for automated network access of devices is provided.

[0084] Before powering on the equipment, the WSC address database and POP location information can be maintained. The WSC address database refers to the address database information on the device controller side. The WSC address database includes the VxLAN address plan for each region. The POP location information includes the geographical location and public IP address of each POP point. After powering on the new equipment, the address information can be registered with the WSC. The address information refers to the geographical location information of the device's location, which can be obtained specifically through GSS positioning.

[0085] WSC can assign VxLAN addresses to new devices based on their geographical location. Then, WSC can assign tunnel configurations to the new devices based on these VxLAN addresses. The tunnel configuration for the new devices includes their local address, peer address, local subnet, and peer subnet. WSC can also assign tunnel configurations to the nearest Point of Presence (POP) based on the assigned VxLAN address. The tunnel configuration for this POP includes its local address, peer address, local subnet, and peer subnet. Specifically, the tunnel configurations for the new devices and the POPs corroborate each other. For example, if the peer address in the new device's tunnel configuration is the same as the local address in the POP's tunnel configuration, both can be the public IP address of the POP. Similarly, if the local subnet in the new device's tunnel configuration is the same as the peer subnet in the POP's tunnel configuration, both can be the assigned VxLAN address.

[0086] After receiving the tunnel configuration, the new device can run the configuration and establish a tunnel with its nearest POP (Point of Presence) to communicate with the headquarters device. The new device can request a service address from the headquarters device's DHCP server. Specifically, the new device can send a DHCP request message to the headquarters device's DHCP server. Upon receiving the DHCP request, the headquarters device's DHCP server can assign a service address to the new device and return that address. After receiving the service address, the new device automatically integrates into the network.

[0087] like Figure 4 The diagram shows an application environment schematic of a method for automated network access of devices.

[0088] OSPF stands for Interior Gateway Protocol. The diagram shows three Points of Presence (POPs). The public IP address of POP in area A is 1.1.1.1. The public IP address of POP in area B is 3.3.3.3. The address database maintains the VxLAN addresses for area A (192.168 / 16) and area B (192.169 / 16).

[0089] Once a device in Area A is powered on, it can obtain its geographical location via GSS and perform zero-configuration online registration, registering with the WSC along with its geographical location information. Based on the geographical location information in the registration information, the WSC assigns it a VxLAN address of 192.168.1.0 / 24 and queries the address database for the nearest POP point. In this example, the nearest POP point has a public IP address of 1.1.1.1, preparing for the subsequent tunnel configuration distribution. The WSC then distributes the tunnel configuration to the device and its nearest POP point. Specifically, the tunnel configuration for the device and its nearest POP point is shown in Table 1 below.

[0090] Table 1. Tunnel configuration of the equipment and its nearest POP point.

[0091]

[0092]

[0093] After receiving the corresponding tunnel configuration, the device and the nearest POP point can negotiate a tunnel. Once the tunnel negotiation is successful, a tunnel route can be generated based on the protected subnet, and OSPF can be enabled. At this point, the nearest POP point can advertise the tunnel route. That is, the network segment 192.168.1.0 / 24 can be advertised on the nearest POP point. Afterwards, the device can send a DHCP request to the headquarters gateway device to obtain a service address. Specifically, the headquarters device enables the DHCP service and plans the address pool. The device sends a DHCP request message outwards. The source address of this request message can be any address of an internal host, and the destination address is VxLAN.

[0094] When a DHCP request message hits the tunnel, the device encrypts it into an ESP message and sends it to the nearest POP (Point of Presence). The nearest POP decrypts the ESP message, recognizes it as a DHCP request message, encrypts it again, and sends it to the headquarters device. Upon receiving the encrypted message from the nearest POP, the headquarters device decrypts it, recognizes it as a DHCP request message, responds, and records the assigned address. The DHCP response message process is the same as the DHCP request message process. At this point, the device obtains a service address and can communicate with the headquarters device, completing network access. If a device in area B is powered on, the process of integrating it into the network is similar to that of a device in area A, and will not be elaborated further here.

[0095] The above solution uses the geographical location information of the device as the unique identifier of the network element, thereby achieving plug-and-play functionality at the edge. The central configuration only needs to maintain relevant regional information. After the WSC and POP points are set up, new devices can automatically join the network without any configuration. The central configuration is unaffected by the edge. The central only needs to maintain the regional-network planning information; any device migration or relocation does not require any changes to the central configuration. The central provides a real-time dynamic display of the network topology. Whether adding, removing, or migrating devices, the network topology can be dynamically displayed based on the activation status of the regional information.

[0096] like Figure 5 The figure shows a timing diagram of a method for automatically connecting devices to the network.

[0097] The WSC (Web Server) can maintain the VxLAN address for each region, as well as the geographical location and corresponding public IP address of each POP (Point of Presence). When a device to be connected to the network powers on, it obtains zero-configuration information and its geographical location information, and generates registration information based on these. The zero-configuration information can be sent by the user. The device to be connected sends the registration information to the WSC. The WSC determines the VxLAN address and the public IP address of the nearest POP based on the geographical location information. The WSC sends the VxLAN address to the device to be connected. Then, the WSC determines the tunnel configuration for the device to be connected and the tunnel configuration for the nearest POP based on the VxLAN address and the public IP address of the nearest POP. Next, it sends the device's tunnel configuration to the device to be connected and the tunnel configuration of the nearest POP to the nearest POP.

[0098] After receiving the corresponding tunnel configuration, the device seeking to join the network and the nearest POP can establish an IPsec tunnel based on the configuration and negotiate the tunnel. Once the tunnel negotiation is successful, both the device seeking to join the network and the nearest POP can determine the tunnel route for the IPsec tunnel based on the VxLAN address. The nearest POP advertises the tunnel route to complete the interconnection with the nearest POP. The device seeking to join the network can obtain DHCP request messages sent by any host connected to it. The DHCP request message includes a source address and a destination address. The source address can be any address of the host, and the destination address is the VxLAN address. If the DHCP request message matches the tunnel route of any IPsec tunnel, the device seeking to join the network encrypts the DHCP request message into an ESP message. The device seeking to join the network then sends the encrypted ESP message to the nearest POP via the matched IPsec tunnel.

[0099] The nearest Point of Presence (POP) decrypts the encrypted ESP message and, if the decrypted message is a DHCP request message, encrypts it again. The nearest POP can then send the re-encrypted DHCP request message, i.e., the ESP message, to the DHCP server. Here, DHCP refers to the DHCP client on the headquarters gateway device. Upon receiving the ESP message, the DHCP server decrypts it. If the decrypted message is a DHCP request message, the DHCP server assigns a service address to the device seeking network access, enabling the device to join the network. Specifically, the DHCP server assigns a service address to the device seeking network access and returns that address to the device, thus enabling it to join the network.

[0100] The above technical solution distributes configuration information to the device and the target network service provider based on the geographical location of the device to be connected to the network, thereby establishing a tunnel between the device and the target network service provider. This allows the device to automatically connect to the network through the tunnel, enabling plug-and-play functionality and reducing the manual costs required for network access.

[0101] Figure 1-3 This is a flowchart illustrating a method for automated device network access in one embodiment. It should be understood that, although... Figure 1-3 The steps in the flowchart are shown sequentially as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise explicitly stated herein, there is no strict order in which these steps are executed, and they can be performed in other orders. Figure 1-3 At least some of the steps in the process may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least some of the sub-steps or stages of other steps.

[0102] In one embodiment, a storage medium is provided on which a program is stored, which, when executed by a processor, implements the above-described method for automated network access of the device.

[0103] In one embodiment, a processor is provided for running a program, wherein the program executes the above-described method for automated network access of the device.

[0104] In one embodiment, an electronic device is provided, characterized in that it comprises:

[0105] The memory is configured to store instructions; and

[0106] The processor is configured to retrieve instructions from memory and, when executing the instructions, to implement the aforementioned method for automated device network access.

[0107] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 6 As shown. The computer device includes a processor A01, a network interface A02, a memory (not shown), and a database (not shown) connected via a system bus. The processor A01 provides computing and control capabilities. The memory includes internal memory A03 and a non-volatile storage medium A04. The non-volatile storage medium A04 stores an operating system B01, a computer program B02, and a database (not shown). The internal memory A03 provides an environment for the operation of the operating system B01 and the computer program B02 stored in the non-volatile storage medium A04. The database stores data such as first configuration information and second configuration information. The network interface A02 communicates with external terminals via a network connection. When the computer program B02 is executed by the processor A01, it implements a method for automated device network access.

[0108] Those skilled in the art will understand that Figure 6 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0109] This application provides a device including a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it performs the following steps: after the device to be connected to the network is powered on, it obtains the geographical location information of the device; it determines the virtual extended local area network address of the device and the public network address of the target network service provider based on the geographical location information; after sending the virtual extended local area network address to the device, it determines the first configuration information of the device and the second configuration information of the target network service provider based on the virtual extended local area network address and the public network address; it sends the first configuration information and the second configuration information to the device and the target network service provider respectively, so as to establish a tunnel between the device and the target network service provider, enabling the device to automatically connect to the network through the tunnel.

[0110] In this embodiment, determining the virtual extended LAN address of the device to be connected to the network and the public network address of the target network service provider based on geographical location information includes: obtaining a first address database and a second address database, wherein the first address database includes multiple preset regions and preset virtual extended LAN addresses for each preset region, and the second address database includes preset geographical location information and corresponding preset public network addresses for multiple preset network service providers; matching the preset regions corresponding to the geographical location information from the first address database; determining the virtual extended LAN address based on the preset virtual extended LAN address corresponding to the matched preset region; and determining the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database.

[0111] In this embodiment of the application, determining the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database includes: determining the connection distance between the device to be connected to the network and each preset network service provider based on the geographical location information and the preset geographical location information of each preset network service provider; selecting the minimum connection distance from all connection distances and selecting the preset network service provider corresponding to the minimum connection distance from the second address database; determining the selected preset network service provider as the target network service provider and determining the preset public network address of the selected preset network service provider as the public network address.

[0112] In this embodiment of the application, the first configuration information includes the local subnet and the peer address, and the second configuration information includes the peer subnet and the local address. Determining the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider based on the virtual extended LAN address and the public network address includes: determining that the local subnet is a virtual extended LAN address and determining that the peer address is a public network address; determining that the peer subnet is a virtual extended LAN address and determining that the local address is a public network address.

[0113] This application also provides a computer program product that, when executed on a data processing device, is adapted to perform the method steps for initializing automated network access for devices.

[0114] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0115] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0116] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0117] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0118] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0119] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0120] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0121] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0122] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A method for device automatic onboarding, the method comprising: Applied to the device controller, the method includes: After the device to be connected to the network is powered on, obtain the geographical location information of the device. The virtual extended local area network address of the device to be connected to the network and the public network address of the target network service provider are determined based on the geographical location information. After the virtual extended LAN address is sent to the device to be connected to the network, the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider are determined based on the virtual extended LAN address and the public network address. The first configuration information and the second configuration information are respectively sent to the device to be connected to the network and the target network service provider, so as to establish a tunnel between the device to be connected to the network and the target network service provider, so that the device to be connected to the network can complete the automatic network access through the tunnel.

2. The method of device auto onboarding according to claim 1, wherein, The step of determining the virtual extended local area network address of the device to be connected to the network and the public network address of the target network service provider based on the geographical location information includes: Obtain a first address database and a second address database, wherein the first address database includes multiple preset regions and preset virtual extended local area network addresses for each preset region, and the second address database includes preset geographical location information and corresponding preset public network addresses for multiple preset network service providers; Match a preset region corresponding to the geographic location information from the first address database; The virtual extended local area network address is determined by the preset virtual extended local area network address corresponding to the matched preset region; The public network address of the target network service provider is determined based on the geographical location information and all preset geographical location information in the second address database.

3. The method for automated network access of equipment according to claim 2, characterized in that, The step of determining the public network address of the target network service provider based on the geographic location information and all preset geographic location information in the second address database includes: The connection distance between the device to be connected to the network and each preset network service provider is determined based on the geographical location information and the preset geographical location information of each preset network service provider. Select the minimum connection distance from all connection distances, and select a preset network service provider point corresponding to the minimum connection distance from the second address database; The selected preset network service provider is determined as the target network service provider, and the preset public network address of the selected preset network service provider is determined as the public network address.

4. The method for automated network access of equipment according to claim 1, characterized in that, The first configuration information includes the local subnet and the peer address, and the second configuration information includes the peer subnet and the local address. The determination of the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider based on the virtual extended LAN address and the public network address includes: The local subnet is determined to be the virtual extended local area network address, and the peer address is determined to be the public network address; The peer subnet is determined to be a Virtual Extended Local Area Network address, and the local address is determined to be the public network address.

5. A method for automated network access of equipment, characterized in that, The method includes: After powering on, the device to be connected to the network sends its geographical location information to the device controller. The device controller determines the virtual extended local area network address of the device to be connected to the network and the public network address of the target network service provider based on the geographical location information. The device controller sends the virtual extended LAN address to the device to be connected to the network. The device controller determines the first configuration information of the device to be connected to the network and the second configuration information of the target network service provider based on the virtual extended LAN address and the public network address. The device controller sends the first configuration information and the second configuration information to the device to be connected to the network and the target network service provider, respectively, to establish a tunnel between the device to be connected to the network and the target network service provider; The device to be connected to the network completes the automated network access process through the tunnel.

6. The method for automated network access of equipment according to claim 5, characterized in that, The device controller determines the virtual extended local area network address of the device to be connected to the network and the public network address of the target network service provider based on the geographical location information, including: The device controller obtains a first address database and a second address database. The first address database includes multiple preset regions and a preset virtual extended local area network address for each preset region. The second address database includes preset geographical location information of multiple preset network service providers and corresponding preset public network addresses. The device controller matches a preset region corresponding to the geographic location information from the first address database. The device controller will determine the virtual extended local area network address by matching the preset virtual extended local area network address corresponding to the preset region. The device controller determines the public network address of the target network service provider based on the geographical location information and all preset geographical location information in the second address database.

7. The method for automated network access of equipment according to claim 6, characterized in that, The device controller determines the public network address of the target network service provider based on the geographic location information and all preset geographic location information in the second address database, including: The device controller determines the connection distance between the device to be connected to the network and each preset network service provider based on the geographic location information and the preset geographic location information of each preset network service provider. The device controller selects the minimum connection distance from all connection distances and selects a preset network service provider point corresponding to the minimum connection distance from the second address database; The device controller determines the selected preset network service provider as the target network service provider, and determines the preset public network address of the selected preset network service provider as the public network address.

8. The method for automated network access of equipment according to claim 5, characterized in that, The automated network access process for the device seeking network access via the tunnel includes: The device to be connected to the network obtains a Dynamic Host Configuration Protocol (DHCP) request message sent by any host connected to the device to be connected to the network. The DHCP request message includes the host's preset address and the Virtual Extended Local Area Network (VLAN) address. Upon receiving the Dynamic Host Configuration Protocol (DHCP) request message sent by the device to be connected to the network, the target device allocates a service address to the device to be connected to the network. The target device sends a response message to the device to be connected to the network, wherein the response message carries the service address; When the device to be connected to the network receives the response message, it is determined that the device to be connected to the network is interconnected with the target device, and it is determined that the device to be connected to the network has completed automatic network access.

9. The method for automated network access of equipment according to claim 8, characterized in that, When the target device receives the Dynamic Host Configuration Protocol (DHCP) request message sent by the device to be connected to the network, the allocation of a service address for the device to be connected to the network includes: When the device to be connected to the network determines that the Dynamic Host Configuration Protocol (DHCP) request message matches the tunnel route of any tunnel, it encrypts the DHCP request message into an Encapsulated Security Payload Protocol (EPP) message. The device to be connected to the network sends the Encapsulated Security Payload Protocol message to the target network service provider. The target network service provides point-to-point decryption of the encapsulated security payload protocol message; If the target network service provider determines that the decrypted message is the Dynamic Host Configuration Protocol (DHCP) request message, the target network service provider will encrypt the DHCP request message again. The target network service provider sends a re-encrypted Dynamic Host Configuration Protocol (DHCP) request message to the target device; The target device decrypts the re-encrypted Dynamic Host Configuration Protocol request message again. If the target device determines that the decrypted message is the Dynamic Host Configuration Protocol (DHCP) request message, the target device will allocate a service address to the device to be connected to the network.

10. A machine-readable storage medium, characterized in that, The machine-readable storage medium stores instructions for causing the machine to perform the method for automated network access of a device according to any one of claims 1 to 9.

11. An electronic device, characterized in that, include: The memory is configured to store instructions; as well as A processor configured to retrieve the instructions from the memory and, when executing the instructions, to implement the method for automated network access of a device according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Communication tunnel construction method and device, equipment and medium

    CN111385180A

  • Method and device for dynamically managing vxlan tunnel based on equipment configuration

    CN111884904A